# Device fingerprinting

Source: https://ordergroup.co/glossary/device-fingerprinting/
Last updated: 2026-10-10

> Device fingerprinting for fraud prevention in lending apps: where to collect device data, how to link it to the application, and what GDPR and ePrivacy require.

[Fintech](https://ordergroup.co/glossary/fintech/)
4 min read

# Device fingerprinting

Also known as: device fingerprint

Definition

Device fingerprinting is the collection of technical attributes of a phone or browser to recognize the same device across sessions. Lending apps use it for fraud checks at login, registration and the loan application. In the EU it falls under the GDPR and Article 5(3) of the ePrivacy Directive.

Cite this entry

Text
"Device fingerprinting". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/device-fingerprinting/
HTML
`<a href="https://ordergroup.co/glossary/device-fingerprinting/">Device fingerprinting</a> - Order Group`

Reviewed by [Mateusz Widenka](https://ordergroup.co/authors/mateusz-widenka/), Head of Delivery
Last reviewed 10 October 2026

## How device fingerprinting works

A device fingerprint is built from technical attributes of a phone or a browser: operating system and its version, device model, screen, language, time zone, network details and signals such as a rooted phone or an emulator. Each attribute alone says little. Together they let a service recognize the same device on a later visit, even when the user is not logged in and has cleared cookies.

The same technique serves two very different purposes. Advertising uses it to follow people across sites and apps. Fraud prevention uses it to answer narrower questions at a sensitive moment: has this device been used with other identities, is it an emulator, has the account just moved to a device never seen before. This entry is about the second use.

In an app the flow usually looks like this. A small SDK from a fraud prevention service collects the attributes when the user performs a sensitive action and sends them to the service together with a session identifier. The app passes the same identifier to the lender's backend with the business event, such as a login or a loan application. The backend asks the fraud service for the result for that session and feeds it into the decision.

## What device fingerprinting means for your software

Choose the collection points. They are the moments a fraudster wants to control: logging in (credential stuffing and account takeover), registration (fake accounts), changes to contact details such as the phone number or e-mail address (a fraudster who takes over an account changes them first so the owner stops getting alerts), changes to the bank account, and the loan application before payout.

Each action needs its own session identifier, so that every result is tied to one event. An identifier reused across actions mixes a login with an application and makes the result hard to explain later.

Collecting and sending the attributes can take up to one or two seconds, which the user notices. Start collection in the background when the user opens the screen, or show a loading state on the action button, so the check does not look like a frozen app.

Decide what happens when the check fails. The SDK can time out and the service can be down. Write down whether the application continues to manual review or waits, and test that branch.

Keep a person in the loop for rejections. Under Article 22 of the GDPR a person has the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, and recital 71 gives the automatic refusal of an online credit application as an example. A high device risk score should usually send an application to review, not reject it outright, unless the lender has a legal basis for an automated decision and the safeguards that come with it.

Keep the data for its purpose. Store the device result with the event it belongs to, set a retention period, and keep it out of analytics and marketing.

Writing the specification?

Add Device fingerprinting to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

Device fingerprinting duties in a lending app
AreaSourceWhat the system needs

Legal basis for fraud preventionGDPR Art. 6(1)(f), recital 47Purpose and basis in the privacy policy; balancing test on fileReading information from the deviceePrivacy Art. 5(3); EDPB Guidelines 2/2023Documented assessment of consent or the strict necessity exemptionRight to objectGDPR Art. 21Process for objections to processing based on legitimate interestAutomated decisionsGDPR Art. 22, recital 71Manual review path for high-risk resultsFraud monitoring by payment service providersRTS 2018/389 Art. 2Device result available to transaction monitoring where the lender also handles paymentsLink between result and eventImplementationNew session identifier per action, passed with the event to the backendSDK or service failureImplementationTimeout, fallback rule and a tested failure branch

## Rules and regulation

Recital 47 of the GDPR states that "the processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned". The legal basis is then Article 6(1)(f), which requires a balancing test against the interests and rights of the person, and gives the person the right to object under Article 21.

Article 5(3) of the ePrivacy Directive adds its own requirement: storing or reading information on the user's device needs consent, unless it is strictly necessary for a service the user explicitly requested. The EDPB confirms in Guidelines 2/2023 that fingerprinting falls within it and that code instructing the device to send information counts as gaining access, as described under [consent management](https://ordergroup.co/glossary/consent-management/). In Poland the rule sits in Article 399 of the Electronic Communications Law. Whether a fraud check at a given moment is strictly necessary for the service the customer asked for, or needs consent, is a legal assessment to make and document before release.

Payment service providers have their own reason to look at devices. Article 2 of the RTS on strong customer authentication (Delegated Regulation 2018/389) requires transaction monitoring mechanisms that detect unauthorized or fraudulent payments.

## From our projects

In the app we have built for AvaFin Poland since January 2026, device fingerprinting is part of the security workstream. The app checks the device with a fraud prevention service on the first loan application. We finished integrating the service in September 2026; in October 2026 it was still in testing. The integration notes in the project recommended collecting device data at login, at registration and before sensitive account changes such as a new phone number or e-mail address, generating a new identifier for each call, and starting collection early because it can take up to one or two seconds. They also noted that the privacy policy has to name fraud prevention as the purpose and legitimate interest as the basis.

## Related terms

- [3-D Secure (3DS)](https://ordergroup.co/glossary/3d-secure/)

3-D Secure (3DS) is the card schemes' protocol for authenticating the cardholder in an online card payment. The merchant's side sends transaction and device data to the card issuer, which approves the payment without friction or asks the cardholder for strong customer authentication.
- [Consent management platform (CMP)](https://ordergroup.co/glossary/consent-management/)

A consent management platform (CMP) is software that asks users for consent, records each decision per purpose, and tells the app or website which tools may run. In the EU it implements the consent rules of the GDPR and of Article 5(3) of the ePrivacy Directive.
- [PESEL restriction](https://ordergroup.co/glossary/pesel-restriction/)

A PESEL restriction is a flag a Polish adult can set on their national identification number (PESEL) in a state register. Since June 1, 2024 a lender must check it before concluding a consumer credit agreement and before an amendment that increases the debt.

## Sources

1. [Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 6(1)(f), 21 and 22, recitals 47 and 71](https://eur-lex.europa.eu/eli/reg/2016/679/oj) - EUR-Lex
2. [Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive), Article 5(3)](https://eur-lex.europa.eu/eli/dir/2002/58/oj) - EUR-Lex
3. [Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, version 2.0](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en) - European Data Protection Board
4. [Commission Delegated Regulation (EU) 2018/389, RTS on strong customer authentication and common and secure communication, Article 2](https://eur-lex.europa.eu/eli/reg_del/2018/389/oj) - EUR-Lex

Mateusz Widenka reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Mateusz Widenka](https://ordergroup.co/media/images/T02DHCC1Z-U039G6G3JS1-8e7d2cd80ccb-512.format-webp.webp)

Mateusz Widenka

Head of Delivery

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Is device fingerprinting legal in the EU?

It can be. Fraud prevention can be a legitimate interest under the GDPR (recital 47), but reading information from the device also falls under Article 5(3) of the ePrivacy Directive. Ask your lawyer to assess whether consent is needed at each collection point, and document the result.

### Is a device fingerprint personal data?

Often yes, because it is used to single out a device and the person using it. Article 5(3) of the ePrivacy Directive applies either way, since it covers any information on the device, personal or not.

### Where in a loan app should device data be collected?

At the moments a fraudster wants to control: login, registration, changes to contact details or the bank account, and the loan application before payout.

### Can a lender reject an application automatically on a device risk score?

A decision based solely on automated processing with significant effects falls under Article 22 of the GDPR, and recital 71 names the automatic refusal of an online credit application as an example. Route high-risk results to manual review unless the lender has a legal basis and safeguards for automated decisions.

Building a system that depends on Device fingerprinting?

See how we build software for this domain, with case studies and the stack we use.

[See Fintech Software Development Services](https://ordergroup.co/fintech-software-development/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
