Google Just Made IP Addresses a Regulated Ad Identifier. The Identity Industry Called This Years Ago

Starting today, August 3, Google begins using IP addresses to build device identifiers for ad personalization across the EEA, UK, and Switzerland. Not routing traffic. Not fraud detection. Ad targeting. Google is updating its registration in the IAB’s Transparency and Consent Framework to cover Feature 3, “identify devices based on information transmitted automatically,” and telling publishers they need valid consent signals covering that feature before the new measurement kicks in.

That’s a lot of compliance language wrapped around a fairly simple admission. IP addresses are identity data. Not adjacent to identity. Not a weak fallback signal. Identity data, precise enough that the largest ad platform on the planet now needs a legal basis to touch it.

Anyone who has spent real time in household graphs, CTV attribution, or cross device resolution has known this for years. What changed is that Google said it out loud, in a jurisdiction where an IP address is legally personal data under GDPR, and now the paperwork has to catch up to what the data already does.

Why This Took So Long

Google has collected IP addresses forever. What makes August 3 different is what happens to that data downstream. The same address used to route a request and flag suspicious traffic will now also be used to construct a device identifier for personalization. That’s the line that triggers consent obligations under GDPR and the UK’s equivalent regime. According to reporting on the rollout, users won’t get an active opt out mechanism on Google’s own properties until later this year or into 2027, so this is launching ahead of the control layer that’s supposed to accompany it. The UK’s ICO has already flagged the gap to publishers.

The identity industry has treated IP as a real signal, with real limitations, since long before this was a regulatory question. Household IP mapping has always been probabilistic at the edges and deterministic at the core, useful for geo and household level inference, weak as a standalone person level identifier. Google collapsing that nuance into a single binary consent toggle is a blunt instrument, but it’s still an acknowledgment the rest of us have been operating on for a decade.

The Accuracy Problem Nobody Wants to Say Out Loud

Here’s the part that should worry anyone leaning on IP as a primary targeting key. Recent joint research from Adstra and InterMedia Advertising, built on Truthset validation data, found that only 23 percent of residential IP addresses actually hit their intended geographic target. IP to email match rates came in at 16 percent. IP to postal matched at 13 percent. Put plainly, standard IP targeting misses its intended household roughly three times out of four, and Truthset estimates the resulting waste costs CTV advertising alone north of seven billion dollars this year.

So the platform now treating IP as identity data serious enough to require consent is also the same signal type independent research shows is wrong most of the time when used on its own. Those two facts aren’t in conflict, they’re the same story. IP is real signal. It is also noisy signal. Both were true before Google’s policy shift, and both remain true after it. The difference now is that using it carelessly carries legal exposure on top of the wasted spend.

What This Means Beyond Europe

US advertisers watching this unfold in the EEA shouldn’t assume it stays there. California’s data broker deletion framework already tightened obligations on anyone handling identity data at scale, and state privacy laws keep converging toward the GDPR model of treating device level identifiers as regulated. Consent infrastructure, TCF strings, CMPs, and vendor list registrations, is quietly becoming core plumbing for identity resolution rather than a compliance afterthought bolted on at the end.

For anyone building or buying identity graphs, this is a good moment to ask a blunt question about provenance. Where did each identifier in your graph come from, was consent captured at collection, and how is a household IP getting validated against other deterministic signals like HEMs or MAIDs before it’s used to make a targeting decision. Raw IP matching, used alone, is exactly the kind of low fidelity signal that regulators are starting to scrutinize and that fraudulent or spoofed device activity hides inside most easily. A validated identity graph that cross references household IP against multiple corroborating signals, filters out fraudulent or non human identifiers, and can show its consent lineage isn’t just cleaner data. It’s increasingly the only defensible way to operate.

The Takeaway

Google didn’t invent the idea that IP addresses carry identity signal. It just made that fact expensive to ignore. The companies that treated IP as one input among several, validated against other signals and grounded in actual consent, are the ones who won’t need to rebuild anything this quarter. The companies that treated IP as a free, unlimited proxy for identity are the ones with a compliance problem and an accuracy problem arriving at the same time.

Worth remembering the next time someone pitches IP targeting as simple.