9 of 14 banking sites leaked data without valid consent
An audit of 14 financial-services sites in Europe and the US found tracking scripts in account-opening and loan flows sent contact details, loan amounts and device fingerprints to third parties. On 9 of 14 sites this happened without a valid consent choice, including hashed emails reaching Google Ads after users rejected cookies.
- 9 of 14 sites sent data before cookie consent or after rejection
- A €2,500 loan amount and 12-month term reached Google Analytics
- A Portuguese bank sent name, age and tax number to Evergage in Base64
- A Dutch site probed local ports used by AnyDesk and TeamViewer
Read next
Policy