Understanding the Source of the Questions
Your analytics dashboard shows 150,000 visits from California IP addresses last quarter. Your legal team is asking if this triggers CCPA applicability. Your CFO wonders if you need to budget for compliance infrastructure. And your engineering lead questions whether each IP address represents a unique California resident.
These questions arise in privacy team meetings, vendor calls, and board presentations. They matter because many state privacy laws apply only to organizations processing personal information of at least 100,000 state residents. If your website traffic doesn't meet that bar, you might not be subject to the statute.
The challenge is that analytics reports aggregate IP addresses, not people. Whether an IP address constitutes personal information is a fact-specific question.
Does an IP Address Count as Personal Information?
Not automatically. Under the California Consumer Privacy Act (as amended by the California Privacy Rights Act), personal information is "information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." The statute lists "Internet Protocol Address" as an example but qualifies it: the IP address must actually identify, relate to, or be reasonably linkable to a particular person.
When the California Attorney General was asked to clarify if IP addresses alone constitute personal information under the CCPA, he declined. His office stated that such a determination is "fact-specific and contextual."
You can't assume every IP address in your analytics report is personal information. You need to assess the type of IP address and whether it resolves to an identifiable person.
Static vs. Dynamic IP Addresses
A static IP address doesn't change over time. It's dedicated indefinitely to a particular computer, network, or user. If someone visits your site from the same home broadband connection repeatedly, they're likely using a static IP.
A dynamic IP address is assigned by a network when a computer connects and changes over time. Each time the user reconnects, they might get a different address. Mobile networks, VPNs, and many corporate networks use dynamic IP assignment.
This matters because a dynamic IP address that changes with each session is harder to link to a specific person. If you can't reasonably link it to an individual, it may not constitute personal information under the statute's definition. And if it's not personal information, it doesn't count toward your volume threshold.
Do 200,000 Visits from Colorado IP Addresses Mean We've Crossed the Threshold?
Almost certainly not. Your analytics are counting visits, not unique residents. Those 200,000 visits likely include:
- Bot traffic: Not personal information, not state residents.
- Tourists and business travelers: They're physically in Colorado but aren't residents. Even if the IP address is personal information, it doesn't count against a resident-based threshold.
- Repeat visits from the same person: If someone visits your site fifty times from their laptop, that's fifty visits but one resident. The threshold refers to the number of state residents, not the number of times they access your site.
- Dynamic IP reassignments: The same person might generate multiple IP addresses if they're reconnecting to a network that assigns dynamic addresses.
- VPN users: Someone in New York using a Colorado VPN endpoint shows up as a Colorado IP address in your reports, but they're not a Colorado resident.
- Business context visits: In states like Colorado, Connecticut, and Virginia, the privacy statute doesn't apply to individuals acting in an employment context. If someone visits your B2B site from their work computer, that might not count even if the IP address is personal information.
You're aggregating thousands or millions of fact-specific situations. It's difficult to determine what percentage of those IP addresses actually represent unique in-state residents.
How to Assess Whether You Meet the Volume Threshold
Don't rely on website analytics alone. Instead, look at the personal information you actually collect and store:
- Customer databases: How many accounts do you have with addresses in the state?
- Email lists: How many subscribers have provided a state-based address?
- Transaction records: How many purchases or service requests came from state residents?
- CRM data: How many leads or contacts are tagged with in-state locations?
These sources give you a count of identifiable individuals, not just IP addresses. They're far more defensible if you need to demonstrate whether the statute applies to your organization.
If you're on the borderline, document your methodology. Show how you distinguished unique residents from repeat visits, bot traffic, and out-of-state users. That documentation becomes your evidence if a state attorney general questions your applicability determination.
What If a State Attorney General Disagrees?
If a state attorney general brings an enforcement action under one of the state privacy laws, they must establish that the statute applies to your organization. Given the difficulty of determining what percentage of website visitors fall into each category, it's unlikely an attorney general would base applicability solely on website visit counts from in-state IP addresses.
They'd need to prove you're processing personal information of at least 100,000 state residents. That's much easier to establish with customer records, email lists, or transaction data than with aggregated IP address reports that include bot traffic, tourists, and VPN users.
This doesn't mean you should ignore the threshold. It means you should focus your compliance assessment on the personal information you can actually identify and count.
When Do IP Addresses Count Toward the Threshold?
If you're collecting static IP addresses and linking them to identifiable individuals in your database, those likely count. For example:
- You operate a membership site where users log in from the same home broadband connection (static IP) each time.
- You're correlating IP addresses with email addresses, names, or account IDs in your systems.
- You're using IP addresses for fraud detection or account security in ways that tie them to specific user profiles.
In these cases, you're not just passively logging IP addresses in analytics. You're actively using them to identify or track individuals. That's much more likely to constitute processing personal information of state residents.
Next Steps
Start with your customer database, not your analytics dashboard. Count the identifiable individuals whose data you're actually processing. If you're close to a volume threshold, document your methodology and assumptions. And if you're building new data collection systems, consider whether you need to track state residency at the point of collection rather than inferring it from IP geolocation after the fact.
The volume thresholds exist to exempt organizations with minimal state presence. If you're genuinely processing data from 100,000+ residents of a state, you probably know it from your customer base, not from your web server logs.



