# Is CrowdSec acting against european privacy regulations?

**URL:** <https://discourse.crowdsec.net/t/is-crowdsec-acting-against-european-privacy-regulations/1363>\
**Category:** crowdsec\
**Created:** [July 23, 2023, 11:35am UTC](https://discourse.crowdsec.net/t/is-crowdsec-acting-against-european-privacy-regulations/1363 "2023-07-23T11:35:17Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![kameo4242](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/kameo4242/32/649_2.png) [@kameo4242](https://discourse.crowdsec.net/u/kameo4242)\
**Post date:** [August 2, 2023, 3:51pm UTC](https://discourse.crowdsec.net/t/is-crowdsec-acting-against-european-privacy-regulations/1363/4 "2023-08-02T15:51:11Z")

</div>

CrowdSec doesn’t export the log, just some meta: timestamp, attack type, aggressive IP.

An IP is considered a private data as per the GDPR standard if it can help identify the user behind it. Here, the **[GDPR recital 49](https://www.privacy-regulation.eu/en/recital-49-GDPR.htm)** makes it very clear that in the context of defensive tools, it is allowed to handle them.

Nevertheless, after 6 months (instead of 1 year allowed by the GDPR), we “blur” the IP in a range (ie 92.56.43.21 → 92.56.43.0/24) and do the same for the timestamp (is 12:34:56 → 12:00 - 13:00).

The combination of time and IP “blurring” is enough for CrowdSec to render its service, yet it’s a way to protect privacy even further than demanded by the GDPR regulatory framework.

Moreover, if you’re in a stricter regulatory framework even, you can disable IP sharing entirely. As well, remember that

---

_[View the full topic](https://discourse.crowdsec.net/t/is-crowdsec-acting-against-european-privacy-regulations/1363)._
