Earlier quoted context omitted.
They said they only did this for US based IP addresses. (Not that it makes it OK...)
Not explicitly, they might have been just using US data as an example in this blog post. Even if they aren't, I still wonder that if they're checking everyones IP addresses against that database, essentially sharing our access of SO with a third-party, would it still be an inappropriate use of personally identifiable information?
Quoting their website, "The organization name is available for about 40% of corporate, government, and educational networks."