Back to Blog
Industry Trends February 10, 2025 5 min read

Google Drops Its Fingerprinting Ban on Feb. 16: What Publishers Should Check

Google's revised ads platform policies take effect this Sunday and no longer prohibit fingerprinting. Regulators are not impressed. Here is what it means for publisher risk and CTV.

HR
HBDR Research
February 10, 2025

The change

On February 16, 2025, Google's ads platforms program policies change. The announcement, published in December, says the update reflects advances in privacy-enhancing technologies such as on-device processing, trusted execution environments and secure multi-party computation, as well as the wider range of surfaces where ads now run, including connected TVs and gaming consoles. The notable difference from the previous version: the explicit prohibition on using device fingerprints is gone.

That is a sharp turn. In 2019 Google described fingerprinting as a technique that subverts user choice and is wrong. The UK Information Commissioner's Office responded to the December announcement the same week, calling the change irresponsible and stating that fingerprinting is not a fair means of tracking users because it reduces people's choice and control over how their information is collected. The ICO statement is worth reading in full if you have UK traffic.

What fingerprinting is, and why it is different

Fingerprinting combines signals a device exposes (IP address, browser and OS version, screen size, language, installed fonts and many more) into an identifier that is often stable enough to recognize the same device across visits. Unlike a cookie, the user cannot clear it. That is exactly why regulators dislike it and why some ad tech companies value it, particularly on screens where cookies never existed.

What does not change

A platform policy is not a law. Google no longer forbidding a technique in its own ad products does nothing to change the legal position:

  • In the UK and EU, storing or accessing information on a device generally requires consent under PECR and the ePrivacy rules, and the ICO has been explicit that this covers fingerprinting. The resulting identifier is personal data under GDPR.
  • In the U.S., state privacy laws define personal data broadly enough to include device identifiers and IP addresses, and opt-outs of targeted advertising apply regardless of the technique used to target.
  • Browsers keep fighting it. Safari and Firefox include fingerprinting protections, and Chrome has signaled its own mitigations such as IP Protection for some browsing modes.

For publishers, the key point is this: if a vendor fingerprints users on your pages, the question of whether that processing is lawful is also your question, because it happens on your property and often under your consent banner.

Where this actually matters: CTV and IP-based targeting

The most practical impact is on connected TV, streaming audio and consoles, where there has never been a cookie and IP address is already the backbone of household targeting and measurement. Google's policy text specifically points to these surfaces. Expect more buyers and platforms to use IP and device signals openly in these environments, and expect more questions from your legal team about what your streaming app or FAST channel partners are doing with them.

On the open web, the effect is less certain. Some demand may lean on probabilistic signals to reach users without third-party cookies, particularly in Safari. Whether that becomes meaningful incremental revenue for publishers, or simply a new compliance liability, depends on how consent and opt-out signals are handled.

A publisher checklist for this week

  1. Update your vendor inventory. For every partner with a script on your pages or an SDK in your apps, ask directly whether it uses fingerprinting or IP-based identification, for what purpose, and under what legal basis. Get the answer in writing.
  2. Check your CMP disclosures. If any vendor fingerprints, your consent notice in the UK and EU needs to say so, and the vendor should not run before consent is given. The IAB Europe TCF includes purposes and special features relevant to device characteristics; make sure your configuration matches reality.
  3. Confirm opt-outs apply to every technique. A U.S. opt-out of targeted advertising should stop targeting, not just stop cookie syncing. Ask vendors how they honor GPP and Global Privacy Control signals when they are not using cookies at all.
  4. Review IP handling in your own stack. Many sites pass full IP addresses in bid requests by default. Decide whether truncation is appropriate for opted-out or non-consented traffic, and check what your wrapper and server-side setup actually send.
  5. Watch CTV contracts. If you syndicate video to streaming platforms, make sure agreements specify what device and household data can be collected and resold.

Questions for your SSPs and wrapper partner

Your supply partners sit between your pages and hundreds of buyers, so they are the best place to get answers at scale. Ask each one:

  • Do you pass full or truncated IP addresses to DSPs, and does that change when a user has opted out or not consented?
  • Do you generate or enrich any device identifier from browser characteristics, and if so, is it disclosed in your TCF registration and privacy documentation?
  • Can you show, in a sample bid request, which consent strings and user fields go out for a UK visitor, an EU visitor and a U.S. visitor who has sent Global Privacy Control?

Vague answers are an answer too. A partner that cannot describe its own data flows is a partner whose risk you are carrying.

Revenue versus risk

It is tempting to read the change as a potential lift in addressability, and in some environments it may be. But the regulatory response was immediate and public, and enforcement actions tend to land on the party with the direct relationship with the user. For most publishers that is you.

Treat fingerprinting like any other data processing on your property: disclosed, consented where required, and switched off for users who opt out.

The sustainable path to addressability without third-party cookies remains the unglamorous one: logged-in and first-party relationships, strong contextual signals, and clean consent data that buyers can trust. A well-run managed setup should be able to show you exactly which partners receive what data, per request, before any of this becomes a problem.

Tags: fingerprinting identity privacy google ctv

Ready to maximize your ad revenue?

Get Started