Privacy

Gated Is Not The Same Word As Compliant

By Rawsoft Team | September 2026 | 7 min read

239 sites out of 47,419

Our Website Privacy Index scanned 47,505 public websites and scored 47,419, January to September 2026, with a mean privacy score of 13.5 out of 100. Sorting every one of them by the mechanism the scan observed gives four groups.

TierSitesShare
Gated2390.5%
Partial1,2362.6%
Exposed12,82827.1%
Unprotected33,11669.8%

Rawsoft Website Privacy Index. n = 47,419 scored sites, scanned January to September 2026.

Half of one percent. That is the hook, and the rest of this piece is about the word that usually gets used instead.

The four tiers in plain language

These are assigned from observed tag behaviour, not from a questionnaire, a self-declaration or a vendor's dashboard. They describe a mechanism, not a company.

The substitution this piece is arguing for

"Compliant" is a legal conclusion. It depends on which jurisdiction applies, what categories of data are involved, what the purpose is, and how counsel reads all of that against a specific set of facts. It is not a property of a web page.

"Gated" is a fact about a page. A tag either fires before a decision or it does not, and anyone with a browser can reproduce the answer in four minutes.

We will say the uncomfortable half out loud: we cannot supply the first one. Rawsoft is a technology firm, not a law firm. We can tell you precisely what your tags do and when. Whether that satisfies an obligation is your counsel's call, and any supplier who tells you otherwise has sold you something that cannot be tested.

Why the two get conflated

Not because buyers are careless. Because the banner is the visible artifact.

It renders. It can be screenshotted. It can be put in a slide and shown to a board, a client or an internal stakeholder as evidence that the thing was handled. The gate has none of those properties. It is invisible, it lives in a tag container, and the only way to show it working is to open a network tab, which nobody does in a steering meeting.

The measured gap

Of the 1,475 sites where a consent platform was detected, 620 (42.0%) tracked anyway, either before any interaction or after a refusal.

Every one of those sites had already done the visible part. Someone chose a platform, paid for it, installed it and signed it off. The mechanism behind why that is not enough is in the piece on banner blocking, and the enforcement side in privacy enforcement comes down to the opt-out.

The four-minute check

  1. Fresh private window. Reject everything. Watch the network tab for what still sends. Installed and sending are different states, and this is the one check that separates them.
  2. Read the full query string on one Google request. A tag firing and a tag firing with a consent signal look identical in a tag assistant. They do not look identical in the request.

If requests go out after a refusal, the site is not gated, whatever anyone has been told. If they do not, it is gated, which is a real and useful thing to know and still not a legal conclusion.

A sentence that survives being questioned

"The tags on this site do not fire before a decision is made, and here is the network trace." That one holds up in front of anybody, because it is falsifiable and it was tested.

"We are compliant." That one does not, because it was never the speaker's to say, and the first person to ask under which law, in which jurisdiction, for which data category will end the conversation.

Who would notice

The last question is the one worth taking away. If the gate on your site stopped holding tomorrow, because of a new tag, a template change or a publish nobody flagged, who at your organization would notice, and would anything tell them?

A consent gate is not a certificate, it is a state that can stop being true on any publish. That is the case for watching it continuously rather than auditing it once, which is what Managed Privacy is for. If you would rather start with a single look at the whole tag layer, book a data and tracking audit.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Is Your Consent Banner Actually Blocking Anything?

We audit 10-15 sites a week. In more than half, the banner looks great but zero scripts are actually being gated. Here's how to check yours in 5 minutes.

April 2026 Read →
Privacy
Every US Privacy Enforcement Action So Far Comes Down to One Broken Link

US state privacy enforcement hasn't hinged on missing policies or big data breaches. It keeps coming back to one thing: the opt-out. Broken "Do Not Sell" links, ignored GPC signals, and consent UIs that make declining harder than accepting.

July 2026 Read →