> Court reporting in 2026 established that Microsoft held a GDID-to-URL/time/IP association in one investigation.
Afaik, this is illegal under GDPR, as an IP has been classified as a personal identifier. > Court reporting in 2026 established that Microsoft held a GDID-to-URL/time/IP association in one investigation.
Afaik, this is illegal under GDPR, as an IP has been classified as a personal identifier.1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test)
2) if proper GDPR Article 13 notice was given and it covers that processing
3) if all Article 5 principals are being followed in regards to it (e.g. data minimization, retention period etc.)
4) if Microsoft had legal basis to transfer the data to police (they probably did, that's not high bar to clear)
> Storing IP address itself is not illegal
True, but associating that with a device the user owns (not Microsoft) would require a very real justification like you mentioned, and I precluded that there is no legitimate interest here. caveat: IANAL.