Clicking "Reject all" on a cookie banner feels like a decisive act of self-protection. New research from security firm Jscrambler suggests that decision often makes no practical difference. Analyzing 14 European financial institutions, the firm found nine cases where tracking technologies collected and transmitted customer data to advertising and analytics companies without a valid consent choice ever being made.
When Consent Becomes a Formality
The mechanics behind cookie banners are more fragile than most users assume. A banner is a piece of software that is supposed to instruct other scripts on the page to stay dormant until a visitor makes a choice. Jscrambler's findings show that tracking pixels from companies such as TikTok and Meta can begin firing before that instruction ever arrives. In practice, this means data can leave a visitor's browser in the fraction of a second before the consent system takes effect, or it can simply ignore the visitor's rejection altogether and keep transmitting information as they move between pages. buy vpn
This is not necessarily deliberate deception by the banks involved. Many of these tracking tools are built by advertising platforms with data collection enabled by default, and once embedded, they can quietly gather far more than a website operator intended. A standard pixel installed to measure ad performance can end up harvesting a person's email address, phone number, or financial details without anyone at the company realizing it.
Sensitive Data, Weak Safeguards
What makes these findings notable is where the tracking occurred. This wasn't happening on generic promotional pages but inside mortgage applications, loan calculators, and account-opening forms - precisely the moments when consumers are sharing their most sensitive financial and personal details. In one case cited by Jscrambler, a Spanish bank sent a customer's hashed email and phone number to TikTok during a mortgage application, despite TikTok not appearing anywhere in the bank's published list of tracking vendors. In another, a Portuguese bank transmitted a customer's name, age, and national tax identification number through Salesforce during account creation.
Hashing data, a common practice in these cases, does not mean it becomes anonymous. Hashed identifiers can often be matched back to a real person, particularly when combined with other identifying details a company already holds. Encoding, which some organizations use instead of genuine encryption, offers even less protection since it can be reversed without any special key.
Where Responsibility Actually Lies
Jscrambler frames this as a shared failure between website operators and the advertising platforms whose code they install. Banks may not configure their tracking tools to extract sensitive fields, but they remain responsible for auditing what those tools actually do once live on their pages. As Jscrambler's head of security research put it, this is fundamentally a third-party risk problem: code the organization neither writes nor fully controls is running on its most sensitive pages, creating privacy exposure and a genuine security vulnerability at the same time.
For consumers, the practical lesson is not that every bank is secretly funneling financial data to advertisers, but that cookie banners cannot be trusted as a complete safeguard. Meaningful protection still requires layered habits.
- Use browser extensions or built-in features that block third-party trackers outright.
- Treat "Reject all" as a preference, not a guarantee, and pair it with privacy-focused browser settings.
- Clear cookies and site data regularly rather than relying on a single consent decision.
- Be cautious about entering sensitive financial details on any page, regardless of stated privacy policies.
Regulators have spent years pushing companies toward clearer consent mechanisms, yet this research suggests the gap between what a privacy policy promises and what code actually does remains wide. Closing it will require organizations to monitor their own websites as rigorously as they audit any other system handling sensitive customer information.