Guide
Is an IP address personal data?
When is an IP address personal data under the GDPR? Here are the rulings, the 2025–26 Digital Omnibus debate, and the rules for keeping logs.
On this page
If you run a website, you probably log IP addresses. If you are in Europe, or serve European visitors, that log may be personal data with legal obligations attached. The answer is nuanced, and it has been actively debated through 2025 and 2026, so here is the current state in plain language.
The short answer
An IP address is personal data when the entity processing it has the means reasonably likely to identify the person behind it. A static, registered address in a corporate network is clearly personal data. A dynamic address becomes personal data for an operator who can ask the ISP for the subscriber — the operator may not hold the name, but they have a realistic route to it. Only where identification is genuinely impossible for that entity does the data fall outside the GDPR's scope.
In practice, for almost every website and app: treat the IP address as personal data. That means a lawful basis, a stated purpose, a retention limit, security safeguards and the ability to answer access requests.
The rulings that settled it
- CJEU, Breyer (C-582/14, 2016). A German website operator argued dynamic IPs were not personal for it because only the ISP could identify the visitor. The Court disagreed: the operator had means reasonably likely to be used to identify the visitor — via legal channels to the ISP — so the address was personal data in its hands. This is the anchor case for the whole discussion.
- CJEU, EDPS v SRB (C-413/23 P, 4 September 2025). The Court reinforced that pseudonymised data can remain personal data where the recipient retains realistic means of re-identification — a decision that shaped how the Commission approached the definition.
- National authorities. Regulators including the UK ICO have long taken the position that IP addresses are personal data in most online contexts; several EU DPA decisions on cookie walls and analytics tools rest on the same premise.
The 2025–26 Digital Omnibus debate
On 19 November 2025 the European Commission published the Digital Omnibus package, proposing targeted amendments to the GDPR. Among them was a clarification of Article 4(1) that would make the concept of personal data more relative to the entity: information would not be personal for a given entity merely because someone else could identify the person.
The proposal drew strong reactions:
- EDPB and EDPS Joint Opinion 2/2026 (10 February 2026) welcomed parts of the simplification agenda but criticised the redefinition — warning that defining what personal data is not would increase legal uncertainty, and recommending the removal of the proposed implementing power over pseudonymisation.
- The Council's compromise text (February 2026) reportedly removed the amended definition of personal data from the package altogether.
At the time of writing, the position most organisations should plan against remains the case law above: relative identifiability, assessed per entity, with realistic means. Follow the legislative process if your compliance depends on the exact wording — and note that even under a narrower definition, a site that could serve a legal request to an ISP is unlikely to escape the personal-data label.
What it means for logs and websites
| Activity | Practical obligation |
|---|---|
| Server access logs | Lawful basis (usually legitimate interests or legal obligation), stated retention (days to weeks for security), access control, deletion schedule |
| Analytics and tracking | Cookie or device-level access generally needs consent under the ePrivacy rules; IP-based analytics platforms still fall under GDPR obligations |
| Anti-abuse and fraud prevention | Legitimate interest, but document the necessity and keep retention proportionate — see IP reputation |
| Privacy policy | Say that IP addresses are processed, why, for how long, and who receives them |
| Access requests | Be able to search what you hold for a given IP — or explain honestly why you cannot link it |
| Geolocation lookups | Passing an IP to ipwho.is, ipquery.io or any lookup API is processing; disclose the recipients, as our own privacy policy does |
Two clarifications worth holding on to: hashing or pseudonymising an address does not automatically anonymise it — the legal test is re-identifiability, not the format. And the fact that an address is personal data does not mean you cannot log it; it means you must have a reason, a basis and a limit.
Beyond the EU
Comparable regimes treat IP addresses similarly: the UK GDPR after Brexit, Brazil's LGPD, and various national laws that import the GDPR's definition. In the United States there is no general federal equivalent — an IP address is often not considered personally identifiable information on its own — but state privacy laws, sectoral rules and the FTC's stance on deceptive privacy claims still constrain what you can do with it. If you serve a global audience, the GDPR test is the safest baseline: assume identifiability, document your purpose, and keep retention short.
Bottom line: an IP address is personal data for anyone who could realistically identify the person behind it — which, in 2026, is most organisations. Plan for consent, disclosure and retention rather than arguing about the definition.
Frequently asked questions
Is an IP address personal data under the GDPR?
Yes, whenever the organisation processing it has means reasonably likely to identify the person — the standard set in the CJEU's Breyer judgment and applied since. Static, corporate and logged dynamic addresses typically qualify.
Can a website store my IP address legally?
Yes, with a lawful basis and a purpose: security logging, fraud prevention and legal obligations are common grounds. It must be disclosed, kept secure and deleted after a proportionate period.
Does hashing an IP address make it anonymous?
Not automatically. Pseudonymised data remains personal data where re-identification is realistically possible — for example by brute-forcing the small address space. Treat hashed addresses as personal unless a documented analysis proves otherwise.
Keep reading
- Check your IP address from the command line
- How to fix an IP address conflict
- MAC address vs IP address
- How to find your IP address on a computer
- How to find your router's IP address
- How to trace an IP address
- What can someone do with my IP address?
- What is a local IP address?
- How to change your IP address
- How to hide your IP address
- What is an IP address?
- Why is my IP location wrong?
- Browse all IP guides
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.