The Line Between Personal and Nonpersonal Information
Where personal ends and nonpersonal begins is unclear and varies by regime. The EU generally treats IP addresses as personal data; U.S. agencies under the Privacy Act do not, though the FTC has called them personal in health-breach contexts.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US exam format and blueprint.
The difference between personal and nonpersonal information depends on what is identifiable, and the line is not always clear - regulators and courts in different jurisdictions may disagree.
| Regime | IP address treatment |
|---|---|
| European Union | Generally considered personal data (identifiable) |
| U.S. federal agencies under the Privacy Act | Not considered covered by the statute |
| U.S. FTC (health-care breach context) | Considered personal information |
Whether an IP address is 'personal' depends on the regulatory regime. Changes in technology (static vs. dynamic IPs, IPv6) can also shift the line toward identifiability.
Key terms - quick answers
What is “IP address”?
What is “Privacy Act”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.