The suits keep coming
Financial-industry counsel report more than a thousand website-tracking suits under the California Invasion of Privacy Act filed in 2025 alone, with similar cases spreading to other states - Florida among the most active.
A runtime audit of your public website and marketing stack: every tag and pixel that fires, which third parties receive data, and how to keep measuring after the risky tags come out.
Built for financial-services marketing teams - and written to be reviewed alongside compliance and counsel.
Website-tracking litigation reached financial services and stayed. None of it requires a breach - the claim is that ordinary marketing tags sent visitor data to third parties without sufficient notice and consent.
Financial-industry counsel report more than a thousand website-tracking suits under the California Invasion of Privacy Act filed in 2025 alone, with similar cases spreading to other states - Florida among the most active.
Named defendants run from the largest banks - TD Bank, Barclays, Capital One - down to community credit unions with a modest online footprint. The pixel is the exposure, not the balance sheet.
Claims are built on state wiretap and eavesdropping statutes, the federal ECPA, and negligence theories that lean on the Gramm-Leach-Bliley Act and the FTC Act - so one tag can carry several causes of action at once.
Net effect: compliance teams rip out tags defensively, marketing goes blind, and nobody can say with confidence what the site still sends, to whom, and under what notice. The way out is not less measurement - it is measurement that is documented, governed, and first-party.
Every financial-services marketing team asks these. The honest answer is the same each time: it depends on your configuration - and the audit is how you find out what your configuration actually does.
It depends on which pages they load on, what parameters ride along, and what your notices actually cover. A pixel on a rates page and the same pixel on an application flow are different exposures.
It depends on what identifiers and page values travel with each request. That is a factual question before it is a legal one - and the facts are measurable.
It depends on what was torn out versus what was replaced. Defensive teardowns usually remove measurement and exposure together - the audit separates the two.
It depends on your stack, but usually yes: first-party collection and server-side pipelines can keep the numbers while cutting the data leaving your domain.
The engagement produces a single artifact: a documented record of what your public site and marketing stack actually do - written for marketing, readable by counsel, with no legal conclusions drawn.
Every script and pixel on public pages, catalogued by vendor, trigger, and page context - application flows flagged separately.
Where each request goes, and which identifiers, parameters, and page values travel with it - the factual core of every pixel claim.
What fires before a consent decision, what changes after, and which disclosures the observed behavior does or does not match.
Timestamped, reproducible records ranked by exposure - written so your privacy officer and outside counsel can act on them directly.
A first-party and server-side collection plan that keeps attribution alive after the risky tags come out.
Read-only runtime capture on public pages. No access to online banking, no account data, no customer information touched at any stage - and no legal conclusions: findings are facts, counsel draws the conclusions.
Multi-department sites where product, mortgage, and campaign teams each added tags nobody has reconciled.
Community-scale institutions are now named in the same suits as national banks - with a fraction of the review capacity.
Growth stacks built for speed - a dozen SDKs and pixels shipped before the first compliance hire.
High-value lead flows where a single form page carries both the best conversion data and the highest sensitivity.
The audit runs on your public pages only - read-only capture, no customer data, no disruption - and produces a findings document marketing, risk, and counsel can all work from.
Request an audit