Tech Insight : Why Google’s New ‘Fingerprint’ Policy Matters

In this Tech Insight, we look at Google’s controversial decision to allow advertisers to use device fingerprinting, exploring what the technology involves, why it has sparked concern, and what it means for users, businesses, and regulators.

A Policy Reversal

In February 2025, Google quietly updated its advertising platform rules, allowing companies that use its services to deploy a tracking method known as ‘device fingerprinting’. The change came with little fanfare but has quickly become one of the most debated privacy developments of the year.

Until now, fingerprinting was explicitly prohibited under Google’s policies. The company had long argued it undermined user control and transparency. In a 2019 blog post, Google described it as a technique that “subverts user choice and is wrong”. But five years later, the same practice is being positioned as a legitimate tool for reaching audiences on platforms where cookies no longer work effectively.

According to Google, the decision reflects changes in how people use the internet. For example, with more users accessing content via smart TVs, consoles and streaming devices, environments where cookies and consent banners are limited or irrelevant, fingerprinting offers advertisers a new way to track and measure campaign effectiveness. The company says it is also investing in “privacy-enhancing technologies” that reduce risks while still allowing ads to be targeted and measured.

However, the reaction from regulators, privacy campaigners and some in the tech community has been far from supportive.

What Is Fingerprinting?

Fingerprinting is a method of identifying users based on the technical details of their device and browsing setup. Unlike cookies, which store data on a user’s device, fingerprinting collects data that’s already being transmitted as part of normal web use.

This includes information such as:

– Browser version and type.

– Operating system and installed fonts.

– Screen size and resolution.

– Language settings and time zone.

– Battery level and available plugins.

– IP address and network information.

Individually, none of these data points reveals much but, when combined, they can create a unique “fingerprint” that allows advertisers or third parties to recognise a user each time they go online, often without them knowing, and without a way to opt out.

Also, because it happens passively in the background, fingerprinting is hard to block. Even clearing cookies or browsing in private mode won’t prevent it. For privacy advocates, that’s a key part of the problem.

How Fingerprinting’s Being Used

With third-party cookies disappearing and users browsing through everything from laptops to smart TVs, fingerprinting essentially offers a way for advertisers to maintain continuity, even when cookies and consent banners can’t keep up.

Advertisers use it to build persistent profiles that help with targeting, measurement, and fraud detection. In technical terms, it’s a highly efficient way to link impressions and conversions without relying on traditional identifiers.

Why Critics Are Alarmed

Almost immediately after Google’s announcement, a wave of criticism followed. For example, the UK’s independent data protection regulator, the Information Commissioner’s Office (ICO), called the move “irresponsible” and said it risks undermining the principle of informed consent.

In a December blog post, Stephen Almond, Executive Director of Regulatory Risk at the ICO, warned: “Fingerprinting is not a fair means of tracking users online because it is likely to reduce people’s choice and control over how their information is collected.”

The ICO has published draft guidance explaining that fingerprinting, like cookies, must comply with existing UK data laws. These include the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). That means advertisers need to demonstrate transparency, secure user consent where required, and ensure users understand how their data is being processed.

The problem, critics say, is that fingerprinting makes this nearly impossible. The Electronic Frontier Foundation’s Lena Cohen described it as a “workaround to offering and honouring informed choice”. Mozilla’s Martin Thomson went further, saying: “By allowing fingerprinting, Google has given itself — and the advertising industry it dominates — permission to use a form of tracking that people can’t do much to stop.”

Google’s Justification

Google insists that fingerprinting is already widely used across the industry and that its updated policy simply reflects this reality. The company has argued that IP addresses and device signals are essential for preventing fraud, measuring ad performance, and reaching users on platforms where traditional tracking methods fall short.

In a statement, a Google spokesperson said: “We continue to give users choice whether to receive personalised ads, and will work across the industry to encourage responsible data use.”

Criticism From Privacy Campaigners

However, privacy campaigners argue that the decision puts business interests above users. They point out that fingerprinting isn’t just harder to detect, but it’s also harder to control. For example, unlike cookies, there’s no pop-up, no ‘accept’ or ‘reject’ button, and no straightforward way for users to opt out.

Pete Wallace, from advertising technology company GumGum, said the change represents a backwards step: “Fingerprinting feels like it’s taking a much more business-centric approach to the use of consumer data rather than a consumer-centric approach.”

Advertisers Welcome the Change

Unsurprisingly perhaps, within the advertising industry, many welcomed Google’s decision because as the usefulness of cookies declines, brands are looking for alternative ways to reach users, especially across multiple devices.

For example, Jon Halvorson, Global VP at Mondelez International, said: “This update opens up more opportunities for the ecosystem in a fragmented and growing space while respecting user privacy.”

Trade bodies such as the IAB Tech Lab and Network Advertising Initiative echoed the sentiment, saying the update enables responsible targeting and better cross-device measurement.

That said, even among advertisers, there’s an awareness that the use of fingerprinting must be handled carefully. Some fear that if it is abused or poorly implemented, it could invite regulatory action, or worse, further erode user trust in the online ad industry.

Legal Responsibilities Under UK Law

For UK companies using Google’s advertising tools, the policy change doesn’t mean fingerprinting is suddenly risk-free. While Google’s own platform rules now allow the practice, UK data protection law still applies, and it’s strict.

For example, organisations planning to use fingerprinting must ensure their tracking methods are:

– Clearly explained to users, with full transparency.

– Proportionate to their purpose, and not excessive.

– Based on freely given, informed consent where applicable.

– Open to user control, including rights to opt out or request erasure.

The ICO has warned that fingerprinting, by its very nature, makes it harder to meet these standards. The fact that it often operates behind the scenes and without user awareness means that it may not be providing the level of transparency required under the UK GDPR and PECR is a significant challenge.

Therefore, any business using fingerprinting for advertising will need to demonstrate that it is not only aware of these rules, but fully compliant with them. Regulators have already signalled their willingness to act where necessary, and given Google’s influence, this policy change is likely to come under particular scrutiny.

The Reputational Risks Are Real

It should be noted, however, that while it’s effective, fingerprinting comes with serious downsides, especially for businesses operating in sensitive or highly regulated sectors. For example, since users often don’t know it’s happening, fingerprinting can undermine trust, even when it’s being used within legal boundaries.

For industries like healthcare, finance, or public services, silent tracking could prove more damaging than the data is worth. If customers feel they’ve been tracked without consent, the backlash, whether legal, reputational or both, can be swift.

Fragmentation Across the Ecosystem

Another practical challenge is that fingerprinting isn’t supported equally across platforms. While Google has now allowed it within its ad systems, others have gone in the opposite direction.

For example, browsers like Safari, Firefox and Brave actively block or limit fingerprinting. Apple in particular has built its privacy credentials around restricting such practices. This means advertisers relying heavily on fingerprinting could see patchy results or data gaps depending on the devices or browsers their audiences are using.

Part of a Broader Toolkit

It’s worth remembering here that fingerprinting isn’t the only tool on the table. Many ad tech providers are combining it with alternatives such as :
— Contextual targeting : Showing ads based on the content you’re looking at (e.g. showing travel ads on a travel blog).
— First-party data : Information a company collects directly from you, like your purchase history or website activity — not from third parties.

— On-device processing : Data is analysed on your phone or computer, never sent to a central server.

— Federated learning : Your device trains a model (like for ad targeting or recommendations), and only anonymised updates are shared — not your personal data.

Therefore, rather than replacing cookies outright, fingerprinting may end up as just one option in a mixed strategy, and used selectively where consent is hard to obtain, or where traditional identifiers are unavailable.

What Does This Mean for Your Business?

For UK businesses, the reintroduction of fingerprinting within its advertising ecosystem may offer more stable tracking across devices and platforms, especially as third-party cookies continue to decline. However, the use of such techniques also brings legal and reputational risks that cannot be delegated to Google or any external platform.

Organisations that advertise online, whether directly or through agencies, should now assess how fingerprinting fits within their broader compliance obligations under UK data protection law. The Information Commissioner’s Office has made it clear that fingerprinting is subject to the same principles of transparency, consent, and fairness as other tracking methods. Simply using a tool because it is technically available does not make its use lawful.

Beyond legal considerations, there’s also a growing risk to customer trust. For example, if users discover that they are being tracked through methods they cannot see, manage or decline, the damage to a brand’s credibility could be significant, particularly in sectors where data sensitivity is high. For many organisations, the question may not just be whether fingerprinting can improve ad performance, but whether it aligns with the expectations of their audience and the values they wish to uphold.

This change also places pressure on advertisers, platforms, and regulators to clarify the boundaries of responsible data use. For some, fingerprinting may form part of a wider privacy-aware strategy that includes contextual targeting or consent-based identifiers. For others, it may prove too opaque or contentious to justify. Either way, businesses will need to make informed decisions, and be ready to explain them.

Company Check – HP’s Deliberate 15-Minute Call-Wait Outcry

HP has come under scrutiny for implementing a policy that enforced a minimum 15-minute wait time for customers seeking telephone support for consumer PCs and printers.

Frustration

The move, which was (quietly) introduced earlier this year, was designed to push customers towards self-service digital support options, but it has triggered frustration among users and raised concerns about customer service standards.

Internal Memo Reveals Strategic Delay

An internal HP memo, which was leaked to the press, appears to show that the 15-minute call delay was intentional. The document stated that the company wanted to “influence customers to increase their adoption of digital self-solve” and “generate warranty cost efficiencies.”

The changed policy affected customers in the UK, Ireland, France, Germany, and Italy, with HP’s phone system informing callers of the extended wait time before redirecting them to HP’s online support tools, such as its website and virtual assistant. The idea was to encourage users to find answers themselves rather than immediately resorting to human customer service.

Customer Backlash and Internal Dissent

However, unfortunately for HP, its decision didn’t go unnoticed. Customers quickly voiced their frustration, arguing that a forced waiting period was an unreasonable tactic to discourage live support requests. Many took to social media and consumer forums, questioning why a major tech company would deliberately delay assistance.

Internally, the policy was reportedly not well received by HP employees either. It’s been reported that sources within the company suggested that frontline staff had no direct involvement in the decision, leaving them to handle complaints from disgruntled customers without a clear justification.

U-Turn After Widespread Criticism

Facing significant backlash, HP reversed the 15-minute waiting policy within weeks of its implementation. The company issued a statement clarifying that the move was meant to encourage digital solutions and reduce enquiry resolution times, but it acknowledged that customer expectations were not met.

“We are committed to delivering an exceptional customer experience and have listened to our customers’ feedback,” HP said. The company assured users that they would no longer experience artificial delays when calling for support.

Part of a Shift From Traditional Customer Service Models?

For businesses that rely on HP devices, the brief but controversial policy raises important questions about customer support access and service reliability. While HP may have abandoned the delay, the incident highlights an ongoing industry trend of shifting away from traditional customer service models. For example:

– Operational efficiency at risk. Businesses that rely on quick resolutions for IT issues could face significant disruptions if similar policies are reintroduced.

– Rising costs and productivity loss. Longer wait times for technical support translate to delayed troubleshooting, which can impact productivity and profitability.

– Trust and vendor loyalty. Companies may start re-evaluating their relationship with HP, particularly if competitors offer more accessible customer support.

A Growing Industry Trend

HP doesn’t appear to be alone in pushing customers towards digital self-service. For example, many technology companies are investing in AI-powered chatbots and automated support to cut costs. Some firms have even implemented fees for live customer support, reinforcing the idea that human assistance is becoming a premium service.

However, the balance between automation and accessibility remains a concern. A recent Gartner report suggests that consumer protection laws in the EU may soon mandate a “right to human support” to prevent companies from making digital-only assistance the default option.

What Does This Mean For Your Business?

HP’s brief experiment with forced waiting times may have ended, but it appears to have left some lingering concerns over how major tech firms balance cost-cutting with customer care. It seems that businesses should, therefore, remain cautious about future shifts in HP’s support strategy, as the company’s willingness to experiment with such measures suggests a broader trend towards digital-first service models.

While automation can streamline some processes (and cut costs), the need for live support remains critical, particularly in high-stakes business environments where downtime can be costly. Companies should evaluate whether HP’s evolving approach aligns with their operational needs or if alternative vendors offer more reliable support.

At the same time, HP and other industry leaders should probably recognise that restricting access to human assistance could drive customers towards competitors who offer direct service rather than cost-saving efficiencies. The growing tension between digital automation and consumer expectations suggests that future policies will need to strike a careful balance or risk further alienating business customers.

As customer expectations continue to evolve, businesses must be prepared to advocate for accessible and reliable support services, whether from HP or any other technology provider.

Tech News : Google’s Fingerprinting Policy Shift Sparks Privacy Concerns

Google’s recent decision to allow device fingerprinting for advertising purposes has triggered alarm among privacy advocates, regulators, and businesses alike.

What Is Device Fingerprinting?

Device fingerprinting is a sophisticated tracking method that collects various data points from a user’s device (e.g. screen size, browser type, language settings, battery level, and time zone) to create a unique digital profile. Unlike cookies, which users can clear or block, fingerprinting operates behind the scenes, offering far fewer opportunities for user control.

When combined with IP address data, fingerprinting allows advertisers to track users across multiple platforms and devices without explicit consent. This makes it a particularly powerful tool for targeted advertising but raises serious questions about transparency and user choice.

Google’s Policy Change

Effective from 16 February 2025, Google’s new policy will allow advertisers using its platform to deploy fingerprinting techniques. This marks a stark reversal from the company’s previous stance. For example, in a 2019 blog post, Google had unequivocally stated that fingerprinting “subverts user choice and is wrong.”

Critics argue that this change in Google’s policy threatens user privacy. However, Google claims it reflects necessary adaptations to changing technology trends and shifts in user behaviour.

As more people access content through devices like smart TVs and gaming consoles, traditional data collection methods (e.g. third-party cookies) are becoming less effective. Google argues that fingerprinting will enable advertisers to reach users across a fragmented digital landscape while maintaining privacy safeguards through privacy-enhancing technologies (PETs) like on-device processing and secure multi-party computation.

Google maintains that these technologies will offer new ways for advertisers to operate on emerging platforms without compromising user privacy.

The ICO and Privacy Campaigners Respond

The UK’s Information Commissioner’s Office (ICO) has criticised the decision, calling it a “threat to user control and transparency.” According to Stephen Almond, the ICO’s Executive Director of Regulatory Risk, fingerprinting reduces users’ ability to control how their data is collected and processed. In a December 2024 blog post, Almond labelled Google’s policy shift as “irresponsible,” stating: “Fingerprinting is not a fair means of tracking users online because it is likely to reduce people’s choice and control over how their information is collected.”

The ICO also warned businesses that deploying fingerprinting techniques would not exempt them from adhering to the UK’s stringent data protection laws, including the requirement to obtain clear user consent and offer transparent information on data usage.

Privacy organisations have echoed these concerns. For example, the Electronic Frontier Foundation has argued that Google’s new policy highlights a shift in focus from prioritising user privacy to maximising business profits. They’ve also raised concerns about how fingerprinting could expose users’ sensitive information to data brokers and surveillance entities.

A Business-Centric Shift?

The advertising technology sector appears divided on Google’s decision. For example, Pete Wallace of GumGum, an ad tech company specialising in contextual advertising, has been quoted as describing the policy shift as a “business-centric approach to the use of consumer data.”

“Fingerprinting sits in a grey area,” Wallace said. “While it offers advertisers powerful targeting capabilities, it simultaneously erodes consumer privacy. This inconsistency is detrimental to the industry’s previous attempts to put user privacy at the forefront.”

Some businesses, however, see fingerprinting as a necessary evolution to replace third-party cookies, which are being phased out by most major browsers. As traditional tracking methods diminish, fingerprinting could become the go-to strategy for advertisers seeking to maintain high levels of ad personalisation and effectiveness.

What About Businesses, Advertisers, and the Public?

For businesses and advertisers, Google’s policy shift could offer new opportunities to refine audience targeting and improve ad performance across platforms. The ability to collect detailed user profiles without relying on cookies could be a game-changer for marketers struggling with the limitations imposed by recent privacy regulations.

However, this comes at a potential cost. Organisations using fingerprinting must still comply with data protection laws such as the UK General Data Protection Regulation (GDPR) and the Privacy and Electronic Communications Regulations (PECR). For example, companies will need to demonstrate that they have obtained meaningful user consent and are transparent about their data practices—standards that many privacy experts believe will be difficult to meet given the covert nature of fingerprinting.

For the public, the implications are more concerning. Unlike cookies, fingerprinting is harder to detect and nearly impossible to block using conventional browser settings. This reduces individuals’ ability to manage their digital footprints, potentially exposing them to more invasive tracking by advertisers, data brokers, and even surveillance agencies.

According to the ICO’s draft guidance, businesses will need to provide clear information about fingerprinting and ensure that users can exercise their data rights, including the right to erasure. However, privacy campaigners argue that even with these measures, true user control is unlikely to be restored.

Google’s Defence

In response to the backlash, Google insists that its use of fingerprinting will adhere to strict privacy standards, leveraging PETs to anonymise data and prevent user re-identification. The company highlights its use of techniques like on-device processing to ensure that sensitive information never leaves the user’s device unless necessary.

Google claims that these measures will allow advertisers to reach their audiences effectively while safeguarding user privacy.

The tech giant also argues that fingerprinting is already widely used across the digital advertising ecosystem and that its new policy merely formalises existing practices while setting a higher bar for privacy.

Ongoing Developments and Industry Implications

As the February 2025 implementation date approaches, the debate around Google’s policy change is likely to intensify. The ICO has pledged to engage further with Google and provide updated guidance for businesses on how to lawfully implement fingerprinting techniques.

The advertising industry, privacy advocates, and regulators will, no doubt, be monitoring the effects of this shift closely, with the broader question remaining, i.e. will the industry’s drive for better ad targeting ultimately undermine the fundamental rights of internet users to control their personal information?

What Does This Mean For Your Business?

Google’s shift in policy towards enabling device fingerprinting for advertising presents a complex dilemma at the intersection of technological innovation, business interests, and individual privacy rights. While the company is defending its decision as an evolution of tracking methods, the concerns raised by regulators, privacy advocates, and sections of the advertising industry can’t be dismissed lightly.

On one hand, fingerprinting offers advertisers a powerful tool to maintain personalisation and relevance in a post-cookie world. For businesses, this represents an opportunity to sustain revenue streams, particularly as users increasingly consume content across diverse devices and platforms. Google’s assurances about deploying privacy-enhancing technologies (PETs) such as on-device processing and secure multi-party computation offer some degree of comfort that sensitive data will be handled with greater care than before.

However, these reassurances do little to address the core issue, i.e. the lack of meaningful user control. Unlike cookies, which users can manage or block, fingerprinting operates invisibly, making it nearly impossible for individuals to opt out without significant technical expertise. This shift risks undermining the principles of transparency and consent that underpin data protection laws such as the GDPR. The criticisms voiced by the ICO and privacy organisations are valid and highlight the tension between commercial interests and the fundamental rights of users to control their personal information.

The challenge ahead for regulators, therefore, will be ensuring that the use of fingerprinting remains within the bounds of legal and ethical standards. While Google’s policy formalises practices already in use, it simultaneously sets a precedent that could normalise more intrusive forms of tracking under the guise of innovation.

Security Stop Press : Microsoft’s RSA Key Policy Change

Microsoft is making a security-focused policy change that will see RSA keys with lengths shorter than 2048 bits deprecated. RSA keys are algorithms used for secure data encryption and decryption in digital communications, i.e. to encrypt data for secure communications over an enterprise network.

However, with RSA encryption keys becoming vulnerable to advancing cryptographic techniques (driven by advancements in compute power) the decision by Microsoft to depreciate them is being seen as a way to stop organisations from using what is now seen as a weaker method of authentication.

Also, the move by Microsoft will help bring the industry in line with recommendations from the internet standards and regulatory bodies who banned the use of 1024-bit keys in 2013 and recommended that RSA keys should have a key length of 2048 bits or longer.

An Apple Byte : Push Notification Policy Change

Following U.S. Senator Ron Wyden revealing that governments can secretly force Apple and Google to hand over the contents of push notifications sent to customers’ phones, Apple has said it’s changed its policy and will no longer do so without a valid judge’s order. This will be either a court order or a search warrant.

Push notifications are the pop-up messages that are sent to phones to alert users to new messages, news, and app-based updates. However, since these notifications are routed through Apple and Google servers, Apple and Google can disclose them to governments as part of surveillance about how people are using certain apps.

Apple’s policy change was made to a passage in its guidelines without an official statement although Google issued a statement saying it had always required judicial approval to hand over this kind of information.