Dynamic IP-addresses can be "personal data" says EU Court of Justice

Dynamic IP-addresses can be "personal data" says EU Court of Justice

Today, the European Court of Justice decided on the question whether or not dynamic IP-addresses constitute "personal data" in the sense of the European data protection legislation (Case C-582/14). 

The full text of the judgment can be found here

The court confirms that the dynamic internet protocol address of a visitor constitutes personal data, with respect to the operator of the website, if that operator has the legal means allowing it to identify the visitor concerned with additional information about him which is held by the internet service provider.

This means that in such cases website operators do need to act in compliance with data protection legislation when processing such dynamic IP-addresses. The operator of a website may however have a legitimate interest in storing certain personal data relating to visitors to that website in order to protect itself against cyberattacks, and does not need to ask for consent from the website visitor.

The ruling is relevant for any website collecting dynamic IP-addresses. The Court leaves room for deciding in each case whether or not dynamic IP-addresses form personal data.

In practice, this means that the following criteria should be used when deciding if dynamic IP-addresses are personal data in a specific situation:

  1. It is not necessary that the dynamic IP addresses alone allows the data subject to be identified, if additional data could help to identify the person.
  2. It is not required that all the information enabling the identification of the data subject must be in the hands of one person.
  3. It must be decided in each case whether the possibility to combine a dynamic IP address with the additional data held by the internet service provider constitutes a means likely reasonably to be used to identify the data subject
  4. That would not be the case if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant

No doubt, and as always with EU Court judgements, food for further consideration!

Erwin AM Geirnaert

Co-founder | Entrepreneur | Chief Hacking Officer | Certified Professional Penetration Tester (eCPPT) | Web Application Penetration Tester (eWPT) | Ethical Hacker | Cloud Security Specialist | Shift Left Security

8 å¹´

This is a big problem for everybody that has a website. All incoming requests log the source IP in a clear-text logfile. This is default behavior of the webserver.

JP Buckley

Advising clients on data issues in many sectors - providing insights and guidance - Partner and DWF Regional Data Protection and Cyber Security Leader

8 å¹´

Thank you Patrick, another important judgment on the scope of "personal data".

要查看或添加评论,请登录

Patrick Van Eecke的更多文章

  • Brexit & GDPR

    Brexit & GDPR

    My great colleagues Andrew Dyson and James Clark just posted below summary of the Brexit impact on GDPR based on the…

    5 条评论
  • GDPR class actions initiated in Europe

    GDPR class actions initiated in Europe

    “My Data is Mine” If you are taking the tube in Brussels nowadays, you may see an advertisement inviting Facebook users…

    5 条评论
  • Good news: Free flow of personal data from EU to Japan soon possible

    Good news: Free flow of personal data from EU to Japan soon possible

    On 17 July 2018 the European Union and Japan agreed to recognise each other’s data protection systems as ‘equivalent’…

  • Data Protection: EC warns that UK becomes "third country" on 30 March 2019.

    Data Protection: EC warns that UK becomes "third country" on 30 March 2019.

    The European Commission publicly announced that, because of Brexit, anybody transferring personal data to the United…

    2 条评论
  • The new Belgian Data Protection Authority: leaner and (probably) meaner

    The new Belgian Data Protection Authority: leaner and (probably) meaner

    On 25 May 2018, the Belgian Privacy Commission will be renamed “Belgian Data Protection Authority” (BDPA) and will gain…

    3 条评论
  • CANADA: What will the European General Data Protection Regulation mean for Canadian employers?

    CANADA: What will the European General Data Protection Regulation mean for Canadian employers?

    By Tamara Hunter and Patrick Van Eecke If you are an employer in Canada, you need to be aware of the European General…

  • 1000 downloads of our GDPR app in first 48 hours!

    1000 downloads of our GDPR app in first 48 hours!

    The EU General Data Protection Regulation, which comes into force in May 2018, will introduce some of the most…

    18 条评论
  • CNIL publishes 6 steps approach for compliance with GDPR

    CNIL publishes 6 steps approach for compliance with GDPR

    The French Data Protection Authority CNIL published a 6-step methodology for companies that want to prepare for the…

  • China adopting new data protection and cybersecurity rules.

    China adopting new data protection and cybersecurity rules.

    My great colleagues in Hong Kong Scott Thiel and Carolyn Bigg report on new changes coming into effect in China in June…

    1 条评论
  • "Let the data flow!", Europe says.

    "Let the data flow!", Europe says.

    Earlier this month, the Commission published its document titled ‘European free flow of data initiative within the…

    1 条评论

社区洞察

其他会员也浏览了