Skip to content
← GDPR for web forms
GDPR · IP addresses

IP addresses and your forms

Every form submission arrives from an IP address, and several systems along the way can write it down: your web server, your CDN, your form backend, a CAPTCHA service. Whether that matters under the GDPR, and what to do about it, comes down to three questions: is the address personal data, why do you keep it, and for how long.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

Is an IP address personal data?

The GDPR defines personal data in Article 4(1) as information about an identified or identifiable person, and names “an online identifier” as one way a person can be identified. Recital 30 gives IP addresses as an example of such an identifier.

The Court of Justice settled the harder case in Breyer v Bundesrepublik Deutschland (C-582/14), decided on 19 October 2016. A website operator usually cannot tell who sits behind a dynamic IP address. The Court held that the address is still personal data for the operator when it has legal means to identify the person with additional data held by the internet provider, for example through the authorities after an attack. The case was decided under the old Directive 95/46, but the definition it interpreted carried over into the GDPR.

The practical reading for a form owner: treat the IP addresses your forms collect as personal data, and design around that.

Where a form setup leaves IP addresses

  • Web server and proxy logs, for the page that shows the form.
  • The form backend, which often keeps the address with the submission for rate limiting and abuse checks.
  • A CDN or firewall in front of either of them.
  • A CAPTCHA or bot check, which the visitor's browser talks to directly.
  • Analytics on the page, if any.

Each one is a separate copy with its own retention and, often, its own location. When you write your record of processing, list them all, not only the form backend.

Why hashing is not the same as anonymising

A common shortcut is to store a SHA-256 hash of the address. It looks unreadable, but the IPv4 space has only about 4.3 billion addresses. Hashing every one of them takes little time on ordinary hardware, after which each stored hash maps straight back to its address.

A keyed hash (an HMAC with a secret key) closes that gap for anyone who does not hold the key. In GDPR terms that is pseudonymisation under Article 4(5): the data can no longer be linked to a person without additional information that is kept separately. Recital 26 is explicit that pseudonymised data is still personal data. So a keyed hash is a good safeguard under Articles 25 and 32, not an exit from the regulation.

Lawful basis and how long to keep it

Spam and abuse protection is the usual reason a form keeps an IP address. Recital 49 states that processing strictly necessary for network and information security is a legitimate interest, which points to Article 6(1)(f). That basis comes with a balancing test, and the balance favours keeping as little as possible for as short as possible.

A rate limit needs the address for minutes, not months. If nothing else depends on it, there is little reason to keep the IP linked to a submission for as long as the message itself. Whatever you choose, say so in your privacy notice.

What Formward does with submitter IPs

  • Keyed hash on receipt. The submitter's address is hashed with HMAC-SHA-256 and a secret server-side salt before anything is stored. The raw address is not written to disk.
  • Used for rate limiting. The hash is what the per-IP, per-form rate limit counts against. By default that is 50 submissions a minute per address, and you can set a lower or higher limit per form.
  • 24-hour removal. In the Privacy center a workspace owner or admin can set a form to drop the hash 24 hours after each submission. A sweep runs every 15 minutes. Without that setting, the hash is kept as long as the submission.
  • Anonymous hosted forms. A hosted form set to anonymous stores no IP hash with its submissions at all.
  • Server logs. Web server access logs keep only a truncated address, as described in the privacy policy.

One exception sits outside Formward's servers. If you switch on Cloudflare Turnstile for a form, the visitor's browser talks to Cloudflare, a US company, which sees challenge data such as the IP address and browser signals, but no form answers. It is off unless you enable it, and it is listed in the sub-processor register. The _gotcha honeypot and the rate limit work without it.

Questions

Is an IP address personal data under the GDPR?
In most cases a website operator should treat it as personal data. Article 4(1) names online identifiers, Recital 30 lists IP addresses among them, and in Breyer (C-582/14) the Court of Justice held that even a dynamic IP address is personal data for a website operator that has legal means to identify the person with the help of the internet provider.
Is a hashed IP address anonymous?
Not by itself. There are only about 4.3 billion IPv4 addresses, so a plain hash can be reversed by hashing all of them. A keyed hash with a secret is pseudonymised data, which Recital 26 says is still personal data. It lowers the risk, and that is worth having, but the GDPR keeps applying to it.
Do I need consent to log IP addresses for spam protection?
Usually not. Recital 49 recognises processing that is strictly necessary for network and information security as a legitimate interest under Article 6(1)(f). Mention it in your privacy notice, keep it to what you need, and delete it on a schedule.
Can Formward stop keeping the IP hash?
Yes. In the Privacy center a workspace owner or admin can set a form to remove the IP hash 24 hours after each submission. Hosted forms set to anonymous store no IP hash at all, while still using it in memory for rate limiting.

Forms that never store the raw address

Every plan hashes submitter IPs on receipt. Switch on 24-hour removal per form in the Privacy center.

Are IP addresses personal data under GDPR? | Formward