Nearly all councils hand user tracking data to marketing companies

A comprehensive scan for hidden advertising trackers on council websites in England and Wales revealed that 96 per cent track users, frequently without their knowledge, and are often breaching EU and UK privacy law. Tech giants Google and Facebook were found to be heavily involved.
In collaboration with the Danish privacy and analytics company Cybot, E&T ran a large-scale analysis by sifting through nearly 1.3 million pages across 408 council websites. This found that 96 per cent of websites were deploying marketing trackers and cookies, many of them without the users’ knowledge.
Forty-one councils deployed more than 100 open and hidden trackers on their websites. On average, councils deployed 36 trackers, with an average of 14 commercial companies constantly monitoring users’ behaviour on each site.
Daniel Johannsen, CEO of Cybot, explains the problems with having so many, often illegal, ad trackers on public service websites: “It is a gigantic data breach that is clearly not aligned with the legal requirements on some very basic things, that can be easily tested. The websites put citizens at risk and expose [councils] to legal risks both on the GDPR and in regards to the e-privacy directive, which requires consent and transparency for this kind of tracking. Most of them are not even close to complying. In general, it is quite a sad picture.”
Three of the councils most aggressively tracking users portray the predatory nature of ad-tech companies on these public service websites. One privacy consultant comments that they also show how to break UK and EU privacy laws.
269 marketing trackers were located via 113 domains and 112 companies. Many of these ad-tech firms that the public may have never heard of. Their practice would not honour privacy law, according to Jamal Ahmed, a privacy consultant at Kazient.
Ahmed’s assessment is based on the fact that the site would “automatically deploy marketing cookies” and that it “should offer users the option to consent to marketing cookies. This option should not be pre-ticked”. Also, it fails to offer users the option to opt-out of accepting analytics cookies.
Similarly, the Enfield Council website, with 238 ad-trackers, features an extensive data privacy notice on its site. Ahmed says due to marketing cookies being pre-ticked, it would breach EU and UK privacy law in a similar fashion.
The website of North Somerset Council, following the user via 225 trackers, has a similar extensive privacy statement.
Ahmed says it breaks privacy law because it also automatically deploys marketing cookies. It should, but does not, offer users the option to consent to marketing cookies and fails to offer users an option for accepting analytics cookies.
“It is profoundly shocking and appalling to learn that local government websites are illegally facilitating and deploying marketing trackers with such aggression,” he adds.
Ahmed explains that both the Information Commissioner’s Office (ICO) guidance and recent case law make it very clear that the deployment of such cookies without the necessary fair processing notice and obtaining valid consent is deemed illegal. E&T’s findings provide clear evidence that local councils are in violation of privacy legislation and therefore exposed to potentially significant fines.
The reason for finding so many trackers, Johannsen explains, is that many are hidden. He says some site owners are probably not aware of their tracking. “There are many sites embedding different services that function as a backdoor or a trojan horse. Plugins or scripts that website owners can easily plug into their websites that provide social sharing buttons, for instance, are often to blame. Once installed, they hand over the control of their website to these plugins”.
Johannsen adds that the technology to spot hidden trackers used by local authorities, researchers and universities currently lacks sophistication and would fail to reveal the real picture.


