
Compliance reference
Fingerprinting laws by jurisdiction.
A plain-English reference to how the world's privacy regulators treat browser and device fingerprinting. 36 jurisdictions live, 47 planned. Not legal advice.
What you'll find here
Each jurisdiction page covers the operative statute, what counts as fingerprinting under it, when consent is required, what enforcement has looked like, and an FAQ. Pages are written for product and engineering teams shipping fingerprinting into production, not lawyers drafting a memo. We cite the statute and the regulator on every claim.
New: interactive
See the whole landscape on one screen.
The fingerprinting-law atlas plots every jurisdiction by consent posture, charts the biggest enforcement fines, and tracks when each regime took effect. Click anything to filter.
Live jurisdictions
Tier 136 of 36 jurisdictions
Europe
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| European Union (all member states) | European Data Protection Board (EDPB) + national DPAs | €20M or 4% of global annual turnover (whichever is higher) | Prior, freely given, specific, informed, unambiguous consent is required before reading fingerprinting signals, with narrow strictly-necessary carve-outs. | 2026-06-06 | |
| European Union (all member states, transposed nationally) | National DPAs in each member state, coordinated by the EDPB | Varies by member state national transposition (e.g. up to €200k under UK PECR before Brexit; up to €3M+ under French Article 82; no single EU-wide ceiling) | Article 5(3) requires prior consent before reading any signals from a user's device; EDPB Guidelines 2/2023 confirm fingerprinting is explicitly in scope. | 2026-06-06 | |
| United Kingdom (England, Scotland, Wales, Northern Ireland) | Information Commissioner's Office (ICO) | £17.5M or 4% of global annual turnover (UK GDPR); £500,000 (PECR, pre-DPDI Bill) | Same consent requirement as EU GDPR for now; ICO has been clearer than most DPAs that fingerprinting is treated as 'similar to a cookie'. | 2026-06-06 | |
| Switzerland (federal, all cantons) | Federal Data Protection and Information Commissioner (FDPIC / EDOB / PFPDT) | CHF 250,000 criminal sanction per individual (not a corporate administrative fine) | Fingerprinting is personal data under nFADP; lawful basis is required, proactive Art 19 notification is mandatory at collection, and criminal penalties fall on individuals rather than corporations. | 2026-06-06 | |
| Turkiye | Kisisel Verileri Koruma Kurumu (KVKK - Personal Data Protection Authority) | ~TRY 9.4M per violation in 2026 (indexed annually); doubles for repeat offenses | Explicit consent is required for most fingerprinting purposes; biometric-signal fingerprinting triggers special-category rules, VERBİS registration is mandatory above threshold, and the 2024 amendments added 72-hour breach notification and DPIA requirements. | 2026-06-06 |
United States
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| California, United States | California Privacy Protection Agency (CPPA) + California Attorney General | $2,500 per violation; $7,500 per intentional violation or violation involving a minor's data | Notice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16. | 2026-06-06 | |
| Virginia, USA | Office of the Attorney General of Virginia | Up to $7,500 per violation in civil penalties | No general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes. | 2026-06-06 | |
| Colorado, USA | Colorado Attorney General + District Attorneys | Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112) | Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes. | 2026-06-06 | |
| Connecticut, USA | Connecticut Attorney General (Privacy and Data Security Section) | Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive relief | Opt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime. | 2026-06-06 | |
| Utah, USA | Utah Attorney General + Utah Division of Consumer Protection | Up to $7,500 per violation in civil penalties (Utah Code §13-61-402) | Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers. | 2026-06-06 | |
| Texas, USA | Texas Attorney General (Consumer Protection Division) | Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155) | No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template. | 2026-06-06 | |
| Oregon, USA | Oregon Attorney General (Department of Justice) | Up to $7,500 per intentional violation (ORS 646A.589) | Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date. | 2026-06-06 | |
| Montana, USA | Montana Attorney General - Office of Consumer Protection | Up to $7,500 per violation (Mont. Code Ann. §30-14-142) | Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026. | 2026-06-06 | |
| Delaware, USA | Delaware Department of Justice - Consumer Protection Unit (Attorney General) | Up to $10,000 per intentional violation (Del. Code §12D-111) | Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025. | 2026-06-06 | |
| Iowa, USA | Iowa Attorney General (Consumer Protection Division) | Up to $7,500 per violation in civil penalties | Opt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset. | 2026-06-06 | |
| Tennessee, USA | Tennessee Attorney General, Office of Consumer Protection | Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214 | Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster. | 2026-06-06 | |
| New Hampshire, USA | New Hampshire Attorney General (Consumer Protection and Antitrust Bureau) | Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costs | Opt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties. | 2026-06-06 | |
| New Jersey, USA | New Jersey Attorney General (Division of Consumer Affairs) | Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act) | Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law. | 2026-06-06 |
Americas
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| Canada (federal, commercial activities; Quebec uses Law 25) | Office of the Privacy Commissioner of Canada (OPC) | Up to CAD $100,000 per violation (Bill C-27 would raise this significantly) | Meaningful, knowledge-based consent is required before collecting fingerprinting signals; the OPC's 2024 guidance names fingerprinting as a practice requiring explicit opt-in. | 2026-06-06 | |
| Brazil (national) | Autoridade Nacional de Proteção de Dados (ANPD) | 2% of the controller's Brazilian revenue, up to BRL 50 million per infringement | Consent is one of ten lawful bases; legitimate interest is workable for fraud and security, with documented assessment. | 2026-06-06 |
Asia-Pacific
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| India (national) | Data Protection Board of India (yet to be fully constituted as of mid-2026) | Up to INR 250 crore per breach category (Section 33) | Consent is the default basis; Section 7 legitimate uses cover fraud and security with notice, without separate consent. | 2026-06-06 | |
| Japan (national) | Personal Information Protection Commission (PPC / 個人情報保護委員会) | Up to ¥100 million (corporate fine, post-2022 amendments) | Fingerprint data is 'personally referable information' under the 2022 amendments; consent is required before sharing it with third parties who can re-identify the user. | 2026-06-06 | |
| People's Republic of China (mainland, excludes Hong Kong and Macau) | Cyberspace Administration of China (CAC), with sectoral roles for MIIT and PBOC | Up to RMB 50 million or 5% of preceding year's annual turnover, plus business suspension and license revocation | Consent is the default lawful basis under PIPL Article 13. Fingerprinting requires prior, voluntary, informed, explicit consent, with separate consent for third-party sharing and cross-border transfers. | 2026-06-06 | |
| Singapore | Personal Data Protection Commission (PDPC) | Higher of S$1 million or 10% of annual turnover in Singapore | Consent is required before collecting fingerprint-derived identifiers; the 2020 'deemed consent by notification' path (s 15A) offers a narrower opt-out-style route, but explicit anti-fraud carve-outs and PDPC advisory guidelines make the overall framework more operationally specific than most APAC peers. | 2026-06-06 | |
| Kingdom of Thailand | Personal Data Protection Committee Office (PDPC, under the Ministry of Digital Economy and Society) | THB 5 million administrative fine per violation + up to 1 year imprisonment and THB 1 million criminal fine for serious violations | Explicit written or electronic-written consent under section 19 is required before collecting fingerprinting signals for most purposes; stricter than GDPR and enforced since 2024. | 2026-06-06 | |
| Australia (Commonwealth) | Office of the Australian Information Commissioner (OAIC) | A$50M, or three times the benefit gained, or 30% of adjusted turnover, whichever is greatest | Fingerprint hashes are personal information under the Privacy Act; collection requires APP 3 necessity, notification under APP 5, and consent when used as biometric data for identification. | 2026-06-06 | |
| New Zealand | Office of the Privacy Commissioner (OPC) | NZ$10,000 per offence (statute); HRRT damages awards up to NZ$350,000 for humiliation, loss of dignity, and injury to feelings | Fingerprinting is regulated under 13 IPPs; IPP 12 requires comparable overseas-recipient safeguards or consent before sending hashes to a non-NZ vendor, making vendor choice a first-order compliance question. | 2026-06-06 |
Middle East & Africa
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| United Arab Emirates (federal mainland; excludes DIFC and ADGM) | UAE Data Office | Administrative fines set by Executive Regulations (pending as of mid-2026); amounts not yet published in final form | Fingerprinting is personal data under the PDPL; biometric-derived hashes require explicit consent. DIFC and ADGM free zones operate under their own stand-alone data protection laws, not the PDPL. | 2026-06-06 | |
| Kingdom of Saudi Arabia | Saudi Data and AI Authority (SDAIA) | Up to SAR 5 million per violation; doubled for repeat offences; up to 2 years imprisonment for unauthorised disclosure of sensitive personal data | Explicit consent is the primary basis for non-security fingerprinting; cross-border transfers must follow the 2023 adequacy or safeguards model, and sensitive data joined to a fingerprint may require in-country storage. | 2026-06-06 | |
| State of Israel | Privacy Protection Authority (PPA) | NIS 320,000 per breach; effective fines up to NIS 1.6M for serious or very serious breaches | Explicit consent is required under Amendment 13; database registration with the PPA is mandatory before processing data from more than 10,000 individuals or any sensitive data, making Israel unique among Western privacy regimes. | 2026-06-06 | |
| South Africa | Information Regulator (South Africa) | R10 million administrative fine or 10 years imprisonment (Section 107) | POPIA is an opt-in regime. Fingerprinting requires a Section 11 lawful basis, and direct marketing to non-customers via electronic means demands prior consent under Section 69. | 2026-06-06 | |
| Federal Republic of Nigeria | Nigeria Data Protection Commission (NDPC) | NGN 10M or 2% of annual gross revenue (data controllers of major importance); NGN 2M or 2% of annual revenue (all others), whichever is higher in each tier | The NDPC's 2024 guidance explicitly classifies device fingerprints as personal data; consent or another s 25 lawful basis is required, with heightened obligations for controllers designated as 'major importance'. | 2026-06-06 |
Topics
| Region | Regulator | Consent posture | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| Cross-jurisdictional | Multiple (EDPB, CNIL, FTC, state AGs) | Varies by jurisdiction; see linked pages | Privacy law treats cookies and fingerprinting substantively the same; the technical differences matter for product design, not for the consent question. | 2026-06-06 | |
| Cross-jurisdictional | Multiple (EDPB, CNIL, ICO, state AGs) | Varies by jurisdiction; see linked jurisdiction pages | Consent banners that name only cookies are legally incomplete; fingerprinting needs its own named purpose with the same Accept-Reject parity. | 2026-06-06 | |
| Cross-jurisdictional | Multiple (EDPB, CNIL, state AGs, sector regulators) | Carve-out is conditional; loss of the carve-out exposes the controller to full consent-regime penalties in each jurisdiction | The exemption is real but narrow; it survives only when the fingerprint flow is architecturally separate from analytics, marketing, and product personalisation. | 2026-06-06 | |
| Cross-jurisdictional | Multiple (data protection authorities globally) | DPA failures expose both controller and processor to direct enforcement; GDPR penalties reach 2% of global turnover for processor-contract failures (Art 83(4)) | Art 28 GDPR is the template most regulations follow; the fingerprinting-specific overlays are signal categories, hash retention, recipient list, and architectural separation. | 2026-06-06 |
Coming soon
Tiers 2 – 4We're publishing jurisdictions in priority order: head-of-funnel regulators first, US states and global long-tail next. Want a jurisdiction prioritised? Drop us a line.
| Jurisdiction | Acronym | Tier | Status |
|---|---|---|---|
| South Africa (Protection of Personal Information Act) | POPIA | Tier 4 | Planned |
| Australia (Privacy Act 1988) | AU PA | Tier 4 | Planned |
| New Zealand (Privacy Act 2020) | NZ PA | Tier 4 | Planned |
| Singapore (Personal Data Protection Act) | SG PDPA | Tier 4 | Planned |
| Thailand (Personal Data Protection Act) | TH PDPA | Tier 4 | Planned |
| UAE (Personal Data Protection Law) | UAE PDPL | Tier 4 | Planned |
| Saudi Arabia (Personal Data Protection Law) | KSA PDPL | Tier 4 | Planned |
| Nigeria (Nigeria Data Protection Act 2023) | NDPA | Tier 4 | Planned |
| Switzerland (Federal Act on Data Protection, revised) | nFADP | Tier 4 | Planned |
| Türkiye (Personal Data Protection Law) | KVKK | Tier 4 | Planned |
| Israel (Privacy Protection Law) | IL PPL | Tier 4 | Planned |
Tooling
Pick a regime; ship fingerprinting that fits it.
Benny the Doorman is free fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction you're serving.
