European Financial Institutions Leak Sensitive Data Via Cookie Trackers
Research reveals European financial institutions are inadvertently exposing customer data, including financial details, to third-party ad platforms through improperly configured cookie trackers.

A recent study by Jscrambler has uncovered a pervasive issue where European financial institutions are leaking sensitive customer data to third-party advertising, analytics, and personalization platforms. This data leakage occurs through the use of tracking pixels and cookie trackers embedded within their websites, often without the explicit knowledge or consent of the customers, and sometimes even after users have opted out of tracking.
The research highlights a disturbing pattern where tracking technologies are activated even before a user makes a consent choice, or continue to operate after a user has rejected all non-essential cookies. Across 14 documented cases involving financial services, nine institutions exhibited tracking that fired without valid consent. The data, which can include personally identifiable information (PII) and sensitive financial details, is then transmitted to a dozen or more third parties, including major players like Google, Meta, TikTok, LinkedIn, Salesforce, and Adobe.
Compounding the issue, this data exposure is not limited to basic informational pages. Jscrambler's findings indicate that tracking pixels are inadvertently sending customer data from high-risk pages, such as loan applications and account opening forms, which contain the most sensitive personal and financial information. In several instances, this data was transmitted in encoded or hashed formats rather than being fully encrypted, meaning it could potentially be de-anonymized and linked back to specific individuals under certain circumstances.
One particularly concerning example involved a Spanish bank where, after a user accepted cookies during a mortgage application process, TikTok received the user's hashed email and phone number. Notably, TikTok was not listed as a vendor in the bank's privacy or cookie policies, leaving customers unaware of this data sharing. In another case with a Portuguese bank, personal data like email addresses, names, ages, and tax numbers were sent unhashed to platforms like Salesforce Interaction Studio during the account opening process.
The implications of this data leakage are significant, particularly concerning compliance with stringent privacy regulations like the General Data Protection Regulation (GDPR) and the Digital Operational Resilience Act (DORA) in Europe. These regulations mandate robust data protection and require financial entities to ensure their technologies and suppliers do not introduce undue risk.
While platforms like TikTok and Meta often place the responsibility on website operators, Jscrambler argues that default platform settings, such as automatic advanced matching features, play a crucial role. These default configurations can enable the collection and hashing of contact details without explicit action from the site owner, making it difficult for banks to claim they did not intentionally enable such data sharing.
The research underscores a shared responsibility across all parties involved in the data collection and transmission chain. Financial institutions must implement more rigorous oversight of their website's tracking technologies, ensuring that data sharing practices align with privacy policies and regulatory requirements. Users, meanwhile, are often left with limited visibility into how their sensitive information is being handled, even when attempting to exercise their privacy rights.
This widespread data exposure through seemingly innocuous cookie trackers highlights a critical gap in how financial institutions manage third-party data sharing. It necessitates a re-evaluation of website security practices, vendor management, and the default configurations of tracking technologies to safeguard customer privacy and maintain regulatory compliance.