Orange textured background

Compliance reference

Fingerprinting laws by jurisdiction.

A plain-English reference to how the world's privacy regulators treat browser and device fingerprinting. 24 jurisdictions live, 35 planned. Not legal advice.

What you'll find here

Each jurisdiction page covers the operative statute, what counts as fingerprinting under it, when consent is required, what enforcement has looked like, and an FAQ. Pages are written for product and engineering teams shipping fingerprinting into production, not lawyers drafting a memo. We cite the statute and the regulator on every claim.

New: interactive

See the whole landscape on one screen.

The fingerprinting-law atlas plots every jurisdiction by consent posture, charts the biggest enforcement fines, and tracks when each regime took effect. Click anything to filter.

Live jurisdictions

Tier 1

Europe

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
European Union (all member states)European Data Protection Board (EDPB) + national DPAs Explicit consent €20M or 4% of global annual turnover (whichever is higher)Prior, freely given, specific, informed, unambiguous consent is required before reading fingerprinting signals, with narrow strictly-necessary carve-outs.2026-06-06
European Union (all member states, transposed nationally)National DPAs in each member state, coordinated by the EDPB Explicit consent Varies by member state national transposition (e.g. up to €200k under UK PECR before Brexit; up to €3M+ under French Article 82; no single EU-wide ceiling)Article 5(3) requires prior consent before reading any signals from a user's device; EDPB Guidelines 2/2023 confirm fingerprinting is explicitly in scope.2026-06-06
United Kingdom (England, Scotland, Wales, Northern Ireland)Information Commissioner's Office (ICO) Explicit consent £17.5M or 4% of global annual turnover (UK GDPR); £500,000 (PECR, pre-DPDI Bill)Same consent requirement as EU GDPR for now; ICO has been clearer than most DPAs that fingerprinting is treated as 'similar to a cookie'.2026-06-06
Switzerland (federal, all cantons)Federal Data Protection and Information Commissioner (FDPIC / EDOB / PFPDT) Conditional CHF 250,000 criminal sanction per individual (not a corporate administrative fine)Fingerprinting is personal data under nFADP; lawful basis is required, proactive Art 19 notification is mandatory at collection, and criminal penalties fall on individuals rather than corporations.2026-06-06

United States

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
California, United StatesCalifornia Privacy Protection Agency (CPPA) + California Attorney General Conditional $2,500 per violation; $7,500 per intentional violation or violation involving a minor's dataNotice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16.2026-06-06
Virginia, USAOffice of the Attorney General of Virginia Conditional Up to $7,500 per violation in civil penaltiesNo general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes.2026-06-06
Colorado, USAColorado Attorney General + District Attorneys Conditional Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112)Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes.2026-06-06
Connecticut, USAConnecticut Attorney General (Privacy and Data Security Section) Conditional Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive reliefOpt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime.2026-06-06
Utah, USAUtah Attorney General + Utah Division of Consumer Protection Conditional Up to $7,500 per violation in civil penalties (Utah Code §13-61-402)Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers.2026-06-06
Texas, USATexas Attorney General (Consumer Protection Division) Conditional Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155)No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template.2026-06-06
Oregon, USAOregon Attorney General (Department of Justice) Conditional Up to $7,500 per intentional violation (ORS 646A.589)Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date.2026-06-06
Montana, USAMontana Attorney General - Office of Consumer Protection Conditional Up to $7,500 per violation (Mont. Code Ann. §30-14-142)Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026.2026-06-06
Delaware, USADelaware Department of Justice - Consumer Protection Unit (Attorney General) Conditional Up to $10,000 per intentional violation (Del. Code §12D-111)Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025.2026-06-06
Iowa, USAIowa Attorney General (Consumer Protection Division) Conditional Up to $7,500 per violation in civil penaltiesOpt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset.2026-06-06
Tennessee, USATennessee Attorney General, Office of Consumer Protection Conditional Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster.2026-06-06
New Hampshire, USANew Hampshire Attorney General (Consumer Protection and Antitrust Bureau) Conditional Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costsOpt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties.2026-06-06
New Jersey, USANew Jersey Attorney General (Division of Consumer Affairs) Conditional Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act)Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law.2026-06-06

Americas

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
Canada (federal, commercial activities; Quebec uses Law 25)Office of the Privacy Commissioner of Canada (OPC) Explicit consent Up to CAD $100,000 per violation (Bill C-27 would raise this significantly)Meaningful, knowledge-based consent is required before collecting fingerprinting signals; the OPC's 2024 guidance names fingerprinting as a practice requiring explicit opt-in.2026-06-06
Brazil (national)Autoridade Nacional de Proteção de Dados (ANPD) Conditional 2% of the controller's Brazilian revenue, up to BRL 50 million per infringementConsent is one of ten lawful bases; legitimate interest is workable for fraud and security, with documented assessment.2026-06-06

Asia-Pacific

RegionRegulatorConsent postureMax penaltyHow the law treats fingerprintingUpdated
India (national)Data Protection Board of India (yet to be fully constituted as of mid-2026) Conditional Up to INR 250 crore per breach category (Section 33)Consent is the default basis; Section 7 legitimate uses cover fraud and security with notice, without separate consent.2026-06-06
Japan (national)Personal Information Protection Commission (PPC / 個人情報保護委員会) Conditional Up to ¥100 million (corporate fine, post-2022 amendments)Fingerprint data is 'personally referable information' under the 2022 amendments; consent is required before sharing it with third parties who can re-identify the user.2026-06-06
People's Republic of China (mainland, excludes Hong Kong and Macau)Cyberspace Administration of China (CAC), with sectoral roles for MIIT and PBOC Explicit consent Up to RMB 50 million or 5% of preceding year's annual turnover, plus business suspension and license revocationConsent is the default lawful basis under PIPL Article 13. Fingerprinting requires prior, voluntary, informed, explicit consent, with separate consent for third-party sharing and cross-border transfers.2026-06-06
SingaporePersonal Data Protection Commission (PDPC) Implicit consent Higher of S$1 million or 10% of annual turnover in SingaporeConsent is required before collecting fingerprint-derived identifiers; the 2020 'deemed consent by notification' path (s 15A) offers a narrower opt-out-style route, but explicit anti-fraud carve-outs and PDPC advisory guidelines make the overall framework more operationally specific than most APAC peers.2026-06-06
Australia (Commonwealth)Office of the Australian Information Commissioner (OAIC) Conditional A$50M, or three times the benefit gained, or 30% of adjusted turnover, whichever is greatestFingerprint hashes are personal information under the Privacy Act; collection requires APP 3 necessity, notification under APP 5, and consent when used as biometric data for identification.2026-06-06

Coming soon

Tiers 2 – 4

We're publishing jurisdictions in priority order: head-of-funnel regulators first, US states and global long-tail next. Want a jurisdiction prioritised? Drop us a line.

JurisdictionAcronymTierStatus
South Africa (Protection of Personal Information Act)POPIA Tier 4 Planned
Australia (Privacy Act 1988)AU PA Tier 4 Planned
New Zealand (Privacy Act 2020)NZ PA Tier 4 Planned
Singapore (Personal Data Protection Act)SG PDPA Tier 4 Planned
Thailand (Personal Data Protection Act)TH PDPA Tier 4 Planned
UAE (Personal Data Protection Law)UAE PDPL Tier 4 Planned
Saudi Arabia (Personal Data Protection Law)KSA PDPL Tier 4 Planned
Nigeria (Nigeria Data Protection Act 2023)NDPA Tier 4 Planned
Switzerland (Federal Act on Data Protection, revised)nFADP Tier 4 Planned
Türkiye (Personal Data Protection Law)KVKK Tier 4 Planned
Israel (Privacy Protection Law)IL PPL Tier 4 Planned

Tooling

Pick a regime; ship fingerprinting that fits it.

Benny the Doorman is free fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction you're serving.