Skip to content
Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Patrick BREYER v. BUNDESREPUBLIK DEUTSCHLAND, (“BREYER”)

Judgment

Personal data
AG Opinion
Summary

The court emphasized, in accordance with the opinion of the Advocate General, that “if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant” then the dynamic IP addresses would not constitute ‘personal data.’

Full text

summary
Concept of personal data: the court held that “a dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data within the meaning of that provision, in relation to that provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person.” (¶49)
other
The court emphasized, in accordance with the opinion of the Advocate General, that “if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant” then the dynamic IP addresses would not constitute ‘personal data.’
¶46 excerpt
Thus, as the Advocate General stated essentially in point 68 of his Opinion, that would not be the case if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant.
¶47 excerpt
Although the referring court states in its order for reference that German law does not allow the internet service provider to transmit directly to the online media services provider the additional data necessary for the identification of the data subject, it seems however, subject to verifications to be made in that regard by the referring court that, in particular, in the event of cyber attacks legal channels exist so that the online media services provider is able to contact the competent authority, so that the latter can take the steps necessary to obtain that information from the internet service provider and to bring criminal proceedings.
¶48 excerpt
Thus, it appears that the online media services provider has the means which may likely reasonably be used in order to identify the data subject, with the assistance of other persons, namely the competent authority and the internet service provider, on the basis of the IP addresses stored.
¶49 excerpt
Having regard to all the foregoing considerations, the answer to the first question is that Article 2(a) of Directive 95/46 must be interpreted as meaning that a dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data within the meaning of that provision, in relation to that provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person.

GDPR Articles Cited (1)

How it connects

2025 Study on the secondary use of personal data in the context of scientific research 2 This study has been prepared by Milieu under Contract No EDPS/2019/02 - 04 for the benefit of the EDPB. The study has been carried out by researchers from KU Leuven (CiTiP) and… EDPB Apr 3, 2025 Personal Data Statistics Scientific Research
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Sep 15, 2026 Consent Right to Object Personal Data
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Jul 28, 2026 Controllers Data Breaches Integrity and Confidentiality Principle
2025 One-Stop-Shop case digest on right of access EDPB/SPE 16 jan 2025 One-Stop-Shop case digest on right of access. Een rapport opgesteld door Hanne Marie Motzfeldt (Københavns Universitet) waarin beslissingen inzake het… EDPB Jan 16, 2025 Right of Access Personal Data Legitimate Interest