Privacy International (PI) published the article Are IP addresses personal data? In the article PI explains what an IP address is and informs the reader on the decisions of the Court of Justice of the European Union.
On the character of the IP address PI writes:
Every time you visit a website or use some other Internet service, you need to tell the other party where you connected from so they can send information back to you. That means giving out your IP address widely and frequently (including to those who place their content on other people’s websites, such as advertisers). As such, IP addresses can, in practice, be used to track and identify us in various ways. They are frequently used within the advertising industry to assist with targeted advertising. They can also be used to help with the geolocation tracking of individuals (even though the location of an IP address may not always match the device’s location). (…)
the UK’s data protection regulator, the Information Commissioner’s Office (ICO) describes IP addresses as ‘online identifiers’; a digital means of identifying an individual within information, which makes it ‘identifiable’ and therefore personal data. IP addresses are also considered to be an ‘online identifer’ within recital 30 of the GDPR which explicitly lists IP addresses as an example.
VPN-protection
The use of IP adresses by advertising companies like Google and Meta and by criminals to follow their targets, is a good reason to use a VPN. That is something that does not seem to be known by law enforcement agencies (LEAs). They want obliged entities (‘OEs’, companies with AML-duties, like banks) to use IP addresses to detect potential criminal activity.
An example of that is found in the draft rules by the Authority for Countering Money Laundering and Financing of Terrorism (AMLA) on ongoing monitoring by OEs [*], marking by me:
27. The following non-exhaustive list of events are provided as instances of what may trigger a review of customer information (…)
b) Behavioural, activity-based or transactional anomalies: unusual transaction patterns, inconsistent behaviour, frequent and unexplained changes of professional service providers, repeated or unusual changes in IP address or device location, where relevant, or any activity that deviates from the customer’s profile or from the expected purpose and intended nature of the business relationship. Obliged entities should consider AMLA’s guidelines pursuant to Article 69(5) AMLR on indicators of suspicious activity or behaviors.
Perhaps the AMLA and the LEAs need some extra training in the areas of cybersecurity and protection against tracking
[*] Page 27 of the consultation document. More information on the consultation: announcement, consultation page, consultation document, my article in Dutch.

