Google to Harvest UK and EU IP Addresses for Ad Targeting Starting August 2026
The same signal Google once branded a privacy red flag becomes a measurement tool, just as the ICO sharpens its consent rules.

Google has told customers it will begin using IP addresses from users in the UK, EEA and Switzerland for ad measurement and personalization on August 3, 2026.
The shift matters because IP is one of the more reliable passive identifiers left after the slow death of third-party cookies. It does not require a login. It does not require a prompt. It just sits in the request headers, courtesy of how TCP/IP works.
That is awkward, because Google has historically argued the opposite case. When Meta and others were caught fingerprinting devices, Google's own ads policy explicitly framed the use of IP-derived signals to identify users as a workaround that bypassed consumer choice. The policy language called it out as a circumvention. Now it is product roadmap.
The company's stated justification is that IP will be used to infer coarse location and approximate identity for attribution and frequency capping, with what it describes as privacy protections layered on top — including limits on how the address is stored and processed. Specifics on whether the raw IP is hashed, truncated to a /24, or fed through something closer to its IP Protection proxy work for Chrome have not been published in detail.
This is fundamentally an identity story, not an ads story. IP plus User-Agent plus a handful of TLS fingerprint bits gets you uncomfortably close to a stable device identifier. That is the same primitive attackers use for session correlation and account takeover triage. When ad networks normalize treating IP as identity, defenders lose a useful anomaly signal: "new IP, same session" stops looking weird if half the ecosystem treats IP drift as routine.
The timing is pointed. The UK's Information Commissioner's Office is consulting on tighter rules around consent for tracking technologies, and the boundary between "strictly necessary" and "requires opt-in" under PECR and the UK GDPR is exactly where IP-based personalization lives. The ICO's existing guidance on cookies and similar technologies already treats device fingerprinting as in-scope, regardless of whether anything is written to the client.
What to watch:
- Whether Google publishes a Data Protection Impact Assessment or relies on legitimate interests under Article 6(1)(f) of the GDPR.
- Whether consent strings in the IAB TCF are updated to cover IP-as-identifier, or whether publishers are left holding the legal bag.
- Whether Chrome's IP Protection work for third-party contexts ships before the August date, or after.
MFA would not have helped here. This is not an auth failure. It is a policy reversal dressed up as a measurement update, and it narrows the gap between advertising telemetry and the kind of passive identification that identity teams spend their careers trying to detect.



