239 sites out of 47,419
Our Website Privacy Index scanned 47,505 public websites and scored 47,419, January to September 2026, with a mean privacy score of 13.5 out of 100. Sorting every one of them by the mechanism the scan observed gives four groups.
| Tier | Sites | Share |
|---|---|---|
| Gated | 239 | 0.5% |
| Partial | 1,236 | 2.6% |
| Exposed | 12,828 | 27.1% |
| Unprotected | 33,116 | 69.8% |
Rawsoft Website Privacy Index. n = 47,419 scored sites, scanned January to September 2026.
Half of one percent. That is the hook, and the rest of this piece is about the word that usually gets used instead.
The four tiers in plain language
- Gated. A consent platform was detected, a Consent Mode v2 signal was observed, and no tracking was seen before consent or after denial.
- Partial. A consent platform was detected, but with gaps: no Consent Mode v2 signal, or tracking seen anyway.
- Exposed. No consent platform detected, though a privacy or cookie preferences link was found.
- Unprotected. Neither a consent platform nor a privacy preferences link detected.
These are assigned from observed tag behaviour, not from a questionnaire, a self-declaration or a vendor's dashboard. They describe a mechanism, not a company.
The substitution this piece is arguing for
"Compliant" is a legal conclusion. It depends on which jurisdiction applies, what categories of data are involved, what the purpose is, and how counsel reads all of that against a specific set of facts. It is not a property of a web page.
"Gated" is a fact about a page. A tag either fires before a decision or it does not, and anyone with a browser can reproduce the answer in four minutes.
We will say the uncomfortable half out loud: we cannot supply the first one. Rawsoft is a technology firm, not a law firm. We can tell you precisely what your tags do and when. Whether that satisfies an obligation is your counsel's call, and any supplier who tells you otherwise has sold you something that cannot be tested.
Why the two get conflated
Not because buyers are careless. Because the banner is the visible artifact.
It renders. It can be screenshotted. It can be put in a slide and shown to a board, a client or an internal stakeholder as evidence that the thing was handled. The gate has none of those properties. It is invisible, it lives in a tag container, and the only way to show it working is to open a network tab, which nobody does in a steering meeting.
The measured gap
Of the 1,475 sites where a consent platform was detected, 620 (42.0%) tracked anyway, either before any interaction or after a refusal.
Every one of those sites had already done the visible part. Someone chose a platform, paid for it, installed it and signed it off. The mechanism behind why that is not enough is in the piece on banner blocking, and the enforcement side in privacy enforcement comes down to the opt-out.
The four-minute check
- Fresh private window. Reject everything. Watch the network tab for what still sends. Installed and sending are different states, and this is the one check that separates them.
- Read the full query string on one Google request. A tag firing and a tag firing with a consent signal look identical in a tag assistant. They do not look identical in the request.
If requests go out after a refusal, the site is not gated, whatever anyone has been told. If they do not, it is gated, which is a real and useful thing to know and still not a legal conclusion.
A sentence that survives being questioned
"The tags on this site do not fire before a decision is made, and here is the network trace." That one holds up in front of anybody, because it is falsifiable and it was tested.
"We are compliant." That one does not, because it was never the speaker's to say, and the first person to ask under which law, in which jurisdiction, for which data category will end the conversation.
Who would notice
The last question is the one worth taking away. If the gate on your site stopped holding tomorrow, because of a new tag, a template change or a publish nobody flagged, who at your organization would notice, and would anything tell them?
A consent gate is not a certificate, it is a state that can stop being true on any publish. That is the case for watching it continuously rather than auditing it once, which is what Managed Privacy is for. If you would rather start with a single look at the whole tag layer, book a data and tracking audit.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.