Privacy

Browser Fingerprinting: The Tracking Method That Skips the Cookie Banner

Quick answer: Browser fingerprinting identifies a visitor by combining dozens of small signals their browser already exposes (screen size, installed fonts, timezone, how their graphics hardware renders a test image) into a single near-unique signature, computed fresh each visit rather than stored as a cookie. That is exactly what worries regulators: a cookie needs consent and can be refused; a fingerprint is usually collected without either.

How a fingerprint gets built without storing anything

A cookie works by leaving a note in the visitor's browser: an ID, saved to disk, read back on the next visit. Fingerprinting skips the note entirely. Instead, a script asks the browser dozens of small questions it already answers for ordinary web pages: what fonts are installed, what the screen resolution is, which timezone and language are set, how the device's graphics card renders a hidden test image on an HTML canvas. None of these answers is unique on its own, but the combination usually is. Run the same checks again next week and you get the same (or a very similar) signature back, which is enough to recognise a returning visitor without ever writing anything to their device.

How common it actually is

Canvas fingerprinting, the rendering-based technique, is used on 12.7% of the top 20,000 websites, according to a large-scale study characterising canvas fingerprinting use across the web. That is a meaningful share of high-traffic sites, concentrated more heavily among popular sites than obscure ones, and it only counts one fingerprinting technique among several in active use.

Why it troubles regulators more than cookies do

When Google announced in late 2024 that it would stop banning fingerprinting techniques in its advertising products from February 2025, the UK's Information Commissioner's Office pushed back directly. Stephen Almond, the ICO's Executive Director of Regulatory Risk, said in response to the change that "fingerprinting is not a fair means of tracking users online because it is likely to reduce people's choice and control over how their information is collected." The underlying problem is structural: cookie consent frameworks exist because a cookie can be blocked or deleted, and a user can decline it up front. A fingerprint is calculated from information the browser hands over for ordinary page rendering, so there is nothing to "accept" or "decline" in the first place.

That gap is not just theoretical. A 2025 study from Texas A&M and Johns Hopkins researchers, led by cybersecurity professor Nitesh Saxena, found that even users who explicitly opt out of tracking under laws like the GDPR and CCPA can still be silently tracked across sites through browser fingerprinting, since opting out of cookies does nothing to stop a script from reading the signals fingerprinting relies on.

Why this matters even if you never built a fingerprinting script

  • It can hide inside a third-party tool. Ad networks, some chat widgets, and certain analytics scripts can fingerprint without it being obvious from your own site's code.
  • A cookie banner does not cover it. Consent collected for cookies has no bearing on a technique that never sets one, which is part of why regulators are treating it as a separate problem.
  • It is a different approach from a rotating daily hash. See how cookieless tracking actually counts visitors for the method that discards its inputs and re-derives a fresh value every day, rather than building a signature designed to persist.

What to check on your own site

Start with your embedded scripts: ad tags, chat widgets, and any third-party analytics beyond your primary tool are the most likely source of fingerprinting you did not choose directly. Pair that audit with what you already know about Consent Mode and cookie-based consent, since the two systems cover different ground and neither one alone is a complete privacy check.

See privacy-first analytics in action

TrackTrendy tracks every visitor without cookies or consent popups. GDPR compliant by design, simple dashboard, from €4/month.

Start free for 30 days →

No credit card required · No cookie banner needed

Newsletter

Enjoyed this article?

Subscribe and new privacy-first analytics guides land straight in your inbox. No spam, unsubscribe anytime.

Double opt-in: confirm by email. Privacy policy.