As has been repeatedly argued in cases of IP-rights-holders-vs-sharers, an IP address on its own does not identify an individual. We argue that both ways depending on what suits us at the time, or we are as bad as the music industry flipping between “you bought the CD” and “you licensed the music” when it suits them to.
This is only true in certain jurisdictions. The GDPR recitals specifically mention IP addresses as examples of personal data:
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
My take: An IP address is usually not, in fact almost always not, PII on its own, but there are circumstances where it is part of a package of data that is PII, and others where it could be considered “circumstantial PII”.