Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
New research from Jscrambler reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms. The analysis of 14 financial institutions across Europe and the US found that tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce. Incidents included a Spanish bank's mortgage process sending a customer's hashed email and phone number to TikTok's pixel endpoint without disclosure, a Portuguese bank's account-opening flow transmitting a customer's email, name, age, and national tax number to Salesforce without consent, and two other Portuguese institutions sharing full loan simulation details with Google Analytics. The research also documented consent failures where tags fired before a cookie banner was actioned, continued after users rejected all tracking, or were not carried into iframes and subdomains handling the same transaction. Jscrambler recommends continuous runtime monitoring and enforcement controls to block unauthorized data exfiltration and verify that rejected consent actually stops data collection.
Adobe Systems IncorporatedAdobe is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Salesforce.com IncSalesforce is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Alphabet Inc Class CGoogle Analytics is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Meta Platforms Inc.Meta (TikTok pixel) is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Pinterest IncPinterest is named as a third party receiving sensitive customer data without valid consent, which could lead to regulatory scrutiny or reputational damage.
Article reports that banking websites send customer data to TikTok's pixel without consent, potentially leading to regulatory scrutiny or restrictions on ByteDance's data collection practices.
Article reports that banking websites transmit customer data to LinkedIn without valid consent, which could lead to regulatory action or reputational damage for LinkedIn.