Privacy Research

More Sites Send A Correct Consent Signal Than Own A Consent Platform

By Rawsoft Team | September 2026 | 7 min read

The number that goes the wrong way round

Across the 47,419 sites scored in our Website Privacy Index, a consent platform was detected on 1,475 of them, and 2,108 showed a working Consent Mode v2 signal. Scanned January to September 2026, across restaurant, hospitality and independent ecommerce.

The population doing the thing correctly is larger than the population that bought a tool to do it.

What a consent platform actually does

It renders a choice and records an answer. That is the whole job, and it is a real job done well by a number of products.

What it does not do, on its own, is stop a tag from firing. That part happens somewhere else.

Where the gating actually lives

It lives in your own tag container, in decisions nobody outside it can make for you:

Those are configuration decisions about your own tags, not features you can buy. A consent platform can supply the answer; something in your container still has to read it. That is the distinction we took apart in a cookie banner is not a consent tool.

The finding runs in both directions

Direction one. 2,108 sites sent a working signal and 1,475 had a platform detected. So at least 633 sites signalled correctly with no consent platform in evidence. Somebody wired it by hand. That group is the interesting one, not the embarrassing one, because it proves the work is doable without a purchase order.

Direction two. Of the 1,475 sites where a platform was detected, 620 still fired tracking before any interaction or carried on after a refusal. That is 42.0%, and the banner results page splits it further.

Read together, the two directions say the same thing from opposite ends. Buying the tool neither guarantees the outcome nor is required for it.

Why procurement produces nothing measurable here

The purchase decision and the enforcement decision are different decisions. They are made by different people, at different times, and only one of them appears on a purchase order.

A procurement process can compare vendors on price, support, jurisdictional coverage and integrations, and it will do that honestly. It has no mechanism for asking whether the twelve tags already in the container will be rewired to read the answer, because that is not something a vendor can commit to on the reader's behalf.

The caveat, in our own voice

Detection is not omniscience. A consent platform the scanner could not fingerprint reads in our data as no platform detected, which is why "at least 633" is a floor and not a count. A site running a custom-built consent layer, or a white-labelled one, would land in exactly that gap.

The two counts are also independent. We are not claiming the populations are disjoint, and we are not claiming one contains the other. The only safe reading is the one stated at the top: the signalling population is larger than the platform population.

Two checks worth running today

  1. Fresh private window, decline everything, then read the full query string on one Google request. Look for whether consent parameters are present at all, rather than whether the tag fired.
  2. Ask the person who owns your tag container what happens to a Google request when a visitor declines. A mechanism is an answer. A vendor name is not.

What the two groups prove together

One group got the signal right with no platform we could see. The other bought a platform and still tracked. Between them they establish that the tool is not the mechanism, and that the only thing worth asking about a site is what its tags actually do when somebody says no.

Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Cookie Banner vs. Consent Tool: Why "We Have a Banner" Fails a 2026 Audit

A banner is a UI. A consent tool is enforcement. The three banner types we see in audits, a two-minute Global Privacy Control test, and the state-by-state reason the implied-consent notice no longer holds.

July 2026 Read →
Privacy Research
More Than A Third Of Cookie Banners Do Not Block Anything

Of 18,524 sites we scored, 1,024 showed a cookie banner and 387 of those tracked the visitor anyway. The problem is not the sites with no consent tooling. It is the ones that bought it, deployed it, and are protected by none of it.

August 2026 Read →