Privacy Research

The Consent Banner Debate Has The Wrong Denominator

By Rawsoft Team | September 2026 | 8 min read

Most of the argument is happening on 3.1% of the sample

The published conversation about consent is almost entirely a conversation about banner design. Reject-all placement. Second layers. Pre-checked boxes. Dark patterns. All of it is real, and all of it presupposes that a banner exists.

On the population we scanned, almost none of them do.

The measurement

Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026, across restaurant, hospitality and independent ecommerce sites. Read on 20 September 2026, the page reports:

Those figures reconcile, and it is worth checking rather than taking on trust: 47,419 minus 45,944 is 1,475, and that is the same 1,475 the 42.0% is drawn from.

What the 96.9% does and does not mean

It means a browser loading those pages did not find a consent platform it could detect. That is all it means.

It does not mean those sites have no privacy policy. Many do. It does not mean they are breaking a law, and a great many of them are not subject to any consent requirement in the first place. And it does not mean there is definitely nothing there, because a custom-built or unfamiliar consent layer reads to a scanner as nothing at all.

The claim is about what a browser could observe, full stop.

Why the conversation is shaped this way

Two reasons, neither of them dishonest.

The people writing about consent UX are, almost by definition, people who already have a consent platform. You do not have opinions about second-layer placement until you have a second layer.

And vendors write about the problems their product solves, which is what vendors are for. Nobody is going to publish a long analysis of the market that has not bought anything, because there is no product in that sentence.

The consequence for the tooling market

If 96.9% have nothing detectable, then the addressable problem is not upgrade your CMP. It is that these sites have never had one, and the tags have been firing the entire time, for years, with nobody having made a decision either way.

That is a different product, a different price point and a different conversation from the one the category is currently having.

And the consequence for the 3.1%

Having the tool is not the same as the tool doing anything. 620 of the 1,475 sites with a platform detected tracked anyway.

We want to be careful here: that is an observation about enforcement, not an accusation about intent. Nobody installs a consent platform in order to ignore it. The mechanism behind that gap is laid out in more than a third of cookie banners do not block anything, and we would rather link it than re-argue it.

What would move this figure

A piece that argues from a denominator owes the reader an honest account of the denominator, so here is what our method is and is not.

Any of those would push the detected share up. We would expect the true figure to be somewhat higher than 3.1% and nowhere near high enough to change the argument.

Two checks, before any pitch

  1. Fresh private window, network tab open before the page loads, touch nothing. Watch what goes out while you have agreed to nothing.
  2. Decline everything, reload, browse, watch again. That second one is where most of the 620 were found.

The question underneath all of it

If the consent layer on your site stopped working tomorrow, who would notice, and would anything tell them? For most of the sites in this index the honest answer is that there is nothing to stop working. For the rest, the answer is usually nobody, and no.

A consent gate is not a certificate, it is a state that can stop being true on any publish. That is the case for watching it continuously rather than auditing it once, which is what Managed Privacy is for. If you would rather start with a single look at the whole tag layer, book a data and tracking audit.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Cookie Banner vs. Consent Tool: Why "We Have a Banner" Fails a 2026 Audit

A banner is a UI. A consent tool is enforcement. The three banner types we see in audits, a two-minute Global Privacy Control test, and the state-by-state reason the implied-consent notice no longer holds.

July 2026 Read →
Privacy Research
Why Restaurant Websites Score Worst On Privacy, And It Is Not Carelessness

Across 18,524 scored sites, restaurants averaged 9.8 out of 100 on privacy and ecommerce averaged 22.8. The gap is not effort. It is how much of a restaurant funnel runs on domains the brand does not own.

August 2026 Read →