PublicIPChecker

Guide

Is an IP address personal data?

7 min read · Updated 2026-10-06

When is an IP address personal data under the GDPR? Here are the rulings, the 2025–26 Digital Omnibus debate, and the rules for keeping logs.

If you run a website, you probably log IP addresses. If you are in Europe, or serve European visitors, that log may be personal data with legal obligations attached. The answer is nuanced, and it has been actively debated through 2025 and 2026, so here is the current state in plain language.

The short answer

An IP address is personal data when the entity processing it has the means reasonably likely to identify the person behind it. A static, registered address in a corporate network is clearly personal data. A dynamic address becomes personal data for an operator who can ask the ISP for the subscriber — the operator may not hold the name, but they have a realistic route to it. Only where identification is genuinely impossible for that entity does the data fall outside the GDPR's scope.

In practice, for almost every website and app: treat the IP address as personal data. That means a lawful basis, a stated purpose, a retention limit, security safeguards and the ability to answer access requests.

The rulings that settled it

  • CJEU, Breyer (C-582/14, 2016). A German website operator argued dynamic IPs were not personal for it because only the ISP could identify the visitor. The Court disagreed: the operator had means reasonably likely to be used to identify the visitor — via legal channels to the ISP — so the address was personal data in its hands. This is the anchor case for the whole discussion.
  • CJEU, EDPS v SRB (C-413/23 P, 4 September 2025). The Court reinforced that pseudonymised data can remain personal data where the recipient retains realistic means of re-identification — a decision that shaped how the Commission approached the definition.
  • National authorities. Regulators including the UK ICO have long taken the position that IP addresses are personal data in most online contexts; several EU DPA decisions on cookie walls and analytics tools rest on the same premise.

The 2025–26 Digital Omnibus debate

On 19 November 2025 the European Commission published the Digital Omnibus package, proposing targeted amendments to the GDPR. Among them was a clarification of Article 4(1) that would make the concept of personal data more relative to the entity: information would not be personal for a given entity merely because someone else could identify the person.

The proposal drew strong reactions:

  • EDPB and EDPS Joint Opinion 2/2026 (10 February 2026) welcomed parts of the simplification agenda but criticised the redefinition — warning that defining what personal data is not would increase legal uncertainty, and recommending the removal of the proposed implementing power over pseudonymisation.
  • The Council's compromise text (February 2026) reportedly removed the amended definition of personal data from the package altogether.

At the time of writing, the position most organisations should plan against remains the case law above: relative identifiability, assessed per entity, with realistic means. Follow the legislative process if your compliance depends on the exact wording — and note that even under a narrower definition, a site that could serve a legal request to an ISP is unlikely to escape the personal-data label.

What it means for logs and websites

ActivityPractical obligation
Server access logsLawful basis (usually legitimate interests or legal obligation), stated retention (days to weeks for security), access control, deletion schedule
Analytics and trackingCookie or device-level access generally needs consent under the ePrivacy rules; IP-based analytics platforms still fall under GDPR obligations
Anti-abuse and fraud preventionLegitimate interest, but document the necessity and keep retention proportionate — see IP reputation
Privacy policySay that IP addresses are processed, why, for how long, and who receives them
Access requestsBe able to search what you hold for a given IP — or explain honestly why you cannot link it
Geolocation lookupsPassing an IP to ipwho.is, ipquery.io or any lookup API is processing; disclose the recipients, as our own privacy policy does

Two clarifications worth holding on to: hashing or pseudonymising an address does not automatically anonymise it — the legal test is re-identifiability, not the format. And the fact that an address is personal data does not mean you cannot log it; it means you must have a reason, a basis and a limit.

Beyond the EU

Comparable regimes treat IP addresses similarly: the UK GDPR after Brexit, Brazil's LGPD, and various national laws that import the GDPR's definition. In the United States there is no general federal equivalent — an IP address is often not considered personally identifiable information on its own — but state privacy laws, sectoral rules and the FTC's stance on deceptive privacy claims still constrain what you can do with it. If you serve a global audience, the GDPR test is the safest baseline: assume identifiability, document your purpose, and keep retention short.

Bottom line: an IP address is personal data for anyone who could realistically identify the person behind it — which, in 2026, is most organisations. Plan for consent, disclosure and retention rather than arguing about the definition.

Frequently asked questions

Is an IP address personal data under the GDPR?

Yes, whenever the organisation processing it has means reasonably likely to identify the person — the standard set in the CJEU's Breyer judgment and applied since. Static, corporate and logged dynamic addresses typically qualify.

Can a website store my IP address legally?

Yes, with a lawful basis and a purpose: security logging, fraud prevention and legal obligations are common grounds. It must be disclosed, kept secure and deleted after a proportionate period.

Does hashing an IP address make it anonymous?

Not automatically. Pseudonymised data remains personal data where re-identification is realistically possible — for example by brute-forcing the small address space. Treat hashed addresses as personal unless a documented analysis proves otherwise.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.