GDPR access request: "delete my IP address from your systems." The team answers "we have no user account." Then you discover: Apache logs 180 days, Matomo 13 months, host WAF 90 days, CDN export 30 days. Four silos, no written policy.
IP addresses flow everywhere in hosting: server logs, reverse proxy, CDN, anti-DDoS, panel, anti-fraud billing. Often personal data under GDPR. "Know what you retain and why" is a minimization duty — not a syslog detail.
Map IP flows
Host side: shared or VPS access logs, firewall logs, mod_security, panel connections, anti-DDoS.
Client side: analytics — Matomo, Plausible with temporary IP —, application logs, home-grown rate limiting.
Third parties: CDN, captcha, payment — subcontractors to list in register with purpose and duration.
| Source | Typical purpose | Duration to document |
|---|---|---|
| Web logs | Security, debug | 30–90 days |
| WAF / DDoS | Attack blocking | 30–180 days |
| Analytics | Audience measurement | Often 13 months |
| App login | Fraud | Per risk |
"Logs rotate by themselves" is not a legal basis.
Legal bases and defensible durations
Legitimate interest security: short term, restricted access, public policy if user impact. Legal obligation: rare for IPs alone; check sector. Analytics consent: if cookies or trackers not exempt.
Set duration per tool, configure automatic purge at host and on your side. Align with log retention policy if present.
The peak: keeping "just in case" without purpose
Decide and move forward without blind spots
This week run tool inventory plus durations plus legal bases, request host log retention in writing for each infrastructure layer, then compare provider transparency via directory and compare tool. See Email retention to align mail and associated logs.
Frequently asked questions
IP = personal data?
Yes when direct or indirect identification possible — timestamp, user-agent, account combined.
Retention duration?
Per documented purpose per flow — not indefinite default retention.
Host retains for us?
Yes infrastructure logs; you too via app, analytics, CDN — two register scopes.
Anonymization?
Yes if irreversible and suited; not excuse to keep everything in clear indefinitely.
IP compliance starts with one question: who, where, how long, for what — not "we have logs."
