All Vendors
dsp

Gumgum

Gumgum deploys comprehensive ad surveillance: behavioral biometrics, cross-domain syncing, consent bypass, and tag manager persistence. Low Oracle risk, severe Broker exposure, critical Counselor violations create multi-layered compliance disaster.

10 IOCs28 detections7% pre-consent26 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Gumgum discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

28 detections across 26 sites7% pre-consent activity
MEDIUM

Pre-Consent Activity

Gumgum was observed loading and executing before user consent was obtained on 7% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps
Customer Impact

What This Means For You

Marketing teams gain visual ad optimization but inherit exponential consent liability: per-visitor × per-sync-partner × special category biometrics. Engineering teams lose control over tracking due to tag manager deployment. Legal teams face simultaneous violations across four GDPR/ePrivacy provisions.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Gumgum

  • Remove Gumgum from tag manager immediately - tag-based deployment prevents consent enforcement
  • Request deletion of all behavioral biometric data and cross-domain sync records
  • Demand list of all cookie-sync partners to assess total liability exposure

If You're Evaluating Gumgum

  • Reject any vendor using tag manager deployment for ad tracking - requires direct script control for compliance
  • Demand written confirmation: no behavioral biometrics, no cross-domain syncing, no pre-consent loading
  • Migrate to privacy-safe advertising: contextual targeting (no tracking), consent-first programmatic, or direct publisher relationships without behavioral profiling

Negotiation Leverage

  • Gumgum deploys four-layer consent violation creating exponential liability: behavioral biometrics + cross-domain syncing + tag manager persistence + pre-consent loading
  • Tag manager deployment makes consent compliance impossible - vendor can modify tracking server-side without customer control
  • Cross-domain syncing multiplies per-visitor penalties by number of ad network partners - exponential enforcement exposure
  • Vendor must eliminate all four violation layers or accept 100% liability for compounded GDPR/ePrivacy regulatory enforcement
Runtime Detections

Runtime Detections

4 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Visual attention tracking (scroll depth, viewability timing, interaction patterns) creates behavioral fingerprints. GDPR Article 9 classifies biometric data as special category requiring explicit consent - pre-consent capture creates heightened penalty exposure.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Cookie syncing with ad network partners before consent creates per-visitor violation multiplied by number of sync recipients. Enforcement agencies can assess penalties per data transfer - 10 sync partners = 10x liability multiplier.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Tracking initialization before consent creates strict liability under GDPR Article 7 and ePrivacy Directive. Combined with biometric capture and cross-domain syncing, elevates to special category data + unauthorized transfer violation.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Deployment via tag manager enables vendor to modify tracking behavior server-side without customer visibility. Customer cannot verify consent-first loading or data minimization even after configuration - creates ongoing compliance risk.

IOC Manifest

IOC Manifest

3 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

No indicators in this category

Ecosystem

Ecosystem & Supply Chain

Gumgum operates in visual advertising ecosystem with contextual and behavioral targeting vendors. Standard cookie-syncing for DSPs, but four-technique surveillance stack creates extreme risk. Higher liability than consent-first ad platforms or contextual-only alternatives (no behavioral tracking).
Loaded By (2)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

10 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details