Roughly eleven to one
Of the 47,419 sites scored in our Website Privacy Index, 23,307 were running Google tags with no Consent Mode signal at all and 2,108 were sending a working Consent Mode v2 signal. The crawl ran January to September 2026 across restaurant, hospitality and independent ecommerce sites.
Those are two independent counts, not two halves of one population, and the ratio between them is roughly eleven to one the wrong way.
The easy explanations do not survive contact
It is not cost. The setting is free. It is not difficulty: this is configuration in a tag container, not engineering. And it is not ignorance, because Consent Mode has been documented, blogged about and required for EEA advertisers for years.
Which leaves the organizational question, and that is the one worth asking.
Two functions, two scoreboards
The privacy function owns whether a decline is honoured. It is measured on whether the banner exists, renders correctly, records a choice and matches the policy. Its review tests the consent layer.
The media function owns whether the account numbers mean anything. It is measured on spend efficiency, conversion volume and attribution. Its review tests the ad account.
Both of those are reasonable jobs, reasonably scoped. Neither is being lazy. The trouble is that the one setting connecting them is not inside either scope.
The orphaned artifact
The consent signal is configured in a tag container. So ask three questions about that container, in this order:
- Who has edit access to it?
- Who signs off a publish?
- Which of the two functions does that person report to?
In most organizations the honest answer to the third is neither, and quite often the container is administered by an agency that reports to a third function again. The artifact that decides what happens when a visitor declines sits in a tool with no line into the privacy org chart and no line into the media one.
Why both reviews pass
This is the part that costs real money, and it is not anybody's fault.
A privacy review scoped to the consent layer confirms the consent layer. The banner is there, the decline is recorded, the policy matches. Pass.
A media audit scoped to the ad account confirms the ad account. Campaigns are structured, conversions import, the tracking template is right. Pass.
Each review is correct within its scope, and the defect lives between the scopes. That is why an organization can buy both reviews, act on both sets of findings, and still send nothing when a visitor declines. Nobody was asked the question, because the question does not belong to either brief.
The mechanical side of what goes missing is covered in more than a third of cookie banners do not block anything, and the enforcement angle in privacy enforcement comes down to the opt-out. We will not restate either here.
What owning it actually means
Not a policy document. Three concrete things:
- One named person. Not a team, not a vendor, not a shared mailbox. A person who can be asked and can answer.
- A written answer to one question: when a visitor declines, what do we send? If the answer is a product name, nobody has answered the question.
- The check placed in whichever review happens more often. Consent state breaks on publishes, not on calendar quarters, so an annual review will always be looking at a different site than the one that broke.
Two checks, both free
- Fresh private window. Decline everything. Then open one Google request in the network tab and read the whole query string. You are not looking for whether the tag fired. You are looking for whether any consent parameters are present at all. A tag that fires with no consent state looks identical to a correct one in most tag debuggers.
- Ask whoever owns the container: when a visitor declines, what do we send Google? A vendor name is not an answer. A description of what happens to the request is.
The reframe
The question in most rooms is which consent platform to buy. On these numbers that was never the part in doubt. The question is whose name goes next to the signal, and it is answerable this afternoon without spending anything.
Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.