Orange textured background

Topical explainer

Cookies vs fingerprinting under privacy law

The law treats cookies and device fingerprinting identically. The technologies could not be more different. Understanding both sides of that gap is what separates a compliant deployment from an exposed one.

Reviewed

RegionCross-jurisdictional
RegulatorMultiple (EDPB, CNIL, FTC, state AGs)
EffectiveOngoing topic
Max penaltyVaries by jurisdiction; see linked pages
Status in-force

The central thesis: same law, different technology

Privacy law treats cookies and device fingerprinting the same. That is the thesis, and it has been settled law in the EU since EDPB Guidelines 2/2023 removed the last technical ambiguity. The technologies themselves, however, could not be more different. Cookies are explicit, user-visible, and clearable. Fingerprints are invisible, persistent across cookie clearing, and able to follow a user across browsers and devices without leaving any client-side trace.

The gap between legal equivalence and technical divergence is where most compliance failures occur. Teams build consent banners for cookies, assume fingerprinting is either covered or not a concern, and discover later that regulators treat the absence of explicit fingerprinting disclosure as a separate violation. This page maps that gap.

What the law says: EU/UK

Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive, also called the cookie law) is the operative rule. Its language is deliberately technology-neutral: it prohibits 'the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user' without prior consent. It was written in 2002 with cookies in mind but has always covered any read or write on the user's device.

The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) resolved any remaining question: 'techniques such as fingerprinting... that access information stored in the terminal equipment of end-users fall within the scope of Article 5(3).' This conclusion holds even for passive fingerprinting, where no cookie is set and the browser only reads values that the device broadcasts. The EDPB's technical analysis treated passive signal-reading as 'gaining of access to information already stored', because the device characteristics being read are stored in hardware, firmware, and operating-system state.

Under UK law, the Privacy and Electronic Communications Regulations 2003 (PECR) is the equivalent instrument, enforced by the ICO. PECR Regulation 6 has the same technology-neutral scope and the ICO's guidance on cookies and similar technologies explicitly references device fingerprinting. The UK retained its PECR framework post-Brexit and it has not diverged substantively from the EU position on fingerprinting consent.

What the law says: United States

CCPA/CPRA (California) covers device fingerprinting as a 'unique personal identifier' under Cal. Civ. Code 1798.140(ae)(1)(A), which lists 'device identifiers' and 'probabilistic identifiers' explicitly. A browser fingerprint, whether based on canvas hash, font enumeration, WebGL renderer strings, or any other signal combination, is a probabilistic identifier once it can be used to recognise a returning Californian. Both cookies containing persistent identifiers and device fingerprints therefore trigger the same opt-out and disclosure obligations under CCPA/CPRA.

The Virginia Consumer Data Protection Act (VCDPA) and the cluster of state laws modeled on it (CPA in Colorado, CTDPA in Connecticut, and others) cover 'unique personal identifiers' in the same way. Universal Opt-Out Mechanisms (UOOMs) and the Global Privacy Control (GPC) signal bind both cookies and fingerprinting: a business that honors GPC for cookie-based tracking but continues fingerprinting after a GPC signal is non-compliant with any state that mandates GPC recognition.

Cross-context behavioral advertising (CCBA) rules apply to both mechanisms. A CCBA opt-out covers the activity, not the technology used to enable it. Switching from cookie-based ad targeting to fingerprint-based ad targeting in response to a CCBA opt-out does not satisfy the opt-out obligation.

Cookies vs fingerprinting: a compliance comparison

DimensionCookiesDevice fingerprinting
Visibility to userVisible in browser DevTools (Application > Cookies); named, inspectableInvisible; no client-side artifact the user can find or inspect
User clearabilityUser can delete at any time via browser settings; site loses the identifierCannot be cleared; clearing cookies does not affect the underlying device characteristics
Cross-browser persistenceBrowser-scoped; a cookie set in Chrome is not visible in FirefoxHardware fingerprint can match the same device across Chrome, Firefox, Safari, and Edge
Cross-device matchingDevice-scoped; synced only if browser account is shared across devicesFingerprint can match the same physical device across browser profiles if hardware signals are stable
User controlsBrowser settings, cookie managers, third-party CMPs, DevTools deleteBrave fingerprinting resistance, Firefox RFP mode, anti-detect browsers; no mainstream browser UI equivalent to cookie settings
Retention mechanicsExpires at a date set by the server (or at session end for session cookies); enforceable by regulatorsNo expiry; the fingerprint exists as long as the hardware characteristics are stable (typically months to years)
Enforcement under GDPR / ePrivacyArt. 5(3) ePrivacy applies; extensive CNIL and ICO enforcement precedent since 2011Art. 5(3) ePrivacy applies equally; EDPB 2/2023 Guidelines confirmed scope; enforcement growing since 2022
Enforcement under CCPA/CPRACovered as 'cookie identifiers' under 1798.140; right to opt out appliesCovered as 'probabilistic identifiers' and 'device identifiers' under 1798.140(ae)(1)(A); same opt-out applies
Strictly necessary / anti-fraud carve-outApplies narrowly; load-balancing and session-security cookies qualify; analytics and ads do notApplies narrowly on the same terms; anti-fraud and ATO detection qualify if scoped and documented; analytics and ads do not
Effect of cookie-blocking extensionsuBlock Origin, Privacy Badger, and similar extensions block third-party cookies effectivelyCookie-blocking extensions have limited effect on server-side or passive fingerprinting; specialized tools (Brave, Canvas Blocker) are needed

Five operational places where cookies and fingerprinting diverge

Legal equivalence does not mean operational identity. There are five specific areas where the technical differences between cookies and fingerprinting create real compliance divergence that teams need to address separately.

1. Consent banner copy

  • A banner that names only 'cookies' is legally incomplete if your deployment also uses fingerprinting. EU enforcement actions consistently cite 'trackers' and 'online identifiers' as the operative category, not just 'cookies'. The EDPB Cookie Banner Taskforce guidance requires that users be informed of the specific technologies used.
  • Practical fix: name 'device fingerprinting' (or 'browser fingerprinting') as a distinct consent purpose alongside cookies in your CMP. The purpose description should explain that device characteristics are read to identify your browser or device, and that this is separate from cookies.
  • A single 'Accept all' that silently covers fingerprinting fails the GDPR Article 4(11) 'specific and informed' requirements and the EDPB's guidance on granular consent.

2. Retention and deletion mechanics

  • Cookie expiry rules have no direct parallel in fingerprinting. A regulator-mandated 13-month cookie lifetime (a common CNIL threshold) is enforceable because the server controls the cookie's Max-Age attribute. A fingerprint has no Max-Age.
  • For fingerprinting, retention is managed server-side: the fingerprint hash and any linked records must be deleted after the documented retention period. This requires an active purge process in your database, not a passive expiry mechanism.
  • Document the retention period for fingerprint-derived identifiers in your Record of Processing Activities (ROPA) alongside cookies. The period should be proportionate to the purpose: anti-fraud fingerprints typically have shorter justified retention than analytics cookies.

3. User-side controls and the GPC signal

  • Users can block cookies with browser settings, delete them via DevTools, or use cookie-focused extensions. Fingerprinting does not have an equivalent mainstream browser control. Brave's fingerprinting resistance randomizes device signals. Firefox's Resist Fingerprinting (RFP) mode does the same. Anti-detect browsers (used by power users and researchers) spoof hardware signals entirely.
  • The Global Privacy Control (GPC) signal is browser-level and covers all personal-data-based tracking, not just cookies. A GPC opt-out must be honored for fingerprinting-based targeting in any US state that mandates GPC recognition. Continuing fingerprinting after a GPC signal while stopping cookie tracking is a non-compliance vector specific to teams that treat them as separate regimes.
  • Transparency in privacy notices should cover both: explain that device fingerprinting is used, that it cannot be blocked via standard browser cookie settings, and what user-side tools (Brave, Firefox RFP) affect it.

4. Cross-device and cross-browser matching

  • A cookie is browser-scoped. A third-party cookie set in Chrome does not travel to Firefox. Cross-device matching via cookies requires server-side probabilistic matching or a deterministic login event.
  • A hardware fingerprint can match the same physical device across browsers if the underlying signals (GPU, screen resolution, font set, time zone, hardware concurrency) are stable. This means fingerprinting introduces a cross-browser re-identification risk that cookies do not, and regulators treat it as a more privacy-invasive technique in this dimension.
  • Under the CCPA 'sharing' definition and the VCDPA cluster's 'targeted advertising' definition, cross-context matching via fingerprint requires the same opt-out as cross-context matching via cookie. Do not treat the cross-browser capability as a feature that escapes the opt-out obligation.

5. Anti-tracking countermeasures affect the technologies differently

  • Cookie-blocking (ITP, third-party cookie deprecation in Chrome, ad-blocker rules) has no direct effect on fingerprinting. This is why fingerprinting grew in use as cookie-blocking became mainstream: from a technical standpoint it is a workaround for declining cookie signal.
  • Fingerprinting countermeasures (Brave's noisification, Firefox RFP, Canvas Blocker extension) have no effect on cookies. They are completely separate technical layers.
  • From a compliance standpoint, the reason a team switches from cookies to fingerprinting matters legally. If fingerprinting is adopted specifically to circumvent users' cookie opt-outs, regulators in the EU and FTC guidance in the US treat that as an aggravating factor, not a workaround.

What this means for your deployment: three operational tips

First, audit your consent banner for coverage. If your CMP lists 'cookies' as the only tracking technology requiring consent but your deployment also reads canvas hashes, font lists, or any other device signals, your banner is legally incomplete in the EU. Add a named fingerprinting purpose category. This is not optional under the EDPB's cookie banner guidance.

Second, separate your retention architecture. Cookie expiry is passive; fingerprint-record deletion is active. Both retention periods should appear in your ROPA, and both should be defensible against the purpose for which the data is collected. Anti-fraud retention periods should be shorter than analytics retention periods. Document the reasoning.

Third, treat GPC as a signal that covers both. If you honor GPC for cookie-based ad targeting, the same signal must suppress fingerprint-based ad targeting in any state where GPC recognition is mandated. Build GPC handling at the purpose level, not at the technology level.

How Benny the Doorman fits into this distinction

Benny is a device fingerprinting SDK. It does not set cookies. The fingerprint it produces is a hardware-derived identifier that persists independently of cookie state, which is precisely why it is useful for fraud detection, account-takeover prevention, and bot mitigation in a world where cookies are increasingly blocked or cleared.

That capability comes with a specific compliance obligation: the Art. 5(3) consent requirement applies to Benny in exactly the same way it applies to any cookie, and your consent banner must cover it explicitly if fingerprinting is used for any non-strictly-necessary purpose. Benny integrates with CMPs through a consent-gate pattern: the fingerprint API is called only after your CMP signals that the user has consented to the relevant purpose category.

For anti-fraud and ATO-detection use cases that qualify under the strictly-necessary carve-out, Benny can operate without a consent gate, but requires a documented legitimate-interest assessment, a privacy-notice disclosure, and an architecturally isolated data flow that does not feed analytics or marketing pipelines. That architectural isolation is the same requirement that applies to a fraud-purpose cookie: the carve-out follows the purpose, not the technology.

Frequently asked questions

Are cookies and fingerprinting treated the same under privacy law?

Yes, substantively. Article 5(3) of the ePrivacy Directive is technology-neutral and covers any access to or storage of information on a user's terminal equipment. EDPB Guidelines 2/2023 explicitly confirmed that fingerprinting is in scope on the same terms as cookies. Under CCPA/CPRA, both qualify as unique personal identifiers. The same consent and opt-out obligations apply to both tracking mechanisms.

Do I need a separate consent banner for fingerprinting?

Not a separate banner, but a separate named purpose within your existing consent banner. If your CMP only mentions cookies and your deployment also uses device fingerprinting, the banner is legally incomplete under the EDPB's cookie banner guidance and Article 5(3) ePrivacy. Add fingerprinting as a distinct purpose category with its own accept and reject controls. A single 'Accept all cookies' button does not cover fingerprinting under GDPR's specific and informed consent requirements.

Does clearing cookies clear my browser fingerprint?

No. Clearing cookies removes client-side storage artifacts. Device fingerprinting reads hardware and software characteristics (screen resolution, GPU, font set, audio stack, time zone) that are not stored in browser cookie storage and are not affected by cookie deletion. A user who clears all cookies is still identifiable by their fingerprint. This technical persistence is one of the reasons regulators treat fingerprinting as more privacy-invasive than cookies in certain dimensions.

Why do Brave and Firefox affect fingerprinting more than cookies?

Brave noisifies device signals (canvas, WebGL, audio) on each page load so that the fingerprint hash changes, making stable re-identification harder. Firefox's Resist Fingerprinting (RFP) mode does similar things: it returns standardized values for screen resolution, time zone, and other signals. These countermeasures have no effect on cookies, because cookies are a separate storage mechanism. Conversely, cookie-blocking tools like ITP and third-party cookie deprecation have no effect on fingerprinting. The two countermeasure stacks are completely separate.

If I switch from cookies to fingerprinting to avoid cookie opt-outs, am I still compliant?

No. Using fingerprinting to circumvent a cookie opt-out is non-compliant with Article 5(3) ePrivacy, CCPA/CPRA, and any US state law that covers unique personal identifiers. The opt-out or consent refusal applies to the purpose (tracking for ads, analytics, personalization), not to the specific technology. Regulators and the FTC have flagged technology substitution as an aggravating factor, not a workaround.

Does the Global Privacy Control (GPC) signal apply to fingerprinting?

Yes, in US states that mandate GPC recognition. The GPC signal is a browser-level opt-out that covers personal-data-based tracking regardless of mechanism. A business that honors GPC for cookie-based targeted advertising but continues fingerprint-based targeted advertising after receiving a GPC signal is non-compliant in California, Colorado, and other GPC-mandating states. GPC handling must be implemented at the purpose level, not at the technology level.

Does the anti-fraud carve-out apply equally to cookies and fingerprinting?

Yes. The strictly-necessary carve-out in Article 5(3) ePrivacy applies to any access to terminal equipment, not only to cookies. A fingerprint used solely for fraud detection and account-takeover prevention, with a short retention period, a documented legitimate-interest assessment, and an isolated data flow, can qualify on the same terms as a fraud-purpose session cookie. The carve-out follows the purpose, not the technology. Both are invalidated the moment the same data feeds an analytics or marketing pipeline.

Do cookie expiry rules apply to fingerprinting?

Not directly. Cookie expiry is a client-side mechanism: the server sets a Max-Age or Expires attribute and the browser discards the cookie when it expires. Fingerprints have no equivalent client-side expiry because no cookie is written. Retention for fingerprint-derived records must be managed server-side through active database purges. The retention period should still be documented in your ROPA and proportionate to the processing purpose, but the enforcement mechanism is architectural rather than protocol-level.

Is fingerprinting more privacy-invasive than cookies?

In some dimensions, yes. Fingerprints are invisible to users, cannot be cleared by standard browser controls, and can track a user across browsers on the same device. Cookies are visible in DevTools, deletable, and browser-scoped. Regulators in the EU have acknowledged this asymmetry in guidance, describing fingerprinting as a more opaque tracking mechanism. Both are regulated identically from a consent-requirement standpoint; the practical privacy impact differs in visibility and user control.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06