Beyond the vault: Who's responsible for what banking sites share?
Nine of fourteen banks broke their own privacy promises: see which trackers customer data reached.
Banks invest substantial resources to convince customers they are the most diligent guardians of personal and financial data. However, a review of 14 financial services websites across Europe and the United States has revealed a different reality: analytics and personalization scripts embedded in account-opening, mortgage, and loan-application processes are transmitting contact details, financial intent, and device fingerprints to third parties, often without the explicit consent of the user. This issue manifests in three distinct patterns, each with significant legal implications.
Firstly, tracking tags are deployed before the cookie banner has been acknowledged, on websites related to wealth management, investment banking, and payment providers. Under the EU's ePrivacy Directive, such actions lack a valid legal basis, as consent is a prerequisite for storing or accessing data on a device.
Secondly, tracking persists even after the user has actively rejected cookies. For instance, at one website, both Google Ads and DoubleClick continued to receive the user's hashed email through the request URL, alongside a signal indicating consent denial. This suggests that the user's rejection was acknowledged but subsequently disregarded.
Thirdly, financial specifics are leaked regardless of the user's consent status. During a personal credit application at a Portuguese bank, details such as a loan amount of €2,500, a 12-month term, and an insurance selection were transmitted to Google Analytics. Additionally, at a Dutch banking site, a customer's name, age, and tax number were sent to Evergage in Base64-encoded text within the request URL during account opening.
In a separate case from the Netherlands, a first-party script combined browser fingerprinting with image requests to localhost on ports 7070 and 5938, effectively verifying whether remote-access software was installed on the visitor's device. This practice raises serious concerns about the security and privacy of users' devices.
The attribution of responsibility in these scenarios is often debated. Platforms like Meta and TikTok argue that they are merely conduits for data collection, citing their privacy controls and policies. They maintain that advertisers determine which events and parameters are sent, and that they only receive what their partners configure.
However, this perspective places the entire responsibility on website operators, which is not entirely accurate. Many of these tracking behaviors are enabled by default, such as Meta's Automatic Advanced Matching feature, which captures and hashes contact form data without additional configuration from the site owner.
Banks, too, bear some responsibility. They select the vendors to deploy, implement the consent banners, and publish cookie policies. Nevertheless, they often adopt default configurations without verifying their actual runtime behavior. This gap between intended and actual data collection practices necessitates a more proactive approach to verification and control.
To address these issues, a comprehensive solution is required. Compliance with regulations such as the EU's GDPR, ePrivacy Directive, and DORA's third-party risk rules, as well as the US's Gramm-Leach-Bliley Act and state laws like the CCPA/CPRA, is essential. Institutions must verify the runtime behavior of third-party scripts, particularly in high-value customer-facing flows, to ensure alignment with intended configurations.
Additionally, they need to monitor for "scope creep," where tags collect more data than originally set up.
Security teams must be equipped to control third-party scripts effectively, blocking unauthorized data transfers and preventing sensitive data from leaving the browser. For instance, consent should lead to a complete stop in data transmission, rather than merely logging a denied signal while the tracking call proceeds. Moreover, features like Meta's Automatic Advanced Matching, which hash and send contact data by default, should be deactivated unless their collection is explicitly documented, disclosed, and legally permissible.
It is crucial to treat scripts on sensitive pages as part of the institution's overall risk surface, subject to the same scrutiny as other vendor integrations. Banks should collaborate with their analytics and personalization vendors to ensure transparency and adherence to consent practices. By implementing these measures, banks can close the gap between what is permitted by consent and what actually occurs, thus mitigating regulatory and customer risks before they are identified.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.