Beyond the vault: Who's responsible for what banking sites share?
Banks spend heavily to convince customers they are the most careful custodians of personal and financial data.
Our review of 14 financial-services websites across Europe and the US found otherwise: tracking and personalization scripts embedded in account-opening, mortgage, and loan-application flows sent contact details, financial intent, and device fingerprints to third parties, with 9 of the 14 sites doing so without a valid consent choice in place.
Head of Security Research at Jscrambler.
The failures fall into three patterns, and the distinction between them matters legally.
First, tags fired before the cookie banner had been answered at all, on wealth-management, investment-banking, and payment-provider sites; under the EU's ePrivacy Directive, that behavior never had a lawful basis, since consent is required before anything is stored on or read from a device.
Second, tracking continued after a user actively rejected cookies: at one site, GoogleAds and DoubleClick still received the...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE