The decision
Our Website Privacy Index scored 47,419 websites. 50 of them scored a perfect 100. The published leaderboard contains none of them, and the report says why in one sentence:
"We also excluded 50 sites that scored a perfect 100 because the scanner found nothing to fail them on. An empty result is not a clean site, and a leaderboard built on absence of evidence would be worthless to everyone reading it."
That sentence cost us the best-looking numbers in the dataset. This piece explains it, because the reasoning applies to any scan report anyone ever hands you.
What a score is actually built from
A privacy score describes observed behavior on the pages a scan reached, at the moment it reached them. Nothing more. It is not a property of the site; it is a property of an observation of the site.
That distinction sounds pedantic until you ask what happens when the observation goes wrong.
Two ways to reach 100
A site can score a perfect 100 because it genuinely holds every tag until a visitor consents. Or a scan can reach 100 because it saw nothing to penalise: a bot wall returned a stripped page, the page never finished rendering, a script loaded in a way the scanner did not recognise, or the crawl hit a maintenance page.
Both possibilities are real and both are general. We are not claiming the 50 perfect scores were scan failures. We have not diagnosed them individually and the page does not either. The exclusion is a policy about what a leaderboard can honestly assert, not a verdict on 50 websites.
Why the top of the table is more fragile than the bottom
Here is the asymmetry that drove the decision.
A zero requires the scan to have observed something. A tracker fired before consent. A request went out after a refusal. There is positive evidence behind every point lost.
A 100 can be produced by observing nothing at all. The output is identical whether the site is exemplary or the scan came back empty, and from the score alone the two are indistinguishable.
So the best-looking number in any scan is the one that needs the most corroboration before anyone repeats it. That is the same failure family as a dashboard reporting zero when it means no data arrived, which we wrote about in zero versus missing, and the same reason we argued that nobody monitors the monitor.
Where 100 sits in this population
Context matters for how unlikely a perfect result is. Across the same 47,419 scored sites:
- The mean privacy score was 13.5 out of 100.
- 18,550 sites scored zero.
- 23,307 sites, 49.2%, ran Google tags with no Consent Mode signal at all.
- 45,944 sites, 96.9%, had no consent platform detected.
In a population sitting this far down, an isolated perfect result is the least likely value in the range and the one most worth checking. That is not cynicism about the sites. It is what the distribution says about the odds.
How to read any clean result you are handed
Most people receive a green report from some tool at some point. The useful question is never what score came back. It is what the scan actually saw.
- Which pages were loaded? A scan of one landing page says nothing about a checkout flow.
- Did they finish rendering? A page that timed out produces a quiet pass.
- Did the scan interact with the banner at all? If it never clicked reject, it never tested the failure that matters most.
- Were any requests observed? Before you trust a report that saw no trackers, confirm it saw anything.
A report that cannot answer those four has told you nothing, however green it looks.
The one browser check
Open your own site in a fresh private window with the network tab open before the page loads. Touch nothing. Confirm you can see requests at all before you trust that you see none from trackers. An empty network tab usually means the tab was opened too late, not that the site is quiet.
The principle
Absence of findings is not a finding. It is the absence of one, and the difference is the whole reason those 50 sites are not on our leaderboard.
Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.