TaxAct’s $275,000 Privacy Settlement Shows Regulators Are Moving From Privacy Policies to Continuous Tracker Monitoring

Table of Contents

A new privacy settlement involving TaxAct, Meta and Google offers businesses one of the clearest examples yet of how regulators expect companies to govern third-party tracking technologies operating on their websites and how software solutions such as Captain Compliance’s privacy tools when implemented correctly can protect against these six-figure regulatory fines not only in Connecticut but in other 22+ other states that are ramping up enforcement of their privacy frameworks.

Connecticut Attorney General William Tong announced Aug. 19, 2026, that TaxAct agreed to pay $275,000 to resolve an investigation into the improper disclosure of sensitive taxpayer information to Meta and Google through third-party tracking technologies.

TaxAct CT. Data Privacy Fine

The investigation found that between January 2018 and December 2022, TaxAct used technologies connected to Meta and Google for analytics and marketing and transmitted detailed financial information about taxpayers without informing them beforehand. The information included rounded adjusted gross income, rounded refunds or amounts owed, the number of dependents, charitable-contribution information, investment income, mortgage interest and student-loan interest.

But the settlement goes considerably further than a financial penalty.

Connecticut is requiring TaxAct to establish formal governance over tracking technologies, document what data those technologies collect (if you have seen our cookie transparency page this automates this requirement), continuously monitor tags operating on its website and undergo independent auditing to confirm that trackers actually function the way the company has approved them to function.

For privacy officers, legal teams, marketing departments and companies deploying analytics and advertising technology, that part of the settlement deserves close attention.

The emerging regulatory standard is no longer simply: What does your privacy policy say?

It is increasingly: What is your website actually sending?

TaxAct Was Handling Some of the Most Sensitive Financial Information Consumers Provide Online

Consumers using a tax-preparation service have little choice but to provide extraordinarily detailed personal and financial information.

A tax return can reveal income, investments, family structure, mortgage information, charitable giving, education expenses, tax liabilities and numerous other details about an individual or household.

According to Connecticut’s investigation, some of that information was transmitted through third-party technologies used by TaxAct for analytics and marketing.

Attorney General Tong’s office identified information including:

  • Rounded adjusted gross income
  • Rounded tax refunds
  • Rounded taxes owed
  • Types of income and deductions
  • Number of dependents
  • Charitable contributions
  • Investment income
  • Mortgage interest
  • Student-loan interest

The state also found that TaxAct did not inform taxpayers before sharing the information with Meta and Google.

That alone would create a substantial privacy issue.

But Connecticut identified another problem involving the relationship between what TaxAct told consumers and what its tracking infrastructure permitted.

TaxAct’s Privacy Promises Did Not Match Its Tracking Environment

According to the Connecticut Attorney General, TaxAct’s privacy notices during the relevant period promised to safeguard consumer privacy and prohibit third parties from sharing TaxAct data.

Yet investigators found sensitive taxpayer information being transmitted to Meta and Google.

The state also found that TaxAct’s agreement with Meta did not limit Meta’s ability to use the information for its own purposes or share it with additional third parties.

That mismatch is one of the most important privacy lessons from the case.

Privacy policies are not independent of website architecture.

If a company’s privacy notice promises that certain information will not be disclosed, while third-party JavaScript, pixels, analytics technologies or SDKs transmit that information anyway, the technical behavior can undermine the legal disclosure.

This is increasingly becoming a recurring theme across privacy enforcement and litigation.

A privacy policy describes what should happen.

Code determines what actually happens.

When those two versions of reality diverge, companies can face regulatory investigations, class actions and other legal exposure.

The Story Started With Website Tracking Code

The TaxAct issue did not begin with a traditional cybersecurity breach.

There was no allegation in Connecticut’s announcement that an attacker hacked into TaxAct’s network and stole these tax records.

The problem involved ordinary web technologies installed for business purposes.

A 2022 investigation by The Markup found that several major online tax-preparation services were transmitting financial information to Meta through the Meta Pixel. TaxAct was among them.

The Markup found that TaxAct’s implementation transmitted data such as filing status, adjusted gross income and refund amounts to Meta. It also found similar financial information being sent to Google through Google Analytics.

That distinction matters.

Pixels and analytics platforms are ubiquitous across the modern web.

Businesses deploy them to:

  • Measure conversions
  • Understand website traffic
  • Analyze user behavior
  • Optimize advertising
  • Retarget visitors
  • Create audiences
  • Measure campaign effectiveness

They are frequently treated as routine marketing infrastructure.

The TaxAct case demonstrates why they can also become privacy infrastructure.

A Pixel Does Not Know That It Is Sitting on a Tax Website

The underlying technical issue illustrates one of the biggest problems with third-party tracking.

A marketing tool does not necessarily understand the sensitivity of the business context around it.

It executes according to its configuration.

The Markup found that different forms of pixel behavior could capture sensitive information in different ways.

For example, some data collection resulted from default functionality, while other information was transmitted through customized events.

The investigation reported that TaxAct sent adjusted gross income and refund amounts to Meta through custom-event parameters. The site also used Meta’s automatic advanced matching capability, which searches web forms for information such as names, phone numbers and email addresses that can be used to match visitors with Meta users.

This is why simply knowing that “Meta Pixel is installed” provides an incomplete picture of privacy risk.

Two websites can run the same technology while transmitting completely different information.

Privacy teams need to understand:

  • What events fire
  • What parameters are attached
  • What URLs are transmitted
  • What form fields can be captured
  • What automatic features are enabled
  • What identifiers are transmitted
  • What happens before and after consent

The configuration matters as much as the name of the technology.

Hashing Data Does Not Automatically Solve the Privacy Problem

The original investigation also demonstrated a recurring misconception around hashed information.

Certain identifying information sent through Meta’s advanced-matching functionality was transformed through hashing before transmission.

That can sound anonymous.

It is not necessarily anonymous.

Hashing can transform information into another representation, but when the purpose of that transformed value is to match the person with an existing user or profile, the privacy implications do not disappear simply because the original text is no longer visible.

The Markup noted that Meta could use hashed information precisely to associate website events with Facebook and Instagram profiles.

Businesses therefore need to be careful with statements such as: “We don’t transmit personal information because the identifier is hashed.”

Privacy analysis needs to consider what can actually be done with the identifier, not merely what the value looks like when transmitted.

Congress Subsequently Investigated the Tax-Preparation Industry

The reporting eventually drew congressional scrutiny.

A Senate-led investigation involving several lawmakers examined TaxAct, H&R Block and TaxSlayer and concluded that tax-preparation companies had shared sensitive taxpayer information with Meta, Google and other technology companies through tracking technologies.

The congressional investigation described the practice as involving potentially millions of taxpayers and raised questions about whether tax privacy laws had been violated.

The report emphasized an important technical lesson: tracking pixels may be commonplace, but placing them on pages where highly sensitive financial or tax information is entered creates dramatically different privacy risks.

That principle extends far beyond tax software.

The same analysis applies when tracking technology appears inside:

  • Healthcare portals
  • Financial applications
  • Insurance websites
  • Fertility services
  • Mental-health platforms
  • Educational systems
  • Legal-service websites
  • Any environment where browsing behavior or form inputs can reveal sensitive information

The fact that a technology is common does not make every deployment appropriate.

TaxAct Also Faced Private Litigation

Regulatory scrutiny was not the only consequence.

TaxAct users brought class-action litigation alleging that the company disclosed personal and financial information to third parties, including Meta and Google, without permission.

The official TaxAct class settlement established a $14.95 million settlement fund and provided for up to another $2.5 million to cover notice and administrative costs, with unused administrative funds potentially returning to the class.

The settlement covers consumers who used qualifying TaxAct online Form 1040 products between Jan. 1, 2018, and Dec. 31, 2022, as well as certain spouses whose information appeared on jointly filed returns.

The Connecticut settlement therefore represents another layer of exposure arising from the same underlying privacy problem.

One tracking implementation can potentially produce:

  • Regulatory investigation
  • Government penalties
  • Class-action litigation
  • Settlement expenses
  • Remediation costs
  • Legal fees
  • Reputational damage
  • Years of ongoing compliance obligations

The cost of the tracker itself may have been negligible.

The downstream liability was not.

The $275,000 Fine Is Not the Most Important Part of Connecticut’s Settlement

The Connecticut settlement becomes particularly interesting when you examine the required remediation.

The Attorney General did not merely tell TaxAct to stop improperly sharing taxpayer information.

Connecticut imposed a governance system around third-party tracking.

According to the Connecticut Attorney General’s announcement, TaxAct must establish stronger controls over the use of third-party tracking technologies.

Those obligations include formal review and approval processes, documentation concerning tracking technologies and data collection, continued monitoring of tags operating across the website, and independent third-party audits of the compliance program.

Those requirements deserve substantially more attention than the size of the fine.

They provide a regulator-approved blueprint for what sophisticated tracking governance can look like.

Connecticut Is Effectively Requiring Continuous Website Monitoring

The tag-monitoring requirement may be the most significant element of the settlement for the broader privacy industry.

Websites are dynamic.

Marketing teams change campaigns.

Developers modify code.

Tag managers get updated.

Agencies add scripts.

Vendors modify their software.

Pixels receive new parameters.

Consent configurations change.

A website inspected in January may behave differently in February.

That means a one-time privacy audit cannot establish continuing compliance.

Connecticut’s settlement recognizes that reality.

Requiring TaxAct to regularly scan its site to ensure third-party technologies are operating as approved moves privacy compliance away from point-in-time review and toward continuous technical verification.

That is an important development.

Traditionally, companies might conduct a privacy assessment once a year.

The assessment identifies technologies operating at that moment.

A report gets produced.

Everyone moves on.

But digital infrastructure can change the following week.

Continuous tag monitoring addresses that gap.

Approved Does Not Mean Permanently Compliant

The settlement contains another subtle but important concept.

New tracking technologies must be reviewed and approved.

Changes to existing tracking technologies must also be governed.

That second requirement matters.

A company may approve a technology for one purpose and one configuration.

Six months later, that same tool might begin:

  • Collecting additional fields
  • Receiving additional parameters
  • Operating on additional pages
  • Sharing information with another destination
  • Being used for another purpose

The technology’s name has not changed.

The privacy risk has.

This is why modern tracker governance must look at configuration and behavior rather than maintaining a static vendor list.

“Meta Pixel — approved” is not sufficient governance.

The question should be: Approved to collect what, on which pages, for what purpose, under what consent state, and with what downstream restrictions?

Data Documentation Is Becoming Part of Tracker Governance

Connecticut also requires TaxAct to document the data points collected by third-party tracking technologies.

That may sound like an obvious requirement.

In practice, many organizations cannot answer it.

A marketing team may know that Google Analytics is installed.

A privacy team may know that Meta Pixel appears in the cookie inventory.

Engineering may know that a tag manager controls both.

But nobody may have a complete inventory showing the individual parameters transmitted through each request.

That is the problem.

Knowing the vendor is not the same thing as knowing the data flow.

A meaningful tracking inventory needs to answer:

  • Which technology is running?
  • Who operates it?
  • On which pages does it activate?
  • When does it activate?
  • What event triggers it?
  • What information is transmitted?
  • What identifiers accompany the transmission?
  • Where does the information go?
  • Why is the information needed?
  • Can the recipient use the information independently?
  • Is consent required?
  • Does rejection actually prevent transmission?

TaxAct demonstrates why that level of visibility matters.

Vendor Contracts Matter Too

The Connecticut investigation also focused on TaxAct’s contractual relationship with Meta.

According to the Attorney General, TaxAct’s agreement did not restrict Meta’s ability to use the information for its own purposes or share it with other third parties.

This provides another lesson.

Website privacy risk does not end when information leaves the browser.

Organizations need to understand the downstream rights granted to vendors receiving the data.

A third-party technology provider that merely processes information under tightly defined instructions presents a different privacy posture than a vendor permitted to use information independently.

Companies should therefore evaluate both the technical transmission and the contractual rights attached to the recipient.

A perfect privacy policy cannot fix an inappropriate vendor contract.

And a perfect vendor contract cannot fix an uncontrolled technical implementation.

Both have to work together.

What Businesses Should Learn From TaxAct

Inventory Every Tracking Technology

Businesses should identify all pixels, cookies, SDKs, session-replay technologies, analytics tools, chat technologies and third-party scripts operating across their digital properties.

Inspect the Actual Data Transmitted

Do not stop at identifying the vendor.

Review the network requests and data fields.

A tracker labeled “analytics” may still transmit URLs, form values, identifiers or other information carrying substantial privacy implications.

Pay Special Attention to Sensitive Pages

Tracking appropriate for a generic homepage may be inappropriate on:

  • Account portals
  • Checkout pages
  • Health forms
  • Financial dashboards
  • Tax forms
  • Loan applications
  • Support conversations
  • Pages revealing highly sensitive interests

Context changes privacy risk.

Establish an Approval Process

Marketing should not have unilateral authority to deploy new tracking technologies onto sensitive digital properties.

Privacy, legal, security and engineering teams should have defined roles in reviewing high-risk integrations.

Reapprove Material Changes

An approved technology should not remain approved forever regardless of configuration changes.

New events, parameters, purposes or destinations should trigger another review.

Monitor Continuously

This is one of the clearest lessons from Connecticut’s settlement.

Websites change continuously.

Privacy monitoring should reflect that reality.

Document What Each Tracker Collects

Organizations should be able to produce a record showing which technologies collect which information and why.

Compare Technical Behavior Against Privacy Notices

Promises made to consumers need to correspond to actual processing.

If the policy says information will not be shared for advertising, technical testing should confirm that the relevant data is not being sent to advertising platforms.

Examine Vendor Rights

Review whether recipients can independently use, combine, retain or redisclose information.

Preserve Evidence

Consent records, tracker scans, configuration histories, approvals, assessments and remediation records can all become important when a regulator or plaintiff asks what occurred months or years earlier.

Privacy Compliance Is Moving From Disclosure to Verification

This may be the broader significance of Connecticut’s TaxAct settlement.

For years, digital privacy programs emphasized disclosure.

Tell consumers what information is collected.

Tell them which categories of companies receive it.

Publish a privacy policy.

Display a cookie banner.

Provide an opt-out mechanism.

Those obligations remain important.

But enforcement is increasingly moving toward verification.

Did the pixel actually stop firing?

What parameters actually went to Meta?

What information actually reached Google?

Did the vendor use the information for its own purposes?

Was the tracker approved?

Did a subsequent configuration change alter its behavior?

Is somebody continuously checking?

Can the company prove it?

Those are fundamentally different questions.

And they require technical evidence.

This Is Exactly Why Privacy Teams Need Real-Time Visibility

The TaxAct settlement demonstrates the weakness of treating websites as static assets.

They are not.

Modern websites are software environments containing code from numerous internal and external sources.

A privacy program needs enough visibility to understand what those technologies are doing in real time.

This is particularly important where sensitive information is involved.

A single unauthorized parameter sent through a widely deployed tracking technology can affect thousands or millions of users before anybody realizes it exists.

The ideal control is therefore not discovering the problem during litigation.

It is discovering the problem when the technology changes.

The Captain Compliance Takeaway

For Captain Compliance, the TaxAct settlement is particularly noteworthy because Connecticut is requiring controls that mirror the direction modern privacy technology has been moving toward: continuous scanning, tracker identification, data-flow documentation, consent governance and evidence that technologies behave as authorized.

The lesson is not that every company needs the exact compliance structure imposed on TaxAct.

It is that regulators increasingly expect organizations to know what is running on their websites and prove that those technologies remain within approved boundaries.

A cookie inventory generated six months ago is not enough if the website has changed since then.

A privacy policy is not enough if a tracker contradicts it.

A consent banner is not enough if technologies activate before or despite the consumer’s choice.

And vendor approval is not enough if nobody monitors what that vendor’s code does afterward.

Privacy compliance increasingly requires continuous technical verification.

The Bigger Warning From TaxAct

TaxAct’s underlying mistake is not unusual.

That is what makes the case important.

Meta Pixel and Google Analytics were not obscure surveillance technologies hidden inside malicious software.

They were common commercial tools being used for analytics and marketing.

The problem was the environment in which they were deployed, the information they were allowed to receive, the controls surrounding them and the difference between those technical practices and the company’s privacy representations.

That scenario can exist on almost any modern website.

And Connecticut’s response provides a clear indication of where privacy enforcement is heading.

Inventory your trackers.

Document the data.

Govern deployment.

Monitor changes.

Audit the system.

And verify continuously that what your privacy program says should happen is what your website actually does.

Because after the TaxAct settlement, continuous tracker monitoring is no longer merely a privacy technology best practice.

A state Attorney General has now made it part of an enforcement remedy.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.