Take-Aways (AI)
  • For­ward-loo­king plan­ning for IPv6 intro­duc­tion: check pri­va­cy exten­si­ons and inform affec­ted users.
  • Inform users cle­ar­ly about the data pro­tec­tion risks of IPv6.
  • Iden­ti­fi­ca­ti­on must not take place auto­ma­ti­cal­ly via IP address; log­in or expli­cit coo­kie per­mis­si­on required.
  • Acti­va­te pri­va­cy-fri­end­ly set­tings by default; acti­va­te pri­va­cy exten­si­ons in ope­ra­ting systems ex works.

The FDPIC has – alre­a­dy on June 7, 2016, but on the sta­tus of May 2016 -. on the sub­ject of data pro­tec­tion and IPv6. It recom­mends the fol­lo­wing measures:

  • To avo­id data pro­tec­tion pro­blems when intro­du­cing IPv6, it is important to plan ahead (check whe­ther the pri­va­cy exten­si­ons are set in the ope­ra­ting system, inform affec­ted users). This applies to Inter­net use by pri­va­te indi­vi­du­als as well as by com­pa­nies and public administrations.
  • Users must always be infor­med in a com­pre­hen­si­ble man­ner about pos­si­ble data pro­tec­tion risks in con­nec­tion with IPv6.
  • The iden­ti­fi­ca­ti­on of the user must not be done auto­ma­ti­cal­ly through the IP address, but through a log­in or expli­cit per­mis­si­on of cookies
  • Mea­su­res to eli­mi­na­te data pro­tec­tion risks must be able to be taken in a simp­le man­ner. Whe­re­ver pos­si­ble, the pri­va­cy-fri­end­ly set­ting is to be sel­ec­ted as the default (pri­va­cy by default)
  • Pri­va­cy Ext­en­ti­ons are to be imple­men­ted in all com­mon ope­ra­ting systems and acti­va­ted ex works.

By “pri­va­cy exten­si­ons”, the FDPIC means a pro­ce­du­re for anony­mi­zing IP addresses.