People repeat this a lot, but it sounds like complete nonsense.
Why does your business need to perform “security anslysis in case of attacks”? Do you get paid to do that? Why would you need IP addresses for that?
Another example is logging requests to secure sections of the site and/or server and perform IP blocks on fishy activity.
I don't see why the IPs would ever have to hit the disk for this purpose, just keep them cached in RAM for a few minutes.
the only way round this is to make the webserver spend a non-trivial amount of time running some derivation function on the IP for each and every request (remember you can't cache the result if the entire point is not to store the IP)
The problem is that it's possible and that is where the GDPR hooks in.
Put another way:
If the goal is to prevent certain actions by making them illegal
and a given boundary can already ensure that, whats the point in widening that boundary even more?
Atleast in germany the boundary has not been widened and most corporations seemed to operate just fine.
> Just because if the name is added to such a database of cars produced, it will be personal identifying?
When you add data to your database you'll have to consider this, yes.
Privacy under the GDPR means that you evaluate whether or not it is necessary to store such data.
Why? Because the GDPR is not only about the present but also about potential problems. If your database gets breached and someone runs of with the data, the GDPR seeks to ensure that the data contained is the absolute minimum necessary and does not threaten the privacy of the users if possible.
Under GDPR you do not own data like car color, built, model, extras. People give you stewardship of the data and you are responsible for it. It is your task to protect it. Protecting people's data is easier when you don't have as much of it.