Get Demo
↑

GDPR and Security Logs: Can a SIEM Store Personal Data? (Recital 49, Retention, Minimisation)

Security logs often contain personal data.

Published: September 2026 Compliance · GDPR 8–12 min read

Yes — a SIEM can store personal data (IPs, usernames, email addresses in logs). Recital 49 recognises processing for ensuring network and information security as a legitimate interest example, but you still owe minimisation, retention limits, access control, and transparency.

Related: GDPR hub · Lawful basis · ThreatHawk.

Objection handling: Security logging is not a free pass to keep everything forever. Define purposes, retention, role-based access, and DSAR search procedures for log stores.

Lawful Basis Themes

Minimisation & Retention

DSARs Against Logs

Logs may be in scope for Article 15. Plan search tooling, third-party redaction, and exemptions. Do not promise “logs are never personal data.”

How CyberSilo Helps

Make SIEM Defensible Under GDPR

Pair detection value with documented basis, retention, and access evidence.

Frequently Asked Questions

Are IP addresses personal data?

Often yes when they can identify an individual, alone or combined with other data — treat them carefully in SIEM design.

Does Recital 49 create a new lawful basis?

No. Recitals guide interpretation. You still need an Article 6 basis (commonly legitimate interests for security).

How long can we keep security logs?

No single GDPR number. Set purpose-based retention and document it in RoPA and policy.

GDPR hub · Article 32 · Retention · ThreatHawk

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!