
Polish Supreme Administrative Court Requires DPAs to Prove Identifiability Before Treating IP Addresses and Cookie IDs as Personal Data
In a significant judgment issued on 16 October 2025 (III OSK 2595/22), the Polish Supreme Administrative Court (NSA) held that the data protection authority (UODO) cannot assume that IP addresses and cookie identifiers always constitute personal data. Instead, the authority must demonstrate - based on objective, case-specific factors - that an individual is identifiable within the meaning of Article 4(1) GDPR. The ruling strengthens procedural rigor in GDPR enforcement and reinforces the contextual approach to identifiability reflected in CJEU case law, including Breyer and Planet49.
9 December 2025










