general
Google to Use UK and EU IP Addresses for Ad Tracking
2026-06-17

From 3 August 2026, Google will begin using IP addresses to identify individual devices for ad measurement and personalisation across the UK, the EEA and Switzerland. Google already receives those addresses every time a request hits its servers. That part is routine. The shift is in what the data is used for: telling one device from another, which is precisely the line GDPR draws around.
Fingerprinting by another name
Identifying a device from the signals it sends automatically is the foundational move in browser fingerprinting, the technique advertisers turn to when cookies are blocked or cleared. The pitch for fingerprinting has always been the same, and so has the problem with it: unlike a cookie, a user cannot wipe a fingerprint. That is not an outside critic's view. In 2019, Google's own Chrome engineering director Justin Schuh called the practice wrong on exactly those grounds.
Then in December 2024, Google quietly dropped its prohibition on fingerprinting for advertisers. The UK's Information Commissioner's Office called the reversal irresponsible within a day. The August 2026 rollout is the operational follow-through.
The awkward timing
On 18 May 2026, the ICO published advice to the UK government recommending that consent should remain mandatory for any advertising that profiles people across services, with a narrow carve-out only for context-based ads. IP-based personalisation across Google's surfaces sits firmly on the consent-required side of that line. The ICO has been clear that existing rules still apply, regardless of what new framework guidance might eventually look like.
Google, for its part, is registering under the IAB Europe Transparency and Consent Framework for Feature 3, the mechanism that covers identifying devices from automatically transmitted data. The supporting language leans heavily on privacy-enhancing technologies: on-device processing, trusted execution environments, the usual phrasing. The customer email sent to advertisers contains a more pragmatic message. They are the ones responsible for collecting valid consent from users in the affected regions.
What advertisers and users are actually left with
For advertisers, that means the legal exposure for IP-based personalisation sits with them, not with Google. Consent management platforms in the UK and EU will need to handle the new processing purpose cleanly, and the documentation trail had better hold up if a regulator asks.
For users, a dedicated choice over IP-based personalisation on Google's own properties has been promised later in the rollout. Until that arrives, the available controls are the familiar ones:
- Rejecting non-essential cookies at consent prompts.
- Reviewing ad personalisation settings at myadcenter.google.com.
- Browser-level protections that obscure or rotate the IP address, such as a VPN or private relay.
None of those is a complete answer. They were not designed to be. The point of the 2019 objection, the one Google itself raised, was that fingerprinting moves identification into a layer the user does not control. Six years on, that layer is being switched on by default across most of Europe, with the regulator already on record about what it thinks of the direction of travel.