Privacy
Browser fingerprinting and the GDPR: what the law requires
ePrivacy consent, GDPR legal bases, data minimization, retention and erasure: a practical guide for teams adding fingerprinting in the EU. Not legal advice.
TraceTail TeamUpdated 4 min read

Browser fingerprinting isn't banned in the EU, but it is regulated by two laws at once: the ePrivacy Directive and the GDPR. This post covers what each requires, the legal bases you can rely on, and the practical steps for a compliant setup.
This is a technical guide, not legal advice. Talk to a privacy lawyer about your situation.
ePrivacy: accessing the device
Article 5(3) of the ePrivacy Directive requires consent for "storing information, or gaining access to information already stored" on a user's device. European regulators treat reading device characteristics for fingerprinting as gaining access, so consent is the default requirement.
There's an exception for access that is strictly necessary to provide a service the user has asked for. Security measures for that service, such as protecting a login, may qualify; analytics and advertising don't. Regulators read the exception narrowly, so document why it applies if you rely on it.
GDPR: processing personal data
A visitor ID singles out a browser, which makes it personal data in the GDPR's sense, even without a name attached. So, in addition to ePrivacy, you need:
- A legal basis (Article 6)
- Purpose limitation: use the data only for what you said
- Data minimization: collect only what you need
- Storage limitation: delete it when it's no longer needed
- Respect for data subject rights, including erasure
Choosing a legal basis
Consent
The cleanest option where consent is required anyway. Valid consent is freely given, specific, informed and unambiguous: an affirmative action, never a pre-ticked box, and as easy to withdraw as to give.
Only identify the visitor after they've agreed:
import { TraceTail } from '@tracetail/js';
const tracetail = new TraceTail({ apiKey: 'YOUR_API_KEY', endpoint: 'https://tracetail.io/api' });
const { visitorId } = await tracetail.generateFingerprint();
async function onConsentGranted() {
const { visitorId } = await tracetail.generateFingerprint();
await fetch('/api/devices', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ visitorId }),
});
}Legitimate interest
For fraud prevention, Article 6(1)(f) can apply. You need a documented legitimate interest assessment:
- Purpose: is the interest legitimate? Preventing fraud is.
- Necessity: is fingerprinting needed to achieve it?
- Balancing: do the person's rights outweigh your interest? Protecting a payment flow weighs differently from general analytics.
Keep in mind that legitimate interest covers the GDPR side only. You still need to satisfy ePrivacy, through consent or the strictly-necessary exception.
Data minimization in practice
In your own systems, store the visitor ID rather than the raw signals behind it, keep it next to the events it explains (sign-ins, orders, signups), and drop it when that purpose is served.
Know what your provider keeps as well. Without an API key, the SDK computes the visitor ID in the browser and sends nothing to TraceTail. With an API key, TraceTail stores each visitor ID together with the browser signals the SDK collected, the IP address and the user agent, until 180 days after that visitor's last visit. You can erase a visitor at any time from Settings in your dashboard, or with DELETE /api/visitors/:visitorId while signed in. If you use TraceTail, TraceTail processes that data on your behalf: you're the controller and TraceTail is the processor.
Erasure requests
Under Article 17 you must be able to delete what you hold about a person without undue delay, normally within a month. For fingerprinting, that means:
- deleting the visitor ID and anything you linked to it in your own database, and
- asking each provider to delete their copy. With TraceTail, erase the visitor from Settings in your dashboard, or call
DELETE /api/visitors/:visitorIdwhile signed in.
// Your backend: erase everything linked to one visitor ID.
async function eraseVisitor(visitorId) {
await db.devices.deleteMany({ visitorId });
await db.signInHistory.deleteMany({ visitorId });
await db.erasureLog.insert({ visitorId, erasedAt: new Date() });
}Retention
Set a retention period for each purpose and automate deletion. Months, not years, is typical for fraud prevention; bot detection often needs only days. TraceTail deletes a visitor's stored record 180 days after their last visit.
Transparency
Your privacy policy should say, in plain words:
- that you use browser fingerprinting,
- which characteristics are read,
- why (for example fraud prevention or bot detection),
- who processes the data on your behalf,
- how long it's kept, and
- how people can ask for deletion.
Checklist
- Decide your purpose and legal basis, and document it.
- Get consent where ePrivacy requires it, before identifying anyone.
- Store visitor IDs, not raw signals, in your own systems.
- Set retention periods and automate deletion.
- Handle erasure requests in your systems and with each provider.
- Update your privacy policy and records of processing.
The bottom line
You can use browser fingerprinting in the EU if you're deliberate about it: pick the right legal basis, collect only what you need, be transparent, and respect people's rights. For fraud prevention, the ground is generally firmer than for analytics or advertising, where consent is effectively required.
Read the docs to see how TraceTail fits into a consent flow.
- GDPR
- ePrivacy
- Compliance
