Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Jscramblerの新たな調査によると、銀行のウェブサイトが、ハッシュ化された識別子、融資詳細、金融意向シグナルなどの機密性の高い顧客情報を、有効な同意なしに第三者広告、分析、パーソナライゼーションプラットフォームに送信していることが明らかになった。欧州と米国の14の金融機関を分析したところ、9つのサイトで有効なユーザー同意なしに追跡技術が作動し、Google、Meta、TikTok、LinkedIn、Pinterest、Adobe、Salesforceを含む少なくとも12の第三者にデータが送信されていた。具体例として、スペインの銀行の住宅ローン手続きで、顧客のハッシュ化されたメールアドレスと電話番号がTikTokのピクセルエンドポイントに送信されたケース、ポルトガルの銀行の口座開設フローで、メールアドレス、氏名、年齢、納税者番号がSalesforceに送信されたケース、さらにポルトガルの別の2つの金融機関では、2万7000ユーロの融資と返済条件を含む完全な融資シミュレーション詳細がGoogle Analyticsと共有されていた。また、調査では、クッキーバナー操作前にタグが発火する、ユーザーが全て拒否した後もタグが継続する、同意選択がiframeやサブドメインに引き継がれないといった同意の不備も記録された。Jscramblerは、継続的なランタイム監視、不正なデータ流出をブロックする制御の実施、iframeやサブドメイン全体に及ぶ同意の強制を推奨している。
Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Salesforce.com IncSalesforce is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
Alphabet Inc Class CGoogle (Alphabet) is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Meta Platforms Inc.Meta is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
Pinterest IncPinterest is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Article highlights that banking websites send data to TikTok's pixel without valid consent, potentially leading to regulatory scrutiny or restrictions on data collection practices.
Article mentions LinkedIn as one of the third parties receiving sensitive customer data without valid consent, which could result in regulatory action or reputational damage.