Are IP Addresses Personal Information? What Businesses Must Know

Alex Solo
byAlex Solo9 min read

If you run an online business (or any business that uses websites, apps, Wi-Fi networks, online advertising, or analytics), you’re probably collecting IP addresses - even if you’ve never asked for one.

An IP address can feel “technical” rather than “personal”. But if you’re dealing with customer data, you need to be confident about where the law draws the line.

This is especially important because privacy compliance isn’t just about avoiding complaints. It can affect how you draft your Privacy Policy, how you use marketing tools, what you disclose to customers, and what you need to do if you have a data breach.

So, is an IP address personal information under Australian law? Let’s break it down in plain English, from a small business perspective.

What Is An IP Address (And Why Do Businesses Collect Them)?

An IP address (Internet Protocol address) is a unique number (or string of numbers/letters) assigned to a device when it connects to the internet.

From a business perspective, IP addresses commonly show up in your systems because:

  • Your website logs traffic (for security, troubleshooting, performance monitoring)
  • Your analytics tools record visitor activity (to measure conversions and user journeys)
  • Your eCommerce platform detects fraud or suspicious activity
  • Your email marketing and ad platforms track engagement
  • Your workplace or customer Wi-Fi network keeps logs (for security and network management)

In many cases, you’re not actively “asking” for an IP address - it’s collected automatically when someone visits your website or uses your service.

That’s exactly why the privacy question matters: if this data is personal information, you may have legal obligations around how you collect, use, store, and disclose it.

Is An IP Address Personal Information Under Australian Privacy Law?

In Australia, privacy obligations for many businesses are shaped by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Under the Privacy Act, personal information generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not, and whether it is recorded in a material form or not.

So the real question isn’t whether an IP address “looks personal”. The key question is:

Can this IP address reasonably identify an individual, either on its own or when combined with other data you hold?

When An IP Address Is More Likely To Be Personal Information

An IP address is more likely to be personal information when:

  • You can link it to an account (eg the visitor is logged in and you can connect IP logs to their customer profile)
  • You collect other identifiers alongside it (eg name, email, phone number, delivery address, device IDs, unique cookies)
  • You or your service providers can reasonably re-identify the person (eg through analytics, advertising tools, CRM integrations)
  • The IP address is static (meaning it stays with the user for long periods, making identification easier)

In practical terms, many businesses hold enough related data that an IP address can become part of a bundle that makes a person “reasonably identifiable”.

When An IP Address Might Not Be Personal Information

An IP address might be less likely to be personal information if:

  • it is stored in isolation with no other identifying data; and
  • you have no reasonable way to link it to an individual; and
  • the IP address is dynamic and frequently changes.

However, for most modern online businesses, the safer assumption is that IP addresses can fall within privacy regulation - particularly if you use typical website tools like analytics, customer logins, or ad tracking.

Why This Matters For Your Business (Not Just “Privacy Paperwork”)

When you treat IP addresses as potentially personal information, you start to see where the legal and commercial risks sit.

For small businesses, this usually affects five key areas:

1) Your Privacy Policy And Disclosures

If your business collects personal information, you generally need to be transparent about what you collect and why.

This is where a properly drafted Privacy Policy becomes important. It should accurately reflect what’s happening on your website and in your back-end systems - including technical data like IP addresses, cookies, and device identifiers (where relevant).

It’s common for businesses to copy/paste a generic policy that doesn’t match their actual data flows. That can create risk if a customer complains, or if you ever need to respond to a regulator.

2) Cookies, Analytics, And Tracking Tools

IP addresses often sit in the background of cookie-based tracking and analytics.

If you use online marketing tools, it’s worth thinking about what you need to disclose to users (and whether you should have a Cookie Policy).

In Australia, consent isn’t always legally required just because cookies or analytics are used, but transparency is still important (and you may need consent depending on the tool, the data involved, and how it’s used). This becomes even more important if you operate internationally or have overseas customers, because other privacy regimes can be stricter than Australia’s.

3) Data Security Expectations

Even if you treat IP addresses as “low sensitivity” data, it can still be valuable in the wrong hands, especially when combined with other data.

If you suffer a cyber incident and IP address logs are exposed alongside customer details, it can increase the harm (and the scrutiny).

As a baseline, you should have appropriate security measures and internal processes to reduce the risk of unauthorised access or disclosure.

4) Data Breach Response Planning

Privacy compliance isn’t just about collecting data “correctly” - it’s also about being ready if something goes wrong.

If your systems capture IP addresses alongside customer details, you should have a plan for how you will respond to incidents. Many businesses formalise this in a data breach response plan, which helps you respond quickly, preserve evidence, communicate appropriately, and reduce ongoing exposure.

5) Contracts With Your IT Providers And Platforms

If you use third-party providers (web developers, cloud platforms, analytics, CRMs), it’s worth checking what they collect and how that aligns with what you disclose to customers.

Depending on your setup, you may also want your contracts to deal with data handling obligations, confidentiality, and security standards - particularly when your service providers can access logs that include IP addresses.

Do Small Businesses Have To Comply With The Privacy Act?

This is where many business owners get caught out.

In Australia, the Privacy Act typically applies to “APP entities”. Many small businesses are not covered, but the small business exemption has important exceptions.

Whether you need to comply may depend on factors like:

  • Your annual turnover (businesses with an annual turnover of $3 million or less may be exempt, unless an exception applies)
  • Whether you trade in personal information (this can bring you within the Act even if you’re under the threshold)
  • Whether you provide certain services (for example, some health-related handling of information and some other regulated activities can trigger coverage)
  • Whether you are related to an entity that is covered (eg connected to an APP entity)
  • Whether other laws or contracts impose privacy obligations (for example, corporate clients may require privacy standards even if you’re otherwise exempt)

Even if you think you’re exempt, privacy still matters because:

  • customers increasingly expect transparency and good data handling practices;
  • platforms and payment providers may require privacy compliance to use their services;
  • privacy failures can turn into reputational damage very quickly; and
  • data handling often overlaps with misleading or unfair conduct risks under the Australian Consumer Law (ACL).

In other words: it’s not just “a big business problem”. If you collect IP addresses (and most online businesses do), it’s worth treating privacy as part of your core risk management.

Practical Steps: How To Handle IP Addresses In Your Business

If you’re wondering what to do next, you don’t need to overhaul everything overnight. A good approach is to map what’s happening in your business and tighten the foundations.

1) Identify Where IP Addresses Are Collected

Start by listing the systems that may collect IP addresses, such as:

  • your website hosting provider and server logs
  • website forms and checkout processes
  • your eCommerce platform
  • analytics dashboards
  • ad pixels and retargeting tools
  • customer support tools (including ticketing and chat)
  • Wi-Fi access logs (if offered in-store or in-office)

This helps you work out what you actually hold, and whether the IP address is linked to other customer identifiers.

2) Check Whether IP Addresses Are Linked To Identifiable Profiles

Ask yourself:

  • Can we tie an IP address to a customer account, order, or enquiry?
  • Do we store IP addresses alongside names, emails, or phone numbers?
  • Do our service providers have the ability to identify the user?

If the answer is “yes” to any of these, you should treat IP addresses as part of your personal information handling framework.

3) Update Your Customer-Facing Documents

Your legal documents should match your real practices.

Depending on your business model, this might include:

  • Privacy Policy (covering technical data like IP addresses and device information where relevant)
  • Cookie Policy (if you use cookies, tracking pixels, or analytics tools)
  • Website terms explaining site usage rules, acceptable conduct, and liability settings

If your business operates online, Website Terms and Conditions can also help set expectations around your platform, including how users can interact with your site and what you’re responsible for.

4) Build Strong Internal Practices (Even If You’re Small)

For many small businesses, good privacy compliance is about consistency and common sense:

  • limit who can access logs and customer databases
  • only keep IP address logs for as long as you need them (for example, for security or troubleshooting)
  • use secure passwords and multi-factor authentication
  • make sure your team knows what to do if something looks suspicious

If you have staff handling customer data, it can also help to set expectations in workplace documents and training - particularly if employees access customer accounts, admin dashboards, or support systems.

5) Be Careful With Marketing And Tracking Claims

If you use IP addresses or tracking tools to personalise ads or content, make sure your disclosures (and any consent settings you do use) are appropriate for what you’re doing.

This is also where your broader compliance matters: for example, if you make statements to customers about being “anonymous” or “not tracking anything”, those statements need to be accurate. Otherwise, you could be exposed to misleading conduct issues under the ACL.

Key Takeaways

  • Is an IP address personal information? In Australia, an IP address can be personal information if it identifies an individual, or if the person is reasonably identifiable (including when combined with other data you hold).
  • For many online businesses, IP addresses are collected automatically through website logs, analytics tools, marketing pixels, and security systems.
  • If you collect IP addresses (especially alongside customer identifiers), your privacy compliance should cover how you collect, use, store, and disclose that data.
  • Your customer-facing documents should reflect your real practices, including an accurate Privacy Policy and (where relevant) a Cookie Policy and Website Terms and Conditions.
  • Even small businesses that believe they are exempt from the Privacy Act may still face contractual, consumer, and reputational risks if they mishandle customer data.
  • Taking practical steps like mapping data collection, limiting access, and preparing a breach response plan can reduce risk and help you stay in control as you grow.

If you’d like help reviewing your data practices or putting the right privacy documents in place (including how you handle IP addresses), you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Official Sources to Check

Rules and regulator guidance can change. Check the current official material most relevant to this issue before relying on the article:

Connect the privacy document to the real data flow

What should the business map before updating its policy?

Collection points, purposes, vendors, disclosures, retention and incident handling must match what the policy and notices actually say.

Alex Solo

Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Connect the privacy document to the real data flow

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.