Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Beyond the vault: Who's responsible for what banking sites share?

TechRadar ·
Beyond the vault: Who's responsible for what banking sites share?

Banks spend heavily to convince customers they are the most careful custodians of personal and financial data.

Our review of 14 financial-services websites across Europe and the US found otherwise: tracking and personalization scripts embedded in account-opening, mortgage, and loan-application flows sent contact details, financial intent, and device fingerprints to third parties, with 9 of the 14 sites doing so without a valid consent choice in place.

The failures fall into three patterns, and the distinction between them matters legally.

First, tags fired before the cookie banner had been answered at all, on wealth-management, investment-banking, and payment -provider sites; under the EU's ePrivacy Directive, that behavior never had a lawful basis, since consent is required before anything is stored on or read from a device.

Second, tracking continued after a user actively rejected cookies: at one site, Google Ads and DoubleClick still received the user's hashed email in the request URL alongside the consent-denied signal, meaning the rejection was recorded and then ignored.

Third, financial specifics leaked regardless of consent status: a loan amount of €2,500, a 12-month term, and an insurance selection reached Google Analytics during one personal credit application, and at a Portuguese bank, a customer's name, age, and tax number were sent to Evergage as Base64-encoded text in a request URL during account opening.

At a Dutch banking site, a first-party script combined browser fingerprinting with image requests to 127.0.0.1 on ports 7070 and 5938, the ports associated with AnyDesk and TeamViewer, effectively checking whether remote-access software was running on the visitor's own device.

Where the responsibility lies Meta and TikTok have each pointed to the website operator as the party in control of what gets collected, in response to earlier research on this topic.

Meta cited its privacy controls and its policy against sharing sensitive data.

TikTok said advertisers decide what events and parameters they send, and that it only receives what partners intentionally configure.

That framing puts the responsibility entirely on the website operator, and it only holds up if the collection was something the operator deliberately turned on.

Often it was not.

Meta's Automatic Advanced Matching feature is turned on by default on the Meta Pixel, and in that default state it captures and hashes contact-form data without any separate configuration step from the site owner.

A bank engineer adding a standard tracking snippet is not choosing to send a mortgage applicant's hashed email and phone number to Meta; the pixel does that by default.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›