Are there any GDPR issues to consider with AWStats. If AWStats only parses raw access logs and does not create any new log of a users IP, and if raw access logs are exempt on the basis they are required for security reasons, then are there no GDPR issues for AWStats?