Fingerprinting (browser fingerprinting) is a technique for identifying users based on the unique characteristics of their browser and device, without using cookies.
What is fingerprinting?
Fingerprinting collects information about the user's browser and device (screen resolution, installed fonts, time zone, plugins) and creates a unique "fingerprint". This fingerprint can identify a user even without cookies.
Collected information
- User Agent – Browser, version, operating system
- Screen resolution – Size and colour depth
- Time zone – And language settings
- Installed fonts – Unique combination
- Canvas fingerprint – The way graphics are rendered
- WebGL fingerprint – Graphics card information
- Audio fingerprint – Audio API characteristics
Why is fingerprinting problematic?
- Users cannot easily block it
- It does not need to store data in the browser
- It is difficult to detect
- It bypasses cookie blocking
Legal perspective
Under the GDPR and ePrivacy, fingerprinting constitutes the processing of personal data and requires user consent. Regulators consider fingerprinting more invasive than cookies because the user has no control.
Protection against fingerprinting
Some browsers (Firefox, Brave, Tor) implement protection against fingerprinting through randomisation or blocking of certain APIs. Apple Safari has Intelligent Tracking Prevention.