Over on Stack Exchange, someone is asking about creating honeypots in order to identify stalkers or hackers. The question proposes creating downloadable files with tracking pixels, using features of platforms like Google Drive, or using the advertising features of Google Analytics to infer location and demographics of the stalker. The files/websites would be crafted to be indexed by Google under search terms that would be interesting to a stalker. The question is what limitations the GDPR would place on such strategies.
On one hand, security measures can clearly be an overriding legitimate interest, cf Recital 49 GDPR.
On the other hand, such measures might not be necessary and proportional, especially when the threat supposed to be countered by these measures is still speculative. I think this scenario is very similar to video surveillance, where the EDPB writes in Guidelines 3/2019:
20. The legitimate interest needs to be of real existence and has to be a present issue (i.e. it must not be fictional or speculative). A real-life situation of distress needs to be at hand – such as damages or serious incidents in the past – before starting the surveillance. In light of the principle of accountability, controllers would be well advised to document relevant incidents […] and related criminal charges.
I also have doubts whether such strategies would be adequate for the stated purpose of inferring the identity of a stalker. For example, Google Analytics is not magic and Google’s estimated age ranges for an individual user are frequently wildly off – if the tracking isn’t blocked outright by the browser. If the processing activity is not adequate for its stated purpose, it would fail the Art 5(1)(c) data minimization principle.
In any case the Art 13 information obligation would make covert data collection illegal, even if these activities were otherwise supported by an overriding legitimate interest. Covert action would have to be done by law enforcement.
What do you think about the GDPR-compliance of honeypots? Are there other factors that should be considered?