IP Address
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Internet protocol addresses as personal data
Overview
15 sources · Jul 15, 2026Legal Framework
Recital 30 GDPR explicitly identifies internet protocol addresses as online identifiers that may be associated with natural persons. When combined with unique identifiers and other server-side information, IP addresses can generate traces used to create profiles and identify individuals. This places IP addresses squarely within the definition of personal data under Article 4(1) GDPR, provided the data subject is identifiable—directly or indirectly—by the controller or by any other person.
Recital 64 GDPR reinforces that controllers must use all reasonable measures to verify data subject identity in the context of online services and online identifiers, while prohibiting retention of personal data solely to respond to potential access requests.
The legal threshold for identifiability turns on whether the controller has the legal means to link the IP address to an individual. Article 2(a) of Directive 95/46—the predecessor provision substantively carried forward into Article 4(1) GDPR—establishes that a dynamic IP address constitutes personal data where the holder possesses legal means enabling identification through additional data held by an internet service provider.
Key Developments
The CJEU's ruling in Breyer v. Bundesrepublik Deutschland established the controlling standard. The Court held that a dynamic IP address registered by an online media services provider constitutes personal data where that provider has the legal means to identify the data subject by combining the IP address with additional data held by the internet service provider. Critically, the Court rejected the argument that only the ISP could make the connection; what matters is whether the website operator possesses a legal right to obtain the identifying data from the ISP, not whether it has already done so.
The Planet49 decision extended the transparency framework to IP addresses collected through cookies, requiring service providers to inform users about cookie duration and third-party access. The Fashion ID ruling clarified that the duty to inform attaches only to processing operations where the operator actually determines purposes and means, and that information must be provided at the point of collection.
Dutch enforcement, including the Microsoft Ireland Operations / Xandr decision, confirmed that cookie IDs and the IP addresses transmitted alongside them are online identifiers constituting personal data under the GDPR. The Dutch DPA has treated the combination of cookie identifiers and IP addresses as personal data without requiring further analysis.
Enforcement actions demonstrate financial exposure: CNIL's €5,000,000 fine against IQVIA Operations France addressed non-compliance with general processing principles, while the Spanish AEPD fined SIPHONE 2020 €4,000 for insufficient legal basis—both contexts involving online identifier processing.
Practical Guidance
Conduct a legal means analysis: For each IP address processing operation, document whether your organization has the legal ability to obtain subscriber-identifying data from the relevant ISP. If such legal means exist—through court orders, police requests, or contractual arrangements—the IP address is personal data and full GDPR obligations apply, per Breyer.
Provide Article 13 transparency at collection point: When IP addresses are collected through website access or cookies, deliver privacy information immediately at the point of collection, including details on cookie duration and third-party access, as required under Planet49 and Fashion ID.
Establish a valid Article 6 legal basis: Relying on legitimate interests under Article 6(1)(f) requires a documented balancing test. The AEPD's action against SIPHONE demonstrates that insufficient legal basis for IP address processing triggers enforcement even at modest processing volumes.
Minimize retention of dynamic IP addresses: Since Recital 64 prohibits retaining personal data solely for potential access request responses, implement technical measures such as truncation or pseudonymization of IP address logs where full retention is not justified by a separate legal basis.
Treat IP addresses combined with cookie IDs as personal data by default: Following the Microsoft/Xandr Dutch decision, do not attempt to argue that cookie IDs or transmitted IP addresses fall outside GDPR scope. Build compliance architecture on the assumption that these identifiers are personal data.