All Vendors
advertising
Taboola

Taboola

Explicitly acknowledges selling personal information for cross-context behavioral advertising while holding ISO 27001/27701 certification. Their own website loads 15 third-party vendors before consent — including identity resolution tools not disclosed in their data partners list.

148 IOCs23 detections20 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Taboola discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

23 detections across 20 sites
HIGH

Vendor Disclosure Gap

15 additional vendors load pre-consent on taboola.com that are not disclosed, including identity resolution (Clay, Crunchbase), session replay (Clarity, Hotjar, VWO), and advertising trackers

GDPR Art 13GDPR Art 28CCPA 1798.100
HIGH

Certification vs Practice

Pre-consent third-party tracking on owned properties contradicts certification requirements for documented privacy controls

ISO 27001 A.18.1.4ISO 27701 7.2.2GDPR Art 7
HIGH

Undisclosed Party

Not in privacy policy

HIGH

Compliance Claim Mismatch

False certification claims

Disclosure Gaps

Claims vs. Observed Behavior

3 gaps
2 HIGH1 MED
Classified:BTI-X01BTI-X05

Vendor Disclosure Gap

GDPR Art 13 · GDPR Art 28 · CCPA 1798.100HIGH
They Claim

Data partners page lists audience targeting vendors

Observed Behavior

15 additional vendors load pre-consent on taboola.com that are not disclosed, including identity resolution (Clay, Crunchbase), session replay (Clarity, Hotjar, VWO), and advertising trackers

Runtime scan 2026-01-23 detected Cheq, Clarity, Clay, Crunchbase, DoubleClick, GoogleAds, GA4, Hotjar, Mapbox, MetaPixel, Slack, Sojern, Stripe, TradeDesk, VWO loading before consent

Certification vs Practice

ISO 27001 A.18.1.4 · ISO 27701 7.2.2 · GDPR Art 7HIGH
They Claim

ISO 27001/27701 certified with GDPR/CCPA compliance

Observed Behavior

Pre-consent third-party tracking on owned properties contradicts certification requirements for documented privacy controls

Trust Center displays ISO certifications while taboola.com loads 15 pre-consent vendors including identity resolution tools

Data Sale Disclosure

CCPA 1798.115MEDIUM
They Claim

Privacy policy discloses data sale

Observed Behavior

Explicit acknowledgment of selling/sharing personal information for behavioral advertising, contradicting privacy-friendly positioning

Privacy policy Section 5.2: We may sell or share for cross-context behavioral advertising purposes

Customer Impact

What This Means For You

If Taboola widgets are deployed on your site, their JavaScript introduces 32+ data partner relationships including LiveRamp, Oracle, Nielsen, and TransUnion for identity resolution and audience enrichment. Under GDPR Art 13 and CCPA §1798.100, you must disclose these data flows to your users. Taboola explicitly states they sell or share personal information for cross-context behavioral advertising — if your privacy policy does not disclose this, you face direct regulatory exposure. Their ISO 27001/27701 certifications do not extend to your deployment. With a 13-month data retention period and 32+ data partners, your visitors' behavioral data has an extensive downstream footprint beyond your control.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Taboola

  • Audit which third-party vendors load via Taboola widgets on your property — their ecosystem includes 32+ data partners including LiveRamp, Oracle, and TransUnion
  • Update your privacy policy to disclose Taboola's explicit data sale practices if using their advertising services
  • Review your CMP configuration for Taboola (IAB TCF vendor #42) to ensure proper consent signals are passed before widget loads
  • Verify your DPA covers their stated 13-month data retention period and 32+ data partner relationships
  • Run a runtime scan on pages with Taboola widgets to inventory actual third-party loading versus what Taboola discloses

If You're Evaluating Taboola

  • Request complete list of data partners that would load via their widget on your property — 32+ disclosed partners is significant third-party exposure
  • Note their explicit acknowledgment of data sale in their privacy policy — this may be incompatible with your enterprise privacy commitments
  • Review pre-consent behavior on taboola.com (15 vendors load before consent) as an indicator of their operational privacy maturity
  • Compare Taboola data partner density against alternatives like Outbrain or direct publisher relationships for reduced exposure
  • Assess whether their 30-year Yahoo partnership and Microsoft integration create competitive intelligence exposure for your demand signals

Negotiation Leverage

  • Data partner audit: Taboola operates 32+ disclosed data partners including LiveRamp, Oracle, Nielsen, and TransUnion. Require complete enumeration of all third-party data flows triggered by their widget on your property, with 30-day advance notice before any partner additions.
  • Data sale limitation: Taboola explicitly acknowledges selling personal information for behavioral advertising. Require contractual prohibition on data sale from your property's visitors, with right to audit data flows quarterly.
  • Pre-consent compliance: 15 vendors load pre-consent on taboola.com despite ISO 27001/27701 certification. Require contractual guarantee that their widget loads zero third-party vendors before consent on your property.
  • Vendor containment: Taboola widgets introduce identity resolution, session replay, and advertising trackers onto your pages. Require contractual right to approve or reject each third-party vendor loaded through their widget on your property.
  • Liability indemnification: Given explicit data sale practices and 32+ data partners, require Taboola to assume full liability for regulatory fines arising from undisclosed data processing triggered by their widget on your property.
Runtime Detections

Runtime Detections

7 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C14Identity Resolution

PII deanonymization

IOC Manifest

IOC Manifest

146 INDICATORS

Indicators of compromise across 6 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/js/main.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/js/front-page.js*
Tracking script
TRACK
*swissknife.taboola.com/TaboolaForm/tbf-dist.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/functions-BN-FkFuk.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/autoplay-DNMS0CMf.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/video-DagFctfo.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/aos-CTsSLbkB.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/parallax-CPfALo53.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lottie-CE1cR1Rb.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lazyload-CwDt0XVP.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/bootstrap-m4Na9FCi.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/simpleAos-BvJMA5Wu.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/swiper-D2tVYthb.js*
Tracking script
TRACK
*www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lottieWeb-DRFmc3CC.js*
Tracking script
TRACK
*www.taboola.com/wp-content/uploads-neo/*/02/vdo-Homepage_Redesign-Marketing_Obj-Website_Eng.json*
Tracking script
TRACK
*cdn.taboola.com/libtrc/unip/*/tfa.js*
Tracking script
TRACK
*trc.taboola.com/*/trc/3/json*
Tracking script
TRACK
*cdn.taboola.com/scripts/eid-ls-new.es5.js*
Tracking script
TRACK
*cdn.taboola.com/scripts/cds-pips.js*
Tracking script
TRACK
*cdn.taboola.com/scripts/eid.es5.js*
Tracking script
TRACK
*www.taboola.com/wp-content/uploads-neo/*/02/vdo-Homepage_Redesign-Marketing_Obj-Lead_Gen.json*
Tracking script
TRACK
*www.taboola.com/wp-content/uploads-neo/*/02/Focus-on-the-Performance-1.json*
Tracking script
TRACK
*www.taboola.com/wp-content/uploads-neo/*/02/vdo-Homepage_Redesign-Marketing_Obj-Online_Purch.json*
Tracking script
TRACK
cdn.taboola.com/libtrc
Tracking script
TRACK
swissknife.taboola.com/TaboolaForm/tbf-dist.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/js/main.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/js/front-page.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/functions-BN-FkFuk.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/bootstrap-m4Na9FCi.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/aos-CTsSLbkB.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/swiper-D2tVYthb.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/autoplay-DNMS0CMf.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lottie-CE1cR1Rb.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lazyload-CwDt0XVP.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/video-DagFctfo.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/parallax-CPfALo53.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/simpleAos-BvJMA5Wu.min.js
Auto-extracted from scan
TRACK
www.taboola.com//wp-content/themes/taboola-neo/dist/assets/lottieWeb-DRFmc3CC.min.js
Auto-extracted from scan
TRACK
cdn.taboola.com/libtrc/unip/1887520/tfa.js
Auto-extracted from scan
TRACK
trc.taboola.com/1887520/trc/3/json
Auto-extracted from scan
TRACK
cdn.taboola.com/scripts/cds-pips.js
Auto-extracted from scan
TRACK
cdn.taboola.com/scripts/eid-ls-new.es5.js
Auto-extracted from scan
TRACK
cdn.taboola.com/scripts/eid.es5.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Taboola sits at the intersection of publisher monetization and advertiser demand. As a content recommendation platform, they are LOADED BY publishers via trc.taboola.com scripts on editorial pages. They in turn LOAD their network of 32+ data partners (LiveRamp, Oracle, Nielsen, TransUnion, Lotame) for identity resolution and audience enrichment. Key ecosystem position: 30-year exclusive Yahoo partnership, 10-year Microsoft partnership, Samsung pre-install deal. Acquisitions of Connexity (e-commerce), Skimlinks (affiliate), and Convert Media (video) expand their supply chain footprint. Their JavaScript executes in high-trust editorial contexts across major news properties.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

148 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details