Skip to content
Topic Contested in court

IP Address

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Internet protocol addresses as personal data

670 linked items 2 Laws67 Case Law37 Guidance427 Enforcement114 News

Overview

22 sources · Sep 8, 2026

Legal Framework

The classification of IP addresses as personal data flows from Article 4(1) GDPR, which defines personal data as any information relating to an identified or identifiable natural person, directly or indirectly, "in particular by reference to an identifier such as a name, an identification number, location data, an online identifier." Recital 30 makes the link to IP addresses explicit:

"Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags."
— GDPR Recital 30

The practical consequence is that collecting, storing, or transmitting an IP address constitutes "processing" under Article 4(2) GDPR, triggering the full suite of GDPR obligations—including lawful basis under Article 6, transparency under Articles 13–14, and security under Article 32. Where the IP address is obtained through access to terminal equipment, the ePrivacy Directive (Article 5(3)) adds a consent requirement before collection occurs, as the EDPB has confirmed that IP addresses fall within that provision's scope.

Key Developments

The CJEU confirmed in Bundesverband der Verbraucherzentralen v Planet49 that the Article 4(1) definition of personal data encompasses online identifiers, embedding the broad interpretation into EU precedent. In Fashion ID, the Court further noted that embedding third-party content on a website necessarily transmits the visitor's IP address to the third-party server, making the website operator a controller for that transmission.

Dutch courts have applied this reasoning to cookie IDs and analogous identifiers. In the Microsoft/Xandr case, the Rechtbank rejected the argument that a cookie ID alone is insufficient to identify a natural person:

The Norwegian DPA's Grindr decision treated IP addresses alongside GPS data and advertising IDs as personal data requiring a valid lawful basis, fining the company for sharing them without valid consent. The Belgian DPA similarly cited Recital 30 when finding online identifiers fall within the GDPR's material scope.

The EDPB's 2023 guidelines on Article 5(3) ePrivacy Directive clarify the technical threshold: IP addresses originating from a user's terminal equipment trigger the consent requirement, with IPv4 addresses behind CGNAT potentially excluded. The guidelines note that "gaining access to IP addresses would only trigger the application of Article 5(3) ePD in cases where this information originates from the terminal equipment of a subscriber or user."

Status of the Debate

The core question—whether IP addresses are personal data—is settled at the EU level. Recital 30, Article 4(1), and consistent CJEU and national case law establish that IP addresses are online identifiers capable of indirectly identifying natural persons. What remains actively contested is the boundary: whether dynamic IP addresses behind carrier-grade NAT (CGNAT) qualify, and at what point an IP address held by an intermediary becomes personal data when the intermediary lacks legal means to identify the individual. The EDPB guidelines signal that unless a controller can affirmatively ensure the IP address does not originate from terminal equipment, Article 5(3) ePD applies. A future CJEU reference on CGNAT-specific scenarios would resolve the remaining ambiguity.

Practical Guidance

  • Treat all IP addresses as personal data by default. Unless you can demonstrably confirm the address does not originate from a user's terminal equipment (e.g., CGNAT scenarios), apply the full GDPR framework per Article 4(1) and Recital 30.
  • Obtain ePrivacy consent before collecting IP addresses from terminal equipment. Article 5(3) of the ePrivacy Directive requires prior informed consent where collection occurs through access to or storage on a user's device, as confirmed by EDPB Guidelines 2/2023.
  • Establish a lawful basis under Article 6 GDPR for any processing of IP addresses beyond mere transmission. Legitimate interest (Article 6(1)(f)) may suffice for security purposes, but sharing IP addresses with third parties for advertising—per the Grindr decision—typically requires explicit, freely given consent.
  • Minimise retention. Recital 64 cautions against retaining personal data solely to respond to potential access requests. Apply storage limitation principles to IP logs, retaining only for the duration necessary for the defined purpose.
  • Document your identification analysis. If you argue an IP address is not personal data in your specific context, record why the holder lacks means to link it to an individual—bearing in mind courts apply a broad, purposive interpretation of "identifiable."
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Online identifiers
why this is here
Such targeting may be rendered possible on the basis of online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses

Mentions IP addresses but not as a focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 2/2023 Technical Scope of Art. 5(3) of ePrivacy Directive Guidelines ·EDPB Guidance EDPB Oct 2024 IP addresses as terminal identifiers
why this is here
This might concern routing identifiers such as the MAC or IP address of the terminal equipment

Mentions IP as one of many identifiers but does not analyze its nature as personal data.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 67 Case Law · all 37 Guidance · all 427 Enforcement · all 23 Literature · all 114 News