GDPR means firms using browser fingerprinting, which makes tracking virtually impossible to control, have to back up claims that doing so is in users' interest
Electronic Frontier Foundation : Tweets: @eff , @torproject , and @eff Tweets: @eff : Thanks to the GDPR, companies using browser and web fingerprinting will have to do what their predecessors in the cookie world did before now: come clean about their practices, or slink further behind the curtain and hope to dodge European law. https://www.eff.org/... The Tor Project / @torproject : Yup, it's “difficult to modify browsers so that they are less vulnerable to [fingerprinting],” but we do it in Tor Browser. When we say Tor protects against tracking and surveillance on the web, we mean it. https://www.eff.org/... @eff : We've got news for companies using browser fingerprinting to track users without consent: it's likely illegal under the GDPR. https://www.eff.org/...
Context & Ripple Effects
The GDPR's standardized data-protection rights across 28 countries are the backdrop here: EFF's argument is that fingerprinting, unlike cookies, cannot be switched off by the user, so firms relying on it face a higher bar — they must substantiate that the tracking serves users' interest or withdraw from European traffic. The Tor Project's response in the same thread is that its browser already does what mainstream vendors call difficult: blocking fingerprinting outright.
The follow-on coverage validates the pressure point. A post-GDPR audit of the top 2,000 sites found ad trackers per page fell for EU users while rising for US visitors ([[a:934392]]), and Google later moved to close the same hole from the browser side with anti-fingerprinting controls proposed for Chrome.
First-order effects
- Companies using browser fingerprinting on EU users must now either document a lawful basis showing the practice benefits users or risk enforcement — the cookie-era choice of disclose-or-hide, applied to a technique users cannot opt out of.
- Privacy-focused browsers like Tor Browser gain a compliance-relevant selling point: protection EFF and the Tor Project frame as real, not theoretical.
Second-order effects
- Browser vendors are forced into the arms race: Google's subsequent Chrome anti-fingerprinting proposals show platform owners absorbing the burden that individual users cannot carry, shifting the battleground from consent notices to browser architecture.
- Advertisers and brokers dependent on fingerprinting face a split market — measurable tracker reductions for EU traffic versus growth for US users — incentivizing geo-differentiated tracking stacks.
Third-order effects
- If the pattern holds, privacy enforcement migrates from legal disclosures to technical defaults: standards like Global Privacy Control extend the same logic of one-click, machine-enforceable opt-outs, making the browser rather than the banner the enforcement point.
- Covert tracking techniques that resist user control become structurally disadvantaged under regimes like the GDPR, pushing the ad ecosystem toward identifiers users can see and revoke.
The trend: Web privacy is shifting from cookie-era disclosure regimes toward technical countermeasures — in browsers and standards — against tracking methods users cannot switch off themselves.