Privacy

IP anonymization

Also called IP masking.

IP anonymization is truncating or hashing an IP address before it is stored so it identifies less. It lowers risk without making the data free of obligations.

How it is measured

A common method zeroes the last octet of an IPv4 address, so 203.0.113.77 becomes 203.0.113.0. For IPv6, drop the final 80 bits or more. The step must happen before the value is written to disk.

Verify by inspecting stored rows and backups. If a full address appears anywhere, truncation came too late or was skipped on one path.

Worked example

A school site logs 5,000 hits a day. Its CDN edge zeroes the last octet, so a row reads 198.51.100.0 instead of 198.51.100.24. City-level location still works.

A support engineer later finds a debug log that kept the raw header. The team removes it, since the truncated table had hidden a leak in the other one.

How it differs

IP anonymization shortens or hashes the value. An IP address in full still points to one connection. Anonymization excludes the host part of the address; the raw address keeps all of it.

Common errors

Anonymizing after logging. Calling a truncated address anonymous when other fields can re-identify. Truncating only IPv4. Hashing without a salt so addresses can be brute-forced. Keeping the original in backups.

In practice

Move truncation to the earliest hop, the edge or the collector. Then grep stored rows and backups for full addresses. Review any other field that could pinpoint a person.

See also

IP address, Personal data, Data retention

Sources

Count this on a real site.

Watch my website