Google to Harvest UK and EU IP Addresses for Ad Targeting Starting August 2026
The same signal Google once branded a privacy red flag becomes a measurement tool, just as the ICO sharpens its consent rules.

Key points
- From 3 August 2026, Google will collect IP addresses from users in the UK, EEA and Switzerland for ad measurement and personalisation.
- IP addresses don't require a login or user prompt: they're embedded in every request by design.
- Google previously called using IP-derived signals to identify devices a circumvention of consumer choice.
- The ICO is consulting on tighter consent rules at the same time, covering the exact territory where IP-based personalisation sits.
- When ad networks treat IP as identity, defenders lose a useful anomaly signal that session-correlation attacks depend on.
Is this actually a privacy problem?
IP is one of the more reliable passive identifiers left after the slow death of third-party cookies. It sits in every request header, courtesy of how TCP/IP works, and it doesn't require a prompt or a login to collect. That combination is what makes it attractive to ad measurement teams and uncomfortable for everyone else.
The awkward history matters here. Google's own ads policy once explicitly framed using IP-derived signals to identify devices as a circumvention that bypassed consumer choice, naming it as the kind of workaround it stood against. Now it's product roadmap.
Google's stated justification is coarse location inference and approximate identity for attribution and frequency capping, with privacy protections layered on top, including limits on how the address is stored and processed. Whether the raw address is hashed or routed through something closer to its IP Protection proxy work for Chrome hasn't been detailed publicly, and that vagueness is doing a lot of work.
Should you worry about what this does to threat detection?
This is an identity story more than an ads story. IP address combined with User-Agent and a handful of TLS fingerprint bits gets uncomfortably close to a stable device identifier. That's the same primitive attackers use for session correlation and account takeover triage. When ad networks normalise treating IP as identity, defenders lose a useful anomaly signal: a new IP appearing on an existing session stops looking suspicious if the broader ecosystem treats IP drift as routine noise.
MFA wouldn't have helped here. This isn't an auth failure.
What's the regulatory exposure?
The timing is sharp. The ICO is currently consulting on tighter rules around consent for tracking technologies, and IP-based personalisation lands exactly on the boundary between "strictly necessary" and "requires opt-in" under PECR and the UK GDPR. The ICO's existing guidance on cookies and similar technologies already treats device fingerprinting as in-scope regardless of whether anything is written to the client. We've followed the ICO closely: this is the tenth story we've filed on the regulator since our first in early June, and the pressure it's under from Google's move is real.
Three things to watch before August:
- Whether Google publishes a Data Protection Impact Assessment or relies on legitimate interests under Article 6(1)(f) of the GDPR.
- Whether consent strings in the IAB Transparency and Consent Framework are updated to cover IP-as-identifier, or whether publishers are left holding the legal exposure.
- Whether Chrome's IP Protection work for third-party contexts ships before the August deadline or after it.
This is a policy reversal dressed as a measurement update. The gap it closes, between advertising telemetry and the passive identification that identity teams spend careers trying to detect, is the part worth watching most carefully.



