> Unless you have some means of ultimately figuring out "this data belongs to Joe Bloggs of 123 Any Street", then it isn't personal data.
That's not exactly accurate.
I like the ICO's literature on this[1] because they put a little more colour on what it means to be "indirectly" identifiable, and they are pretty clear:
• You don’t have to know someone’s name for them to be directly identifiable, a combination of other identifiers may be sufficient to identify the individual.
• It is important to be aware that information you hold may indirectly identify an individual and therefore could constitute personal data.
• That additional information may be information you already hold, or it may be information that you need to obtain from another source.
That's the case here: An ISP such as Vodafone knows the IP addresses of their broadband users, and perhaps even some of their cookies -- they have this other piece of data that makes what Google is providing personal data. To my knowledge Google isn't attempting to even argue otherwise, instead they have taken the position that the person has consented (using various consent managers or click-to-accept dialog boxes), so therefore it's pseudonymous, which makes your next paragraph a little more important:
> Pseudonymous data falls within the scope of GDPR if other information could be used to associate that data with an identifiable natural person. Truly anonymous data is exempt...
This is incorrect. Again from the ICO:
• Pseudonymised data can help reduce privacy risks by making it more difficult to identify individuals, but it is still personal data.
• Information which has had identifiers removed or replaced in order to pseudonymise the data is still personal data for the purposes of GDPR.
Very clear: All it takes is for the data to relate to a person.
> It really isn't clear to me that Google are in breach in this instance
It's not clear to me either, or (to my knowledge) to the Irish DPC at this stage, but part of their responsibility is to figure it out. They have released very little information so far[2] so there's little point armchair-lawyering on what their position or defence would be.
[1]: https://ico.org.uk/for-organisations/guide-to-data-protectio...
[2]: https://www.dataprotection.ie/en/news-media/press-releases/d...