---
title: "Browser fingerprinting and the GDPR: what the law requires — TraceTail"
description: "ePrivacy consent, GDPR legal bases, data minimization, retention and erasure: a practical guide for teams adding fingerprinting in the EU. Not legal advice."
url: https://tracetail.io/blog/gdpr-compliant-fingerprinting
updated: 2026-10-04
---

# Browser fingerprinting and the GDPR: what the law requires

ePrivacy consent, GDPR legal bases, data minimization, retention and erasure: a practical guide for teams adding fingerprinting in the EU. Not legal advice.

_TraceTail Team · published January 22, 2025 · updated October 4, 2026 · 4 min read_

Browser fingerprinting isn't banned in the EU, but it is regulated by two laws at once: the ePrivacy Directive and the GDPR. This post covers what each requires, the legal bases you can rely on, and the practical steps for a compliant setup.

**This is a technical guide, not legal advice.** Talk to a privacy lawyer about your situation.

## ePrivacy: accessing the device

Article 5(3) of the ePrivacy Directive requires consent for "storing information, or gaining access to information already stored" on a user's device. European regulators treat reading device characteristics for fingerprinting as gaining access, so consent is the default requirement.

There's an exception for access that is _strictly necessary_ to provide a service the user has asked for. Security measures for that service, such as protecting a login, may qualify; analytics and advertising don't. Regulators read the exception narrowly, so document why it applies if you rely on it.

## GDPR: processing personal data

A visitor ID singles out a browser, which makes it personal data in the GDPR's sense, even without a name attached. So, in addition to ePrivacy, you need:

1. **A legal basis** (Article 6)
2. **Purpose limitation**: use the data only for what you said
3. **Data minimization**: collect only what you need
4. **Storage limitation**: delete it when it's no longer needed
5. **Respect for data subject rights**, including erasure

## Choosing a legal basis

### Consent

The cleanest option where consent is required anyway. Valid consent is freely given, specific, informed and unambiguous: an affirmative action, never a pre-ticked box, and as easy to withdraw as to give.

Only identify the visitor after they've agreed:

```javascript
import { TraceTail } from '@tracetail/js';

const tracetail = new TraceTail({ apiKey: 'YOUR_API_KEY', endpoint: 'https://tracetail.io/api' });
const { visitorId } = await tracetail.generateFingerprint();

async function onConsentGranted() {
  const { visitorId } = await tracetail.generateFingerprint();
  await fetch('/api/devices', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({ visitorId }),
  });
}
```

### Legitimate interest

For fraud prevention, Article 6(1)(f) can apply. You need a documented legitimate interest assessment:

1. **Purpose**: is the interest legitimate? Preventing fraud is.
2. **Necessity**: is fingerprinting needed to achieve it?
3. **Balancing**: do the person's rights outweigh your interest? Protecting a payment flow weighs differently from general analytics.

Keep in mind that legitimate interest covers the GDPR side only. You still need to satisfy ePrivacy, through consent or the strictly-necessary exception.

## Data minimization in practice

In your own systems, store the visitor ID rather than the raw signals behind it, keep it next to the events it explains (sign-ins, orders, signups), and drop it when that purpose is served.

Know what your provider keeps as well. Without an API key, the SDK computes the visitor ID in the browser and sends nothing to TraceTail. With an API key, TraceTail stores each visitor ID together with the browser signals the SDK collected, the IP address and the user agent, until 180 days after that visitor's last visit. You can erase a visitor at any time from Settings in your dashboard, or with `DELETE /api/visitors/:visitorId` while signed in. If you use TraceTail, TraceTail processes that data on your behalf: you're the controller and TraceTail is the processor.

## Erasure requests

Under Article 17 you must be able to delete what you hold about a person without undue delay, normally within a month. For fingerprinting, that means:

- deleting the visitor ID and anything you linked to it in your own database, and
- asking each provider to delete their copy. With TraceTail, erase the visitor from Settings in your dashboard, or call `DELETE /api/visitors/:visitorId` while signed in.

```javascript
// Your backend: erase everything linked to one visitor ID.
async function eraseVisitor(visitorId) {
  await db.devices.deleteMany({ visitorId });
  await db.signInHistory.deleteMany({ visitorId });
  await db.erasureLog.insert({ visitorId, erasedAt: new Date() });
}
```

## Retention

Set a retention period for each purpose and automate deletion. Months, not years, is typical for fraud prevention; bot detection often needs only days. TraceTail deletes a visitor's stored record 180 days after their last visit.

## Transparency

Your privacy policy should say, in plain words:

- that you use browser fingerprinting,
- which characteristics are read,
- why (for example fraud prevention or bot detection),
- who processes the data on your behalf,
- how long it's kept, and
- how people can ask for deletion.

## Checklist

1. Decide your purpose and legal basis, and document it.
2. Get consent where ePrivacy requires it, before identifying anyone.
3. Store visitor IDs, not raw signals, in your own systems.
4. Set retention periods and automate deletion.
5. Handle erasure requests in your systems and with each provider.
6. Update your privacy policy and records of processing.

## The bottom line

You can use browser fingerprinting in the EU if you're deliberate about it: pick the right legal basis, collect only what you need, be transparent, and respect people's rights. For fraud prevention, the ground is generally firmer than for analytics or advertising, where consent is effectively required.

[Read the docs](https://tracetail.io/docs) to see how TraceTail fits into a consent flow.

Tags: GDPR, ePrivacy, Compliance
