Financial institutions in Europe and the US are inadvertently exposing sensitive customer information to third-party advertising, analytics, and personalization platforms via cookie tracking technology. This alarming trend raises serious concerns about compliance, security, and data privacy.
Jscrambler’s latest research has shed light on this pattern of behavior among financial services companies. The study found that 14 institutions, including some of the largest banks in Europe and the US, were transmitting customer data to around a dozen third-party platforms, including Google, Meta, TikTok, LinkedIn, and Salesforce. This data was often sent without users’ consent or even after they had rejected tracking technologies.
The research highlights how financial institution websites are firing tracking pixels that collect sensitive information from customers. In some cases, this information is transmitted as deterministic hashes or encoded rather than encrypted, making it potentially linkable back to specific individuals. For instance, a Spanish bank was found to be transmitting hashed email and phone numbers to TikTok through an embedded iframe on its mortgage application page. What’s more, the bank’s cookie policy and privacy policy did not mention TikTok as a vendor, leaving customers unaware of this data transfer.
This study is part of a broader trend that has seen social media platforms like TikTok and Meta use tracking pixels to follow users even after they click over to advertiser sites. The research suggests that financial institutions may be unwittingly contributing to this problem by activating tracking pixels on their own websites, including pages containing sensitive customer data such as loan applications.
The findings have significant implications for the financial services industry. Not only do these practices raise serious compliance and security concerns but also expose customers’ sensitive information to unregulated third-party platforms. As Jscrambler’s research notes, most institutions are unlikely to realize how much of this is happening by default, highlighting the need for greater transparency and accountability.
To mitigate this risk, financial institutions must take immediate action to review their cookie tracking policies and ensure that they are not inadvertently exposing customer data to third-party platforms. This includes conducting thorough audits of their websites and implementing robust consent mechanisms to inform customers about data collection and transfer practices. By taking proactive steps to address these issues, financial institutions can better protect their customers’ sensitive information and maintain trust in the digital economy.
Ultimately, this research underscores the need for greater awareness and understanding among consumers about how their personal data is being used online. As we navigate the complex landscape of digital tracking and advertising, it’s essential that companies prioritize transparency and accountability to ensure the protection of customer data.
Source: Dark Reading — 2026-07-22