Skip to content
Topic Contested in court

IP Address

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Internet protocol addresses as personal data

1,627 linked items 2 Laws110 Case Law35 Guidance1280 Enforcement177 News

Overview

15 sources · Jul 15, 2026

Legal Framework

Recital 30 GDPR explicitly identifies internet protocol addresses as online identifiers that may be associated with natural persons. When combined with unique identifiers and other server-side information, IP addresses can generate traces used to create profiles and identify individuals. This places IP addresses squarely within the definition of personal data under Article 4(1) GDPR, provided the data subject is identifiable—directly or indirectly—by the controller or by any other person.

Recital 64 GDPR reinforces that controllers must use all reasonable measures to verify data subject identity in the context of online services and online identifiers, while prohibiting retention of personal data solely to respond to potential access requests.

The legal threshold for identifiability turns on whether the controller has the legal means to link the IP address to an individual. Article 2(a) of Directive 95/46—the predecessor provision substantively carried forward into Article 4(1) GDPR—establishes that a dynamic IP address constitutes personal data where the holder possesses legal means enabling identification through additional data held by an internet service provider.

Key Developments

The CJEU's ruling in Breyer v. Bundesrepublik Deutschland established the controlling standard. The Court held that a dynamic IP address registered by an online media services provider constitutes personal data where that provider has the legal means to identify the data subject by combining the IP address with additional data held by the internet service provider. Critically, the Court rejected the argument that only the ISP could make the connection; what matters is whether the website operator possesses a legal right to obtain the identifying data from the ISP, not whether it has already done so.

The Planet49 decision extended the transparency framework to IP addresses collected through cookies, requiring service providers to inform users about cookie duration and third-party access. The Fashion ID ruling clarified that the duty to inform attaches only to processing operations where the operator actually determines purposes and means, and that information must be provided at the point of collection.

Dutch enforcement, including the Microsoft Ireland Operations / Xandr decision, confirmed that cookie IDs and the IP addresses transmitted alongside them are online identifiers constituting personal data under the GDPR. The Dutch DPA has treated the combination of cookie identifiers and IP addresses as personal data without requiring further analysis.

Enforcement actions demonstrate financial exposure: CNIL's €5,000,000 fine against IQVIA Operations France addressed non-compliance with general processing principles, while the Spanish AEPD fined SIPHONE 2020 €4,000 for insufficient legal basis—both contexts involving online identifier processing.

Practical Guidance

  • Conduct a legal means analysis: For each IP address processing operation, document whether your organization has the legal ability to obtain subscriber-identifying data from the relevant ISP. If such legal means exist—through court orders, police requests, or contractual arrangements—the IP address is personal data and full GDPR obligations apply, per Breyer.

  • Provide Article 13 transparency at collection point: When IP addresses are collected through website access or cookies, deliver privacy information immediately at the point of collection, including details on cookie duration and third-party access, as required under Planet49 and Fashion ID.

  • Establish a valid Article 6 legal basis: Relying on legitimate interests under Article 6(1)(f) requires a documented balancing test. The AEPD's action against SIPHONE demonstrates that insufficient legal basis for IP address processing triggers enforcement even at modest processing volumes.

  • Minimize retention of dynamic IP addresses: Since Recital 64 prohibits retaining personal data solely for potential access request responses, implement technical measures such as truncation or pseudonymization of IP address logs where full retention is not justified by a separate legal basis.

  • Treat IP addresses combined with cookie IDs as personal data by default: Following the Microsoft/Xandr Dutch decision, do not attempt to argue that cookie IDs or transmitted IP addresses fall outside GDPR scope. Build compliance architecture on the assumption that these identifiers are personal data.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 2
rec 30 Recital 30 — online identifiers enabling personal profiling GDPR Apr 2016 rec 64 Recital 64 — data subject identity verification for access GDPR Apr 2016
Case Law 110
¶26 It is apparent from the order for reference that one feature of the internet is that, when a website is visited, the browser allows content from diffe… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶14 Under Paragraph 113b of the TKG: ‘(1) Operators to which Paragraph 113a(1) applies shall retain data in national territory as follows: 1. for 10 weeks… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – ¶39 In those circumstances, the Bundesverwaltungsgericht (Federal Administrative Court) decided to stay the proceedings and to refer the following questio… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – ¶77 In the first place, as regards the extent of the data retained, it is apparent from the order for reference that, in the context of the provision of t… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 793/19 Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – Court of Justice of the European Union Oct 2022 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 621/22 Judgment of the Court (Ninth Chamber) of 4 October 2024.#Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Amsterdam.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interest Court of Justice of the European Union Oct 2024 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 597/19 Judgment of the Court (Fifth Chamber) of 17 June 2021.#Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA.#Request for a preliminary ruling from the Ondernemingsrechtbank Antwerpen.#Reference for a preliminary ruling – Intellectual property – Copyright and related rights – Directive 2001/29/EC – Article 3(1) and (2) – Concept of ‘making available to the public’ – Downloading of a file containing a protected work via a peer-to-peer network and the simultaneous Court of Justice of the European Union Jun 2021 673/17 Bundesverband der Verbraucherzentralen v Planet49 GmbH CJEU Oct 2019 740/22 Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’ Court of Justice of the European Union Mar 2024 496/17 Judgment of the Court (Third Chamber) of 16 January 2019.#Deutsche Post AG v Hauptzollamt Köln.#Request for a preliminary ruling from the Finanzgericht Düsseldorf.#Reference for a preliminary ruling — Customs union — The Union Customs Code — Article 39 — Status of authorised economic operator — Implementing Regulation (EU) 2015/2447 — The second subparagraph of Article 24(1) — Applicant not a natural person — Questionnaire — Collection of personal data — Directive 95/46/EC — Articles 6 and 7 — R Court of Justice of the European Union Jan 2019 252/21 Meta Platforms v noyb CJEU Jan 2023 17/22 Judgment of the Court (Fourth Chamber) of 12 September 2024.#HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others.#Requests for a preliminary ruling from the Amtsgericht München.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Points (b), (c) and (f) of the firs Court of Justice of the European Union Sep 2024 319/20 Judgment of the Court (Third Chamber) of 28 April 2022.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 80 – Representation of the data subjects by a not-for-profit association – Representative action Court of Justice of the European Union Apr 2022 Hof van Justitie EU HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Hof van Justitie EU Jul 2020 487/21 Österreichische Datenschutzbehörde v CRIF CJEU Oct 2023 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 Show 90 more →
Guidance 35
guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on technical scope of art 53 of eprivacy directive Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive EDPB Oct 2024 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 Show 15 more →
Enforcement 1280
NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Information Commissioner (ICO) Reddit, Inc.: Non-compliance with general data processing principles Information Commissioner (ICO) Feb 2026 French Data Protection Authority (CNIL) IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) May 2026 ICO (UK) ICO (UK) - KRA Consultancy Ltd ICO (UK) May 2026 Italian Data Protection Authority (Garante) Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2026 DSB (Austria) DSB Austria: No fine imposed on COVID mask shop for cookie consent failure DSB (Austria) Jan 2026 Italian Data Protection Authority (Garante) Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2026 Spanish Data Protection Authority (aepd) SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) Apr 2026 Spanish Data Protection Authority (aepd) Aena, een klein en middelgroot bedrijf (KMO), S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Spanish Data Protection Authority (aepd) Nov 2025 NL Croatian Data Protection Authority (azop) Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) Dec 2025 Slovenian Supervisory Authority (Informacijski pooblaščenec) Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) Apr 2026 Spanish Data Protection Authority (aepd) Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Apr 2026 DSB (Austria) Austrian DSB rules 360-degree feedback unlawful without specific works agreement DSB (Austria) Mar 2026 Spanish Data Protection Authority (aepd) Aena, S.M.E., S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Nov 2025 French Data Protection Authority (CNIL) Company: Non-compliance with general data processing principles French Data Protection Authority (CNIL) Dec 2025 Croatian Data Protection Authority (azop) Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Croatian Data Protection Authority (azop) Nov 2025 Spanish Data Protection Authority (aepd) ORNITOLÓGICA DE ANDALUCÍA FOA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Mar 2026 Spanish Data Protection Authority (aepd) Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Mar 2026 Show 1260 more →
News 177
Electronic Frontier Foundation Age Verification is a Privacy Nightmare Electronic Frontier Foundation May 2026 Electronic Frontier Foundation More License Plate Reader Mission Creep: School Residency Verification, Background Checks, and Noise Complaints Electronic Frontier Foundation May 2026 European Digital Rights When the data relates to us. European Digital Rights Dec 2025 CNIL Sanctions et mesures correctrices : la CNIL présente le bilan 2025 CNIL Feb 2026 FR European Digital Rights Ensuring human rights-based, global perspectives in the DSA enforcement: the DSA Human Rights Alliance’s guidelines European Digital Rights Feb 2026 GDPRhub AEPD (Spain) - EXP202306073 GDPRhub Jan 2026 GDPRhub VDAI (Lithuania) - Decision No. 3R-1700. GDPRhub Jan 2026 EDPB Stakeholder event on anonymisation and pseudonymisation: express your interest EDPB Nov 2025 GDPRhub DSB (Austria) - 2025-0.395.497 GDPRhub Jan 2026 Electronic Frontier Foundation DSA Human Rights Alliance Publishes Principles Calling for DSA Enforcement to Incorporate Global Perspectives Electronic Frontier Foundation Jan 2026 GDPRhub AEPD (Spain) - EXP202500113 GDPRhub Jan 2026 European Digital Rights Information Integrity & Wikipedia: How community-governed platforms can inform future policy-making. European Digital Rights Feb 2026 EDPB Support the EDPB’s work as an expert EDPB Nov 2025 European Digital Rights UK adequacy decision: a risk for the future and a lesson to be learnt European Digital Rights Feb 2026 European Digital Rights Fighting for algorithmic justice: lessons learned in working closely with affected people European Digital Rights Jan 2026 EDPB Coordinated Enforcement Framework: EDPB selects topic for 2026 EDPB Oct 2025 noyb - European Center for Digital Rights An internal draft document from the European Commission appears to undermine the core principles of the GDPR (General Data Protection Regulation). noyb - European Center for Digital Rights Nov 2025 Access Now DSA Human Rights Alliance publishes principles calling for DSA enforcement to incorporate global perspectives Access Now Jan 2026 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 CNIL Deuxième édition du Prix CNIL-EHESS CNIL Feb 2026 FR Show 157 more →
Literature 23
Journal of Information Technology Building data management capabilities to address data protection regulations: Learnings from EU-GDPR Journal of Information Technology Jan 2023 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Journal of Risk Regulation The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation Jul 2026 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 Show 3 more →