The classic trap
Recital 30 has a direct consequence too often ignored: an IP address, a cookie ID, a mobile advertising identifier (IDFA, GAID) or an RFID tag are personal data as soon as they allow, alone or combined, the identification of an individual. The CNIL and the CNPD regularly sanction companies that still treat these identifiers as merely technical or anonymous, and exploit them (analytics, retargeting, fingerprinting) without an article 6 legal basis or article 7 consent. The EDPB reaffirmed this in its guidelines on the targeting of social media users: simply dropping a third-party profiling cookie triggers the full application of the GDPR.
What this recital changes for your website and apps
- Every IP logged by your web servers, firewalls or WAFs is personal data: justified retention period, documented purpose, article 30 record kept current.
- Fingerprinting (canvas, fonts, timezone, user-agent combined) falls under the same regime as cookies: prior consent required, in line with article 5(3) of the ePrivacy directive.
- Mobile advertising identifiers (Apple IDFA, Google GAID) trigger the same duties as cookies, including withdrawal of consent as easy as granting it.
- RFID tags on access badges, store products or logistics inventories are caught as soon as they can be linked to an individual (employee, loyalty cardholder).
- Combining multiple pseudo-anonymous identifiers (IP + user-agent + timestamp) is enough to build an identifiable profile: the re-identification test must be documented in your DPIA.
How Luxgap automates this risk
Our Luxgap Identifier Footprint Scanner exposes the invisible: every online identifier your organisation collects, propagates and stores without realising it. A lightweight JS snippet on your public websites, combined with API connectors to Cloudflare, AWS CloudFront, Azure Front Door, Google Tag Manager, Matomo, Piano Analytics and your CMP (Didomi, OneTrust, Axeptio), rebuilds in real time the full map of your identifier footprint, page by page, journey by journey, market by market.
- Scans each page of your public websites and detects every identifier set (cookies, localStorage, sessionStorage, canvas fingerprinting, invisible pixels) with its real issuer and probable purpose.
- Automatically classifies each identifier against the CNIL/CNPD grid: strictly necessary, exempted audience measurement, tracker subject to consent, transfer outside the EU.
- Detects consent breaches in real time: a tag firing before "Accept" is clicked, a pixel persisting after "Reject", a mobile identifier transmitted without IDFA opt-in.
- Inspects the network flows of your iOS and Android apps to identify third-party SDKs that exfiltrate IDFA, GAID, IP or device identifiers without disclosure in your privacy notice.
- Computes a re-identification score for each combination of pseudo-anonymous identifiers found in your server logs, and alerts on risky joins (IP + user-agent + fine-grained timestamp).
- Produces a timestamped PDF report, defensible before the CNPD or CNIL during an audit, that demonstrates ePrivacy article 5(3) compliance and identifier governance in the sense of recital 30.
Available as part of a Luxgap DPO mandate or as a standalone SaaS module depending on your digital perimeter. Request a tailored quote and our teams deploy a free 48-hour scan on your websites and apps, to materialise your real exposure before any commitment.