The images in this article were generated with artificial intelligence. How we publish
Google has notified advertisers that, from 3 August 2026, it will start using IP addresses in the European Union, the European Economic Area, the United Kingdom and Switzerland not only to routing traffic, but also to identify devices for the purpose of measuring and customizing ads. In global practice this is common, but in the EEA and the United Kingdom IP is considered personal data and its use for identification purposes fits the legal definition of tracing that requires explicit consent under applicable data protection rules.
The novelty is not so much the reception of the IP by Google - which already gets it through labels, SDKs, HTTP calls and loads - but the change of purpose: use that automatic signal to link behavior between services and profile users. Google has also announced its registration to the IAB Europe transparency framework for the call "Feature 3" the part of the framework that recognizes the use of automatically transmitted data to distinguish devices; however, adherence to the TCF does not replace the consent obligations imposed by laws such as the GDPR. For legal explanation of IP as a personal data, see the GDPR text in https: / / gdpr-info.eu / recitals / no-30 / and the IAB note on Feature 3 in https: / / iabeurope.eu / iab-europe-transparency-conform-framework-policies / #: ~: text = scanning% 20device% 20characteristics, Feature, -3.

From the technical point of view, placing the IP as an identification piece is part of what is known as fingerprinting: combine signals (IP, headers, browser prints, cava fingerprints or sources) to recognize a device even when cookies are deleted. The actual accuracy of the IP varies: in domestic networks it provides a geographical and sometimes supplier track, while in mobile NAT / CGNAT and shared proxies reduce uniqueness. Even so, when combined with other identifiers it can facilitate cross-site correlation that concerns regulators and privacy advocates.
The regulatory context makes Google's decision have audible implications: the United Kingdom and the European Commission are reviewing the consent rules for online advertising. The Office of the United Kingdom Information Commissioner (ICO) has already publicly stated its concern when Google made its internal ban on fingerprinting more flexible in 2024, and in May 2026 published recommendations that favour keeping consent to techniques that profile users through services. Treatment managers and advertisers using these signals therefore face two simultaneous risks: the technician (possible inaccuracy and IP identification bias) and the regulatory (inspections, fines or adjustment requirements by data authorities).
For advertisers and editors, Google's "get and manage consent" instruction does not exempt liability: by August 3, they must review labels, SDKs and contracts with suppliers to ensure that any use of IP for customization purposes is covered by a valid and documented consent. It is recommended to conduct a data protection impact assessment (DPIA) focused on the re-use of technical signals, update consent banners to leave explicit these purposes, and review contractual clauses with Google and other intermediaries. Google's EU consent policy can be found at https: / / www.google.com / about / company / user-consent-policy /.

For end-users, the immediate options remain known: deny non-essential cookies, refuse consent on banners and review the ad customization settings in the Google account at https: / / myadcenter.google.com /. They also help protection measures on the device and on the network, such as privacy-oriented browsers, tracker-blocking extensions or the use of virtual private networks that change the IP view for services. It is important to understand, however, that these defenses are not perfect and that true protection depends in large part on the proper application of the legal framework by companies and authorities.
From a public policy perspective, Google's movement presents a test of how privacy standards will be applied in practice: if large suppliers can normalize the reuse of technical signals under consent frameworks, the digital advertising ecosystem could turn to a model in which the line between context and behavioral is blurred. European and UK regulators are attentive; companies that are now acting to document legal bases, limit the retention of identification signals and provide clear controls to users will reduce their legal and reputational exposure.
In short, the novelty that comes into force in August is not technical but legal and governance: using IP as an identifier for customization changes the rules of the game in territories where that signal is considered personal data. Advertisers must audit their advertising stack, update their consent processes and prepare compliance tests; users must review and exercise their privacy options; and authorities will have the last word on whether this type of practice respects the limits imposed by the right of data protection. In the meantime, the development of regulatory decisions and public guides of the ICO and other European authorities should be monitored.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...