Generally yes, for three reasons. Under EU case law, a visitor's IP address is personal data if you can identify them with help from others, as is usually the case with ordinary server logs. The GDPR expressly treats pseudonymous identifiers, such as analytics cookies, as personal data: anonymity must be achieved rather than assumed. Embedded third-party scripts may create joint controllership where you jointly determine the purposes and means of specific operations. Depending on the setup, the third party may instead be a processor or an independent controller. The first question is therefore technical: what does your website load in the background?
A brochure website has no contact form, registration or newsletter. Nobody enters a name, so there seems to be nothing to protect. Yet website personal data arises from the visit itself, not only a completed form. GDPR applicability therefore depends on what happens in the background when the site loads.
An IP address is personal data
Article 4(1) GDPR defines personal data as information relating to an identified or identifiable person, including through an online identifier. In Breyer (C-582/14, judgment of 19 October 2016), the Court of Justice of the EU assessed dynamic IP addresses in a website operator’s logs. They are personal data where the operator has legal means to identify the visitor with help from others, typically the internet service provider. The test is relative rather than automatic. For an ordinary website with server logs, however, the usual conclusion is that the logs contain personal data and retaining them is already processing. Security logging can usually rely on legitimate interests rather than consent.
Pseudonymity is not anonymity
A second misconception is: “We do not know who it is; we only see an identifier.” Recital 26 GDPR states that pseudonymised data attributable to a person using additional information is information about an identifiable person. Data is anonymous only when identification is not reasonably likely using any means reasonably expected to be used. An analytics cookie identifier, device ID or browser fingerprint therefore falls squarely within the online identifiers envisaged by the GDPR.
Responsibility must be determined for third-party scripts
The third reason is often overlooked. An embedded social media button, analytics, map, remotely hosted font or video player transmits visitor data to a third party as the page loads. In Fashion ID (C-40/17, judgment of 29 July 2019), the Court of Justice held that a website operator embedding a “Like” button is a joint controller with the social network for collecting and transmitting visitor data. In that case, joint controllership arose from jointly determining the purposes and means of collection and transmission; it did not automatically extend to all subsequent processing by the social network. The same outcome cannot be applied without assessment to every font, map or analytics tool. For each one, the specific operations must be identified, together with whether the parties act jointly, independently, or as controller and processor. Responsibility cannot, however, be avoided merely by pointing to a third-party script.
Simple website changes can reduce the risks: static sharing buttons instead of embedded scripts, locally hosted fonts, a video preview image linking to the platform, and analytics activated only after consent. Non-essential cookies require consent under Section 109(8) of Act No. 452/2021 Coll.. We explain compliant banners in cookie walls.
A small website’s minimum package
Start with an inventory: which scripts load, what the host logs and where data flows. Follow this with concise legal documentation: a privacy notice containing Article 13 GDPR information, legitimate interests for logs, a processing agreement with the host, and a cookie banner only if non-essential cookies are actually used. A website without them needs no banner. We summarise other requirements in personal data processing duties.
How we can help
Our GDPR and personal data protection service combines a technical and legal website inventory with documents reflecting what the site actually does. Our cookies and website configuration service configures banners and scripts, while shops can use our e-commerce legal services package. Send us the website address: a script inventory is the first step, and we can conduct it from our side.
This answer provides general information on the law as at 10 September 2026. It does not constitute legal services or replace an assessment of an individual case. The details of your situation may differ. Book a consultation to discuss them.