A startup processes only IP addresses and argues they can never be personal data. Which GDPR position is correct?
Select an answer to reveal the explanation.
Short Explanation
An IP address can be a digital nametag when it points back to a person with reasonably available means—ISP logs, account records, the usual toolkit. “We only store IPs” is not a free pass out of GDPR if identification is still on the table.
Full Explanation
Recital 30 and Article 4(1) GDPR recognise online identifiers as examples of identifiers that may render a natural person identifiable. CJEU case law (for example on dynamic IP addresses) confirms that IP addresses can constitute personal data when identification is reasonably possible. Absolute categorical exclusion is incorrect; neither a public court naming nor co-storage with a passport is a universal prerequisite.