Is it okay to store user locations? The Next CEO of Stack OverflowAm I allowed to store data of EU citizens as an Indian company?Can companies use user data for App Store marketing screenshots?Are data processors allowed to locally store live customer information for testing GDPRGDPR and logging which user accessed which personal informationUser consent required under GDPRGDPR - Withdrawn user consentGDPR - A mobile App that allows user to store media do we have to option user consent?GDPR - Can I store domain names?GDPR - is user social ID personal dataHow can GDPR affect user generated content?

Why were Madagascar and New Zealand discovered so late?

MAZDA 3 2006 (UK) - poor acceleration then takes off at 3250 revs

Rotate a column

Why is there a PLL in CPU?

Horror movie/show or scene where a horse creature opens its mouth really wide and devours a man in a stables

How do I solve this limit?

How can I open an app using Terminal?

Increase performance creating Mandelbrot set in python

Explicit solution of a Hamiltonian system

Can a caster that cast Polymorph on themselves stop concentrating at any point even if their Int is low?

Any way to transfer all permissions from one role to another?

How can I quit an app using Terminal?

Why is Miller's case titled R (Miller)?

Why do professional authors make "consistency" mistakes? And how to avoid them?

% symbol leads to superlong (forever?) compilations

What does "Its cash flow is deeply negative" mean?

Should I tutor a student who I know has cheated on their homework?

Why does GHC infer a monomorphic type here, even with MonomorphismRestriction disabled?

Why do remote companies require working in the US?

How to safely derail a train during transit?

How to start emacs in "nothing" mode (`fundamental-mode`)

Only print output after finding pattern

Inappropriate reference requests from Journal reviewers

Grabbing quick drinks



Is it okay to store user locations?



The Next CEO of Stack OverflowAm I allowed to store data of EU citizens as an Indian company?Can companies use user data for App Store marketing screenshots?Are data processors allowed to locally store live customer information for testing GDPRGDPR and logging which user accessed which personal informationUser consent required under GDPRGDPR - Withdrawn user consentGDPR - A mobile App that allows user to store media do we have to option user consent?GDPR - Can I store domain names?GDPR - is user social ID personal dataHow can GDPR affect user generated content?










2















I know it might sound quite bad. But here I explain the whole situation.



I'm developing a mobile application based on visiting different places. And I would store in some database (surely AWS) all different locations each user has been in. By location I don't mean I would store coordinates, just all cities in which he/she has checked in (really no coordinate would be stored).



I've been told to be really cautious with this because of recent GDPR law.



But to be honest I know barely nothing about law and its interpretation.



So my question is if I can store this kind of information (as it is not really precise data) and if I should ask for user's explicit consent.



Thanks.










share|improve this question









New contributor




Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
























    2















    I know it might sound quite bad. But here I explain the whole situation.



    I'm developing a mobile application based on visiting different places. And I would store in some database (surely AWS) all different locations each user has been in. By location I don't mean I would store coordinates, just all cities in which he/she has checked in (really no coordinate would be stored).



    I've been told to be really cautious with this because of recent GDPR law.



    But to be honest I know barely nothing about law and its interpretation.



    So my question is if I can store this kind of information (as it is not really precise data) and if I should ask for user's explicit consent.



    Thanks.










    share|improve this question









    New contributor




    Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.






















      2












      2








      2








      I know it might sound quite bad. But here I explain the whole situation.



      I'm developing a mobile application based on visiting different places. And I would store in some database (surely AWS) all different locations each user has been in. By location I don't mean I would store coordinates, just all cities in which he/she has checked in (really no coordinate would be stored).



      I've been told to be really cautious with this because of recent GDPR law.



      But to be honest I know barely nothing about law and its interpretation.



      So my question is if I can store this kind of information (as it is not really precise data) and if I should ask for user's explicit consent.



      Thanks.










      share|improve this question









      New contributor




      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.












      I know it might sound quite bad. But here I explain the whole situation.



      I'm developing a mobile application based on visiting different places. And I would store in some database (surely AWS) all different locations each user has been in. By location I don't mean I would store coordinates, just all cities in which he/she has checked in (really no coordinate would be stored).



      I've been told to be really cautious with this because of recent GDPR law.



      But to be honest I know barely nothing about law and its interpretation.



      So my question is if I can store this kind of information (as it is not really precise data) and if I should ask for user's explicit consent.



      Thanks.







      privacy gdpr data-storage






      share|improve this question









      New contributor




      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.











      share|improve this question









      New contributor




      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      share|improve this question




      share|improve this question








      edited 5 hours ago







      Sergi Mascaró













      New contributor




      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked 5 hours ago









      Sergi MascaróSergi Mascaró

      112




      112




      New contributor




      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      Sergi Mascaró is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.




















          1 Answer
          1






          active

          oldest

          votes


















          5














          It seems clear that this is personal information under the GDPR. If you are subject to the GDPR, you need to have a "lawful basis" to store or process such information. (You are subject to the GDPR if you are locates in the EU, or if your users are. My understanding is that it is location at the time the app is accessed that matters, not a user's citizenship. I am not totally sure about that, however. Unless your app is limited to non-EU access, it it probably safest to comply with the GDPR)



          The degree of precision of your location data will not matter -- a specific city is quite enough to make it personal data if it can be tied to a specific person.



          There are various lawful bases that may be relied on for processing and storage, but explicit consent is probably the one with the widest applicability.



          To use consent as the lawful basis, you must present an OPT-IN decision to the user, and record the results. If the user does nothing, the result must record lack of consent. You may not use a pre-checked consent box or another mechanism that has the effect of an opt-out choice. You should be clear about what information will be stored, and how it will or might be used.



          You will also need to consider how your app will function for those who do not consent, and how to handle requests to withdraw consent.



          So if an app obtains user consent to store location data in a manner that complies with the GDPR, it may store user location data. The consent should make the possible uses of the data clear. If the data is to be shared, the consent should make the possible extent of sharing clear.






          share|improve this answer

























          • So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

            – Sergi Mascaró
            5 hours ago






          • 2





            @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

            – David Siegel
            4 hours ago











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "617"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: false,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          noCode: true, onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );






          Sergi Mascaró is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2flaw.stackexchange.com%2fquestions%2f38533%2fis-it-okay-to-store-user-locations%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          5














          It seems clear that this is personal information under the GDPR. If you are subject to the GDPR, you need to have a "lawful basis" to store or process such information. (You are subject to the GDPR if you are locates in the EU, or if your users are. My understanding is that it is location at the time the app is accessed that matters, not a user's citizenship. I am not totally sure about that, however. Unless your app is limited to non-EU access, it it probably safest to comply with the GDPR)



          The degree of precision of your location data will not matter -- a specific city is quite enough to make it personal data if it can be tied to a specific person.



          There are various lawful bases that may be relied on for processing and storage, but explicit consent is probably the one with the widest applicability.



          To use consent as the lawful basis, you must present an OPT-IN decision to the user, and record the results. If the user does nothing, the result must record lack of consent. You may not use a pre-checked consent box or another mechanism that has the effect of an opt-out choice. You should be clear about what information will be stored, and how it will or might be used.



          You will also need to consider how your app will function for those who do not consent, and how to handle requests to withdraw consent.



          So if an app obtains user consent to store location data in a manner that complies with the GDPR, it may store user location data. The consent should make the possible uses of the data clear. If the data is to be shared, the consent should make the possible extent of sharing clear.






          share|improve this answer

























          • So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

            – Sergi Mascaró
            5 hours ago






          • 2





            @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

            – David Siegel
            4 hours ago















          5














          It seems clear that this is personal information under the GDPR. If you are subject to the GDPR, you need to have a "lawful basis" to store or process such information. (You are subject to the GDPR if you are locates in the EU, or if your users are. My understanding is that it is location at the time the app is accessed that matters, not a user's citizenship. I am not totally sure about that, however. Unless your app is limited to non-EU access, it it probably safest to comply with the GDPR)



          The degree of precision of your location data will not matter -- a specific city is quite enough to make it personal data if it can be tied to a specific person.



          There are various lawful bases that may be relied on for processing and storage, but explicit consent is probably the one with the widest applicability.



          To use consent as the lawful basis, you must present an OPT-IN decision to the user, and record the results. If the user does nothing, the result must record lack of consent. You may not use a pre-checked consent box or another mechanism that has the effect of an opt-out choice. You should be clear about what information will be stored, and how it will or might be used.



          You will also need to consider how your app will function for those who do not consent, and how to handle requests to withdraw consent.



          So if an app obtains user consent to store location data in a manner that complies with the GDPR, it may store user location data. The consent should make the possible uses of the data clear. If the data is to be shared, the consent should make the possible extent of sharing clear.






          share|improve this answer

























          • So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

            – Sergi Mascaró
            5 hours ago






          • 2





            @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

            – David Siegel
            4 hours ago













          5












          5








          5







          It seems clear that this is personal information under the GDPR. If you are subject to the GDPR, you need to have a "lawful basis" to store or process such information. (You are subject to the GDPR if you are locates in the EU, or if your users are. My understanding is that it is location at the time the app is accessed that matters, not a user's citizenship. I am not totally sure about that, however. Unless your app is limited to non-EU access, it it probably safest to comply with the GDPR)



          The degree of precision of your location data will not matter -- a specific city is quite enough to make it personal data if it can be tied to a specific person.



          There are various lawful bases that may be relied on for processing and storage, but explicit consent is probably the one with the widest applicability.



          To use consent as the lawful basis, you must present an OPT-IN decision to the user, and record the results. If the user does nothing, the result must record lack of consent. You may not use a pre-checked consent box or another mechanism that has the effect of an opt-out choice. You should be clear about what information will be stored, and how it will or might be used.



          You will also need to consider how your app will function for those who do not consent, and how to handle requests to withdraw consent.



          So if an app obtains user consent to store location data in a manner that complies with the GDPR, it may store user location data. The consent should make the possible uses of the data clear. If the data is to be shared, the consent should make the possible extent of sharing clear.






          share|improve this answer















          It seems clear that this is personal information under the GDPR. If you are subject to the GDPR, you need to have a "lawful basis" to store or process such information. (You are subject to the GDPR if you are locates in the EU, or if your users are. My understanding is that it is location at the time the app is accessed that matters, not a user's citizenship. I am not totally sure about that, however. Unless your app is limited to non-EU access, it it probably safest to comply with the GDPR)



          The degree of precision of your location data will not matter -- a specific city is quite enough to make it personal data if it can be tied to a specific person.



          There are various lawful bases that may be relied on for processing and storage, but explicit consent is probably the one with the widest applicability.



          To use consent as the lawful basis, you must present an OPT-IN decision to the user, and record the results. If the user does nothing, the result must record lack of consent. You may not use a pre-checked consent box or another mechanism that has the effect of an opt-out choice. You should be clear about what information will be stored, and how it will or might be used.



          You will also need to consider how your app will function for those who do not consent, and how to handle requests to withdraw consent.



          So if an app obtains user consent to store location data in a manner that complies with the GDPR, it may store user location data. The consent should make the possible uses of the data clear. If the data is to be shared, the consent should make the possible extent of sharing clear.







          share|improve this answer














          share|improve this answer



          share|improve this answer








          edited 4 hours ago

























          answered 5 hours ago









          David SiegelDavid Siegel

          15.1k3159




          15.1k3159












          • So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

            – Sergi Mascaró
            5 hours ago






          • 2





            @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

            – David Siegel
            4 hours ago

















          • So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

            – Sergi Mascaró
            5 hours ago






          • 2





            @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

            – David Siegel
            4 hours ago
















          So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

          – Sergi Mascaró
          5 hours ago





          So, to make things clear as water, if the user gives consent I can store his/her locations, right? And I guess I should also let them revoke the consent given and erase all their data. Thanks! (After this response I'll accept your answer)

          – Sergi Mascaró
          5 hours ago




          2




          2





          @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

          – David Siegel
          4 hours ago





          @Sergi Mascaró Right. See my edit above. There can be valid reasons to retain data even if consent is revoked under the GDPR, but if you don't need to retain it, allowing deletion is probably simplest. Otherwise you wiull have to determine if some other lawful basis applies

          – David Siegel
          4 hours ago










          Sergi Mascaró is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          Sergi Mascaró is a new contributor. Be nice, and check out our Code of Conduct.












          Sergi Mascaró is a new contributor. Be nice, and check out our Code of Conduct.











          Sergi Mascaró is a new contributor. Be nice, and check out our Code of Conduct.














          Thanks for contributing an answer to Law Stack Exchange!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2flaw.stackexchange.com%2fquestions%2f38533%2fis-it-okay-to-store-user-locations%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Андора Зьмест Гісторыя | Палітыка | Адміністрацыйны падзел | Геаграфія | Эканоміка | Дэмаграфія | Крыніцы | Вонкавыя спасылкі | Навігацыйнае мэню"CIA World Factbook entry: Andorra"."Andorra 2008, Departament d'estadística d'Andorra"Андорарр

          J. J. Abrams Índice Traxectoria | Filmografía | Premios | Notas | Véxase tamén | Menú de navegacióne"J.J. Abrams: Biography"Arquivado"'Star Trek' sequel on track"Arquivado"J.J. Abrams Producing Samurai Jack Movie"Arquivado"EXCLUSIVE: J.J. Abrams Goes Into Warp Speed with Star Trek and Beyond"Arquivado"David Semel To Direct Jonah Nolan/J.J. Abrams' CBS Pilot 'Person Of Interest'"Arquivado"Fox orders J.J. Abrams pilot 'Alcatraz'"ArquivadoJ. J. AbramsJ. J. AbramsWorldCat81800131p24091041000XX116709414031616ma11226833654496ID052246713376222X511412nm00091900000 0001 1772 5428no98124254ID0000002883100650044xx0054597000141374297344064w64f2mjx14255303415344

          Сэнт-Люіс Вонкавыя спасылкі | Навігацыйнае мэню38°37′38″ пн. ш. 90°11′52″ з. д. / 38.62722° пн. ш. 90.19778° з. д. / 38.62722; -90.1977838°37′38″ пн. ш. 90°11′52″ з. д. / 38.62722° пн. ш. 90.19778° з. д. / 38.62722; -90.19778stlouis-mo.govСэнт-ЛюісAnnual Estimates of the Resident Population for Incorporated Places – U.S. Census Bureau, Population Division