CJEU Decision on Dynamic IP Addresses: Does it impact fundamental data protection law?
15th May 2023
CJEU Decision on Dynamic IP Addresses: Does it impact fundamental data protection law?
[REMINDER]
The European Court of Justice (CJEU) issued a significant judgment in Case C-582/14: Patrick Breyer v Bundesrepublik Deutschland (2016), which may have significant repercussions.
Let’s begin by defining an IP address because that is the crux of this decision.
What is an IP address?
An IP address, or internet protocol address, is a label made up of numbers assigned by your Internet Service Provider (ISP) to identify your network or device and provide a general indication of its geographic location. It plays a crucial role in distinguishing various websites, devices, and networks on the Internet, making it an essential component for the functioning of the world wide web as a whole.
Every device possesses both an external (public) IP address and an internal (private) IP address. The external address is associated with your home or business and specifically identifies your router. On the other hand, internal addresses are assigned to individual devices within your network, enabling differentiation among them and facilitating communication within your home or office setup.
A static IP address remains constant, allows continuous identification of a specific device, and is most common for businesses and organisations.
A dynamic IP address is an IP address assigned to a device temporarily by an ISP when it connects to a network.
A dynamic IP address is subject to change each time the device connects or disconnects from the network. This dynamic allocation of IP addresses is commonly used by ISPs to efficiently manage their pool of available addresses and accommodate a large number of users without running out of IP addresses. If you use a Virtual Private Network (VPN), your original IP address is replaced with a rotating IP address.
Dynamic IP addresses are most commonly used in homes.
What does the CJEU Decision on Dynamic IP Addresses state?
The CJEU’s judgment determined that dynamic IP addresses can be classified as personal data for website operators if there is a means to identify the visitor through additional data held by a third party, such as an internet service provider (ISP).
This has implications for data protection legislation, as any data that makes it possible to identify a living individual falls under the rules of the GDPR.
The judgement does leave us with a grey area.
The court stated that this is SUBJECTIVE / RELATIVE, i.e. if it is legally and practically possible for the website operator (the company or organisation) to obtain additional data from the ISP to identify the visitor, then the dynamic IP address is considered personal data.
Additionally, the CJEU addressed the lawful basis of processing and stated that consent was not always necessary and that the legitimate interest of the organisations operating the websites and their need to ensure the functioning of their websites was acknowledged. Therefore, they should be able to collect and use the IP address of a visitor’s device for operability purposes, even after the visitor disconnects from the website.
The judgment concerns the treatment of IP addresses as personal data, particularly dynamic IP addresses. However, the practicality of the subjective/relative criteria makes it challenging for website operators to determine whether additional data from an ISP can identify a particular IP address at the time of collection.
As a result, organisations may opt to treat all IP addresses as personal data to ensure compliance.
Further consideration should be given to using login, cookies, trackers, and other online identifiers that can also link a dynamic IP address to a specific individual and are already protected under ePrivacy legislation (PECR).
What should I do now?
The CJEU’s decision provides important insights into the classification of personal data and the role of legitimate interests in data protection. As business owners and organisations, you should carefully consider the implications of this ruling on your data processing practices, particularly concerning dynamic IP addresses and profiling activities.
It is advisable to assess data protection practices on a case-by-case basis, considering the legal and practical means to identify individuals.
How easy is it for you to do this?
At the moment, there doesn’t seem to be a definition of what is ‘practical’, so a common-sense approach will need to be taken.
The CJEU’s judgment is likely to have a broader impact on the definition of personal data, going beyond dynamic IP addresses due to the issue regarding the data holder’s ability to identify individuals by combining it with third-party knowledge – the question now arises – what other data do you hold, that when combined with another set of data that is easy to access, makes it personally identifiable?
If anything is certain in the world of data protection, it is that it keeps us on our toes! If you need any help, please take advantage of your complimentary thirty-minute consultation here.