Most discussion of online tracking still centres on cookies. The more consequential shift happened in February 2025, when Google stopped prohibiting advertisers from using browser fingerprinting, reversing a position it had held publicly since 2019.
That reversal matters more than any technical development in the field, because it moved fingerprinting from a practice the largest ad platform condemned to one it permits. Understanding what fingerprinting is, and what obligations now attach to using it, is a compliance question before it is a technical one.
Key Takeaways
- A fingerprint is built from device and browser traits, so clearing cookies does not remove it.
- Google permitted fingerprinting in its ad products from 16 February 2025.
- The ICO called that change irresponsible and confirmed PECR still applies.
- Deploying fingerprinting for advertising is a data protection question, not just a technical choice.
- Legitimate multi-account management is solved by platform tooling, not by masking device identity.
What a Browser Fingerprint Is
A fingerprint is assembled from signals a browser exposes as a normal part of connecting: operating system, screen dimensions, language, time zone, installed fonts, graphics rendering behaviour, browser version, and hardware characteristics. No single signal identifies anyone. Combined, they frequently produce a profile distinctive enough to recognise the same device across sessions.
The structural difference from cookies is control. A cookie is stored on the device and can be deleted. A fingerprint is derived from traits the browser keeps presenting, so clearing storage or opening a private window changes little. That is precisely why the ICO’s objection focused on user agency rather than on the technique itself.
Fingerprinting has genuine defensive uses. Fraud detection, bot filtering and account takeover prevention all rely on recognising that a session does not match a device’s established pattern. The same capability, pointed at advertising, becomes cross-site tracking that a user cannot see or switch off.
The Reversal That Changed the Question
In December 2024, Google told organisations using its advertising products that from 16 February 2025 it would no longer prohibit them from employing fingerprinting techniques.
The reversal is notable because of Google’s earlier position. In 2019 the company stated that fingerprinting subverts user choice and is wrong, on the reasoning that users cannot consent to it the way they can to cookies, and therefore cannot control how their information is collected.
The UK’s Information Commissioner’s Office responded that the change was irresponsible, and made the regulatory position explicit: businesses do not have free rein to use fingerprinting as they please, data protection law including PECR applies, and the ICO would act where deployment is not lawful and transparent. The regulator also noted the practical asymmetry, that fingerprinting is harder for browsers to block, so even privacy-conscious users struggle to prevent it.
For anyone running ad technology, the operative point is that a platform policy permitting something is not a legal basis for doing it. Those are separate questions, and only one of them carries a regulator.
Where Detection Systems Actually Look
Modern risk systems do not evaluate a fingerprint alone. They correlate browser identity with network behaviour, session patterns and interaction timing, then assess whether the combination is internally consistent.
This is why sessions get flagged when no individual signal looks unusual. A browser configuration can be ordinary and a network path can be ordinary while the pairing of the two is not. It is also why masking one layer tends to fail: a device claiming to be a Windows machine in Frankfurt, connecting through residential infrastructure in another country, with interaction timing that does not match either, is more distinctive than an unmodified browser would have been.
The Multi-Account Problem, and What Actually Solves It
There is a real operational difficulty here, and it gets used to justify tools that do not address it.
An agency running paid campaigns for several clients, or a retail team operating regional storefronts, does need separation between environments. Shared logins get messy, sessions overlap, and nobody can tell which setup belongs to which account.
The platforms built for this. Meta Business Manager, Google Ads manager accounts, TikTok Business Center and their equivalents exist so that one organisation can administer many client accounts under named individual logins with scoped permissions and an audit trail. An agency using them does not need to disguise device identity, because it is not pretending the accounts are unrelated. It is declaring the relationship and being granted access on that basis.
That reframes what fingerprint-masking tools are for. If accounts are legitimately connected and the platform provides a mechanism for administering them, the remaining reason to make them look unconnected is to prevent linkage the platform would otherwise make. That is a different objective from operational tidiness, and it carries different consequences, since enforcement lands on the accounts rather than on the software.
The honest version of the advice: fix access management first with named logins, single sign-on, scoped roles and a password manager. Most of the mess these tools promise to solve is credential hygiene wearing a technical costume.
Enterprise Browsers Are a Different Category
Worth separating two things that get conflated, sometimes deliberately.
Gartner predicts that by 2028, 25% of organisations will deploy at least one secure enterprise browser to complement existing remote access and endpoint security tools, up from fewer than 10% today. The driver is credential theft and phishing, and the purpose is visibility: embedding security controls into the browsing experience so security teams can enforce policy and see what is happening inside sessions.
That is the opposite of a tool designed to obscure device identity from the services being accessed. One category exists so an organisation can see and govern browser activity. The other exists so a platform cannot. Citing the first as evidence of demand for the second is a category error, and it appears often enough in vendor content to be worth naming.
Reducing Your Own Exposure
For individuals rather than operators, the defensive options are real but modest.
Browsers that randomise or standardise the signals most used for fingerprinting reduce distinctiveness, which works better than making yourself unusual. Uncommon configurations make a device easier to recognise, not harder, which is the counterintuitive part most privacy advice gets backwards. Reducing installed extensions and unusual fonts helps for the same reason. Tools that report how identifiable your browser appears are worth running before and after any change, because the intuition is unreliable.
None of it produces anonymity. It narrows the gap between your device and the crowd, which is the achievable goal.
Conclusion
Browser fingerprinting became a business issue in 2026 for a reason that has little to do with the technique improving. It became one because the largest advertising platform stopped forbidding it and a regulator immediately said that permission is not the same as lawfulness.
For teams deploying ad technology, that means documenting a lawful basis rather than relying on a platform policy. For teams managing multiple accounts, it means using the administration tools the platforms built and fixing credential hygiene. Neither answer is a product purchase, which is probably why neither gets recommended much.
Read Next
- How to Evaluate an SEO Agency: What to Check Before You Sign
- Google Maps Business Data: What You Can Extract, Store, and Send
- X Marketing in 2026: The Algorithm Is Public, So What Are You Paying For?











