# CJEU, judgment of 19 October 2016, C-582/14, Breyer

Dynamic IP addresses as personal data; processing to ensure the functionality of publicly accessible websites as a legitimate interest under Article 7(f) of the Data Protection Directive.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.37-eugh-breyer
> Sprache: en



## 1 Overview [#1-overview]

A user had brought proceedings against the storage of dynamic IP addresses by the operators of publicly accessible websites of the German federal administration. The IP addresses were stored after the end of a session in order to make it possible to trace and defend against attacks on those sites. The German Federal Court of Justice (BGH) referred questions to the CJEU on the classification of dynamic IP addresses as personal data and on the interpretation of Article 7(f) of Data Protection Directive 95/46/EC (the predecessor provision to Article 6(1)(f) GDPR).

## 2 Headnotes [#2-headnotes]

Dynamic IP addresses constitute personal data for the website operator where the operator has legal means enabling it to determine the identity of the data subject with reasonable effort and with the assistance of third parties (in particular the internet access provider) (paras. 43 et seq.).

Article 7(f) of the Data Protection Directive precludes a national rule which permits a public body to store IP addresses in order to ensure the functionality of its generally accessible online services **without** allowing a balancing, in the individual case, of the interest in the data processing against the data subject's interest in protection. Ensuring the functionality of a publicly accessible website may constitute a legitimate interest, but it must be weighed against the rights of users (paras. 60 et seq.).

## 3 Significance [#3-significance]

Breyer is the starting point for the treatment of IP addresses under data protection law and for the recognition of network and website security as a legitimate interest. Those principles continue to apply under Article 6(1)(f) GDPR and are expressly confirmed by Recital 49 GDPR.

<Cards>
  <Card title="Legitimate interests" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen" description="Article 6(1)(f) GDPR." />

  <Card title="Legal bases (Article 6 GDPR)" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung" description="Structure and overview." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.