US and European Banks Sharing Loan Details and Customer Data With Third Parties Without Valid Consent

RegulationIndustry
โดย PR Newswire·Read original
Summary · why it matters

New research from Jscrambler reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms without valid consent. The analysis of 14 financial institutions across Europe and the US found that tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce. Examples include a Spanish bank's mortgage process sending a customer's hashed email and phone number to TikTok's pixel endpoint, a Portuguese bank's account-opening flow sending email, name, age, and national tax number to Salesforce, and two other Portuguese institutions sharing full loan simulation details including a €27,000 loan with repayment terms to Google Analytics. The research also documented consent failures such as tags firing before cookie banner action, tags continuing after users rejected all, and consent choices not carrying into iframes or subdomains. Jscrambler recommends continuous runtime monitoring, enforcement controls to block unauthorized data exfiltration, and consent enforcement that extends across iframes and subdomains.

Impact on stocks 5

Artificial Intelligence · 3 stocks
Adobe Systems Incorporated
ADBE
▼ NegativeRegulationrelevance

Adobe is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.

Salesforce.com Inc
CRM
▼ NegativeRegulationrelevance

Salesforce is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.

Alphabet Inc Class C
GOOG
▼ NegativeRegulationrelevance

Google (Alphabet) is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.

Spatial Computing / AR/VR · 1 stocks
Meta Platforms Inc.
META
▼ NegativeRegulationrelevance

Meta is named as a third party receiving sensitive data without valid consent, potentially facing regulatory or reputational consequences.

Communication Services · 1 stocks
Pinterest Inc
PINS
▼ NegativeRegulationrelevance

Pinterest is named as a third party receiving sensitive data without valid consent, which could lead to regulatory scrutiny or reputational damage.

Theme Impact 3

Off-coverage companies 3

ByteDancePrivate▼ Negative
Regulationrelevance

Article highlights that banking websites send data to TikTok's pixel without valid consent, potentially leading to regulatory scrutiny or restrictions on data collection practices.

LinkedIn CorporationPrivate▼ Negative
Regulationrelevance

Article mentions LinkedIn as one of the third parties receiving sensitive customer data without valid consent, which could result in regulatory action or reputational damage.

JscramblerPrivate± Mixed
relevance

Related news

Commvault Enables FedRAMP High Cloud for Federal Agencies

Commvault Systems has enabled its managed service provider partners to deliver FedRAMP High Authorized Commvault Cloud for Government services to U.S. federal agencies and defense contractors, broadening the company's public sector reach. The move lands on a stock with a 7 day share price return of 10.29% and a 90 day share price gain of 11.67%, though its 1 year total shareholder return is down 23.35% while the 3 year total shareholder return is up 111.68%. The most followed valuation narrative puts fair value at $161.15 against a last close of $145.21, implying roughly 10% upside, and rests on analyst expectations of about 10.6% annual revenue growth, profit margins rising toward 9.8%, and an 8.85% discount rate. That story leans on recurring SaaS economics, including 63% SaaS ARR growth, a 45% increase in multi-product customers, and 125% SaaS net dollar retention. A contrasting read notes the stock trades at a P/E of 88.1x versus 30.5x for the wider US Software group and a fair ratio of 38.7x, signaling valuation risk if sentiment cools.
Simply Wall St·1dRead more →

Varonis Systems Launches Data Lifecycle Management Capability

Varonis Systems, Inc. launched Varonis Data Lifecycle Management, a new capability that automatically identifies and remediates redundant, obsolete, and trivial data across enterprise environments using its existing Data Security Platform. The launch ties data cleanup directly to sensitivity, access, and activity context, aiming to reduce storage waste, improve AI output quality, and help organizations address compliance exposures from scattered sensitive information. The DLM tool stacks on top of Varonis Atlas, the AI security platform that went generally available in March 2026, which targets discovery, posture management, and runtime protection for AI workloads. Together, Atlas and DLM broaden Varonis' role from guarding unstructured data to governing how that data is stored, used, cleaned up, and exposed across Snowflake, Claude, Cursor, and other cloud and AI partnerships. Varonis Systems' narrative projects $1.1 billion revenue and $120.7 million earnings by 2029, yielding a $50.68 fair value, an 8% upside to its current price, while the most pessimistic analysts were already modeling about US$1.0 billion of 2029 revenue.
Simply Wall St·1dRead more →

Hackers threaten to leak Revolut customer data, demand $3 million ransom in Monero

Hackers have threatened Revolut with a ransom demand, seeking $3 million in Monero within 24 hours or they will expose the company's customer data. The hackers claim to be behind a cyberattack that leaked KYC and personal data of Revolut customers. The incident represents a significant security risk for the crypto company and its users, who must remain vigilant about the leakage of their personal data.
efin.finance·2dRead more →