
Compliance reference
Fingerprinting laws by jurisdiction.
A plain-English reference to how the world's privacy regulators treat browser and device fingerprinting. 24 jurisdictions live, 35 planned. Not legal advice.
What you'll find here
Each jurisdiction page covers the operative statute, what counts as fingerprinting under it, when consent is required, what enforcement has looked like, and an FAQ. Pages are written for product and engineering teams shipping fingerprinting into production, not lawyers drafting a memo. We cite the statute and the regulator on every claim.
New: interactive
See the whole landscape on one screen.
The fingerprinting-law atlas plots every jurisdiction by consent posture, charts the biggest enforcement fines, and tracks when each regime took effect. Click anything to filter.
Live jurisdictions
Tier 124 of 24 jurisdictions
Europe
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| European Union (all member states) | European Data Protection Board (EDPB) + national DPAs | €20M or 4% of global annual turnover (whichever is higher) | Prior, freely given, specific, informed, unambiguous consent is required before reading fingerprinting signals, with narrow strictly-necessary carve-outs. | 2026-06-06 | |
| European Union (all member states, transposed nationally) | National DPAs in each member state, coordinated by the EDPB | Varies by member state national transposition (e.g. up to €200k under UK PECR before Brexit; up to €3M+ under French Article 82; no single EU-wide ceiling) | Article 5(3) requires prior consent before reading any signals from a user's device; EDPB Guidelines 2/2023 confirm fingerprinting is explicitly in scope. | 2026-06-06 | |
| United Kingdom (England, Scotland, Wales, Northern Ireland) | Information Commissioner's Office (ICO) | £17.5M or 4% of global annual turnover (UK GDPR); £500,000 (PECR, pre-DPDI Bill) | Same consent requirement as EU GDPR for now; ICO has been clearer than most DPAs that fingerprinting is treated as 'similar to a cookie'. | 2026-06-06 | |
| Switzerland (federal, all cantons) | Federal Data Protection and Information Commissioner (FDPIC / EDOB / PFPDT) | CHF 250,000 criminal sanction per individual (not a corporate administrative fine) | Fingerprinting is personal data under nFADP; lawful basis is required, proactive Art 19 notification is mandatory at collection, and criminal penalties fall on individuals rather than corporations. | 2026-06-06 |
United States
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| California, United States | California Privacy Protection Agency (CPPA) + California Attorney General | $2,500 per violation; $7,500 per intentional violation or violation involving a minor's data | Notice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16. | 2026-06-06 | |
| Virginia, USA | Office of the Attorney General of Virginia | Up to $7,500 per violation in civil penalties | No general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes. | 2026-06-06 | |
| Colorado, USA | Colorado Attorney General + District Attorneys | Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112) | Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes. | 2026-06-06 | |
| Connecticut, USA | Connecticut Attorney General (Privacy and Data Security Section) | Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive relief | Opt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime. | 2026-06-06 | |
| Utah, USA | Utah Attorney General + Utah Division of Consumer Protection | Up to $7,500 per violation in civil penalties (Utah Code §13-61-402) | Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers. | 2026-06-06 | |
| Texas, USA | Texas Attorney General (Consumer Protection Division) | Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155) | No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template. | 2026-06-06 | |
| Oregon, USA | Oregon Attorney General (Department of Justice) | Up to $7,500 per intentional violation (ORS 646A.589) | Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date. | 2026-06-06 | |
| Montana, USA | Montana Attorney General - Office of Consumer Protection | Up to $7,500 per violation (Mont. Code Ann. §30-14-142) | Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026. | 2026-06-06 | |
| Delaware, USA | Delaware Department of Justice - Consumer Protection Unit (Attorney General) | Up to $10,000 per intentional violation (Del. Code §12D-111) | Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025. | 2026-06-06 | |
| Iowa, USA | Iowa Attorney General (Consumer Protection Division) | Up to $7,500 per violation in civil penalties | Opt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset. | 2026-06-06 | |
| Tennessee, USA | Tennessee Attorney General, Office of Consumer Protection | Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214 | Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster. | 2026-06-06 | |
| New Hampshire, USA | New Hampshire Attorney General (Consumer Protection and Antitrust Bureau) | Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costs | Opt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties. | 2026-06-06 | |
| New Jersey, USA | New Jersey Attorney General (Division of Consumer Affairs) | Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act) | Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law. | 2026-06-06 |
Americas
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| Canada (federal, commercial activities; Quebec uses Law 25) | Office of the Privacy Commissioner of Canada (OPC) | Up to CAD $100,000 per violation (Bill C-27 would raise this significantly) | Meaningful, knowledge-based consent is required before collecting fingerprinting signals; the OPC's 2024 guidance names fingerprinting as a practice requiring explicit opt-in. | 2026-06-06 | |
| Brazil (national) | Autoridade Nacional de Proteção de Dados (ANPD) | 2% of the controller's Brazilian revenue, up to BRL 50 million per infringement | Consent is one of ten lawful bases; legitimate interest is workable for fraud and security, with documented assessment. | 2026-06-06 |
Asia-Pacific
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| India (national) | Data Protection Board of India (yet to be fully constituted as of mid-2026) | Up to INR 250 crore per breach category (Section 33) | Consent is the default basis; Section 7 legitimate uses cover fraud and security with notice, without separate consent. | 2026-06-06 | |
| Japan (national) | Personal Information Protection Commission (PPC / 個人情報保護委員会) | Up to ¥100 million (corporate fine, post-2022 amendments) | Fingerprint data is 'personally referable information' under the 2022 amendments; consent is required before sharing it with third parties who can re-identify the user. | 2026-06-06 | |
| People's Republic of China (mainland, excludes Hong Kong and Macau) | Cyberspace Administration of China (CAC), with sectoral roles for MIIT and PBOC | Up to RMB 50 million or 5% of preceding year's annual turnover, plus business suspension and license revocation | Consent is the default lawful basis under PIPL Article 13. Fingerprinting requires prior, voluntary, informed, explicit consent, with separate consent for third-party sharing and cross-border transfers. | 2026-06-06 | |
| Singapore | Personal Data Protection Commission (PDPC) | Higher of S$1 million or 10% of annual turnover in Singapore | Consent is required before collecting fingerprint-derived identifiers; the 2020 'deemed consent by notification' path (s 15A) offers a narrower opt-out-style route, but explicit anti-fraud carve-outs and PDPC advisory guidelines make the overall framework more operationally specific than most APAC peers. | 2026-06-06 | |
| Australia (Commonwealth) | Office of the Australian Information Commissioner (OAIC) | A$50M, or three times the benefit gained, or 30% of adjusted turnover, whichever is greatest | Fingerprint hashes are personal information under the Privacy Act; collection requires APP 3 necessity, notification under APP 5, and consent when used as biometric data for identification. | 2026-06-06 |
Coming soon
Tiers 2 – 4We're publishing jurisdictions in priority order: head-of-funnel regulators first, US states and global long-tail next. Want a jurisdiction prioritised? Drop us a line.
| Jurisdiction | Acronym | Tier | Status |
|---|---|---|---|
| South Africa (Protection of Personal Information Act) | POPIA | Tier 4 | Planned |
| Australia (Privacy Act 1988) | AU PA | Tier 4 | Planned |
| New Zealand (Privacy Act 2020) | NZ PA | Tier 4 | Planned |
| Singapore (Personal Data Protection Act) | SG PDPA | Tier 4 | Planned |
| Thailand (Personal Data Protection Act) | TH PDPA | Tier 4 | Planned |
| UAE (Personal Data Protection Law) | UAE PDPL | Tier 4 | Planned |
| Saudi Arabia (Personal Data Protection Law) | KSA PDPL | Tier 4 | Planned |
| Nigeria (Nigeria Data Protection Act 2023) | NDPA | Tier 4 | Planned |
| Switzerland (Federal Act on Data Protection, revised) | nFADP | Tier 4 | Planned |
| Türkiye (Personal Data Protection Law) | KVKK | Tier 4 | Planned |
| Israel (Privacy Protection Law) | IL PPL | Tier 4 | Planned |
Tooling
Pick a regime; ship fingerprinting that fits it.
Benny the Doorman is free fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction you're serving.
