The Shift to IP Address Band-Aids In A Cookie-Less World

Diagram showing an IP address being used to identify a device for ad personalisation, with a consent requirement flagged under European privacy law
The stopgap identity signal just became a formally regulated one, not an obsolete one.

IP-based targeting was never a great identity solution, it was a workaround. Chrome keeping third-party cookies didn’t retire it. Google’s own move to formally use IP addresses for ad personalisation in Europe from August 2026 confirms the opposite: this “band-aid” identity signal is now a compliance-relevant one.

An IP address was never designed as an identity signal. It identifies a connection point, a household router, a corporate network, a mobile carrier’s shared address pool, not a specific person. Advertisers reached for it anyway once cookie-based tracking came under pressure, because it was available, persistent enough to be useful, and mostly unregulated. That last part just stopped being true.

Why IP address became a fallback signal in the first place

IP-based targeting and measurement filled gaps that cookies and device identifiers couldn’t, cross-device household matching, geographic targeting at a granularity cookies don’t provide, and basic fraud and bot detection. It was always a blunt instrument: an IP address representing a household of five people, a shared office network, or a rotating carrier-assigned address is a genuinely weak proxy for an individual. Treating it as a precise identity signal was always the workaround, not the solution.

Google’s August 2026 shift changes the compliance picture

From 3 August 2026, Google began using IP addresses to identify devices for ad measurement and personalisation across the European Economic Area, the UK and Switzerland, a formal expansion beyond the traffic-routing and fraud-prevention uses IP addresses were previously put to. Because this use case falls under personalisation rather than legitimate interest, Google is registering it under Feature 3 of IAB Europe’s Transparency and Consent Framework, meaning it now requires the same cookie-style consent flow most users are already used to seeing. The practical effect: accepting cookies on a site running this framework will, in most cases, mean also consenting to IP-based ad personalisation, whether the user notices that specific line item or not.

The timing is worth sitting with. This shift landed a little over a year after Google reversed course on cookie deprecation entirely. Read together, the two moves tell a coherent story: Google didn’t step back from using persistent identifiers to power advertising, it just redistributed which identifiers carry that weight, and formalised the consent obligations attached to the ones it’s leaning on more heavily now.

Related Reading
Free Tools

Need to put a number on your next media decision?

Model the impact of a media or marketing decision on your own numbers, browse the full library of strategic calculators and decision tools, and get definitions straight on the industry terms that come up along the way, three free resources, ready whenever you need them.

Try the calculators → Explore strategic decision tools → Browse the glossary →

Under the GDPR and UK GDPR, an IP address is treated as personal data by default, following European Court rulings that an IP address can identify an individual when combined with data an internet service provider holds, regardless of whether the business collecting it can make that link itself. The US picture is more fragmented: the CCPA treats an IP address as personal information only when it can reasonably be linked to a specific consumer or household, meaning identical data can carry different legal weight depending on jurisdiction and what else it’s combined with. That inconsistency, not any single ruling, is the real operational headache for a business running campaigns across multiple markets.

What this means for identity infrastructure now

IP-based signals were always going to need governance, whether Chrome deprecated cookies or not. Google formalising IP-based personalisation, with a corresponding consent requirement, is confirmation that this identity layer is now a compliance surface in its own right, not just a legacy fallback nobody’s paying attention to. The same principle covered in How to Balance Data Privacy and Marketing Attribution applies directly here: know which decisions actually require which kind of signal, and treat every identity layer, IP address included, as something that needs an explicit governance answer rather than an assumed one.

Free Playbook

The Customer Data Strategy engagement model covers auditing every identity signal in a measurement stack, IP-based included, against current consent and governance requirements.

Get the Executive Playbooks
Common Questions

IP Address Targeting: FAQ

Is IP address considered personal data everywhere?

No. The GDPR and UK GDPR treat it as personal data by default. The CCPA only treats it as personal information when it can reasonably be linked to a specific consumer or household, meaning the same data point carries different legal obligations depending on jurisdiction.

Does Google’s August 2026 change require new consent from users?

Yes, in the EEA, UK and Switzerland. Because the new use case falls under personalisation rather than legitimate interest, Google is registering it under the IAB Europe Transparency and Consent Framework, which requires consent through the standard cookie-consent flow.

Is IP-based targeting accurate at the individual level?

Generally not. An IP address typically represents a household, office network or carrier-assigned address shared across multiple people, making it a weak proxy for individual identity even where it’s legally permitted to use.

Discover more from The Media Guides

Subscribe now to keep reading and get access to the full archive.

Continue reading