You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager

  • Gilles Mertens*
  • , Nataliia Bielova
  • , Vincent Roca
  • , Cristiana Santos
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

Abstract

Tag Management Systems (TMS) were developed in order to support website Publishers in installing multiple third-party JavaScript scripts (Tags) on their websites. Google has proposed its own TMS called "Google Tag Manager"(GTM) that is currently present on 52% of the top 1 million most popular websites. However, GTM has not yet been thoroughly evaluated by the academic research community. In this work, we study, for the first time, the Tags provided within the GTM system. Our methodology consists in installing Tags in isolation to analyze the types of data that Tags collect and contrast them to the legal and technical documentation, in collaboration with a legal expert. Across three studies - in-depth analysis of 6 Tags, automated analysis of 718 Tags, and analysis of Google "Consent Mode"- we discover multiple hidden data leaks, incomplete and diverging declarations, undisclosed third- parties and cookies, personal data sharing without consent and we further identify potential legal violations within EU Data Protection law.

Original languageEnglish
Title of host publicationProceedings - IEEE 10th European Symposium on Security and Privacy, Euro S and P 2025
PublisherIEEE
Pages93-112
Number of pages20
ISBN (Electronic)9798331594930
DOIs
Publication statusPublished - 26 Aug 2025
Event10th IEEE European Symposium on Security and Privacy, Euro S and P 2025 - Venice, Italy
Duration: 30 Jun 20254 Jul 2025

Publication series

NameProceedings - IEEE 10th European Symposium on Security and Privacy, Euro S and P 2025

Conference

Conference10th IEEE European Symposium on Security and Privacy, Euro S and P 2025
Country/TerritoryItaly
CityVenice
Period30/06/254/07/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • consent
  • GDPR compliance
  • Google Tag Manager
  • GTM
  • online tracking
  • privacy
  • website Publishers

Fingerprint

Dive into the research topics of 'You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager'. Together they form a unique fingerprint.

Cite this