# Google Shifts to IP-Based Ad Targeting in Europe, Defying Privacy Watchdog Warnings
Google is set to deploy IP address-based device identification and ad personalization across the UK, EU, EEA, and Switzerland starting August 3, 2026—a move that inverts the company's own prior stance on fingerprinting and puts it at odds with regulators who have explicitly warned against the practice.
The change marks a significant inflection point in the post-cookie advertising landscape, forcing European regulators, advertisers, and privacy advocates to confront whether consent-based frameworks can scale to the technical realities of modern ad measurement.
## What's Changing
Google notified advertisers on June 17, 2026 that it will expand the use of IP addresses from their current purpose—routing traffic and detecting fraud—to a new one: identifying devices for ad measurement and personalization. The company will register under the IAB Europe Transparency and Consent Framework (TCF) for "Feature 3," which governs device identification based on automatically transmitted signals.
The critical distinction is purpose. Google already receives IP addresses constantly through customer tags, SDKs, HTTP calls, and data uploads. August 3 is when those same addresses shift into use cases that trigger consent requirements under UK and EU law. IP addresses are classified as personal data under the GDPR, and using them to identify devices across services constitutes fingerprinting—a tracking technique that bypasses cookie clearing because users cannot revoke it the way they can clear browser cookies.
Key changes at a glance:
| Element | Before August 3 | After August 3 |
|---------|-----------------|----------------|
| IP address use | Traffic routing, fraud prevention | + Device ID for ad personalization |
| Regulatory trigger | Legitimate interest (no consent required) | Personal data processing (consent required) |
| User control | Limited; ad settings at myadcenter.google.com | Same, plus promised user-facing choice (timeline TBD) |
| Framework registration | Not required for routing | Required under IAB TCF Feature 3 |
## Background and Context: The Fingerprinting Reversal
To understand why this announcement is contentious, context matters.
In 2019, Google's then-Chrome engineering director Justin Schuh wrote that fingerprinting "subverts user choice" because it enables tracking that users cannot revoke, unlike cookies. That philosophy underpinned Chrome's privacy initiatives and positioned Google as a steward of anti-tracking principles.
That stance lasted until December 2024, when Google reversed its fingerprinting prohibition for advertisers. The company announced that Chrome would no longer block fingerprinting techniques, effectively licensing advertisers to track users across sites when cookies fail.
Within a day, the UK's Information Commissioner's Office called the reversal "irresponsible." The ICO argued that allowing fingerprinting undermined the entire consent model on which UK and EU privacy law depends.
The timing of Google's IP address expansion is, however, the awkward part.
On May 18, 2026—just weeks before this announcement—the ICO published guidance to the UK government proposing changes to the consent rules for online advertising. The office's preferred approach would allow context-based advertising (ads targeted to what you're currently viewing, not who you are) without consent, but would keep consent mandatory for tracking that profiles people across services over time.
IP-based personalization across multiple surfaces sits squarely on the consent-required side of that line.
## Technical Details: How IP-Based Identification Works
IP addresses are fundamental to internet routing—every request to load a web page, click an ad, or send data must include the requester's IP. Advertisers and publishers have long seen IP addresses as a privacy-friendly alternative to third-party cookies because they're ephemeral (ISPs reassign them) and harder for users to manipulate.
Yet IP-based identification for cross-service tracking operates differently:
Google frames the change around privacy-enhancing technologies (PETs)—on-device processing, trusted execution environments, and secure multi-party computation. These technologies promise to enable personalization without exposing raw data to advertisers. However, none of these mitigates the fundamental issue: IP addresses are personal data, and using them to identify devices requires consent under GDPR and UK law.
## Implications for Users, Advertisers, and Regulators
### For Users
Until Google deploys its promised user-facing choice on IP-based personalization (expected later this year or early next), users have limited remedies:
These controls address cookie-based personalization, not IP-based fingerprinting.
### For Advertisers
Google's customer email pushes the compliance burden onto advertisers themselves. Advertisers remain bound by Google's EU User Consent Policy and must obtain valid consent from users in affected regions. However, without clear guidance on whether Google's PET infrastructure meets GDPR requirements, advertisers face legal uncertainty. Some will likely implement additional consent checks or opt-out mechanisms for affected users.
### For Regulators
The ICO and EU regulators now face a test case. Google is asserting that IP-based personalization can coexist with consent frameworks; regulators are signaling it cannot—not without explicit user agreement. The ICO's May advice recommended that consent remain mandatory for cross-service profiling. Google's rollout puts regulators' resolve to the test: will they enforce that principle, or will IP-based fingerprinting become normalized in Europe the way it is elsewhere?
## What Organizations Should Know
Privacy teams and legal counsel should:
Advertisers should:
Publishers using Google's ad network should verify that their consent management platforms correctly capture and transmit user choices for Feature 3.
---
## HackWire Analysis
Google's shift to IP-based fingerprinting in regulated markets exposes a structural mismatch between technical possibility and legal reality.
The company's argument—that IP addresses are already common and that PETs minimize exposure—is technically defensible but legally insufficient. The GDPR doesn't ask whether a personal data processing technique is "common" or "enhanced with privacy tech." It asks: Is consent required? For cross-service profiling, the answer is yes. Google obtained an exemption to its own fingerprinting rules for advertisers in December 2024, and now it's extending that exemption to Europe through a side door: redefining the purpose of data it already collects.
What makes this moment significant is not that Google is using IP addresses for personalization—advertisers have done this informally for years. What matters is that Google is doing it explicitly, at scale, and in the regulatory crosshairs, after the ICO explicitly warned against this move. If Google proceeds without explicit user consent and regulators fail to enforce, fingerprinting becomes normalized in Europe. If regulators act, Google faces substantial remediation costs.
The real risk is that we're watching a repeat of the 2016-2020 playbook: Google deploys a practice, regulators object, the company margins it as "privacy-enhanced," and by the time enforcement happens (if it happens), the practice is entrenched. The May 2026 ICO guidance suggested regulators wanted to avoid this loop. Google's August 3 rollout tests whether they meant it.
The practical stakes for users are immediate: for anyone accessing Google properties from the UK, EU, EEA, or Switzerland, device fingerprinting via IP is about to become invisible and irreversible—at least until Google delivers on its vague promise to offer user-facing choices later this year.
— HackWire Editorial
---
## Recommendations
1. For users: Enable a VPN if you're in affected regions and want to limit IP-based tracking. Monitor Google's account settings for the promised personalization controls when they arrive.
2. For organizations: Audit consent flows in your analytics and ad measurement infrastructure. If you use Google Ads, ensure UK and EU traffic is subject to additional consent verification.
3. For regulators: Issue guidance clarifying whether IP-based fingerprinting violates the GDPR, and establish enforcement timelines. The ICO's May advice left ambiguity; clarity now prevents a year of technical uncertainty.
---
## Related Coverage