An IP address is the number that lets websites and services send data back to a device or its network. In UK data protection law, the question is whether that number counts as “personal data”, and the answer affects what websites, apps and VPN providers may do with it. This article summarises the Information Commissioner’s Office (ICO) guidance on identifiers under the UK GDPR, and explains what that means for people who use VPNs. It concerns the UK GDPR as described by the ICO. The ICO’s pages carry a notice that the guidance is under review following the Data (Use and Access) Act, so the current text should be checked.
The legal test: identifiable, not named
The ICO says personal data is information that relates to an identified or identifiable individual. What identifies a person could be as simple as a name or a number, or could include other identifiers such as an IP address or a cookie identifier, or other factors. Its guide explains that if a person can be distinguished from other individuals, they are “identified” or “identifiable”. Whether any potential identifier actually identifies someone depends on the context. For information that does not directly identify a person, the ICO says to consider whether the person is still identifiable, taking into account the information together with all the means reasonably likely to be used by either the organisation holding it or any other person to identify the individual.
Online identifiers
The UK GDPR specifically includes the term “online identifiers”. According to the ICO, these may include information relating to the device an individual is using, applications, tools or protocols. Recital 30 gives a non-exhaustive list of internet protocol (IP) addresses, cookie identifiers and other identifiers such as radio frequency identification (RFID) tags. The ICO adds other examples that may be personal data: MAC addresses, advertising IDs, pixel tags, account handles and device fingerprints. It explains that the use of these may leave traces which, when combined with unique identifiers and other information received by servers, may be used to create profiles of individuals and identify them.
The ICO says that when assessing identifiability, an organisation must consider whether online identifiers, on their own or in combination with other information, may be used to distinguish one user from another. This may be as a named individual or simply as a unique user of electronic communications and other internet services. One of its examples is that using cookies or similar technologies to track an individual across websites involves personal data if the tracking uses online identifiers to create a profile. It also gives the example of a social media username that seems anonymous but is personal data if it distinguishes one individual from another, regardless of whether the online identity can be linked to a real-world name.
What the ICO does not say
The guidance does not say that every IP address is always personal data in every hands. Its test is contextual: identifiability depends on the information available and the means reasonably likely to be used. Nor does it discuss VPNs. Any statement about the effect of a VPN on identifiability is therefore an application of the ICO’s test rather than something the ICO states.
Applying the test to VPN use
With a VPN, the website sees an address belonging to the VPN provider rather than the household’s connection. What that means for identifiability depends on what other information exists. The ICO’s framing points to two questions. First, can the website, on its own or with other information such as account details or cookies, still single out the user? The ICO’s examples about cookies and usernames show that identifiers other than an IP address can also single out a user. This is the same point the site’s guide to browser fingerprinting makes from the technical side. Second, what does the VPN provider itself hold? A provider that keeps records linking a customer’s account, payment details and connection times is processing data that relates to identifiable people. The site’s guide to logging policies and independent audits explains how “no-logs” statements are claims that audits may or may not test.
What follows for users and providers
- For users. An IP address can be part of the data a site holds about a visit, and under the ICO’s guidance it may count as personal data. For the EU side of the law, see the site’s guide to VPNs and GDPR.
- For providers. The ICO says that where it is uncertain whether information is personal data, as a matter of good practice it should be treated as though it is: kept secure, protected from inappropriate disclosure, collected openly and justified.
- For comparing services. Statements about what a provider does with IP addresses belong in its privacy policy and are the provider’s own claims unless independently verified.
Common questions
Is an IP address personal data? The ICO lists it as an identifier that may allow identification, and treats it as personal data where the user can be singled out, on its own or with other information.
Does a VPN stop a website identifying me? The ICO guidance does not address VPNs. Its test looks at whether the person can be distinguished from others by any information available, not only by IP address.
The bottom line
Under UK GDPR guidance from the ICO, an IP address can be personal data because it is an online identifier that may, alone or combined with other information, distinguish one user from another. The ICO does not discuss VPNs, so how a VPN changes identifiability depends on what other identifiers a website has and what the VPN provider records. Users comparing services should treat logging and privacy statements as provider claims unless independently verified. This is general information about UK guidance, not legal advice.