Contact ussales@ventavid.com
VentaVid

Glossary

Our sales with video glossary is here to help you gain an understanding of specific video and marketing terms

Device fingerprinting

In this article

Device fingerprinting explained: what it recognises, what it proves, and where it misleads

Device fingerprinting is the practice of combining observable properties of a device and its browser, such as screen dimensions, installed fonts, time zone, language settings and graphics rendering behaviour, into a single identifier that can recognise the same device on a later visit without storing anything on the device itself. The combination is what identifies. No individual property is unusual.

It is sometimes written as device fingerprinting, browser fingerprinting or canvas fingerprinting depending on which signals are used. In counter-fraud work the purpose is almost always the same: noticing that a device has been here before.

How does device fingerprinting work?

A page or app reads a set of properties the environment exposes anyway, then hashes them into a value. Any one property is shared by millions of devices. Twenty of them together are often close to unique, which is the entire idea.

Unlike a cookie, nothing is written to the device, so clearing browser storage does not clear the fingerprint. That property is what makes it useful for fraud teams and what makes it contentious with regulators.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

What a device fingerprint actually proves

It proves recurrence, and only that. The same device, or a device that looks statistically identical, has appeared before. It does not establish who was holding it, who owns it, or whether the person behind this submission is the person behind the previous one.

It is also commonly confused with a digital fingerprint, which is a completely different thing: a SHA-256 hash of a file's contents, used to prove that a stored file has not changed since receipt. One identifies a device. The other identifies a file. Getting these two mixed up in a case note or a witness statement is an avoidable own goal.

Device fingerprinting example: the body shop laptop

A model flags that one device fingerprint appears across six unrelated motor claims in four months, which looks like organised activity until someone picks up the phone. The device is a courtesy tablet at a repairer, handed to customers so they can complete their submission before they leave.

The signal was accurate. The inference would have been wrong. That gap is the whole reason a signal belongs in a review queue rather than in a decision rule.

Where device fingerprinting produces false signals

  • Shared devices: household tablets, workplace machines, repairer and body shop devices, and public terminals all produce legitimate repeat appearances.
  • Collisions: two devices of the same model, on the same operating system build, with default settings, can produce the same fingerprint. Common configurations are the least distinctive.
  • Drift: a browser update, an OS upgrade, a new font or a changed display setting can alter the fingerprint, so one device becomes two in your data.
  • Deliberate randomisation: privacy-focused browsers and modes actively randomise or flatten the signals being read. The user is protecting themselves, not evading you, and the effect on your data is the same either way.
  • Enterprise fleets: managed device estates are configured identically by design, so an entire company can look like one device.

Is device fingerprinting legal in Europe?

It is a live data protection question rather than a settled technical detail, and it belongs in the design conversation early. Article 29 Working Party Opinion 9/2014 established that device fingerprinting falls within the technical scope of Article 5(3) of the ePrivacy Directive, the provision better known for cookie consent. The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3), adopted in October 2024, confirmed and expanded that position, covering fingerprinting techniques, tracking pixels and certain local processing, and reminding controllers that each case needs its own assessment of whether consent is required or an exemption applies.

Separately, under the GDPR you still need a lawful basis for the processing itself. Recital 47 recognises that processing strictly necessary for fraud prevention constitutes a legitimate interest, which is helpful and is not a blanket permission. It does not answer the ePrivacy access question, it does not remove transparency obligations, and a fingerprinting deployment across a claims journey is the sort of processing that usually warrants a data protection impact assessment.

Using the signal without over-reading it

  • Corroborate before acting: a device signal read alongside IP intelligence, claim history and the content of the submission is worth far more than any of them alone.
  • Grade rather than gate: a common pattern is a severity ladder from ignore through informational and amber to red, feeding review priority rather than an outcome.
  • Record the reasoning: if a device signal changed how a file was handled, the file should say so, in the same way any other fraud indicator would be recorded.
  • Never let it decide: it is one of many control points. A signal is a reason to look. It is not a finding of dishonesty, and treating it as one produces bad decisions and worse complaints.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

See the damage before you decide

Send one link, get guided, verified claim video back. No app, no account.