Orange textured background

Compliance reference

Fingerprinting laws by jurisdiction.

A plain-English reference to how the world's privacy regulators treat browser and device fingerprinting. 36 jurisdictions live, 47 planned. Not legal advice.

What you'll find here

Each jurisdiction page covers the operative statute, what counts as fingerprinting under it, when consent is required, what enforcement has looked like, and an FAQ. Pages are written for product and engineering teams shipping fingerprinting into production, not lawyers drafting a memo. We cite the statute and the regulator on every claim.

New: interactive

See the whole landscape on one screen.

The fingerprinting-law atlas plots every jurisdiction by consent posture, charts the biggest enforcement fines, and tracks when each regime took effect. Click anything to filter.

Live jurisdictions

Tier 1

Europe

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
European Union (all member states)European Data Protection Board (EDPB) + national DPAs Explicit consent €20M or 4% of global annual turnover (whichever is higher)Prior, freely given, specific, informed, unambiguous consent is required before reading fingerprinting signals, with narrow strictly-necessary carve-outs.2026-06-06
European Union (all member states, transposed nationally)National DPAs in each member state, coordinated by the EDPB Explicit consent Varies by member state national transposition (e.g. up to €200k under UK PECR before Brexit; up to €3M+ under French Article 82; no single EU-wide ceiling)Article 5(3) requires prior consent before reading any signals from a user's device; EDPB Guidelines 2/2023 confirm fingerprinting is explicitly in scope.2026-06-06
United Kingdom (England, Scotland, Wales, Northern Ireland)Information Commissioner's Office (ICO) Explicit consent £17.5M or 4% of global annual turnover (UK GDPR); £500,000 (PECR, pre-DPDI Bill)Same consent requirement as EU GDPR for now; ICO has been clearer than most DPAs that fingerprinting is treated as 'similar to a cookie'.2026-06-06
Switzerland (federal, all cantons)Federal Data Protection and Information Commissioner (FDPIC / EDOB / PFPDT) Conditional CHF 250,000 criminal sanction per individual (not a corporate administrative fine)Fingerprinting is personal data under nFADP; lawful basis is required, proactive Art 19 notification is mandatory at collection, and criminal penalties fall on individuals rather than corporations.2026-06-06
TurkiyeKisisel Verileri Koruma Kurumu (KVKK - Personal Data Protection Authority) Explicit consent ~TRY 9.4M per violation in 2026 (indexed annually); doubles for repeat offensesExplicit consent is required for most fingerprinting purposes; biometric-signal fingerprinting triggers special-category rules, VERBİS registration is mandatory above threshold, and the 2024 amendments added 72-hour breach notification and DPIA requirements.2026-06-06

United States

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
California, United StatesCalifornia Privacy Protection Agency (CPPA) + California Attorney General Conditional $2,500 per violation; $7,500 per intentional violation or violation involving a minor's dataNotice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16.2026-06-06
Virginia, USAOffice of the Attorney General of Virginia Conditional Up to $7,500 per violation in civil penaltiesNo general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes.2026-06-06
Colorado, USAColorado Attorney General + District Attorneys Conditional Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112)Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes.2026-06-06
Connecticut, USAConnecticut Attorney General (Privacy and Data Security Section) Conditional Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive reliefOpt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime.2026-06-06
Utah, USAUtah Attorney General + Utah Division of Consumer Protection Conditional Up to $7,500 per violation in civil penalties (Utah Code §13-61-402)Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers.2026-06-06
Texas, USATexas Attorney General (Consumer Protection Division) Conditional Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155)No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template.2026-06-06
Oregon, USAOregon Attorney General (Department of Justice) Conditional Up to $7,500 per intentional violation (ORS 646A.589)Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date.2026-06-06
Montana, USAMontana Attorney General - Office of Consumer Protection Conditional Up to $7,500 per violation (Mont. Code Ann. §30-14-142)Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026.2026-06-06
Delaware, USADelaware Department of Justice - Consumer Protection Unit (Attorney General) Conditional Up to $10,000 per intentional violation (Del. Code §12D-111)Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025.2026-06-06
Iowa, USAIowa Attorney General (Consumer Protection Division) Conditional Up to $7,500 per violation in civil penaltiesOpt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset.2026-06-06
Tennessee, USATennessee Attorney General, Office of Consumer Protection Conditional Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster.2026-06-06
New Hampshire, USANew Hampshire Attorney General (Consumer Protection and Antitrust Bureau) Conditional Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costsOpt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties.2026-06-06
New Jersey, USANew Jersey Attorney General (Division of Consumer Affairs) Conditional Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act)Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law.2026-06-06

Americas

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
Canada (federal, commercial activities; Quebec uses Law 25)Office of the Privacy Commissioner of Canada (OPC) Explicit consent Up to CAD $100,000 per violation (Bill C-27 would raise this significantly)Meaningful, knowledge-based consent is required before collecting fingerprinting signals; the OPC's 2024 guidance names fingerprinting as a practice requiring explicit opt-in.2026-06-06
Brazil (national)Autoridade Nacional de Proteção de Dados (ANPD) Conditional 2% of the controller's Brazilian revenue, up to BRL 50 million per infringementConsent is one of ten lawful bases; legitimate interest is workable for fraud and security, with documented assessment.2026-06-06

Asia-Pacific

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
India (national)Data Protection Board of India (yet to be fully constituted as of mid-2026) Conditional Up to INR 250 crore per breach category (Section 33)Consent is the default basis; Section 7 legitimate uses cover fraud and security with notice, without separate consent.2026-06-06
Japan (national)Personal Information Protection Commission (PPC / 個人情報保護委員会) Conditional Up to ¥100 million (corporate fine, post-2022 amendments)Fingerprint data is 'personally referable information' under the 2022 amendments; consent is required before sharing it with third parties who can re-identify the user.2026-06-06
People's Republic of China (mainland, excludes Hong Kong and Macau)Cyberspace Administration of China (CAC), with sectoral roles for MIIT and PBOC Explicit consent Up to RMB 50 million or 5% of preceding year's annual turnover, plus business suspension and license revocationConsent is the default lawful basis under PIPL Article 13. Fingerprinting requires prior, voluntary, informed, explicit consent, with separate consent for third-party sharing and cross-border transfers.2026-06-06
SingaporePersonal Data Protection Commission (PDPC) Implicit consent Higher of S$1 million or 10% of annual turnover in SingaporeConsent is required before collecting fingerprint-derived identifiers; the 2020 'deemed consent by notification' path (s 15A) offers a narrower opt-out-style route, but explicit anti-fraud carve-outs and PDPC advisory guidelines make the overall framework more operationally specific than most APAC peers.2026-06-06
Kingdom of ThailandPersonal Data Protection Committee Office (PDPC, under the Ministry of Digital Economy and Society) Explicit consent THB 5 million administrative fine per violation + up to 1 year imprisonment and THB 1 million criminal fine for serious violationsExplicit written or electronic-written consent under section 19 is required before collecting fingerprinting signals for most purposes; stricter than GDPR and enforced since 2024.2026-06-06
Australia (Commonwealth)Office of the Australian Information Commissioner (OAIC) Conditional A$50M, or three times the benefit gained, or 30% of adjusted turnover, whichever is greatestFingerprint hashes are personal information under the Privacy Act; collection requires APP 3 necessity, notification under APP 5, and consent when used as biometric data for identification.2026-06-06
New ZealandOffice of the Privacy Commissioner (OPC) Conditional NZ$10,000 per offence (statute); HRRT damages awards up to NZ$350,000 for humiliation, loss of dignity, and injury to feelingsFingerprinting is regulated under 13 IPPs; IPP 12 requires comparable overseas-recipient safeguards or consent before sending hashes to a non-NZ vendor, making vendor choice a first-order compliance question.2026-06-06

Middle East & Africa

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
United Arab Emirates (federal mainland; excludes DIFC and ADGM)UAE Data Office Explicit consent Administrative fines set by Executive Regulations (pending as of mid-2026); amounts not yet published in final formFingerprinting is personal data under the PDPL; biometric-derived hashes require explicit consent. DIFC and ADGM free zones operate under their own stand-alone data protection laws, not the PDPL.2026-06-06
Kingdom of Saudi ArabiaSaudi Data and AI Authority (SDAIA) Explicit consent Up to SAR 5 million per violation; doubled for repeat offences; up to 2 years imprisonment for unauthorised disclosure of sensitive personal dataExplicit consent is the primary basis for non-security fingerprinting; cross-border transfers must follow the 2023 adequacy or safeguards model, and sensitive data joined to a fingerprint may require in-country storage.2026-06-06
State of IsraelPrivacy Protection Authority (PPA) Explicit consent NIS 320,000 per breach; effective fines up to NIS 1.6M for serious or very serious breachesExplicit consent is required under Amendment 13; database registration with the PPA is mandatory before processing data from more than 10,000 individuals or any sensitive data, making Israel unique among Western privacy regimes.2026-06-06
South AfricaInformation Regulator (South Africa) Explicit consent R10 million administrative fine or 10 years imprisonment (Section 107)POPIA is an opt-in regime. Fingerprinting requires a Section 11 lawful basis, and direct marketing to non-customers via electronic means demands prior consent under Section 69.2026-06-06
Federal Republic of NigeriaNigeria Data Protection Commission (NDPC) Explicit consent NGN 10M or 2% of annual gross revenue (data controllers of major importance); NGN 2M or 2% of annual revenue (all others), whichever is higher in each tierThe NDPC's 2024 guidance explicitly classifies device fingerprints as personal data; consent or another s 25 lawful basis is required, with heightened obligations for controllers designated as 'major importance'.2026-06-06

Topics

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
Cross-jurisdictionalMultiple (EDPB, CNIL, FTC, state AGs) Conditional Varies by jurisdiction; see linked pagesPrivacy law treats cookies and fingerprinting substantively the same; the technical differences matter for product design, not for the consent question.2026-06-06
Cross-jurisdictionalMultiple (EDPB, CNIL, ICO, state AGs) Conditional Varies by jurisdiction; see linked jurisdiction pagesConsent banners that name only cookies are legally incomplete; fingerprinting needs its own named purpose with the same Accept-Reject parity.2026-06-06
Cross-jurisdictionalMultiple (EDPB, CNIL, state AGs, sector regulators) Conditional Carve-out is conditional; loss of the carve-out exposes the controller to full consent-regime penalties in each jurisdictionThe exemption is real but narrow; it survives only when the fingerprint flow is architecturally separate from analytics, marketing, and product personalisation.2026-06-06
Cross-jurisdictionalMultiple (data protection authorities globally) Conditional DPA failures expose both controller and processor to direct enforcement; GDPR penalties reach 2% of global turnover for processor-contract failures (Art 83(4))Art 28 GDPR is the template most regulations follow; the fingerprinting-specific overlays are signal categories, hash retention, recipient list, and architectural separation.2026-06-06

Coming soon

Tiers 2 – 4

We're publishing jurisdictions in priority order: head-of-funnel regulators first, US states and global long-tail next. Want a jurisdiction prioritised? Drop us a line.

JurisdictionAcronymTierStatus
South Africa (Protection of Personal Information Act)POPIA Tier 4 Planned
Australia (Privacy Act 1988)AU PA Tier 4 Planned
New Zealand (Privacy Act 2020)NZ PA Tier 4 Planned
Singapore (Personal Data Protection Act)SG PDPA Tier 4 Planned
Thailand (Personal Data Protection Act)TH PDPA Tier 4 Planned
UAE (Personal Data Protection Law)UAE PDPL Tier 4 Planned
Saudi Arabia (Personal Data Protection Law)KSA PDPL Tier 4 Planned
Nigeria (Nigeria Data Protection Act 2023)NDPA Tier 4 Planned
Switzerland (Federal Act on Data Protection, revised)nFADP Tier 4 Planned
Türkiye (Personal Data Protection Law)KVKK Tier 4 Planned
Israel (Privacy Protection Law)IL PPL Tier 4 Planned

Tooling

Pick a regime; ship fingerprinting that fits it.

Benny the Doorman is free fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction you're serving.