ResearchTrend.AI
  • Papers
  • Communities
  • Events
  • Blog
  • Pricing
Papers
Communities
Social Events
Terms and Conditions
Pricing
Parameter LabParameter LabTwitterGitHubLinkedInBlueskyYoutube

© 2025 ResearchTrend.AI, All rights reserved.

  1. Home
  2. Papers
  3. 2312.08806
21
0
v1v2v3v4v5 (latest)

Google Tag Manager: Hidden Data Leaks and its Potential Violations under EU Data Protection Law

14 December 2023
Gilles Mertens
Nataliia Bielova
Vincent Roca
Cristiana Santos
Michael Toth
ArXiv (abs)PDFHTML
Abstract

Tag Management Systems were developed in order to support website publishers in installing multiple third-party JavaScript scripts (Tags) on their websites. In 2012, Google developed its own TMS called "Google Tag Manager" (GTM) that is currently present on 28 million live websites. In 2020, a new "Server-side" GTM was introduced, allowing publishers to include Tags directly on the server. However, neither version of GTM has yet been thoroughly evaluated by the academic research community. In this work, we study, for the first time, the two versions of the Google Tag Management (GTM) architectures: Client- and Server-side GTM. By analyzing these systems with 78 Client-side Tags, 8 Server-side Tags and two Consent Management Platforms (CMPs) from the inside, we discover multiple hidden data leaks, Tags bypassing GTM permission system to inject scripts, and consent enabled by default. With a legal expert, we perform an in-depth legal analysis of GTM and its actors to identify potential legal violations and their liabilities. We provide recommendations and propose numerous improvements for GTM to facilitate legal compliance.

View on arXiv
@article{mertens2025_2312.08806,
  title={ You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager },
  author={ Gilles Mertens and Nataliia Bielova and Vincent Roca and Cristiana Santos },
  journal={arXiv preprint arXiv:2312.08806},
  year={ 2025 }
}
Comments on this paper