TL;DR, Quick Answer
7 min readUnder the GDPR, an IP address is personal data in the hands of a controller that has legal means to identify the person behind it, which is the test the Court of Justice of the European Union applied to dynamic IP addresses in Breyer, Case C-582/14. The Court did not rule that every IP address is personal data for everyone who holds one. United States law gives no single answer: California's CCPA names Internet Protocol address in its statutory list of identifiers, while Virginia's law defines personal data by a linkability test and never mentions IP addresses.
Is an IP address personal data under the GDPR?
A site operator asking "is an IP address personal data" gets a yes under the GDPR whenever that operator has the legal means to identify the person behind the address, which is exactly how the Court of Justice of the European Union framed the answer for dynamic IP addresses in Breyer, Case C-582/14, decided on 19 October 2016. The mechanism is indirect identification: GDPR Article 4(1) defines personal data as information relating to a person "who can be identified, directly or indirectly", so the controller does not need to hold every piece of the puzzle itself. Anyone logging visitor IP addresses therefore has to ask a question about their own position, not about IP addresses in the abstract.

What did the CJEU actually decide in Breyer?
The Court ruled that a dynamic IP address logged by an online media services provider is personal data in relation to that provider "where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person". Patrick Breyer had sued the Federal Republic of Germany over federal websites that stored the IP address of every visitor in their logfiles, and the German court asked whether those addresses counted as personal data for the website operator when only the access provider held the subscriber records. The Court answered by pointing at German law: at paragraph 47 of the judgment it noted that in the event of cyber attacks, "legal channels exist so that the online media services provider is able to contact the competent authority", which can then obtain the subscriber information from the internet service provider.
Two details get lost in most summaries. Breyer interprets Article 2(a) of Directive 95/46, the law the GDPR replaced in 2018, not Article 4(1) of the GDPR. And the case concerned dynamic addresses, which the Court distinguished at paragraph 36 from static addresses that "allow continuous identification of the device connected to the network".
Does Breyer mean every IP address is personal data?
No. The Court set a limit in the same judgment, at paragraph 46: the combination of an IP address with data held elsewhere is not a means "likely reasonably to be used" where identification "was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant". A blanket claim that IP addresses are always personal data for everyone skips that paragraph and skips the conditional wording of the ruling itself.
The Court restated that relative approach in EDPS v SRB, Case C-413/23 P on 4 September 2025, holding at paragraph 86 that pseudonymised data "must not be regarded as constituting, in all cases and for every person, personal data for the purposes of the application of Regulation 2018/1725". That regulation covers the EU institutions rather than the GDPR, though the Court found at paragraph 52 that the two definitions of personal data are essentially identical. At paragraph 83 it read Breyer as turning on whether the controller "had legal means of obtaining additional information from another person making it possible to identify the data subject".
Where does the GDPR text itself address IP addresses?
GDPR Recital 30 names them directly, saying natural persons "may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers". Recital 26 supplies the deciding test: "account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person", weighing "the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing". Recital 30 says association is possible, and Recital 26 resolves each case. The controller runs that assessment, not the processor logging addresses on its instructions, a split covered in the difference between a data controller and a data processor.
Is an IP address personal information under US law?
California answers yes by name, and other states answer by test, not by list. Cal. Civ. Code section 1798.140 includes "Internet Protocol address" in the identifier list at subdivision (v)(1)(A) and again in the definition of "unique identifier" at subdivision (aj). Both sit under the opening condition of (v)(1), which reaches information "reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household", and (v)(2) and (v)(3) carve out publicly available, deidentified and aggregate data.
Virginia took the other drafting route. Va. Code section 59.1-575 defines personal data as "any information that is linked or reasonably linkable to an identified or identifiable natural person" and excludes de-identified data and publicly available information, with no list of example identifiers and no mention of IP addresses. A third federal rule treats the same string as a hard identifier: the HIPAA Safe Harbor method at 45 CFR 164.514(b)(2)(i)(O) requires a covered entity to remove "Internet Protocol (IP) address numbers" before health information counts as de-identified.
| Source | What it says about IP addresses | Test applied |
|---|---|---|
| GDPR Article 4(1) | No mention by name | Identified or identifiable, directly or indirectly |
| GDPR Recital 26 | No mention by name | All means "reasonably likely to be used", by the controller or another person |
| GDPR Recital 30 | Lists "internet protocol addresses" as online identifiers | Persons "may be associated with" them |
| CJEU, Breyer C-582/14 | Dynamic IP address is personal data for the site operator | Operator has legal means to identify with ISP data |
| Cal. Civ. Code 1798.140(v)(1)(A), (aj) | Names "Internet Protocol address" twice | Reasonably capable of association with a consumer or household |
| Va. Code 59.1-575 | No mention | Linked or reasonably linkable |
| 45 CFR 164.514(b)(2)(i)(O) | "Internet Protocol (IP) address numbers" must be removed | Removal of enumerated identifiers |
What is still unsettled?
The threshold where "reasonably likely" identification stops is unsettled, and none of the sources above fixes it as a number. Recital 26 lists cost, time and available technology as the factors, Breyer paragraph 46 sets the floor at prohibited by law or practically impossible, and C-413/23 P confirms the assessment is made per holder, not once for all holders, so the same address can be personal data for one party and not for another.
This page describes what the cited instruments and judgments say, and is not legal advice.

What does this mean for analytics logs?
Any tool that writes visitor IP addresses to storage holds data the tests above can classify as personal, so the first question is what the tool retains and for how long. Flowsery is cookie-free, EU-hosted and GDPR by design, and its privacy-first analytics approach sits alongside the Flowsery GDPR page. Identifiers that do the same work appear in how browser fingerprinting identifies you without a cookie, tracking without cookies and the identifiers Google Analytics collects. On how the two regimes differ elsewhere, see CCPA versus GDPR and sensitive personal data under the GDPR.
Frequently Asked Questions
Is a dynamic IP address personal data under the GDPR?
A dynamic IP address is personal data in relation to a controller that has the legal means to identify the person, which is the holding of Breyer, Case C-582/14. The Court reached that result even though the site operator held no subscriber records, because German law gave it a route through a competent authority to the internet service provider.
Did Breyer rule that IP addresses are always personal data?
No. The ruling is conditional on the words "where the latter has the legal means which enable it to identify the data subject". Paragraph 46 of the judgment carves out cases where identification is prohibited by law or practically impossible, so that the risk of identification "appears in reality to be insignificant".
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Does the GDPR name IP addresses anywhere?
Recital 30 names "internet protocol addresses" as an example of online identifiers that natural persons may be associated with. Article 4(1) does not name them, and Recital 26 supplies the identifiability test that decides whether a given address qualifies in a given controller's hands.
Does the CCPA treat an IP address as personal information?
California's statute lists "Internet Protocol address" in the identifier category at Cal. Civ. Code section 1798.140(v)(1)(A) and again in the definition of "unique identifier" at section 1798.140(aj). Both sit under the opening condition of subdivision (v)(1), that the information be reasonably capable of association with a particular consumer or household.
Do all US states answer this question the same way?
They do not. Virginia's Consumer Data Protection Act defines personal data as information "linked or reasonably linkable" to a person and lists no example identifiers, while California enumerates IP addresses in the statute. HIPAA takes a third path, requiring removal of IP address numbers under the Safe Harbor de-identification method at 45 CFR 164.514(b)(2)(i)(O).
Which law applies when a US company logs IP addresses of EU visitors?
GDPR Article 3(2) extends the regulation to controllers not established in the Union where the processing relates to offering goods or services to people in the Union, or to "the monitoring of their behaviour as far as their behaviour takes place within the Union". A US company can therefore fall under the GDPR test and a US state test for the same log line. Which obligations follow from each is a separate question from whether the address is personal data.
Does HIPAA treat IP addresses as personal information?
HIPAA's Safe Harbor de-identification method, at 45 CFR 164.514(b)(2)(i)(O), requires a covered entity to remove "Internet Protocol (IP) address numbers" before health information counts as de-identified. That sits alongside the GDPR's identifiability test and California's statutory list as a third approach: a flat requirement to strip the identifier rather than a case-by-case judgment.
Does California's IP address rule cover publicly available or deidentified data?
The carve-outs in Cal. Civ. Code section 1798.140(v)(2) and (v)(3) exclude publicly available, deidentified and aggregate data from the identifier list in (v)(1). The address named in (v)(1)(A) only counts as personal information when it meets the opening condition of (v)(1): reasonably capable of association with, or reasonably linked to, a particular consumer or household.
Can the same IP address be personal data for one company but not another?
EDPS v SRB, Case C-413/23 P, confirms it can be. The CJEU held that pseudonymised data is not automatically personal data for every holder, reading Breyer as turning on whether a given controller had legal means to identify the person. Breyer's own paragraph 46 backs this up: when identification would require a disproportionate effort, the risk of identification appears insignificant for that holder, even though the same address might identify someone else with more resources.
Who runs the identifiability assessment, the controller or the processor?
The controller runs the identifiability assessment, not the processor that logs IP addresses on the controller's instructions. Recital 26 frames the test as weighing the costs and time required for identification, a judgment tied to whoever decides why the data is processed, which is the controller's role under the GDPR.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Glossary Terms


Reversibility decides pseudonymisation vs anonymisation under the GDPR
Reversibility decides pseudonymisation vs anonymisation. Article 4(5) data stays personal data. Recital 26 anonymous data leaves the GDPR for good.


Understanding CPRA, California's privacy rights act
The CPRA amended the CCPA in 2023, adding sensitive personal information rules, a right to correct data, and a dedicated enforcement agency, the CPPA.


Where the Do Not Sell or Share My Personal Information link must appear
California puts the Do Not Sell or Share My Personal Information link in a homepage header or footer, with the exact title fixed by Civil Code 1798.135.


The Test That Settles Data Controller vs Data Processor
The GDPR test for data controller vs data processor is who determines the purposes and means. What each role signs, owes, and does when a breach hits.


Google Lists Seven Separate Causes of not set in GA4
Google's docs give not set in GA4 a different cause per dimension, from a missing session_start to an empty content_group. Here is each cause and its fix.
What Server Side Tracking Fixes, and What It Leaves Untouched
Learn what server side tracking moves to your own server, which Safari cookie caps it escapes, how to deduplicate events, and why consent obligations stay.
Related Articles


What the Numbers Say About Average Bounce Rate by Industry
Nine tracked industries return a documented average bounce rate by industry ranging from 35.76% to 48.38%, sourced from Databox data dated September 2024.


Working Through the Average Order Value Formula Step by Step
The average order value formula divides revenue by orders, and a single discount code or return policy can quietly distort every number a team reports.


How B2B and B2C Sites Compare on Average Session Duration Benchmarks
Databox's own data puts average session duration benchmarks at 77.61 seconds for B2B sites and 92.33 seconds for B2C sites, split by industry and device too.

