The Trace Every Website Leaves
A compliance officer researching a counterparty, a lawyer reviewing an adverse party's public profile, an investigator building a source picture, and a family office principal reading market commentary all do the same ordinary thing dozens of times a day: they load a webpage. What happens in the milliseconds after that page begins to load is, for most visitors and most website operators, entirely invisible. It is also, for firms whose work depends on discretion, one of the least examined risks in their own operating environment.
The mechanism is called, informally, digital exhaust: the trail of technical and behavioural data a device emits simply by connecting to and rendering a webpage. IP address, device and browser fingerprint, approximate or precise location, referring page, time on page, and, where third-party tracking scripts are present, a persistent identifier that follows the same visitor across unrelated websites. On the large majority of commercial websites, this exhaust is not merely logged locally. It is transmitted, in real time, to companies the visitor has never heard of and the website operator frequently cannot fully account for.
From a Single Page Load to a Global Data Market
The primary mechanism through which this happens is Real-Time Bidding (RTB), the auction system that decides which advertisement appears in the space next to the content a visitor is reading. Each time an ad-supported page loads, an automated auction broadcasts a "bid request" containing data about the visitor and their inferred interests to a large number of advertising technology companies, who bid in milliseconds for the right to show an ad. The broadcast happens whether or not any company wins the auction, and it happens to every company invited to bid, not only the winner.
The Irish Council for Civil Liberties (ICCL), a nonprofit that has investigated RTB since 2018, documented in its 2022 analysis that this broadcast occurs approximately 178 trillion times per year across the United States and Europe combined, exposing the average American's online activity and location 747 times a day. Its 2023 follow-up reports, "Europe's Hidden Security Crisis" and "America's Hidden Security Crisis," went further: the RTB industry's own advertiser-facing audience taxonomies include categories such as "intelligence and counterterrorism," "military personnel," and "aerospace and defense," meaning the system is not merely capable of exposing sensitive-role individuals; it is commercially organised to identify and package them as an advertising audience segment. The same reports documented specific instances of this data flowing to AiData, a Russian data broker, and to advertising intermediaries operating under Chinese jurisdiction, where national security laws grant state agencies access to commercially held data. Once broadcast, ICCL's analysis notes, there is no technical means to limit further redistribution of that data or to verify what any receiving party subsequently does with it.
None of this requires the visited website to be an advertising platform, a data broker, or a bad actor. It requires only that the website carries a single third-party analytics or advertising script that participates in the standard commercial ad-tech ecosystem, the default configuration on a substantial share of the world's websites, including firms in the due diligence, legal, and investigations sector whose clients specifically retain them to manage exposure of this kind.
The Confidentiality Problem Is Not Hypothetical
The clearest documented precedent for how this plays out in a professional-services context comes from healthcare, not advertising. Beginning in 2022, journalists and subsequently plaintiffs' counsel established that Meta's tracking script (the "Meta Pixel"), embedded on hospital and healthcare provider websites for what those providers understood to be routine marketing analytics, was transmitting appointment-booking activity, patient portal interactions, and search terms entered on provider websites back to Meta, associated with the visitor's Facebook account where one existed. The resulting litigation, consolidated in the U.S. federal courts as the Meta Pixel Healthcare Litigation, proceeded through 2023, 2024, and into 2025 on claims including violation of federal wiretap and electronic communications statutes and state medical privacy law. The providers named in these suits had not intended to disclose patient information to an advertising platform. Their marketing analytics configuration did so anyway, because that is what the script is designed to do by default.
The relevant lesson for a due diligence, legal, or investigations firm is structural, not sector-specific. If a hospital's patient-facing website can inadvertently transmit "this individual searched for information about a specific medical condition" to a third party, a due diligence firm's client-facing website can just as readily transmit "this individual, from this location, at this time, researched a specific due diligence, security, or investigations service" to the same category of third party. For a prospective client whose reason for approaching an investigations firm is itself sensitive, whether that is a family office vetting a co-investor, a fund conducting pre-acquisition diligence on a target it has not yet approached, or a firm quietly assessing a personnel risk, the mere fact of the visit, correlated across the browsing history a tracker builds, can itself constitute the disclosure that a confidentiality-first engagement is designed to prevent. The website becomes the point of exposure the client hired the firm to eliminate.
The Regulatory Position Is Not Ambiguous
This is not an area where the law has yet to catch up with the technology. The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data defines personal data broadly enough to capture data used to identify a person directly or indirectly, including behavioural and location data, and its Articles 22 and 23 impose specific, documented conditions on any cross-border transfer of that data; that is precisely what a third-party tracking script does by design, since the receiving ad-tech or analytics company is, by construction, outside the website operator's own systems and frequently outside the UAE. For firms serving European counterparties, clients, or investors, the EU's GDPR and the ePrivacy Directive classify third-party tracking cookies and RTB bid-request data as personal data requiring documented, informed, prior consent, and Belgium's data protection authority, joined by 27 other EU regulators under the GDPR's one-stop-shop mechanism, ruled in 2022 that the advertising industry's own standard consent mechanism for RTB, the IAB Europe Transparency and Consent Framework, did not meet that standard, a finding substantially upheld by Belgium's Market Court on further appeal through 2025.
The practical implication is that a website which exports visitor data through standard third-party analytics or advertising trackers is not managing a grey area. It is operating a specific, examined, and in the EU's case, specifically sanctioned data-transfer mechanism, on a legal footing that presumes consent infrastructure most professional services websites do not have in place, and that a confidentiality-oriented visitor has no meaningful way to evaluate before they arrive.
Why This Is a Supply-Chain Risk, Not a Marketing Question
Due diligence practice treats a counterparty's fourth-party exposure, meaning the vendors and data processors its vendors use, and the vendors those vendors use in turn, as a legitimate line of enquiry precisely because risk does not stop at the first contractual relationship. A website's advertising and analytics stack is a fourth-party exposure of exactly this kind, and it is one a firm creates for itself, on its own domain, usually without a documented inventory of which third parties receive what data. Two structural features make this specifically a supply-chain question rather than a marketing-preference question.
First, the data flow is continuous and automated rather than transactional. A single advisor relationship or vendor contract can be reviewed, scoped, and terminated. A tracking script re-executes on every page load, for every visitor, indefinitely, and its downstream distribution, which reaches the hundreds or, per some ad exchanges' own disclosures, thousands of companies invited into a given RTB auction, is not something the website operator can audit after the fact. Second, the exposure compounds silently. A visitor who researches a firm before an engagement, who is referred by an existing client, or who is a journalist, regulator, or opposing party conducting their own assessment, all generate the same exhaust, and none of that population has consented to being profiled in connection with their interest in the firm specifically. The firm's own site becomes a source of intelligence about who is interested in it, available to a supply chain the firm does not control and, in the RTB case documented by ICCL, cannot even fully enumerate.
Practitioner Implications
For firms in due diligence, legal advisory, investigations, family office services, and adjacent sectors where client confidentiality is the product, the practical response follows directly from how the exposure arises:
• Treat the firm's own website analytics and advertising configuration as an in-scope item in its own operational security review, not a marketing team decision made independently of security and compliance functions. The same question applied to a counterparty's data handling, namely what is collected, where does it go, and who can access it, applies to the firm's own site.
• Distinguish first-party, self-hosted analytics (which retain visitor data on infrastructure the firm itself controls, and typically require no cookie-consent apparatus because no data leaves the firm's own systems) from third-party analytics and advertising scripts (which, by design, transmit data to outside companies and, per the EU's 2022 and 2025 rulings on RTB consent frameworks, frequently fail to meet the consent standard that transmission legally requires).
• Where advertising spend requires some form of conversion measurement, scope that measurement as narrowly as the objective allows, for example a server-side conversion signal tied only to a completed enquiry, rather than deploying a general-purpose analytics or advertising pixel site-wide, which exposes every visitor rather than only those who convert.
• Document the firm's own tracking posture with the same evidentiary discipline applied to a client engagement file. A verbal assurance that "we don't really track people" is the same standard of proof this paper's companion pieces have already argued is insufficient when a counterparty offers it during due diligence.
A Test Any Visitor Can Run
The claim that a website sets no third-party trackers is independently verifiable, and it should be. Any visitor, on any website, can open their browser's developer tools, F12 on most Windows browsers, or Cmd+Option+I on a Mac, select the Network tab, and reload the page. The resulting list shows every request the page makes and every domain it makes a request to. A site with no third-party trackers will show requests only to its own domain. A site running standard analytics, advertising pixels, or RTB-integrated ad serving will show requests to a range of external domains, typically including one or more of the major ad-tech and analytics platforms, within the first few seconds of page load.
This is not a technique available only to specialists. It takes under a minute, requires no software installation, and produces an answer that does not depend on trusting a privacy policy. For a sector whose entire commercial proposition rests on verifiable rather than asserted diligence, holding one's own website to that same standard is not a marketing position. It is the same discipline applied inward that this firm applies outward on every engagement.