Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
New research from Jscrambler reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms without valid consent. The analysis of 14 financial institutions across Europe and the US found that tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce. Examples include a Spanish bank's mortgage process sending a customer's hashed email and phone number to TikTok's pixel endpoint, a Portuguese bank's account-opening flow sending email, name, age, and national tax number to Salesforce, and two other Portuguese institutions sharing full loan simulation details including a €27,000 loan with repayment terms to Google Analytics. The research also documented consent failures such as tags firing before cookie banner action, tags continuing after users rejected all, and consent choices not carrying into iframes or subdomains. Jscrambler recommends continuous runtime monitoring, enforcement controls to block unauthorized data exfiltration, and consent enforcement that extends across iframes and subdomains.
Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Salesforce.com IncSalesforce is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
Alphabet Inc Class CGoogle (Alphabet) is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Meta Platforms Inc.Meta is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.
Pinterest IncPinterest is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Article highlights that banking websites send data to TikTok's pixel without valid consent, potentially leading to regulatory scrutiny or restrictions on data collection practices.
Article mentions LinkedIn as one of the third parties receiving sensitive customer data without valid consent, which could result in regulatory action or reputational damage.