Three numbers
Between January and September 2026 we scanned 47,505 public websites and scored 47,419 of them. On 1,475 of those sites the scanner found a consent platform.
620 of that 1,475 tracked the visitor anyway.
That is 42.0% of the sites that had a banner. Not 42.0% of the web, and not 42.0% of everyone. 42.0% of the group that had already gone to the trouble of putting a consent interface on the page.
What was actually measured
Each site was loaded the way a first-time visitor loads it, with no history and no stored preference. The scan recorded whether a consent platform appeared, when it appeared, what fired before anyone touched it, and what fired after a refusal.
That is detection, and it is worth saying so here rather than in a footnote, because the distinction is the entire reason the number is quotable. We observed what loaded on a public page. We did not read anyone's contracts, their processing agreements, their legal basis or their regulator correspondence. Nothing here says any site is non-compliant, and nothing here says any site is fine either. An absence of findings is not a clean bill of health, and that applies to our own scanning as much as to anyone else's.
The scope needs stating plainly too. This is a crawl of restaurant, hospitality and independent ecommerce sites. It is not a sample of the web and the figures should not be read as one.
The 96.9% is the boring half
The largest finding in the index is that 45,944 of 47,419 sites had no consent platform detected at all. That is 96.9%, and it is a big number that leads nowhere.
Those businesses have not started. Some do not believe the rules reach them, some have never been asked, most have simply never had the conversation. Nobody is surprised and nobody is misled. There is no gap between what those companies believe and what is happening on their sites, because nothing was ever claimed.
Write your headline off that number and you get an article saying the web is bad at privacy. Everyone already knows, and nobody acts on it on a Tuesday.
The 42.0% is the story
The interesting group is thirty times smaller and considerably worse off.
These are companies that recognized the problem. Someone raised it in a meeting, someone found budget, someone evaluated tools, someone deployed one. There is a banner on the page and a line item on an invoice. And on 620 of those 1,475 sites, tags fired before the visitor touched anything, or kept firing after a refusal.
Those are two different failures and they deserve separating. 196 sites tracked before the visitor interacted with the banner at all, which means the interface arrived after the data did. The remainder passed that test and then ignored the answer, which is the harder one to defend: the banner appeared on time, the visitor declined, and the tags carried on regardless.
Here is the asymmetry that makes this the group worth writing about. A site with no banner has an open problem, and everyone in the building knows it is open. A site with a banner that does not gate has a closed problem, and the closure is what does the damage. Someone reported it as done. It came off the risk register. It has a renewal date, a vendor contact and a screenshot in a board deck. Nobody is looking, because looking is what you do to open problems.
They carry the license cost, the maintenance, the consent-rate hit on their own analytics, and none of the protection they are paying for.
How a banner ends up not blocking
None of this requires anyone to have been careless, which is exactly why it is so common. The mechanisms are mundane, and one or two of them sit close to the default state of a normal deployment.
- Tags that load before the decision resolves. The consent platform is asynchronous and the tag is not, or the tag sits directly in the page rather than behind the tag manager, so it runs while the banner is still fetching its configuration. The order looks correct in the source and is wrong at runtime.
- An allowlist that quietly exempts the vendors that matter. Somebody classified analytics or a major advertising tag as necessary during setup, usually to close a measurement gap that appeared the week the banner went live. The banner works perfectly. The exemption is doing all the work.
- Storage written before the banner renders. An identifier is set on page load, the banner appears half a second later, and the refusal stops the next write rather than removing the first one.
- A banner that records the choice and gates nothing. The preference is stored correctly and the consent API returns the right answer, but no tag was ever wired to consult it. This is the one we see most, and it is invisible from inside the consent tool's own dashboard, which will report a healthy consent rate the whole time.
We are not naming any consent platform as the cause, because none of these is a product defect. Every one of them can be produced with any of the major tools, and most of them come from configuration nobody has revisited since launch. The distinction between the interface and the enforcement behind it is the subject of Cookie Banner vs. Consent Tool, which is the piece to read if those four bullets sounded familiar.
The five-minute self-test
You do not need us for this and you do not need a tool. You need a browser and about five minutes.
- Open a private or incognito window, so you start with no stored preference.
- Open developer tools and switch to the Network tab before you load the page.
- Load your site. Watch what fires before you touch anything at all. Look for requests going out to analytics and advertising domains. If they are already leaving, your banner arrived after your data did.
- Now decline. Refuse everything the banner lets you refuse.
- Clear the network log, then navigate to a second page on the site.
- Watch again. If the same requests are firing after a no, the banner is decoration.
Two caveats, because the test is only honest in one direction. If you see tracking after a refusal you have found something real. A quiet result proves much less, because you tested one journey, on one device, on the domains you happen to own. If your checkout or ordering flow sits on a vendor's domain, this test never reaches it, for reasons covered in Your Checkout Is on a Different Domain.
The rest of the picture
The consent-signal side of the index tells the same story from another angle. Across the same 47,419 scored sites, 23,307 were running Google tags with no Consent Mode signal at all, which is 49.2%. 2,108 showed a working Consent Mode v2 signal, which is 4.4%. The mean privacy score across the whole sample was 13.5 out of 100.
Every figure in this piece comes from the Website Privacy Index, measured on one crawl between January and September 2026, and every one of them carries its base deliberately. A percentage that travels without its denominator turns into a different claim inside about two shares. The figures above were re-derived in September 2026 against a larger crawl than the one this piece was first written from, which is the whole argument for publishing denominators in the first place.
Where the verticals separate
The gap between industries came out wider than we expected. Restaurants averaged 9.9 out of 100 across 31,167 sites. Independent ecommerce averaged 24.0 across 8,386. Hospitality sat between them at 18.6 across 704.
We have a hypothesis about why, and it is a hypothesis rather than a finding: a restaurant brand runs more of its customer funnel on domains it does not own than almost any other kind of business. We measured the gap. We did not measure the cause, and the index does not prove the explanation. The argument is written out separately in Why Restaurant Websites Score Worst On Privacy.
Why this shape of failure is worth the attention
There is a reason to care beyond tidiness. The US state enforcement actions so far have not turned on missing policies or dramatic breaches. They have mostly turned on the opt-out: the link that does not work, the signal that is ignored, the choice that is recorded and then overruled. We went through that pattern in Every US Privacy Enforcement Action So Far Comes Down to One Broken Link.
A banner that keeps firing after a refusal has that shape exactly. And if you operate across borders, the same configuration tends to behave differently by region, which is its own problem and the subject of the consent gap on international domains.
The honest close
The number in the headline is not an accusation. Most of those 620 are companies that tried, which is more than 45,900 others in this crawl can say. The failure is that trying and succeeding look identical from the inside, and the only thing that separates them is somebody opening the Network tab.
Run the test. It takes less time than booking the meeting about it.
The full methodology, the per-vertical breakdown and every figure quoted here are published on the Website Privacy Index. If you would rather have someone else run the test across your whole funnel, including the domains you do not own, book a Data Audit.
Figures from the September 20, 2026 index. The live report updates as scans continue.
More from the Website Privacy Index: Cookie banner adoption · Consent platform market share · Do cookie banners work?
Rawsoft provides technical implementation and analysis, not legal advice. Please confirm any regulatory interpretation with your counsel.
Part of the guide: Consent Mode v2: Setup, Testing and Common Failures