All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Consumers are taught that clicking "Reject all" on a cookie banner protects their privacy. But new Jscrambler research suggests that isn't always what happens.[1]
The security firm analyzed financial institutions across Europe and found multiple cases where websites transmitted customer information to advertising and analytics companies such as Google, Meta, TikTok, LinkedIn and Salesforce — sometimes before visitors made any cookie choice, and in other cases even after they explicitly rejected tracking cookies.
"Tracking pixels were once just a small snippet of code on a webpage to confirm an ad impression or to log a visit," Jscrambler wrote. "What many website owners likely don't realize is that TikTok and Meta's pixels go far beyond traditional tracking tags, collecting user emails, phone numbers, and addresses and turning seemingly anonymous browsing data into persistent, identifiable user profiles."
While the findings focused on European banks, they raise broader questions about whether consumers can rely on cookie banners to accurately reflect what's happening behind the scenes.
Mortgage applications and account openings weren't off limits
Why this isn't just the banks' problem
What it means for you
Researchers found customer data flowing to major tech companies
Jscrambler analyzed 14 financial institutions and found tracking technologies activated without valid user consent at nine organizations.
According to the researchers, tracking sometimes began before users interacted with a cookie banner, restarted after they moved to another section of the same website, or continued despite visitors selecting "essential cookies only."
"Tracking fired without a valid consent choice at nine separate companies, whether before the banner was actioned, after the user rejected all cookies, or despite an essential-cookies-only selection," the researchers wrote.
The data was transmitted to roughly a dozen third parties.
Researchers also found that "both TikTok and Meta's pixel code can load and begin transmitting data before the website's consent management system has time to block it, meaning information can leave the browser before the user's choice is applied."
In several cases, customer information was either hashed or merely encoded instead of encrypted. Hashed or encoded information can still be linked back to an individual under the right circumstances.
Mortgage applications and account openings weren't off limits
The findings become more concerning because the tracking wasn't limited to generic marketing pages.
In one example, an unnamed Spanish bank transmitted a customer's hashed email address and phone number to TikTok after the customer accepted cookies while applying for a mortgage. According to Jscrambler, TikTok wasn't listed as a vendor in the bank's cookie or privacy policy.
Another Portuguese bank was found sending even more sensitive information through Salesforce tracking technology. According to Jscrambler, requests included a customer's email address, followed later by their name, age, Portuguese tax identification number, and a Salesforce contact identifier during the account-opening process.
Researchers also found a consumer lender transmitting loan application details to Google Analytics through a URL containing encoded financial information, including the requested loan amount, repayment term, and insurance selection.
As Jscrambler noted, the problem is that tracking technologies originally designed for advertising are now embedded on pages handling highly sensitive financial information.
"Tracking pixels and personalization tags were once simple tools for confirming an ad impression or counting a visit. On a banking website, the same tags now sit alongside mortgage calculators, account-opening forms, and loan applications...They collect contact details, hash them, attach them to persistent identifiers, and transmit product and financial intent to platforms the bank does not control. Most institutions are unlikely to realize how much of this is happening by default."
Why this isn't just the banks' problem
The issue isn't as straightforward as banks intentionally handing customer information to advertisers.
Jscrambler argues many advertising platforms enable features such as automatic data matching by default, meaning organizations may unknowingly transmit more information than they intended after installing standard tracking code.
"A bank that drops in a standard pixel does not intentionally configure it to send a customer's hashed email and phone number from a mortgage page," the researchers wrote.
Instead, the firm says responsibility is shared between website operators and the companies providing the tracking technologies.
Gareth Bowker, head of security research at Jscrambler, told Dark Reading the problem crosses multiple disciplines: "At its root, it's a third-party risk problem: code the organization does not write or fully control is executing on its most sensitive pages."
Bowker added that it quickly becomes a privacy issue when personal information is transmitted without meaningful consent and a security issue because sensitive information can end up in third-party systems.
What it means for you
This research doesn't mean every bank is secretly sharing your financial information with advertisers. It does, however, serve as a reminder that clicking "Reject all" on a cookie banner doesn't necessarily guarantee that your privacy preferences are being enforced exactly as you expect.
Modern websites often rely on dozens of third-party scripts for advertising, analytics, personalization, and customer support. Jscrambler says many organizations understand that tracking pixels measure conversions but may not realize how much additional customer information those tools can collect automatically through default settings and third-party integrations.
If privacy is a priority, security experts generally recommend:
- Using an ad blocker that stops third-party trackers.
- Rejecting non-essential cookies whenever possible.
- Using browsers with built-in tracking protection.
- Regularly clearing cookies and site data.
Jscrambler also says organizations should continuously monitor how tracking pixels behave after they're installed rather than assuming default settings align with their privacy policies.
"It is the responsibility of every organization to ensure that the tracking pixels it implements on its website are configured correctly to close the gap between what it is permitted to do and what it is actually doing."
The research underscores a broader question for internet users. Are cookie banners giving people meaningful control over their personal data, or simply the appearance of it?
[1] Beyond Analytics: The Silent Collection of Commercial Intelligence by TikTok and Meta Ad Pixels