Browser Fingerprinting
Browser fingerprinting is a technique that identifies and tracks a particular browser, and by extension its user, by collecting and combining details about the device, its settings, and its configuration. Unlike cookies, it does not rely on storing a file on the user's device, which makes it harder to notice and to clear. Because it can operate without visible storage, it is often described as a hidden or persistent way for websites and third parties to recognize returning visitors.
Browser fingerprinting is the systematic collection and combination of attributes exposed by a remote device and its browser (for example device details, system information, and browser settings) to derive an identifier that distinguishes one browser or user from others. It functions as a tracking method that does not depend on cookies or other client-side storage, which distinguishes it from mechanisms increasingly blocked or cleared by browsers. From a compliance perspective, although fingerprinting is not literally a cookie, in most EU and UK jurisdictions it typically falls within the same rules governing access to or storage of information on a user's device under the ePrivacy Directive and its national implementations, and any resulting processing of personal data is generally subject to the GDPR; where used for tracking, it would generally require valid prior consent under EU law, subject to evolving regulatory guidance. Requirements and enforcement positions differ across jurisdictions, and this definition does not resolve contested questions about when specific fingerprinting techniques qualify as exempt.
Why it matters
Browser fingerprinting matters because it can recognize and track returning visitors without storing anything on their device, unlike cookies. As mainstream browsers increasingly block or clear third-party cookies by default, fingerprinting has drawn attention as an alternative tracking method that is harder for users to notice and harder to clear. This has direct compliance implications: even though fingerprinting is not literally a cookie, in most EU and UK jurisdictions it typically falls within the same rules that govern access to or storage of information on a user's device under the ePrivacy Directive and its national implementations, and any resulting processing of personal data is generally subject to the GDPR.
For privacy officers and compliance teams, the significance lies in the fact that the covert nature of fingerprinting does not exempt it from consent obligations. Where fingerprinting is used for tracking purposes in the EU, it would generally require valid prior consent, meaning consent that is freely given, specific, informed, and unambiguous through a clear affirmative action. Because the technique operates without visible storage, organizations may overlook it when scoping their consent management, leaving a gap between what a consent banner covers and what tracking technologies are actually deployed.
The legal treatment of specific fingerprinting techniques remains an area of evolving regulatory guidance, and reasonable questions persist about when, if ever, certain fingerprinting uses might qualify as exempt or as strictly necessary. Requirements and enforcement positions also differ across jurisdictions; approaches under US state privacy laws, for example, often rely on opt-out mechanisms rather than the opt-in model prevalent in the EU. Organizations should therefore treat fingerprinting as a tracking technology requiring the same scrutiny as cookies rather than assuming the absence of a stored file removes it from scope.
Who it's relevant to
Inside Browser Fingerprinting
Common questions
Answers to the questions practitioners most commonly ask about Browser Fingerprinting.

