Orange textured background

Canadian federal law

PIPEDA and browser fingerprinting

How the Personal Information Protection and Electronic Documents Act treats device fingerprinting, what the Office of the Privacy Commissioner's 2024 guidance requires, and how Quebec's stricter Law 25 changes the picture.

Reviewed

RegionCanada (federal, commercial activities; Quebec uses Law 25)
RegulatorOffice of the Privacy Commissioner of Canada (OPC)
Effective1 January 2001 (fully phased in by 1 January 2004)
Max penaltyUp to CAD $100,000 per violation (Bill C-27 would raise this significantly)
Status in-force

What PIPEDA says about fingerprinting

PIPEDA does not mention fingerprinting by name. It does not need to. Section 2(1) defines personal information as 'information about an identifiable individual' without restriction to format or method of collection. The Office of the Privacy Commissioner confirmed in Report of Findings 2009-008 (the Facebook investigation) that online identifiers used to track individuals across sessions qualify as personal information, a position that has only hardened in the years since.

A browser fingerprint (the composite hash of a device's screen resolution, installed fonts, GPU renderer, audio stack, time zone, and dozens of other passively observable characteristics) is personal information under PIPEDA the moment the organisation can use it to recognise the same device or user across visits. The fingerprint does not need to be linked to a name; 'identifiable' covers the ability to single out, not formal identification.

The OPC made this concrete in its 2024 update to the 'Guidelines for obtaining meaningful consent'. The guidance explicitly names fingerprinting and persistent unique identifiers as practices that users are unlikely to expect and therefore cannot be considered implicitly consented to under the earlier framework. Organisations using fingerprinting for anything other than narrow, documented security purposes must obtain express consent.

Section 6.1 and what meaningful consent requires

PIPEDA Section 6.1 was added by the Digital Privacy Act in 2015 and codifies the OPC's long-standing position: for consent to be valid, 'the organisation must make a reasonable effort to ensure that the individual is advised of the purposes for which the information will be used or disclosed'. The section goes further: if the purposes are such that a reasonable person would not expect them, consent is not meaningful unless the organisation expressly draws attention to them.

The OPC's 2018 'Guidelines for obtaining meaningful consent', updated in 2024 to address fingerprinting and device-level tracking, translate this into five operational requirements. First, specify what information is collected, naming the category ('device fingerprint', 'persistent device identifier') rather than a generic 'usage data'. Second, explain why it is collected and who it will be shared with. Third, obtain consent at or before the time of collection, not after. Fourth, make consent as easy to withdraw as to give. Fifth, refresh consent when purposes change materially.

The 2024 update adds particular emphasis to the first point for fingerprinting: because users do not recognise fingerprinting as a form of tracking the way they recognise cookies, the OPC expects organisations to use plain, non-technical language that makes clear a device-level identifier is being created and used.

Consent obligations under Schedule 1 for a fingerprinting deployment

  • Principle 3 (consent): Knowledge and consent of the individual are required. Fingerprinting without disclosure violates Principle 3 on its face: there can be no consent without knowledge.
  • Principle 4.3 (specific consent): Consent is most meaningful at the time of collection. Bundled consent inside a terms-of-service click-through, without calling out fingerprinting, does not satisfy this principle.
  • Principle 4.3.2 (express consent): Where information is likely to be considered sensitive, and device-level persistent identifiers are treated as sensitive by the OPC's 2024 guidance, express consent is required rather than implied consent.
  • Principle 4.3.6 (withdrawal): Individuals must be able to withdraw consent at any time, subject to legal or contractual restrictions. An opt-out mechanism that stops future fingerprinting but retains historical identifiers for continued profiling is non-compliant.
  • Principle 1 (accountability): The organisation is responsible for any personal information in its custody, including fingerprints held or processed by third-party SDKs or analytics vendors. You cannot contract away accountability under PIPEDA.

Section 7 exceptions: narrow and enumerated

PIPEDA Section 7 lists the circumstances in which personal information may be collected, used, or disclosed without the knowledge and consent of the individual. The list is closed. For commercial fingerprinting deployments, only two warrant attention.

Section 7(1)(b) permits collection without consent when 'it is reasonable to expect that obtaining consent would compromise the availability or accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province'. This is the closest equivalent to GDPR's fraud-prevention carve-out. The OPC's guidance makes clear it requires a documented, specific fraud investigation context, not a general-purpose fraud-score pipeline running on every visitor.

Section 7(2)(c.1) permits disclosure (not collection) without consent for the purpose of detecting or suppressing fraud. This is narrower than it looks: it applies to disclosure to third parties, not to the act of fingerprinting a user in the first place.

Everything else (analytics, personalisation, A/B testing, behavioural advertising, frequency capping) falls squarely within Principle 3 and requires meaningful consent. The absence of a general legitimate-interest provision means the PIPEDA default is tighter than GDPR for commercial tracking purposes.

Common fingerprinting purposes and the PIPEDA consent question

PurposeSection 7 exception available?Consent required?
Anti-fraud: blocking known bad device IDs at login or paymentPossibly, if s.7(1)(b) conditions met and documentedPotentially no, if genuinely scoped
Account takeover detectionPossibly, same conditions as abovePotentially no, with transparency
Bot mitigation on a public-facing formArguable for security-of-serviceOften no, if truly scoped
Behavioural advertisingNoYes, express consent required
Cross-site tracking or retargetingNoYes, express consent required
Product analytics (funnels, page views)NoYes, express consent required
Personalisation and A/B testingNoYes, express consent required
Session continuity within a single authenticated visitContextually reasonable in some casesInform users; implied consent may suffice

Enforcement: OPC investigations and the Tim Hortons case

The OPC's enforcement powers under PIPEDA are complaint-driven and, until Bill C-27 passes, rely on public findings and Federal Court applications rather than direct fines. The nominal CAD $100,000 fine is per violation but has been rarely tested at scale. The reputational and court-order risk is, in practice, the primary deterrent.

The most instructive recent case for fingerprinting practitioners is the joint investigation into Tim Hortons (OPC, Quebec, British Columbia, Alberta, June 2022). Tim Hortons had deployed a mobile analytics SDK that collected granular geolocation data, creating a persistent behavioural record, without meaningful consent. Regulators found violations of PIPEDA Principle 3, Principle 4.3, and Quebec privacy law. Tim Hortons was ordered to delete the data, implement a privacy management programme, and publish the investigation findings. The case was not about canvas fingerprinting, but the regulatory reasoning maps directly: passive, persistent device-level tracking without disclosed, specific consent violates PIPEDA regardless of the technical mechanism.

PIPEDA Report of Findings 2009-008 (the Facebook investigation) established that profile identifiers used to track individuals across a platform are personal information. Although that decision addressed user IDs rather than device fingerprints, the OPC has cited it consistently in subsequent guidance to confirm that any persistent identifier tied to device or behavioural data is covered.

Bill C-27: what the replacement law would change

Bill C-27, the Consumer Privacy Protection Act (CPPA) plus the Artificial Intelligence and Data Act (AIDA), was tabled in June 2022 and has been under Parliamentary review since. If passed as currently drafted, it would replace PIPEDA for private-sector commercial activity and make several changes relevant to fingerprinting.

Fines would increase to up to CAD $25,000,000 or 5% of global gross revenues for serious violations, comparable to GDPR's upper tier. The CPPA introduces an express right to object to profiling for the purpose of making decisions that affect individuals, which would cover fingerprint-based scoring. It also codifies a 'legitimate interest' provision (Section 18 of the draft), but with a proportionality test and an explicit requirement to inform individuals before relying on it; it is not a GDPR-equivalent blank cheque for commercial tracking.

As of June 2026, Bill C-27 has not received Royal Assent. PIPEDA remains the operative federal law. Organisations building systems now should, however, design for CPPA compliance, since the consent and transparency obligations in the CPPA are meaningfully higher than PIPEDA's current bar.

Territorial reach: who must comply

PIPEDA applies to 'every organisation that collects, uses or discloses personal information in the course of commercial activity' in Canada. 'Commercial activity' is defined broadly: it includes displaying advertising to Canadian visitors, running e-commerce transactions with Canadian customers, and offering digital services to Canadian users.

A US or EU organisation that fingerprints Canadian visitors to its website is collecting personal information in the course of commercial activity in Canada. The OPC has applied PIPEDA to foreign organisations in its investigations; Report of Findings 2009-008 (Facebook) is a clear example. There is no de minimis exception based on company size or Canadian revenue share.

For organisations already operating under GDPR, the practical additional ask is relatively small: PIPEDA's meaningful consent standard is largely compatible with GDPR's requirements, and a consent mechanism built to GDPR spec will generally satisfy PIPEDA. The gap is on the exceptions side: PIPEDA's narrow Section 7 list means some use cases that rest on GDPR legitimate interest need explicit consent in Canada.

How Benny the Doorman fits into a PIPEDA-aware deployment

Benny is a fingerprinting SDK, not a consent management platform. The integration pattern for Canadian compliance follows the same principle as for GDPR: your consent layer should gate the call to Benny's fingerprint API, and the fingerprint should only be requested after the user has given meaningful consent for the specific purpose you have named.

For PIPEDA specifically, three additional steps apply. First, name 'device fingerprinting' or 'persistent device identifier' as a distinct purpose in your privacy notice, using the plain-language framing the OPC's 2024 guidelines recommend. Second, if you serve Quebec users, complete a privacy impact assessment covering the fingerprinting pipeline and publish the technology description as required by Law 25. Third, if you are relying on the Section 7(1)(b) fraud-investigation exception, document the specific fraud context; a general statement that fingerprinting 'helps prevent fraud' is not sufficient.

Benny's fraud-prevention use case is the most natural fit for the Section 7 carve-out. Benny's session-continuity and device-recognition capabilities used for analytics or personalisation require disclosed, express consent under both PIPEDA and Law 25.

Frequently asked questions

Is browser fingerprinting legal under PIPEDA?

Yes, fingerprinting is not prohibited, it is regulated. You can collect fingerprints lawfully if you obtain meaningful consent under PIPEDA Schedule 1 Principle 3, or if a narrow Section 7 exception applies (typically a documented fraud investigation context). Fingerprinting without either is what creates legal exposure under PIPEDA.

Do I need consent for fingerprinting under PIPEDA?

In almost all commercial cases, yes. PIPEDA Schedule 1 Principle 3 requires knowledge and consent for collection, use, and disclosure of personal information. The OPC's 2024 guidance specifically names fingerprinting as a practice requiring meaningful, express consent. The Section 7 exceptions are narrow and do not cover analytics, advertising, or personalisation use cases.

What counts as 'meaningful consent' for fingerprinting under PIPEDA?

Under PIPEDA Section 6.1 and the OPC's 2018 and 2024 guidelines, meaningful consent requires plain-language disclosure of what data is collected (naming 'device fingerprint' specifically), why it is collected, who it is shared with, and how to withdraw consent. A generic 'usage data' disclosure or buried terms-of-service clause does not satisfy the standard when fingerprinting is in play.

Can I use fingerprinting for fraud prevention without consent under PIPEDA?

Possibly, under a narrow reading of Section 7(1)(b), which permits collection without consent in the context of investigating a breach of an agreement or a contravention of law. This requires a specific, documented fraud-investigation context, not a general-purpose fraud-score pipeline. The use case must be genuinely security-scoped and not repurposed for analytics or marketing.

How does Quebec's Law 25 differ from PIPEDA for fingerprinting?

Law 25 (Quebec's Act respecting the protection of personal information in the private sector, in force through September 2023) is stricter than PIPEDA. It requires opt-in consent for personal information collected through technological means, a privacy impact assessment for technologies that identify or profile individuals, and a specific published policy describing technological identifiers. The Commission d'acces a l'information (CAI) has direct fine and order powers that go beyond the OPC's current enforcement tools.

What enforcement risk does the OPC have under PIPEDA?

The OPC cannot currently impose fines directly; it investigates complaints and publishes findings. Persistent non-compliance can lead to Federal Court applications and compliance orders. The nominal fine ceiling is CAD $100,000 per violation. Reputational risk from published findings, as in the Tim Hortons case (2022), has historically been the more significant deterrent.

What would Bill C-27 change for fingerprinting compliance?

Bill C-27 (the Consumer Privacy Protection Act, not yet passed as of June 2026) would raise maximum penalties to CAD $25M or 5% of global revenue, introduce a right to object to profiling, and codify a limited legitimate-interest provision with a proportionality test. Organisations should design for CPPA compliance now, since the consent and transparency bar would be materially higher than current PIPEDA requirements.

Does PIPEDA apply to foreign companies that fingerprint Canadian users?

Yes. PIPEDA applies to any organisation collecting personal information in the course of commercial activity in Canada, regardless of where the organisation is headquartered. Fingerprinting Canadian visitors to your website is collecting personal information in Canada. The OPC applied PIPEDA to Facebook (a US company) in Report of Findings 2009-008, establishing the extraterritorial principle clearly.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06