Somewhere between the customer complaint and the analytics renewal, the question lands on your desk: whether the IP addresses your systems record are personal information. The answer decides whether the Privacy Act 1988 (Cth) applies to that data, what you have to tell people about it, how long you can keep it, and what happens if it leaks. It is not a question the technology answers for you. The same IP address can be personal information in one business's hands and not in another's, depending entirely on what surrounds it.
Two ways to run this decision
The first option is to treat IP addresses as personal information and handle them under the Australian Privacy Principles (APPs). That means publishing a privacy policy that covers them, only collecting what you reasonably need, telling people what you do with the data, securing it, destroying or de-identifying it when it is no longer needed, and notifying the regulator if a breach is likely to cause serious harm. The second option is to take the view that the IP addresses you hold are not personal information in your hands, either because they cannot be linked to any identifiable individual or because the Act does not reach your business at all.
The options look more distinct than they are, and two things collapse them. First, "not personal information" is a factual characterisation of your actual data, not a label you get to choose. Deciding not to look at the logs does not stop them being linkable. Second, even where the Privacy Act does not bind you, customers expect the same transparency, and the regulator's stated default is caution. The real question is not which label to adopt. It is whether, on your data, the characterisation is defensible, and whether you can actually avoid the burden of complying.
Six factors that decide the call
What the Privacy Act definition actually requires
Personal information is defined in s 6(1) of the Privacy Act 1988 (Cth) as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether it is recorded in a material form or not. Two things must both be true before an IP address counts. The information must be about an individual, and the individual must be identified or reasonably identifiable from it, either on its own or together with other information you hold or can access.
The "about" limb matters more than most summaries admit. In Privacy Commissioner v Telstra Corporation Ltd [2017] FCAFC 4, the Full Federal Court held that the words "about an individual" have real content: the individual must be a subject matter of the information. The case concerned a journalist's request for the metadata Telstra held about his mobile service, including the IP addresses allocated to his device. The court upheld the tribunal's conclusion that network data describing how a message was transmitted was information about the service, not about the customer, because the connection between a person and the IP address allocated to a device was too ephemeral. The result is not that IP addresses can never be personal information. It is that the analysis runs through both limbs: whether the data is about a person, and whether that person can be identified.
For the second limb, the Office of the Australian Information Commissioner (OAIC) asks whether a reasonable person would regard identification as practicable, looking at:
- Nature and amount of information: how much identifying material surrounds the IP address.
- Who holds and can access it: whether anyone with access can cross-reference other records.
- Other available information: what else you hold, and how practical it is to use it to identify someone.
- Motivation: whether anyone would realistically try to identify individuals.
Where there is doubt, the OAIC's guidance is blunt: err on the side of caution and treat the information as personal information.
What sits next to the IP address in your systems
A bare IP address in a web server log, kept briefly and never matched to anything else, will often fall outside the definition in the sense the Telstra case describes: it records a transmission, and the connection to a person is too remote. The moment the address is stored next to identifying material, the position changes, because the reasonable identifiability test looks at everything you hold together.
- High-link setups: IP addresses joined to logins, accounts, email addresses, purchase history, support tickets, cookies, device identifiers or location data. These are hard to argue out of the definition.
- Low-link setups: IP addresses in isolated technical logs, aggregated analytics with no key back to individuals, short retention, no cross-referencing. These can sit outside the definition.
Two businesses can collect the same IP address and end up on different sides of the line. A checkout page that stores the IP address against the order and the customer's email holds personal information. A firewall that logs the same address for 24 hours to block attacks, and never links it to a person, may not.
What you do with the data, and how long you keep it
Purpose changes characterisation. Collecting IP addresses for security, fraud prevention, rate limiting and network integrity is a different proposition from collecting them to build profiles, target advertising or map locations. The more the data is used to say something about a person, the harder it is to argue that it is not about them.
APP 3 of the Privacy Act requires an APP entity to collect only personal information that is reasonably necessary for its functions or activities, and APP 11 requires reasonable steps to protect it from misuse, interference, loss and unauthorised access. The same principles set the retention answer. Under APP 11.2, once you no longer need the information, you must destroy it or de-identify it unless a law requires you to keep it. Short retention periods are the cheapest risk control available, because data that is not kept cannot be breached, profiled or re-identified.
If you do retain data, genuine de-identification changes the analysis: de-identified information is not personal information. But de-identification must be real. If you keep the key that lets anyone re-identify individuals, the data stays personal information in your hands. The OAIC also notes that information holdings are dynamic: data that is not personal information today can become personal information tomorrow, if new links or new data change what is identifiable.
Whether the Act reaches your business at all
The Privacy Act binds APP entities: Australian Government agencies and most private sector organisations with annual turnover above the threshold. Under s 6D of the Act, a business is a small business if its annual turnover for the previous financial year was $3 million or less, and small businesses are generally exempt from the APPs.
The exemption has significant carve-outs. A small business is still covered if it:
- Provides health services and holds health information.
- Trades in personal information, by disclosing it for a benefit, service or advantage, or collecting it in exchange for a benefit.
- Works under a Commonwealth contract as a contracted service provider.
- Is a credit reporting body.
- Is related to a body corporate that is not itself a small business.
The exemption is also easier to lose than many founders assume. Under s 6D(4), a business that has had annual turnover of more than $3 million in any financial year since it started carrying on the business is not a small business operator at all, even if the current year is quiet. And the exemption protects you from the APPs, not from the characterisation question: if you are exempt, that question simply matters less, because most of the obligations do not attach. One caveat is worth watching. The Privacy Act Review has flagged the small business exemption as an area where the law needs recalibration, and further reform on it is still in development.
What it costs to get the call wrong
Where the Act applies and the data is personal information, the enforcement stack is serious. The OAIC can investigate complaints, conduct assessments, accept enforceable undertakings and seek civil penalties in the Federal Court. Since the December 2022 amendments, the maximum penalty for a serious interference with privacy by a body corporate is the greatest of $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover; for other entities it is up to $2.5 million (s 13G of the Privacy Act).
The Notifiable Data Breaches scheme adds a separate obligation that runs from the moment you hold personal information. Under Part IIIC of the Act, if there is unauthorised access to, unauthorised disclosure of, or loss of, personal information that is likely to result in serious harm to individuals, you must notify the OAIC and affected individuals as soon as practicable. The scheme has applied since 22 February 2018, and it does not care whether the data was an IP address in a log or a customer database: if it is personal information and it leaks, the clock starts.
There is also the slower cost. The regulator publishes its determinations, and a privacy complaint about a small operator rarely stays local. For a business whose reputation rests on customer trust, the defensibility of the "not personal information" call matters as much as the penalty.
What your vendors do with the same data
Most businesses do not hold their IP addresses directly. Analytics, advertising, payment and customer support platforms process them on the business's behalf, and that does not move the problem. If the data is personal information in your hands, handing it to a third party is a disclosure of personal information, and the APPs regulate use, disclosure and overseas transfer. APP 8 sets requirements for disclosing personal information to recipients outside Australia, so an analytics provider that stores visitor IPs on servers in another country can create cross-border obligations you did not set out to take on.
This factor rarely decides the call on its own, but it determines what the call costs. If your position is that visitor IP addresses are not personal information, your vendor agreements and your data flow map need to support that position. If your position is that they are, the agreements need to say who does what with the data, how long it is retained, and who notifies if something goes wrong.
How Artificer Legal helps you make and defend the call
This is a decision best made with someone who can test it against your actual systems. An Artificer Legal privacy lawyer would start by mapping where IP addresses enter your business: website, checkout, analytics, live chat, payment gateways and security tools. We would then run the identifiability analysis on that real data, not in the abstract, and document why each dataset is or is not personal information in your hands, so the reasoning can be defended if it is ever questioned.
Where the data is personal information, we would draft or review the privacy policy that covers it, set collection and retention limits that match APP 3 and APP 11, review the agreements with your vendors, and build a notifiable data breach response plan so your team knows what to do if something leaks. Where the small business exemption is in play, we would stress-test the turnover calculation and the carve-outs against what your business actually does. The point of the exercise is a call you can act on and a record you can stand behind.
The answer is in your data, so run the assessment and write it down
The thing people most often get wrong is assuming the question has one answer. "Is an IP address personal information?" is not answered by the technology. It is answered by what you hold, what you do with it and who you are. The OAIC's default is caution, the definition turns on identifiability in your hands, and the penalties and breach notification duties attach the moment the data is personal information. For most businesses running a modern stack, the safer call is to treat IP addresses as personal information and build the compliance around them, and the only safe way to make that call is on the evidence, not on a guess.
Everything in this article points to the same conclusion. The definition in s 6(1) of the Privacy Act is broad and contextual, and the Full Federal Court has confirmed that both the "about" limb and the identifiability limb must be satisfied. The small business exemption protects businesses under the $3 million threshold unless they trade in personal information, provide health services, work on Commonwealth contracts or sit inside a corporate group, but it does not answer the characterisation question. Where the Act applies, the obligations are a published privacy policy, limited collection, secure storage, sensible retention, honest notification and a workable breach plan. The reform agenda points one way, towards broader coverage and stronger enforcement, so the businesses that will stay comfortable are the ones that treat privacy as an ongoing program rather than a one-off label.