You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager

Publication date

2025-08-26

Authors

Mertens, Gilles
Bielova, Nataliia
Roca, Vincent
Teixeira Santos, CristianaISNI 0000000514348654

Editors

Advisors

Supervisors

Document Type

Part of book
Open Access logo

License

taverne

Abstract

Tag Management Systems (TMS) were developed in order to support website Publishers in installing multiple third-party JavaScript scripts (Tags) on their websites. Google has proposed its own TMS called "Google Tag Manager"(GTM) that is currently present on 52% of the top 1 million most popular websites. However, GTM has not yet been thoroughly evaluated by the academic research community. In this work, we study, for the first time, the Tags provided within the GTM system. Our methodology consists in installing Tags in isolation to analyze the types of data that Tags collect and contrast them to the legal and technical documentation, in collaboration with a legal expert. Across three studies - in-depth analysis of 6 Tags, automated analysis of 718 Tags, and analysis of Google "Consent Mode"- we discover multiple hidden data leaks, incomplete and diverging declarations, undisclosed third- parties and cookies, personal data sharing without consent and we further identify potential legal violations within EU Data Protection law.

Keywords

consent, GDPR compliance, Google Tag Manager, GTM, online tracking, privacy, website Publishers, Taverne, Computer Networks and Communications, Information Systems and Management, Safety, Risk, Reliability and Quality

Citation

Mertens, G, Bielova, N, Roca, V & Santos, C 2025, You Can't Trust Your Tag Neither : Privacy Leaks and Potential Legal Violations within the Google Tag Manager. in Proceedings - IEEE 10th European Symposium on Security and Privacy, Euro S and P 2025. Proceedings - IEEE 10th European Symposium on Security and Privacy, Euro S and P 2025, IEEE, pp. 93-112, 10th IEEE European Symposium on Security and Privacy, Euro S and P 2025, Venice, Italy, 30/06/25. https://doi.org/10.1109/EuroSP63326.2025.00015, conference