logo Lawwwing

Is an IP address personal data? The GDPR, CJEU and AEPD’s answer

The question of whether an IP address constitutes personal data for the purposes of data protection regulations has been the subject of intense legal debate, progressively resolved by the Court of Justice of the European Union (CJEU), the former Article 29 Working Party, and, in Spain, by the Spanish Data Protection Agency (AEPD). In this […]
Legal Lawwwing
October 5, 2026

The question of whether an IP address constitutes personal data for the purposes of data protection regulations has been the subject of intense legal debate, progressively resolved by the Court of Justice of the European Union (CJEU), the former Article 29 Working Party, and, in Spain, by the Spanish Data Protection Agency (AEPD).

In this article, we will analyze how each of these bodies has ruled on the matter.

1. The European regulatory framework: the GDPR

First, we need to look at the definition of "personal data" provided by Article 4.1 of the General Data Protection Regulation (GDPR):

"any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."

Therefore, under this provision, personal data is considered to be any information relating to a natural person who is identified or who can be identified, directly or indirectly. For a clearer definition, recitals 26 and 30 of the Regulation itself elaborate on this content.

As we have seen, Article 4.1 states that a person is "identifiable" if their identity can be determined directly or indirectly, and recital 26 sets out the aspects that must be taken into account when assessing the possibility of identification:

  • All the means reasonably likely to be used by the controller or by any other person (not just the controller) must be taken into account.
  • And to determine whether those means are reasonable, three factors must be assessed: cost, time, and available technology.

We have also seen that Article 4.1 generically mentions online identifiers as an example of data that can make someone identifiable. Recital 30 elaborates on this, mentioning: internet protocol (IP) addresses, cookies, or radio frequency identification tags. Therefore, this recital directly refers to the IP address as data that can identify a person.

This article and these recitals will be the fundamental provisions on which the CJEU will base its rulings when deciding whether an IP address is considered personal data.

2. The position of the Article 29 Working Party

The Article 29 Working Party specifically addressed this issue in its Opinion 4/2007 on the concept of personal data.

The Working Party considered IP addresses to be data relating to an identifiable person, noting that Internet access providers and local network administrators can, by reasonable means, identify the users to whom they have assigned IP addresses, since they systematically log the date, time, duration, and dynamic IP address assigned to each user. The same applies to Internet service providers that maintain a log file on the HTTP server. In these cases, the opinion concludes, there is no doubt that this can be referred to as personal data.

The opinion particularly highlights cases where the processing of IP addresses is carried out for the purpose of identifying computer users, for example, when copyright holders seek to sue users for intellectual property infringement. In such cases, the data controller anticipates that the means reasonably likely to be used to identify individuals can be obtained through the competent courts, meaning the information must be considered personal data.

The opinion also considers a particular case: IP addresses assigned to computers installed in internet cafés, where customers are not asked for any identification. In this scenario, it could be argued that the data collected on the use of a specific computer during a particular time slot does not allow the user to be identified by reasonable means and would therefore not constitute personal data.

However, the Working Party itself warns that, in practice, Internet service providers are not usually certain whether a specific IP allows for identification or not. For this reason, the most prudent approach is to treat all IP addresses as if they were personal data, unless there is absolute certainty that they are not.

In summary, for the Working Party, an IP address is personal data whenever there is a reasonable possibility of linking it to an individual, whether directly or through additional information held by third parties.

3. The doctrine of the Court of Justice of the European Union

The Breyer ruling (C-582/14) is the leading decision on this matter. The Court draws a distinction between static and dynamic IP addresses.

Unlike static addresses, dynamic IP addresses do not, through publicly accessible files, allow a specific computer to be linked to the physical network connection used by the access provider.

As a general rule, the Court had already previously established that IP addresses are personal data for Internet access providers (ISPs), since they can directly identify their users.

The more complex issue arises with regard to dynamic IP addresses retained by a website operator. In this case, the ruling concludes that the IP address is considered personal data if the operator has legal means available that would allow it to identify the user with the help of additional information held by a third party, such as the Internet access provider.

The Court also reaffirms the criterion of indirect identification: data is personal not only when it allows someone to be identified directly, but also indirectly. Here we should recall the recitals of the GDPR mentioned earlier, which state that, in order to determine whether a person is identifiable, all means reasonably likely to be used must be considered, whether by the data controller or by any other person.

However, the ruling also sets a limit: data is not considered personal if identification would be practically impossible or prohibited by law, for example, if it would require a disproportionate effort in terms of time, cost, and human resources. Even so, the Court notes that, in the case of cyberattacks, there are legal avenues for obtaining the user's identity through the authorities and the Internet access provider, which reinforces the personal-data status of the IP address in these cases.

In conclusion, the Breyer ruling establishes that a dynamic IP address is personal data for an online service provider if that provider has the legal means to identify the data subject by resorting to the additional information held by the Internet access provider.

This more recent judgement confirms and develops the Breyer doctrine. In paragraph 83, the Court recalls that, in line with its previous case law, data which is impersonal in itself, collected and retained by the data controller, is linked to an identifiable person when the controller has legal means available to obtain from third parties the additional information that allows that person to be identified. The Court considers that the fact that the information necessary for identification is held by different parties does not prevent the identification of the data subject by the controller.

The judgement also notes that impersonal data can acquire personal character when the controller makes it available to other persons who have means that could reasonably enable the identification of the data subject. In that context, such data is of a personal nature both for those other persons and, indirectly, for the controller itself.

Finally, the CJEU states that if it cannot be ruled out that a third party is capable of attributing that pseudonymized data to a specific person (for example, through cross-referencing), the data subject must be considered identifiable. Therefore, under such circumstances, pseudonymized data must be considered personal data.

4. The position of the Spanish Data Protection Agency (AEPD)

In Spain, the AEPD has repeatedly and consistently maintained that an IP address is personal data, regardless of whether it is static or dynamic in nature.

In its Report 0261/2012, drawing on a ruling by the Audiencia Nacional (National High Court), the AEPD concludes that an IP address is personal data based on the criterion of identifiability. For this reason, if an IP address allows someone to be identified, it must be subject to the same safeguards as any other personal data.

Subsequently, Report 0005/2016 consolidates this position, noting that the Agency has repeatedly affirmed that an IP address is to be considered personal data. The AEPD holds that the possibility of identifying an internet user exists in many cases and, therefore, IP addresses (both static and dynamic) are considered personal data.

Conclusion

Taken together, the regulatory sources and case law lead to the conclusion that an IP address, whether static or dynamic, tends to be classified as personal data whenever there is a reasonable possibility (whether directly or through third parties) of linking it to an identifiable natural person. The CJEU has progressively refined this criterion of reasonable identifiability throughout its case law, from the Breyer ruling to the more recent EDPS v. SRB decision, reinforcing the idea that the mere existence of legal avenues to obtain additional information from a third party (such as an Internet access provider) is sufficient to attribute personal-data status to the information. In Spain, the AEPD has adopted an even more protective criterion, considering that any IP address, regardless of its type, constitutes personal data.

In practice, this means that any controller or processor that collects, retains, or processes IP addresses must do so in accordance with the safeguards and principles of the GDPR, including having an appropriate legal basis, complying with the duty to inform, and applying the corresponding security measures.

How can we help you?
If you have any questions, our specialists are here to assist you whenever you need it.
Live Chat
Share this article
Blog

Related Articles

Businesses trust Lawwwing to ensure their legal compliance, keeping their documents up-to-date and avoiding penalties.
cross