Analytics and Tracking

Fingerprinting

Also called Device fingerprinting, browser fingerprinting

Recognising a device from its own characteristics rather than a stored cookie, leaving the person nothing to clear.

Quick facts: Fingerprinting

Category
Analytics and Tracking
Also called
Device fingerprinting, browser fingerprinting
Level
Advanced
Affects
Legal exposure, platform policy risk, data accuracy
Where to see it
Browser DevTools, Firefox and Safari privacy settings, vendor documentation
In this article4
  1. How fingerprinting works
  2. Why fingerprinting matters
  3. Where fingerprinting goes wrong
  4. What to do about it

How fingerprinting works

Every browser gives away small details as it loads a page: the operating system, screen size, timezone, language, installed fonts, graphics behaviour, audio processing, which extensions have altered the page. Individually none of these identifies anyone. Combined, they form a pattern distinctive enough to recognise the same device on a later visit, or on another website, with no cookie stored anywhere.

Passive fingerprinting reads what the browser announces anyway. Active fingerprinting goes further and asks the device to perform small tasks — draw a shape, process a sound — because the tiny differences in the result vary between hardware and driver combinations. The output is turned into an identifier and stored on a server, not on the device, which is the whole point: there is nothing for the visitor to clear.

Browsers now push back. Safari and Firefox both reduce or randomise the signals available, Firefox blocks known fingerprinting scripts in its stricter mode, and privacy-focused browsers make devices look deliberately alike.

Why fingerprinting matters

It matters mostly because it is what gets sold to you. As third-party cookies became unreliable, a wave of tools appeared promising cookieless identity, full attribution or complete recovery of lost conversions. A fair number of them are doing some form of fingerprinting under a friendlier name.

That creates real exposure. Removing the cookie does not remove the legal question: European and UK rules treat reading information from someone’s device, and building a profile from it, as something that needs a lawful basis and usually consent. Ad platform policies have long restricted it, and although the wording on some platforms has been loosened, data protection regulators have been openly critical of that direction. Browsers, meanwhile, are moving the other way. A technique that is simultaneously being blocked and being questioned by regulators is a poor foundation for a measurement plan.

Where fingerprinting goes wrong

The first failure is the assumption that no cookie means no consent needed. That is not how the law reads, and it is the reasoning most often used to justify buying one of these tools.

The second is accuracy. Fingerprints drift. A browser update, a new monitor, a font install or a switch from mobile data to wi-fi can change the pattern, so the same person is counted twice or two similar office laptops are merged into one. Reports built on it look precise and are not.

The third is a confusion of purpose. Checking a device signal to stop repeated fraud on a payment form is a narrower and more defensible use than following someone around the web to sell them a sofa. Vendors often quote the first to justify the second.

What to do about it

Do not buy identity you are not allowed to keep. Ask any vendor promising cookieless measurement exactly what signals they read and where the identifier is stored; if the answer is vague, that is your answer.

Build on data people knowingly give you instead: an email address at checkout, a phone number on an enquiry form, a logged-in account. That information can be hashed before it is sent to an ad platform, which is a different thing entirely from covertly identifying a device. Pair it with server-side collection and honest reconciliation against your own sales records, and you end up with numbers you can defend to a client and to a regulator.

Do and do not

Do

  • Ask vendors which browser signals their tool reads
  • Use data customers knowingly gave you instead
  • Take legal advice before any device-level identification

Do not

  • Assume no cookie means no consent needed
  • Treat fingerprint-based reports as precise counts
  • Accept cookieless as an explanation of how something works

Questions people ask about this

Is fingerprinting illegal?

It is not automatically illegal everywhere, but in the EU and UK it is treated as accessing information on a person's device and building a profile from it, which needs a lawful basis and normally consent. Ad platform policies add their own restrictions, and those have changed over time. Check the current rules for your markets and the platforms you use before relying on it.

How is fingerprinting different from hashed email matching?

The difference is knowledge and choice. Hashed matching uses an email address or phone number the customer gave you, scrambled before it is shared, for a purpose they were told about. Fingerprinting identifies a device from characteristics the person never offered and cannot withdraw, because nothing is stored on their machine for them to delete.

A vendor says their tool is cookieless. Should I be worried?

Ask how it works before deciding. Cookieless can mean server-side collection using your own first-party data, which is fine, or it can mean device fingerprinting dressed up. The questions to put in writing are which signals are read from the browser, where any identifier is stored, and how a person withdraws consent.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.