1. Analysis
  2. The exploration
  3. Why logs
  4. What is required
  5. By jurisdiction
  6. Locating the actor
  7. For framework builders

Knowing which law applied, without making the log personal data

Every duty in this analysis reaches a system because of where somebody is. So a record that shows the duty was met has to show where they were, and a record of where somebody was is a record about a person. This document is about that trap and the one way out of it that both halves of the law accept.

Why a location brings a law into play

The pattern is the same across every regime read for this document, and it is not the pattern people expect. A jurisdiction's law reaches a service because of what the service's own conduct does toward a place: it offers goods there, monitors behaviour there, puts the output of an AI system to use there, makes material available there, avails itself of that market. It does not reach the service because a log happens to carry a user's coordinates.

European data-protection law's extraterritorial limb runs on the location of processing activity relative to people in the Union, judged by the EDPB's own multi-factor targeting test rather than on any one user's position. The Union's AI law runs on where the output is used. And for a controller established in the Union, three decided cases put the question entirely inside the controller's own footprint, so it never reaches the user's location at all.

Where a location becomes personal data

The other half of the problem has a line in it, and the line is drawn in statute rather than left to judgement. California's privacy statute makes precise geolocation a sensitive category at a radius measured in feet. European rules on electronic communications gate location data derived from a network separately from other traffic data. And the European court's reasoning about a dynamic address held alongside a provider's own subscriber records is the reason a coarse signal and a precise one are not the same kind of value.

A digest does not rescue a precise signal, and this is the part most often got wrong. A record that carries a hash of an address carries the address: a four-billion-value space is enumerated in seconds. The standards draft for agent action records states the rule for its own equivalent problem in as many words:

hashing is not anonymization for low-entropy identifiers. Session and user identifiers and similar low-entropy values are recoverable by dictionary attack against their digest [...] Identity MUST be excluded, not digested.

draft-mih-scitt-agent-action-capsule-04, section 14.1

A precise location is the same kind of value once it narrows far enough to single out one person, which is exactly the range this question needs.

What the law already accepts as evidence

Two things make the way out of this available rather than theoretical. United States export and sanctions regulators treat a coarse, gating location signal as precisely the compliance tool a risk-based programme is expected to hold, so a country-level check is not a weaker substitute for something better: it is the accepted instrument. And the age-verification statutes are direct evidence that a legislature can require this exact shape, locate and characterise and then discard, as a matter of law rather than as good practice.

The compromise

Record the answer, not the evidence. A log should carry a coarse jurisdiction result, a country or state-level label or the word unknown, as the output of a deterministic check run against evidence that is itself never written into the record, together with a commitment binding that answer to an evidence record held somewhere else.

So the line in the log reads: this request was evaluated as directed at the European Union, evidence commitment such-and-such. Never an address, never a coordinate, never a value from which either could be recovered.

The commitment is not a hash of the signal, and that difference is the whole of the design. It has to be a commitment over an evidence record that includes a random value of its own, with both the record and that value held in an access-controlled store and never in the log. Then the commitment is checkable by anyone who is shown the evidence and inert to everyone who is not, which is what a bare digest of the signal fails to be.

One caveat belongs beside that, because a field is safe only in the company it keeps. A country label is a derived, non-identifying value read alone. A country label sitting next to a session identifier in the same record is a country label attached to a person. The rule has to be enforced across every field admitted to the record, not checked once on this one.

The predicate can be confidently wrong

Everything above is about what the record may carry. None of it makes the answer correct, and the design's own strength is what hides that. The commitment is a commitment over an evidence record, so a predicate fed the wrong evidence produces a record that is internally consistent, verifiable, signed, and wrong. Every integrity property the arrangement buys still holds, and holds around a false answer.

That is the failure a tamper-evident log is worst at surfacing, because nothing downstream has any reason to doubt it. An absent label invites the question. A wrong one, committed and countersigned, answers it.

The common way to produce one is a content delivery network. At an origin behind one, the IP address at the other end of the socket belongs to the network's own point of presence rather than to the person, so a check run on it returns a confident label for the wrong place; the actual client IP address arrives in a header the edge sets, and only there. A predicate written against the socket is not a predicate that sometimes fails. It is one that reliably answers a different question. The short statement of this argument, for a reader arriving from a standards working group rather than from this index, is What a tamper-proof log still cannot tell you.

So the inputs are part of what has to be got right, and they are the part this design does nothing to protect. A record that cannot be retracted once anchored is the worst place to put a value nobody will think to check.

The predicate is per party, not per action

Different bodies of law pivot on different parties to the same event, so one answer for the whole action is the wrong shape. A scraping duty keys on the operator's own establishment. A privacy duty keys on the controller's establishment together with the data subject's location. The Union's AI law asks whether a provider or a deployer put the system on the Union market. An age-assurance duty asks where the user was at the moment of access.

Which means the check runs once per party per action, and the six parties the rest of this analysis uses are the natural axis for it. That is the same split the opening document draws, and it is why the answer to "which law applied" is several answers rather than one.

What this leaves unresolved

The compromise satisfies both halves of the law, and it costs something real. An auditor who wants to check the jurisdiction determination has to be shown the evidence store, which means the store has to survive as long as the log and be governed as carefully. A log that is genuinely self-sufficient, one an auditor can check from the record alone, is not available on these terms, and no shape read for this analysis offers one. That is a trade rather than a solution, and it is worth naming as one.

The statutory grounding, the decided cases and the exact wording behind every paragraph above are recorded with their sources and their reading dates in the research determination behind this page. What a record built on this rule would actually contain is the last document.

  1. Analysis
  2. The exploration
  3. Why logs
  4. What is required
  5. By jurisdiction
  6. Locating the actor
  7. For framework builders

LexLint is a research index and a lint, not a lawyer. These pages describe published law as read on the date beside each figure, and set out what would have to be recorded to show it was followed. They do not apply that law to any product, project or organisation, and they are not a certification, an assurance or a compliance programme. Whether a duty reaches a particular system, and what to do about it, is a question for counsel.

The instruments behind every figure are on the LexLint software-law corpus, indexed by jurisdiction and dated on every row. The terms these pages share are defined in the LexLint glossary.