Glossary

Browser fingerprinting

Identifying a device from the characteristics it exposes (fonts, canvas rendering, screen metrics, timing) rather than from anything stored on it.

Stores
Nothing on the device
Still covered
It gains access to information on the device
Detection
Hard; inference from behaviour and vendor

How it works

Properties such as installed fonts, canvas and WebGL rendering, screen dimensions, timezone, language list and hardware concurrency can be combined into an identifier used to recognise a device across sessions without relying on a cookie.

Fingerprinting is used both for fraud prevention, where it is genuinely defensive, and for advertising identity, where it is a cookie replacement. The technique does not tell you which; the vendor and the context do.

Common questions

Does fingerprinting need consent?

For non-necessary purposes, yes, on the same basis as a cookie. Fraud prevention strictly necessary to a service the visitor requested is a different analysis, and one worth documenting rather than assuming.

Can a consent platform block fingerprinting?

It can keep the script that performs it from loading, which is the same control as for any other technology. It cannot stop a technique embedded inside code you have chosen to load.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.