Most of the argument is happening on 3.1% of the sample
The published conversation about consent is almost entirely a conversation about banner design. Reject-all placement. Second layers. Pre-checked boxes. Dark patterns. All of it is real, and all of it presupposes that a banner exists.
On the population we scanned, almost none of them do.
The measurement
Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026, across restaurant, hospitality and independent ecommerce sites. Read on 20 September 2026, the page reports:
- Of the 47,419 scored, 45,944 (96.9%) had no consent platform detected.
- That leaves 1,475 (3.1%) where one was detected.
- Of those 1,475, 620 (42.0%) tracked anyway, either before the visitor interacted with the banner or after a refusal.
- The mean privacy score across the whole sample was 13.5 out of 100.
Those figures reconcile, and it is worth checking rather than taking on trust: 47,419 minus 45,944 is 1,475, and that is the same 1,475 the 42.0% is drawn from.
What the 96.9% does and does not mean
It means a browser loading those pages did not find a consent platform it could detect. That is all it means.
It does not mean those sites have no privacy policy. Many do. It does not mean they are breaking a law, and a great many of them are not subject to any consent requirement in the first place. And it does not mean there is definitely nothing there, because a custom-built or unfamiliar consent layer reads to a scanner as nothing at all.
The claim is about what a browser could observe, full stop.
Why the conversation is shaped this way
Two reasons, neither of them dishonest.
The people writing about consent UX are, almost by definition, people who already have a consent platform. You do not have opinions about second-layer placement until you have a second layer.
And vendors write about the problems their product solves, which is what vendors are for. Nobody is going to publish a long analysis of the market that has not bought anything, because there is no product in that sentence.
The consequence for the tooling market
If 96.9% have nothing detectable, then the addressable problem is not upgrade your CMP. It is that these sites have never had one, and the tags have been firing the entire time, for years, with nobody having made a decision either way.
That is a different product, a different price point and a different conversation from the one the category is currently having.
And the consequence for the 3.1%
Having the tool is not the same as the tool doing anything. 620 of the 1,475 sites with a platform detected tracked anyway.
We want to be careful here: that is an observation about enforcement, not an accusation about intent. Nobody installs a consent platform in order to ignore it. The mechanism behind that gap is laid out in more than a third of cookie banners do not block anything, and we would rather link it than re-argue it.
What would move this figure
A piece that argues from a denominator owes the reader an honest account of the denominator, so here is what our method is and is not.
- Detection is behavioural and markup-based. A differently-named script, a self-hosted build or a custom consent layer can go unrecognised and will be recorded as nothing detected.
- It runs at one moment, on one page set. A consent layer that loads only on certain templates, or after an interaction we did not perform, is invisible to it.
- Geography changes what a site serves. Many sites show a consent layer to European visitors and nothing to anyone else. Our crawl is not a European visitor.
- The sample is three verticals, not the web. Restaurant, hospitality and independent ecommerce sites are not a random draw, and the figure would move in either direction on a different population. The restaurant cut alone is covered in why restaurant websites score worst on privacy.
Any of those would push the detected share up. We would expect the true figure to be somewhat higher than 3.1% and nowhere near high enough to change the argument.
Two checks, before any pitch
- Fresh private window, network tab open before the page loads, touch nothing. Watch what goes out while you have agreed to nothing.
- Decline everything, reload, browse, watch again. That second one is where most of the 620 were found.
The question underneath all of it
If the consent layer on your site stopped working tomorrow, who would notice, and would anything tell them? For most of the sites in this index the honest answer is that there is nothing to stop working. For the rest, the answer is usually nobody, and no.
A consent gate is not a certificate, it is a state that can stop being true on any publish. That is the case for watching it continuously rather than auditing it once, which is what Managed Privacy is for. If you would rather start with a single look at the whole tag layer, book a data and tracking audit.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.