GLBA and Website Tracking on Financial Sites

Summary
The Gramm-Leach-Bliley Act (GLBA) limits how financial institutions share customers’ nonpublic personal information, and a tag that sends that information to a third party can fall within those limits. Federal courts, including the Eighth Circuit, have held that GLBA gives individuals no private right of action, so pixel lawsuits run under wiretap and consumer-protection laws.
GLBA is the 1999 federal law that governs how banks, lenders, insurers, investment firms, tax preparers, and many fintechs handle customer data. On a website, the question it raises is simple to state: are your analytics, advertising, session-replay, and chat tools sending customer financial information to companies outside your institution?
The sections below cover what GLBA requires of financial websites, what counts as nonpublic personal information, and why session replay and chat matter. Later sections cover whether customers can sue, what courts and regulators look for, and how to check what your tags send.
What does GLBA require of financial websites?
GLBA has two main rules that matter for tracking.
The Privacy Rule requires a financial institution to give customers a privacy notice and, before sharing their nonpublic personal information with an unaffiliated third party, an opportunity to opt out. The opt-out does not apply to service providers when the institution discloses the sharing and has a contract requiring the provider to keep the information confidential.
The Safeguards Rule requires an information security program that protects customer information. For institutions under FTC jurisdiction, it requires overseeing service providers by taking reasonable steps to select and retain providers capable of maintaining appropriate safeguards, requiring those safeguards by contract, and periodically assessing the providers.
GLBA is enforced by regulators, including the Consumer Financial Protection Bureau (CFPB), the federal banking agencies, the Securities and Exchange Commission (SEC), and the FTC, depending on the institution. State insurance regulators cover insurers.
What counts as nonpublic personal information on a website?
Nonpublic personal information, or NPI, is personally identifiable financial information about a consumer. Under Regulation P, it includes even the fact that someone is or has been your customer. It also includes information a consumer gives you to get a financial product and information from their transactions with you.

On a website, NPI can reach a tag in several ways. A loan or account application form can pass income, loan amounts, or account types. A logged-in page can reveal balances or products held. A page URL can carry an application status. And the simple fact that an identified person reached a logged-in account page can show they are a customer.
Can customers sue under GLBA?
No. Federal courts, including the Eighth Circuit in Dunmire v. Morgan Stanley DW (2007), have held that GLBA gives individuals no private right of action. Its privacy rules are enforced by regulators. That is why pixel lawsuits against financial institutions rely on other laws.
Wiretap laws. The federal Wiretap Act, part of the Electronic Communications Privacy Act (ECPA), prohibits intercepting communications, though it generally allows interception when one party consents, unless the interception is for the purpose of committing a criminal or tortious act. Plaintiffs argue that exception applies. State laws such as the California Invasion of Privacy Act (CIPA) require the consent of all parties, and CIPA lets a person injured sue for the greater of $5,000 per violation or three times actual damages.
State consumer-protection and contract claims. Plaintiffs also argue that sharing data with ad platforms broke the institution’s privacy promises or was an unfair practice.
Why session replay and chat matter on financial sites
Session replay and chat tools create a distinct exposure. Session-replay scripts record what a visitor does on a page, including what they type into forms. Chat widgets, often run by an outside vendor, carry the conversation itself. On a financial site those can include account numbers, income, and questions about a customer’s own finances.

Under CIPA, plaintiffs argue that a third-party vendor capturing those interactions without consent is wiretapping. That theory does not depend on GLBA. For the details, see CIPA and website tracking and Session replay and privacy.
What are courts and regulators looking for?
Courts want specific facts about what a tracker actually sent. In Stevens v. TD Bank, the U.S. District Court for the District of New Jersey dismissed the first complaint without prejudice in June 2025 because it described what the Meta Pixel could collect, not what it actually sent. On June 30, 2026, the court denied TD’s motion to dismiss the amended complaint on standing. That complaint alleges TD actually transmitted information identifying the plaintiff as a TD Bank customer, and the banking functions he performed, to Meta and Google. The court converted TD’s consent defense into a summary judgment question. The claims are negligence, breach of confidence, breach of contract, and New York consumer-protection law. No wiretap, CIPA, or GLBA claim was pleaded.
Regulators and plaintiffs who have that evidence do act on it. TaxAct, an online tax-preparation service, agreed to a $14.95 million class settlement over allegations that it shared users’ personal and financial information with third parties including Meta and Google. The settlement received final approval on December 30, 2024. Objectors appealed, and cash payments are on hold until the appeal is resolved. In August 2026, TaxAct also settled with the Connecticut Attorney General for $275,000. The Attorney General’s announcement said the settlement requires written policies for third-party tracking, documentation of the data points tracked, a tag monitoring system that scans the website regularly, and two independent audits.
Both point the same way. The strength of a claim, and of a defense, depends on a record of what each tag actually transmitted. For the cases themselves, see Enforcement Watch.
Does the CCPA apply to financial institutions?
In part. The California Consumer Privacy Act (CCPA) exempts personal information collected, processed, sold, or disclosed under GLBA (and the California Financial Information Privacy Act). The exemption applies to that data, not to the institution. Website browsing and advertising data that is not collected under GLBA can still fall under the CCPA and other state privacy laws, including their opt-out requirements. The CCPA’s private right of action for data breaches still applies. See CCPA and CPRA for tags.
How to check what your tags send
Every question on this page, for regulators and courts alike, comes down to facts about your tags: which ones run on which pages, what each one sends, and whether consent is honored before anything fires.
DataTrue tests your live site in a real browser and records what every tag sends. A Coverage test crawls the whole site and reports what is tagged on every page, including tags added outside your tag manager. A Simulation test walks a defined journey, such as a loan application or a login to online banking, in each consent state, and checks what fires at each step. Sensitive Data Detection inspects the payloads, including what session-replay and chat tools capture, for personal and financial data. Because the tests use fictitious personas, invented customers with fake account details, no real customer’s information is involved.
Tests run on a schedule, with alerts when something changes, such as a tag your policy doesn’t allow on the application flow after a release. The output is a timestamped record of which tags sent what, on which pages. That is the kind of evidence a tracking-governance program needs, and it is the evidence gap the TD Bank court pointed to.
What should financial institutions do?
- Keep advertising tags off application flows and logged-in pages, and confirm with testing that they stay off.
- Review session replay and chat for what they capture, mask sensitive fields, and get consent before they run.
- Put vendors under contract, including confidentiality and safeguards terms, and confirm the tags match the contract.
- Keep a record of what each tag transmits, checked on a schedule, so you can answer a regulator or a court with evidence.
- Treat non-GLBA website data under state privacy laws, including opt-outs and Global Privacy Control.
Questions
Does GLBA apply to website tracking pixels?
It can. GLBA limits how financial institutions share customers’ nonpublic personal information with unaffiliated third parties. A pixel that sends application details, account information, or the fact that someone is a customer to an ad platform can be that kind of sharing.
Can customers sue a bank under GLBA for using tracking pixels?
No. Federal courts, including the Eighth Circuit, have held that GLBA gives individuals no private right of action. Regulators enforce it. Pixel lawsuits against financial institutions are brought under wiretap laws, such as the federal Wiretap Act and the California Invasion of Privacy Act, and under state consumer-protection and contract law.
What happened in the TD Bank pixel lawsuit?
In Stevens v. TD Bank (D.N.J.), the court dismissed the first complaint without prejudice in June 2025 because it described what the Meta Pixel could collect, not what it actually sent. On June 30, 2026, the court denied TD’s motion to dismiss the amended complaint, which alleges what TD actually transmitted to Meta and Google, on standing, and converted TD’s consent defense into a summary judgment question.
Is a financial institution exempt from the CCPA?
Only in part. The CCPA exempts personal information collected under GLBA, not the institution itself. Other data, such as website browsing and advertising data not collected under GLBA, can still fall under the CCPA.
Do session replay and chat tools create risk on financial sites?
Yes. They can capture what customers type, including financial details, and send it to an outside vendor. Plaintiffs argue under the California Invasion of Privacy Act that this is wiretapping when it happens without consent.
Find personal data in your tags before an ad platform does
DataTrue fills your forms with test personas and reads each tag request for emails, names and card numbers. A leak shows up in a test, with the tag and the page that sent it.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
