Platform
Device Fingerprinting
Definition
Identifying a customer's device from the combination of its browser, operating system, hardware and network characteristics, so it can be recognised across sessions and accounts without cookies. A core tool against multi-accounting, bonus abuse and self-exclusion evasion.
Key takeaways
- Device fingerprinting recognises a device from its characteristics, without cookies, across sessions and accounts.
- It is the main tool for linking duplicate accounts: bonus abuse, self-exclusion evasion and returning restricted bettors.
- Regulators expect it for self-exclusion enforcement; data-protection law treats it as tracking that needs a lawful basis.
- Shared devices and privacy tools limit it; it is one signal in a fraud model rather than a conclusive identifier.
Why it matters
Gambling operators need to know when two accounts are the same person, and device fingerprinting is one of the main ways they find out. A customer who opens a second account to claim a welcome bonus again, a self-excluded customer registering under a relative's name, a bonus-abuse ring running dozens of accounts from one room, or a restricted sharp bettor returning under a new identity will usually use the same device or the same few devices, and a fingerprint that survives cleared cookies and new email addresses links them. The fingerprint is a hash of dozens of signals, stable enough to recognise a device over time and specific enough to distinguish it from millions of others, and it is combined with IP intelligence, behavioural signals and identity data in the operator's fraud and risk models.
The technique sits at the intersection of fraud prevention, responsible gambling and data protection. On the fraud side it is standard, supplied by specialist vendors and integrated into the platform's registration and payment flows. On the responsible-gambling side it is increasingly expected: regulators ask how operators detect self-excluded customers who return, and device matching is part of the answer. On the data-protection side it is regulated: fingerprinting is tracking, it requires a lawful basis and transparency under European rules, and the e-privacy rules on storing and accessing information on a device apply to it as they do to cookies.
It has limits. Shared devices produce false matches, privacy tools and browser changes degrade signals, and sophisticated fraud rings rotate devices; the technique is a signal in a model, not a verdict.
Frequently asked questions
How does device fingerprinting detect multi-accounting?
By recognising that two accounts registered under different names and emails are used from the same device, which is a strong signal that they belong to one person, especially when combined with matching IP, behaviour or payment details.
Is device fingerprinting legal under GDPR?
It is lawful with a lawful basis and transparency, and fraud prevention is a recognised legitimate interest. The e-privacy rules on accessing information stored on a device also apply, so the operator’s privacy notice and consent handling matter.
Can device fingerprinting be defeated?
Partly. Privacy browsers, virtual machines and device rotation degrade the signal, which is why operators combine it with other signals rather than relying on it alone.