Oh, it’s simple. Just comply with EU law, and it’s all okay.
That includes:
1. You can not collect anything without explicit opt-in
2. You can not transmit any data to a third party
3. If a user requests it, you have to provide all data stored about them, and have to provide a way for them to delete all of that. (And you have to provide this at least once every 12 months via letter, fax or email for free) (compare §34 BDSG)
That includes IP addresses (just connecting to a socket without a user explicitly starting that action), names, emails, hashed IPs, it includes usernames, CC data, messages, interactions with webpages.
Anything that in any way is connected to a person is covered by this.
This directive is also the origin of the cookie disclaimers, which require opt-in before collecting statistics or loading any third party tracking solution.
But be aware, in May 2018 it all changes as the new EU GDPR comes into force, and that’s a bit more restrictive (and even applies to anyone processing or storing data of EU citizen, no matter where the processing entity is located)
That includes:
1. You can not collect anything without explicit opt-in
2. You can not transmit any data to a third party
3. If a user requests it, you have to provide all data stored about them, and have to provide a way for them to delete all of that. (And you have to provide this at least once every 12 months via letter, fax or email for free) (compare §34 BDSG)