EU and US Banks Found Leaking Customer Data via Advertising Trackers

Tracking pixels embedded in banking websites have been quietly transmitting customer data to advertising platforms, exposing financial institutions to significant compliance and privacy risk.

AI-generated illustration depicting policy for the story: EU and US Banks Found Leaking Customer Data via Advertising Trackers

Tracking pixels embedded in banking websites have been quietly transmitting customer data to advertising platforms, exposing financial institutions to significant compliance and privacy risk.

Summary

  • European and US financial institutions inadvertently sent customer data to advertising platforms through embedded tracking pixels and cookie trackers.
  • The data transmissions raise serious concerns under GDPR and other financial privacy regulations.
  • Banks appear largely unaware of the extent to which third-party ad technology embedded in their web properties collects and forwards customer information.
  • The exposure sits at the intersection of marketing technology decisions and security governance — a gap many institutions have not adequately closed.
  • Security and compliance teams need visibility into what tracking technologies are active on customer-facing digital properties.

The problem hiding in plain sight

A pattern has emerged among European and US financial institutions: customer data is leaving their environments not through breaches or intrusions, but through the advertising and analytics technology embedded in their own websites. Tracking pixels — small pieces of code typically deployed by marketing teams to measure campaign performance — have been transmitting customer information to third-party advertising platforms without adequate controls or, in many cases, apparent awareness from security and compliance functions.

What is being transmitted

According to the source reporting, the data flowing out through these trackers includes information that financial institutions are obligated to protect under both privacy law and sector-specific regulation. The precise data fields involved vary, but the concern is that behavioural data, and potentially more sensitive customer details, are reaching ad platforms whose data handling practices are outside the bank’s direct control. The institutions involved span both European jurisdictions — where GDPR sets a high bar for lawful data processing — and the United States, where financial privacy rules under frameworks such as the Gramm-Leach-Bliley Act apply.

A compliance exposure with multiple dimensions

For a CISO operating in or with exposure to European markets, the GDPR angle is the most immediate pressure point. Transferring customer personal data to a third party — including an advertising platform — requires a lawful basis, and in many cases that basis will be absent or inadequately documented for tracker-driven transmissions. Regulators have already demonstrated willingness to pursue enforcement actions against organisations that rely on tracking technology without proper consent mechanisms. Financial institutions carry an additional layer of exposure because their customers reasonably expect a higher standard of data stewardship than they might from a retail website.

The governance gap between marketing and security

What makes this issue structurally difficult is where it originates. Tracking pixels are typically deployed by marketing or digital teams, often through tag management systems that allow new scripts to be added quickly and with limited security review. The result is that customer-facing web properties can accumulate a significant inventory of third-party code over time — code that security teams may not have catalogued, assessed, or approved. This is not a novel problem, but its presence in regulated financial institutions suggests that tag governance processes are not keeping pace with the speed at which marketing technology is deployed.

Third-party risk at the browser layer

This situation is a useful reminder that third-party risk extends beyond vendors with whom an institution has a formal contract. A tracking pixel from an advertising network represents a data flow that may carry real customer information to an entity that is not subject to the same contractual obligations as a managed service provider. The browser, in this context, becomes a data exfiltration vector — one that is difficult to monitor using traditional security tooling focused on network perimeter or endpoint activity.

Corroboration is limited

It should be noted that the reporting on this issue comes from a single source, Dark Reading, and no corroborating coverage was available at the time of writing. The specific institutions named, the volume of data involved, and the precise nature of what was transmitted are not independently verified through this briefing. CISOs should treat this as a signal to audit their own environments rather than as a fully characterised incident with confirmed details.

Why it matters

For CISOs in financial services, this issue sits uncomfortably across three domains at once: data privacy compliance, third-party risk management, and security governance of customer-facing applications. The risk is not hypothetical — regulators in both the EU and US have appetite for enforcement where customer data is mishandled, and ‘the marketing team added it’ is not a defensible position. The reputational dimension is also real: customers who bank online do not expect their financial behaviour to inform advertising profiles. If your institution does not have a current, complete inventory of what tracking technology is active on your web properties, and how data flowing through those tools is governed, that gap needs to close.

What to do now

  • Conduct an audit of all tracking pixels, cookies, and third-party scripts active on customer-facing web properties, including those deployed via tag management systems.
  • Assess whether existing consent mechanisms and privacy notices accurately reflect the data flows generated by advertising and analytics trackers.
  • Establish or reinforce a governance process requiring security and privacy review before any new third-party tracking technology is deployed on customer-facing platforms.
  • Review data processing agreements — or their absence — with advertising and analytics platforms that receive data from your web properties.
  • Engage your legal and compliance function to evaluate whether current tracker deployments satisfy the lawful basis requirements under applicable privacy regulation, including GDPR where relevant.

Sources