Privacy Research

More Than A Third Of Cookie Banners Do Not Block Anything

By Rawsoft Team | August 2026 | 9 min read

Three numbers

Between January and August 2026 we scanned 18,613 public websites and scored 18,524 of them. On 1,024 of those sites the scanner found a consent platform.

387 of that 1,024 tracked the visitor anyway.

That is 37.8% of the sites that had a banner. Not 37.8% of the web, and not 37.8% of everyone. 37.8% of the group that had already gone to the trouble of putting a consent interface on the page.

What was actually measured

Each site was loaded the way a first-time visitor loads it, with no history and no stored preference. The scan recorded whether a consent platform appeared, when it appeared, what fired before anyone touched it, and what fired after a refusal.

That is detection, and it is worth saying so here rather than in a footnote, because the distinction is the entire reason the number is quotable. We observed what loaded on a public page. We did not read anyone's contracts, their processing agreements, their legal basis or their regulator correspondence. Nothing here says any site is non-compliant, and nothing here says any site is fine either. An absence of findings is not a clean bill of health, and that applies to our own scanning as much as to anyone else's.

The scope needs stating plainly too. This is a crawl of restaurant, hospitality and independent ecommerce sites. It is not a sample of the web and the figures should not be read as one.

The 94.5% is the boring half

The largest finding in the index is that 17,500 of 18,524 sites had no consent platform detected at all. That is 94.5%, and it is a big number that leads nowhere.

Those businesses have not started. Some do not believe the rules reach them, some have never been asked, most have simply never had the conversation. Nobody is surprised and nobody is misled. There is no gap between what those companies believe and what is happening on their sites, because nothing was ever claimed.

Write your headline off that number and you get an article saying the web is bad at privacy. Everyone already knows, and nobody acts on it on a Tuesday.

The 37.8% is the story

The interesting group is twenty times smaller and considerably worse off.

These are companies that recognised the problem. Someone raised it in a meeting, someone found budget, someone evaluated tools, someone deployed one. There is a banner on the page and a line item on an invoice. And on 387 of those 1,024 sites, tags fired before the visitor touched anything, or kept firing after a refusal.

Those are two different failures and they deserve separating. 118 sites tracked before the visitor interacted with the banner at all, which means the interface arrived after the data did. The remainder passed that test and then ignored the answer, which is the harder one to defend: the banner appeared on time, the visitor declined, and the tags carried on regardless.

Here is the asymmetry that makes this the group worth writing about. A site with no banner has an open problem, and everyone in the building knows it is open. A site with a banner that does not gate has a closed problem, and the closure is what does the damage. Someone reported it as done. It came off the risk register. It has a renewal date, a vendor contact and a screenshot in a board deck. Nobody is looking, because looking is what you do to open problems.

They carry the licence cost, the maintenance, the consent-rate hit on their own analytics, and none of the protection they are paying for.

How a banner ends up not blocking

None of this requires anyone to have been careless, which is exactly why it is so common. The mechanisms are mundane, and one or two of them sit close to the default state of a normal deployment.

We are not naming any consent platform as the cause, because none of these is a product defect. Every one of them can be produced with any of the major tools, and most of them come from configuration nobody has revisited since launch. The distinction between the interface and the enforcement behind it is the subject of Cookie Banner vs. Consent Tool, which is the piece to read if those four bullets sounded familiar.

The five-minute self-test

You do not need us for this and you do not need a tool. You need a browser and about five minutes.

  1. Open a private or incognito window, so you start with no stored preference.
  2. Open developer tools and switch to the Network tab before you load the page.
  3. Load your site. Watch what fires before you touch anything at all. Look for requests going out to analytics and advertising domains. If they are already leaving, your banner arrived after your data did.
  4. Now decline. Refuse everything the banner lets you refuse.
  5. Clear the network log, then navigate to a second page on the site.
  6. Watch again. If the same requests are firing after a no, the banner is decoration.

Two caveats, because the test is only honest in one direction. If you see tracking after a refusal you have found something real. A quiet result proves much less, because you tested one journey, on one device, on the domains you happen to own. If your checkout or ordering flow sits on a vendor's domain, this test never reaches it, for reasons covered in Your Checkout Is on a Different Domain.

The rest of the picture

The consent-signal side of the index tells the same story from another angle. Across the same 18,524 scored sites, 10,094 were running Google tags with no Consent Mode signal at all, which is 54.5%. 1,276 showed a working Consent Mode v2 signal, which is 6.9%. The mean privacy score across the whole sample was 13.8 out of 100.

Every figure in this piece comes from the Website Privacy Index, measured on one crawl between January and August 2026, and every one of them carries its base deliberately. A percentage that travels without its denominator turns into a different claim inside about two shares.

Where the verticals separate

The gap between industries came out wider than we expected. Restaurants averaged 9.8 out of 100 across 10,653 sites. Independent ecommerce averaged 22.8 across 2,466. Hospitality sat between them at 19.4 across 499.

We have a hypothesis about why, and it is a hypothesis rather than a finding: a restaurant brand runs more of its customer funnel on domains it does not own than almost any other kind of business. We measured the gap. We did not measure the cause, and the index does not prove the explanation. The argument is written out separately in Why Restaurant Websites Score Worst On Privacy.

Why this shape of failure is worth the attention

There is a reason to care beyond tidiness. The US state enforcement actions so far have not turned on missing policies or dramatic breaches. They have mostly turned on the opt-out: the link that does not work, the signal that is ignored, the choice that is recorded and then overruled. We went through that pattern in Every US Privacy Enforcement Action So Far Comes Down to One Broken Link.

A banner that keeps firing after a refusal has that shape exactly. And if you operate across borders, the same configuration tends to behave differently by region, which is its own problem and the subject of the consent gap on international domains.

The honest close

The number in the headline is not an accusation. Most of those 387 are companies that tried, which is more than 17,500 others in this crawl can say. The failure is that trying and succeeding look identical from the inside, and the only thing that separates them is somebody opening the Network tab.

Run the test. It takes less time than booking the meeting about it.

The full methodology, the per-vertical breakdown and every figure quoted here are published on the Website Privacy Index. If you would rather have someone else run the test across your whole funnel, including the domains you do not own, book a Data Audit.

Rawsoft provides technical implementation and analysis, not legal advice. Please confirm any regulatory interpretation with your counsel.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Cookie Banner vs. Consent Tool

A banner is a UI. A consent tool is enforcement. The three banner types we see in audits, a two-minute Global Privacy Control test, and the state-by-state reason the implied-consent notice no longer holds.

July 2026 Read →
Privacy
Your Checkout Is on a Different Domain

If your transaction flow runs on a vendor's domain, the consent your banner captured cannot be read there. Why that happens, why the domain does not decide who is responsible, and how to check your own site in two minutes.

August 2026 Read →