- Art. 4 GDPR requires private individuals to record extensive, automated processing of particularly sensitive personal data or high-risk profiling.
- Logs must record all accesses (human and machine) with identity, action, date/time and must be kept separately for at least one year.
- FDPIC recommends technical measures: standardized formats, parsing/indexing, time synchronization, access controls, anomaly detection and concept documentation.
The FDPIC has published a new version dated September 15, 2023 (but probably not available until the end of October). Technical recommendations for logging in accordance with Art. 4 GDPR of the FDPIC published.
The recommendations are not legally binding. They appear to be tailored to private individuals; in any case, only private individuals are mentioned, and the file name is “Recommendation on logging according to DSV – Private.pdf”, even though there is no explicit restriction to this effect in the document.
Art. 4 regulates the following in the private sector:
- According to Art. 4 GDPR, private individuals – including contract processors – must keep records if they process particularly sensitive personal data automatically on a large scale or carry out high-risk profiling.
- This does not apply if the preventive measures “ensure data protection”.
- The log must at least record the storage, modification, reading, disclosure, deletion and destruction of the data and “provide information about the identity of the person who carried out the processing, the type, date and time of the processing and, if applicable, the identity […] of the recipient of the data”.
- Logs must be stored separately from the productive system for at least one year.
This provision raises Various questions for example:
- What is “large-scale” processing?
- When is processing “automated”? Is it sufficient that it involves electronically stored data, or is automation also required for the content of the processing procedure?
- Under what conditions can preventive measures guarantee data protection?
- How are the logs stored separately? In particular: Do logs have to be transferred to a separate system in real time when they occur in the productive system, or only at intervals, and if so, at what intervals? May the logs also remain stored in the production system?
- To what extent or under what conditions is the processor obliged to keep logs, since he often does not even know whether the logging requirements are met and whether the preventive measures of the controller ensure data protection within the meaning of Art. 4 para. 1 GDPR? Can or should he therefore oblige the controller to clarify the logging obligation, to obtain an optional logging service if necessary and to provide the processor with corresponding proof for documentation purposes on request?
- Do the logging requirements constitute minimum data security requirements, the intentional violation of which is punishable by law (see here)?
The non-binding recommendations of the FDPIC aim to “provide an overview of what is included in this logging and what must be done for technical compliance with Art. 4 GDPR”. The system-side implementation is not the subject of the recommendations.
The following points should be emphasized:
- „Read” – a process that must be logged except in the case of publicly accessible data – means “access without ‘modification’ ”. It is therefore sufficient “if the access to personal data and the modification of this data are logged”.
- It must all accesses are logged not only human access, but also machine access (e.g. by peripheral systems).
- In accordance with the purpose of logging Log data analyzed on demand become can. This is an understandable concern, but the analysis of log data is not a requirement of the DPA or the GDPR. If log data is not analyzed because the controller is unable or unwilling to do so, this does not in itself constitute a breach of data protection. It can only raise questions about data security. However, the FDPIC’s statements are also to be understood as recommendations and not as an interpretation of the minimum standard.
- It is a “Concept for logging which should “contain a comprehensive and systematic description of the logging policy and procedures”. The FDPIC makes recommendations for the content of such a concept.
In technical aspects the FDPIC recommends the following:
- Standardized logging formats should be used, such as Syslog or the Common Event Format (CEF).
- Logs “should not only be stored, but also read and interpreted (parsing and indexing)”. In doing so, “all information elements should be extracted during reading (ingestion) using pattern extraction and supplemented with information from existing logs where appropriate (correlation). Unused information fields should be omitted in this process in order to save storage space, among other things.”
- The log data should be “checked regularly”.
- Mechanisms for detecting anomalies in the log data should be implemented”.
- Suitable access controls for the log data” are to be implemented.
- Log data must be time-stamped. All systems in the network should also have “reliable and accurate time synchronization”.
- Log data should be enriched with additional information (data enrichment) to enable a better understanding of the events.
- The protocol analysis applications should inform you immediately if anomalies or known security-relevant events occur.
Go to Storage of log data the FDPIC recommends, among other things, keeping log data available for analysis for as long as it is needed to detect and respond to indicators. They can then be moved to a longer-term storage system. Long-term storage – within the limits of what is permitted – is also an “important part of the data protection strategy”. Unfortunately, this leaves open the question of how the separate storage required by law is to be understood in concrete terms.
At the Transitional provision (Art. 46 GDPR), the FDPIC seems to assume that they also for private individuals apply. This is welcome, albeit surprising:
-
Art. 46 para. 1 DPA sets out the transitional provisions for existing applications:
1 For data processing operations that do not fall within the scope of Directive (EU) 2016/6804, Article 4(2) shall apply at the latest three years after the entry into force of this Regulation or at the latest after the end of the life cycle of the system. In the meantime, these processing operations shall be subject to Article 4(1).
With new applications, it is relatively easy to log all activities with personal data right from the start. With existing, older applications, however, it is not always possible to adapt the application itself. However, there are various solutions for these cases.
The implementation of logging depends on many aspects such as the programming language, the runtime environment and the development methods used for the application. Our recommendations are therefore generic in nature, but can support planning for specific applications.
- The FDPIC follows this up with recommendations for dealing with legacy systems. If processing only takes place locally at the user, i.e. without communication with a server, it is sufficient, for example, to log the initial download. If no other logging is already possible and none takes place at network level, the application must be expanded.
Finally, you will find FAQwith, among other things, the following references, which apparently originate from the NCSC:
- Data is “generally publicly available” within the meaning of Art. 4 para. 1 GDPR if it is “widely accessible without authentication, such as an address search via a website”.
- A backup of the log data satisfies the requirement for separate storage in accordance with Art. 2 para. 5 GDPR (see above: the interval is open, but obviously not meant to be real-time – accordingly, a certain risk is accepted that log data may be compromised before the backup in the event of a ransom attack).
- Access in unstructured data repositories (e.g. opening a document in a local drive) does not have to be logged, but only access “in automated data processing systems”. Here, the FDPIC and the NCSC rely on Art. 3 para. 3 lit. a GDPR.
- Not all logs need to be stored in the same place. It is sufficient if they can be merged in a meaningful way.