Fingerprinting

Data & Tracking

Also: Device Fingerprinting · Browser Fingerprinting · Canvas Fingerprinting

What it isIdentifying a device without cookies
HowCombines browser and device signals
Watch forGrey area under privacy law
Compared toCookies, but harder to opt out of

Quick definition

Fingerprinting is a tracking method that identifies a device by combining details like screen size, browser type, fonts, timezone and installed plugins into a unique profile. Unlike a cookie, there's nothing stored on the device to delete, which makes fingerprinting harder for users to block or opt out of.

How it varies across Australia

Adoption of fingerprinting techniques among Australian advertisers has grown as third-party cookie support fades, though usage sits below markets with looser privacy enforcement. Businesses relying on it face rising scrutiny rather than rising tolerance.

See data and tracking maturity across Australian industries

What it actually means

A cookie is a note left in someone's browser. Fingerprinting is reading the shape of their hand instead. It combines signals that seem harmless alone, screen resolution, installed fonts, timezone, browser version, graphics card behaviour, into a combination unique enough to identify a single device among millions.

This matters because cookies are visible and deletable. A user can clear them, block them, or reject the consent banner. Fingerprinting leaves nothing to delete. There's no consent-management-platform toggle that removes a graphics card signature.

That's exactly why regulators treat fingerprinting with more suspicion than cookies, not less. It sits awkwardly against first-party-data and third-party-data frameworks built around consent, because fingerprinting was designed to work whether or not consent was given.

For attribution and analytics teams losing cookie-based tracking, fingerprinting looks like a tempting workaround. It often isn't a safe one. The accuracy is also imperfect. Fingerprints drift as browsers update, so identification degrades over weeks, not indefinitely.

A cookie asks permission and can be deleted. A fingerprint asks nothing and can't be washed off.

How it shows up

Fingerprinting shows up inside fraud-prevention tools, ad-verification platforms and some analytics vendors marketed as cookieless solutions. It appears in vendor contracts as phrases like device intelligence or probabilistic matching. It also shows up in privacy audits as a flagged risk, since most consent-management-platform tools were not built to disclose or block it clearly.

The Australian context

The Office of the Australian Information Commissioner (OAIC) treats device identifiers as personal information when they can reasonably identify an individual, which most fingerprinting techniques do in practice. Businesses relying on fingerprinting without disclosure risk falling foul of the Privacy Act, particularly as proposed reforms tighten definitions of tracking and profiling. Australian legal guidance here trails the European Union's stricter stance but is moving in the same direction.

Where people get this wrong

Assuming fingerprinting avoids consent requirements because nothing is stored locally.Regulators assess whether a technique can identify a person, not whether it stores data on their device. Fingerprinting usually qualifies as personal data collection either way.
Treating fingerprint-based identification as equally reliable as cookies.Fingerprints degrade as software updates change the signals being read, so matches become less accurate the longer the tracking window runs.
Adding fingerprinting quietly through a third-party vendor without checking their methods.Many analytics and ad-fraud tools use fingerprinting under the hood. If your privacy policy doesn't disclose it, the business carries the compliance risk, not the vendor.

Related terms

Common questions

Is fingerprinting legal in Australia?

It isn't banned outright, but if it identifies an individual it likely counts as personal information under the Privacy Act, which means disclosure and lawful basis requirements apply. Undisclosed fingerprinting is where the legal risk concentrates.

Why do businesses use fingerprinting instead of cookies?

Cookies are being phased out by major browsers and users can block or delete them easily. Fingerprinting survives both of those limits, which makes it attractive for fraud prevention and ad measurement, though the compliance trade-off is real.

Can users block fingerprinting?

Partially. Privacy-focused browsers and extensions can randomise or mask some signals, but no consumer tool blocks it completely the way cookie blockers can. This is exactly what makes regulators uneasy about it.

Does fingerprinting work as well as cookie tracking?

Not perfectly. Accuracy is high in short windows but degrades as software updates change the signals being read. It's better suited to fraud detection over minutes than long-term attribution over months.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →