In a troubling revelation uncovered by Jscrambler, it has been found that numerous banks across the United States and Europe are inadvertently (or perhaps deliberately) sending sensitive customer information—including hashed identifiers, loan details, and financial intents—to third-party platforms like Google, Meta, TikTok, LinkedIn, and Salesforce without obtaining valid consent. This alarming trend surfaces as more and more essential banking activities shift to digital platforms, escalating concerns about customer privacy and data security.
The investigation spanned 14 different financial institutions, including a mix of retail banks, investment banks, payment service providers, and consumer credit platforms. Astonishingly, the findings revealed that tracking technologies were activated before customers made explicit cookie consent decisions on nine out of those 14 bank websites. Of particular concern was the revelation that this data is sent even after users opt-out of tracking.
Key Findings
The Jscrambler report contains several striking highlights:
- - Across several banking websites analyzed, sensitive information—like hashed emails, phone numbers, and loan details—was transmitted to third parties before users had the chance to express their consent through cookie policies.
- - There were cases where, after cookie acceptance, a customer's sensitive details such as email and phone number were sent to tracking endpoints like TikTok's pixel.
- - One particular Portuguese bank's account-opening flow shared customer information—including name, age, and national tax ID—directly with Salesforce without any valid consent.
- - Instances were reported where financial intent signals, for example, detailed loan requests, flowed freely to Google Analytics, creating a troubling overlap between customer privacy and banking operations.
These practices create a precarious landscape, exposing sensitive customer interactions to risks beyond traditional application security controls.
Implications for Regulatory Compliance
The implications of these revelations are vast and significant, invoking serious compliance considerations under regulations such as GDPR and the ePrivacy Directive, both of which strongly emphasize prior consent before personal data is collected. Moreover, this data transmission behavior contradicts the expectations set forth by the EU's DORA framework governing third-party risk and various U.S. regulations like the Gramm-Leach-Bliley Act and California's CCPA.
Recommendations for Banks
In response to these critical vulnerabilities, Jscrambler suggests a comprehensive approach for financial institutions:
- - Transitioning from static tag audits to continuous runtime monitoring of interactions where personal data is involved.
- - Implementing stringent enforcement controls that prevent unauthorized data scraping from websites, especially in transaction-related flows.
- - Ensuring that consent rejection genuinely stops data tracking instead of just being logged as a denied signal.
- - Extending consent enforcement across iframes and subdomains to maintain privacy throughout the customer journey.
Conclusion
As financial services embrace digital transformations and personalization, the potential for sensitive data exposure intensifies. While banks have historically been trusted custodians of customer data, Jscrambler's findings underscore a disconnect between the perceived care for customer information and the troubling reality of data practices that fail to protect privacy. As the digital landscape continues to evolve, so too must the strategies employed to safeguard customer data against rampant third-party exposure. Financial institutions must now prioritize rigorous auditing practices to align their operational frameworks with the responsibilities mandated by existing regulations. To delve deeper into these findings, Jscrambler will also be hosting a comprehensive webinar on August 20, 2026, where experts will explore how these sensitive data exposures occur and what steps can be implemented to regain control over browser activity.