Google has told advertisers it will start using IP addresses to measure and personalize ads across the European Economic Area, the UK, and Switzerland on or shortly after August 3, 2026. That single sentence sounds bureaucratic, but it marks a real shift in how Google treats the one piece of data that follows you everywhere online, whether you clear your cookies or not.

What’s actually changing

Google already sees your IP address. It has to. Routing traffic, serving ads, and running basic fraud checks all require knowing where a request came from. That part isn’t new.

What’s new is the purpose. Starting in August, Google will use those same IP addresses to identify individual devices for ad measurement and personalization, according to BleepingComputer’s reporting on the advertiser notices Google has been sending out. Instead of an IP address being a technical detail that helps a page load, it becomes an identifier tied to a profile of your behavior across sites and apps.

That distinction matters under European law. GDPR doesn’t just regulate what data a company collects, it regulates what a company does with it. Collecting an IP to route a connection is one purpose. Using that same IP to build an ad profile and follow you across the web is a different one entirely, and switching purposes without fresh consent is exactly the kind of move the regulation was built to stop. gHacks confirmed the August 3 date and noted that some personalization features tied to this change won’t roll out until later in 2026 or early 2027, at which point Google says users on its own properties will get a choice about IP-based personalization. Third-party publishers running Google ads don’t get that same opt-in framing, which is part of why the ICO has been vocal about consent here.

Why an IP address counts as personal data

An IP address is not an anonymous number. Under GDPR, it’s treated as personal data because it can identify a specific person or household, and European courts have upheld that interpretation for over a decade. What makes this particular change unusual is the technique behind it: using an IP address to identify and track a device is a basic building block of fingerprinting.

Fingerprinting doesn’t rely on a cookie sitting in your browser. It stitches together signals, IP address, device type, browser configuration, screen resolution, to recognize you again even after you’ve cleared every cookie you own. That’s the part that should worry anyone who thinks “I use private browsing” is enough. Fingerprinting works precisely because it doesn’t depend on anything you can delete.

The ICO has already called this “irresponsible”

This isn’t the first time Google has moved in this direction. In December 2024, Google quietly reversed a long-standing policy and lifted its ban on advertisers using fingerprinting techniques. The UK’s Information Commissioner’s Office responded immediately and bluntly, calling the reversal irresponsible and warning that fingerprinting “reduces people’s choice and control” over their own data, precisely because people can’t clear it the way they clear a cookie.

The timing of the current change adds another layer. On May 18, 2026, the ICO published advice to the UK government on reforming consent rules for online advertising. Its preferred approach would allow some contextual advertising without consent, based on the page someone is viewing rather than their behavior over time, while keeping consent mandatory for anything that profiles people across services and sessions. Google’s August rollout lands squarely in the category the ICO wants to keep behind a consent wall.

Why this matters even if you’ve never clicked “accept all”

If you’re diligent about rejecting cookie banners, you might assume you’re covered. IP-based tracking doesn’t ask permission the same way. It sits underneath the cookie layer, at the network level, which means the usual privacy hygiene, clearing cookies, using private browsing, blocking third-party trackers, doesn’t touch it. Your IP address is assigned by your internet provider and stays the same across every site you visit until your connection changes, giving advertisers a stable thread to pull across your whole browsing session and beyond.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

How a VPN helps, and where it doesn’t

A VPN routes your traffic through a remote server, so every site and ad network sees that server’s IP address instead of the one your provider assigned you. That directly undercuts what Google is rolling out: if your visible IP is shared among thousands of other VPN users and changes every time you reconnect, it stops being a reliable identifier that ties an ad profile back to your home network or your specific device.

That’s a genuine countermeasure, not a marketing claim. Our guide on what a VPN actually hides from your internet provider covers the mechanics of IP masking in more detail if you want the full picture of what changes and what doesn’t when you connect.

But a VPN is one layer, not a fix for the whole problem. It doesn’t touch cookies sitting in your browser, and it does nothing about browser fingerprinting based on your screen size, fonts, or installed extensions. Most importantly, if you’re logged into a Google account while browsing, none of this matters: Google already knows who you are through that login, IP address or not. A VPN masking your network identity and a logged-in Google account revealing your actual identity can both be true at the same time, and the second one wins.

If your VPN is leaking your real IP without you noticing, you get none of this protection while believing you’re covered, which is worse than not using one at all. It’s worth running the checks in our guide to spotting VPN IP leaks periodically, especially given how much is now riding on that address staying hidden.

For anyone weighing which provider to trust with this, look for one with a strict no-logs policy that’s actually been audited, not just claimed. NordVPN is a solid option if you want that layer in place before August.

The realistic takeaway

Nothing about this change is illegal on its face, and Google will likely argue that its legal basis (consent banners, updated privacy policies, contractual terms with publishers) covers it. Whether that consent is meaningful, given how buried these settings tend to be and how little most users understand about IP-based fingerprinting, is a separate question, and it’s the one the ICO keeps raising.

What’s certain is that come August 3, the IP address your provider assigns you becomes a more valuable and more actively used piece of advertising infrastructure across Europe than it was the week before. Masking it with a VPN is a reasonable, low-effort response. Just don’t mistake it for the whole answer.

Our Verdict

Google's shift turns a technical necessity, seeing your IP to route ads, into an active tracking purpose, using that IP to fingerprint and profile your device. That change is exactly what GDPR consent rules exist to catch, which is why the ICO keeps pushing back. A VPN masks the one signal this change depends on, your stable, provider-assigned IP address, and it's worth using for that reason alone. It won't stop cookie tracking or a logged-in Google account from identifying you, so treat it as one layer of a broader privacy habit, not a single fix.

Sources: BleepingComputer on Google’s IP-based ad personalization | gHacks on the August 3 rollout | ICO’s response to Google’s fingerprinting policy change | TechRadar on why a VPN matters more now