The bottom line: European banks inadvertently transmitted customer data to ad platforms via tracking pixels—a violation of GDPR and regulatory requirements.
European financial institutions routed customer data to advertising platforms through tracking pixels. This violates data protection and compliance requirements and reveals weaknesses in the control of external scripts.
Financial institutions in the European Union have transmitted customer data to advertising platforms through so-called tracking pixels. These tracking mechanisms were embedded in the banks’ websites and applications and functioned without explicit consent from the data subjects affected.
From a compliance and regulatory perspective, this presents several problems: The transmission of personal data to third parties violates the fundamental requirements of the General Data Protection Regulation (GDPR) and the NIS2 Directive, which obligate financial institutions as critical infrastructure to particularly strict standards. Unauthorized data flows to ad networks also jeopardize the trustworthiness of the institution and can lead to enforcement action by data protection authorities.
For CISOs, this means prioritizing measures to control external scripts, third-party dependencies, and data flows. Audits of all embedded tracking services, governance for third-party scripts, and mechanisms to validate data transmissions are necessary. Special considerations in the financial sector: Additional sector-specific regulations apply here, such as the requirements of the European Central Bank (ECB) and national financial supervisory authorities.
Source: www.darkreading.com · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.