The GDPR at Six: Where Privacy Protection Succeeds and Stumbles
On the eve of Data Privacy Day 2024, the EU Commission has issued a call for evidence on the functioning of the General Data Protection Regulation (GDPR) as it approaches its sixth anniversary. The exercise invites a critical assessment of whether the regulation has actually improved privacy outcomes for individuals. The honest answer is that in most respects it has — but in two significant areas, the way the GDPR has been applied to internet data flows has done little for privacy and may have actively undermined it.
The GDPR remains the global benchmark for data protection legislation. It has shaped privacy laws across jurisdictions, enshrined data subject rights that other regimes have copied, and raised expectations for how organizations should handle personal data. There is little question that it has moved the needle in giving people more control over their information. However, a close look at the regulation's enforcement reveals problems, particularly with how some regulators treat cross-border data transfers and IP addresses.
The Limits of Geographic Thinking
The GDPR's architecture assumes that legal protections should travel with data based on where it is located — where it is generated, processed, or stored. Articles 44 to 49 set conditions for transferring data to jurisdictions outside the EU, with the intent that GDPR protections follow the data wherever it goes. The approach was influenced by post-Snowden concerns about government surveillance and the reality of intelligence agencies tapping internet choke points.
This tension reached its peak in July 2020 with the European Court of Justice's Schrems II decision1. The ruling invalidated the EU-US Privacy Shield adequacy standard and cast doubt on standard contractual clauses as a transfer mechanism. While some data protection authorities found room within the ruling to allow transatlantic data flows, others doubled down on the view that EU personal data could not be processed in the US consistently with the GDPR — effectively making data localization a proxy for data protection.
That framing is fundamentally backwards. Data localization threatens an organization's ability to achieve integrated cybersecurity risk management and limits access to state-of-the-art threat mitigation that depends on cross-border data flows. Cloudflare's Bot Management product, for instance, improves in accuracy through continuous use across a global network; locality and diversity of traffic signals feed the models that detect and block malicious bots. Fragmented internet infrastructure would blind these systems to attack patterns crossing regional boundaries. An attack trend observed in Asia would remain invisible to mitigation efforts in Europe, leaving services that process personal data more exposed — not less.
This cuts against the GDPR's own security obligations. Article 32 requires controllers and processors to implement "technical and organisational measures to ensure a level of security appropriate to the risk," taking into account "the state of the art." Data protection authorities routinely insist on robust cybersecurity measures in enforcement actions following breaches, yet data localization directly undercuts the very information sharing — within industry and with government agencies — that effective cybersecurity depends on. The GDPR's cross-border transfer rules, applied as a blunt instrument, prioritize geographic control over actual data security.
IP Addresses and the Threat of a Walled-off Internet
The second problematic area lies in an overbroad interpretation of what constitutes "personal data" in the context of IP addresses. If IP addresses are always treated as personal data — and therefore subject to the GDPR's transfer restrictions — the consequences edge toward requiring a Europe-only internet. Providers would be pushed toward building segmented networks so that EU IP addresses never cross jurisdictional boundaries. The result would be absurd: European users unable to reach services hosted in the US, and vice versa, in a world that depends on global interconnection.
The intellectual foundation for treating IP addresses as personal data comes from the 2016 CJEU ruling in Breyer v. Bundesrepublik Deutschland. There, the court held that even dynamic IP addresses could constitute personal data — but only if the entity processing them could link them to an individual. The court did not say IP addresses are always personal data. Yet that nuance was lost on EU data protection authorities. Several, including the Austrian DSB, the French CNIL, and the Italian Garante, took the stance that an IP address should always be treated as personal data, even when the entity processing it has no means to tie it to a natural person3. Only the Spanish AEPD followed the more measured Breyer interpretation.
The question is again before the CJEU. In April 2023, the lower EU General Court ruled in SRB v EDPS4 that transmitted data can qualify as anonymized — and therefore outside of GDPR coverage — when a recipient lacks records reasonably likely to enable re-identification and has no legal avenue to obtain them. The European Data Protection Supervisor is appealing, arguing that a unique identifier should be treated as personal data if it could ever be linked to an individual by anyone, regardless of the actual capabilities of the entity holding it.
There is a strong argument that the lower court's "relative" approach is the correct one. An IP address should not be treated as personal data when a party like a network infrastructure provider processes it with no means of mapping it to a person. If IP addresses are not always personal data, they are not always subject to the GDPR's transfer rules — and the threat of a balkanized European internet recedes.
This may seem counterintuitive to privacy advocates, but it would actually be a win for privacy outcomes. If IP addresses can flow freely, EU entities can draw on global cybersecurity providers that use machine learning and predictive techniques on traffic metadata to defend against DDoS attacks, bot networks, and data breaches. These models improve with data drawn from adversarial patterns worldwide. Restricting IP addresses as always-personal data would deprive European organizations of tools necessary to keep personal data safe.
A Path Back to Privacy-First Enforcement
This Data Privacy Day, EU policy makers would do well to study how the GDPR's application can inadvertently elevate geographic restrictions over the security measures Article 32 demands. When data regulators knee-jerkily favor data localization — however well-intentioned — they risk harming privacy as much as protecting it. Taken to its extreme, this approach threatens not just cybersecurity but the functioning of the global internet itself.
Two reforms would help. First, EU policymakers should issue guidance — or legislation — clarifying that IP addresses should not be considered personal data when the processing entity cannot link them to an identifiable person. Second, the GDPR should be applied bearing in mind the cybersecurity benefits of data processing. Recital 49 already recognizes a legitimate interest in processing for security purposes; an exemption from international transfer restrictions should follow when the processing is genuinely for cybersecurity defense. Such an interpretation would align GDPR enforcement with the regulation's fundamental purpose: protecting people's data rather than erecting geographic walls around it.
1 Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems.
3 Rulings by the Austrian DSB (December 2021), French CNIL (February 2022), and Italian Garante (June 2022) concerning Google Analytics rejected the Breyer relative approach and held IP addresses are always personal data. The Spanish AEPD (December 2022) aligned with Breyer. See also Guidelines by Supervisory Authorities for Tele-Media Providers, DSK (2021), para. 109 and 136.
4 Single Resolution Board v EDPS, Court of Justice of the European Union, April 2023.



