> Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time.
That's actually the most frightening thing I've heard in a long time. Does the GDPR actually make that connection? If so, it literally links people to an IP address, rather than simply a connection.
If that line is accurate, I'm surprised it hasn't been mentioned before, associating an IP address to an specific person. I have to believe you are wrong, otherwise the legal implications are scary.
For those that don't understand: my concern is that in the US, for a long time, in copyright claims by the RIAA or MPAA, for example, was to go after someone because of an IP address, a common defense was basically: An IP Address is not a person. The above commenter made the claim that an IP address alone can be associate a specific person. So, I'm wondering if 1) that's accurate and 2) what are the ramifications of an IP address being a person in the world of law enforcement?
No, the GDPR does not actually link people to an IP address. The GDPR never even refers to an IP Address, and where it refers to an Internet address, it is clear it's referring to email addresses.
The ICO (furthermore) has given guidance that they don't think an IP address is uniquely identifying an individual, and have confirmed this to me on the phone.
Where you get into trouble is in transmitting your browser logs/activity to a third party who wants to keep them for their own purposes (e.g. Google). In this circumstance, you have to let people know that you've done this, and to transmit their preferences that you receive onward.
Yes, it explicitly mentions it, because it's actually very often true. Of course there are plenty of examples where it would be extremely difficult to link to an individual, but there are tonnes of examples where it's extremely easy. GDPR says that because it's sometimes easy, you have to consider it personal data.
Again, it's not always saying an IP address is a personal identify. It just is often enough.
> Again, it's not always saying an IP address is a personal identify. It just is often enough.
Well, that's not what you said or implied. I'm just thinking of all the cases in the US were the defense is you can't assume that an IP address ties to a specific person. Anyone could use the computer, or someone could attach to an open wifi.
Basically, if the legal argument is the IP address can be associated with a person, that raises legal concerns.
I said they can be used to identify an individual in a moment in time. That's correct.
Can it always identify an individual? No. Is the standard of identification good enough for a criminal case? Certainly not. But why are you comparing these? The GDPR is a standard about privacy and data protection; a UK postcode (like a zip code in the US) is considered personal data for exactly the same reason.
That's actually the most frightening thing I've heard in a long time. Does the GDPR actually make that connection? If so, it literally links people to an IP address, rather than simply a connection.
If that line is accurate, I'm surprised it hasn't been mentioned before, associating an IP address to an specific person. I have to believe you are wrong, otherwise the legal implications are scary.
For those that don't understand: my concern is that in the US, for a long time, in copyright claims by the RIAA or MPAA, for example, was to go after someone because of an IP address, a common defense was basically: An IP Address is not a person. The above commenter made the claim that an IP address alone can be associate a specific person. So, I'm wondering if 1) that's accurate and 2) what are the ramifications of an IP address being a person in the world of law enforcement?