Privacy

Nobody Owns The Wire Between Your Consent Banner And Your Ad Platform

By Rawsoft Team | September 2026 | 7 min read

Roughly eleven to one

Of the 47,419 sites scored in our Website Privacy Index, 23,307 were running Google tags with no Consent Mode signal at all and 2,108 were sending a working Consent Mode v2 signal. The crawl ran January to September 2026 across restaurant, hospitality and independent ecommerce sites.

Those are two independent counts, not two halves of one population, and the ratio between them is roughly eleven to one the wrong way.

The easy explanations do not survive contact

It is not cost. The setting is free. It is not difficulty: this is configuration in a tag container, not engineering. And it is not ignorance, because Consent Mode has been documented, blogged about and required for EEA advertisers for years.

Which leaves the organizational question, and that is the one worth asking.

Two functions, two scoreboards

The privacy function owns whether a decline is honoured. It is measured on whether the banner exists, renders correctly, records a choice and matches the policy. Its review tests the consent layer.

The media function owns whether the account numbers mean anything. It is measured on spend efficiency, conversion volume and attribution. Its review tests the ad account.

Both of those are reasonable jobs, reasonably scoped. Neither is being lazy. The trouble is that the one setting connecting them is not inside either scope.

The orphaned artifact

The consent signal is configured in a tag container. So ask three questions about that container, in this order:

  1. Who has edit access to it?
  2. Who signs off a publish?
  3. Which of the two functions does that person report to?

In most organizations the honest answer to the third is neither, and quite often the container is administered by an agency that reports to a third function again. The artifact that decides what happens when a visitor declines sits in a tool with no line into the privacy org chart and no line into the media one.

Why both reviews pass

This is the part that costs real money, and it is not anybody's fault.

A privacy review scoped to the consent layer confirms the consent layer. The banner is there, the decline is recorded, the policy matches. Pass.

A media audit scoped to the ad account confirms the ad account. Campaigns are structured, conversions import, the tracking template is right. Pass.

Each review is correct within its scope, and the defect lives between the scopes. That is why an organization can buy both reviews, act on both sets of findings, and still send nothing when a visitor declines. Nobody was asked the question, because the question does not belong to either brief.

The mechanical side of what goes missing is covered in more than a third of cookie banners do not block anything, and the enforcement angle in privacy enforcement comes down to the opt-out. We will not restate either here.

What owning it actually means

Not a policy document. Three concrete things:

  1. One named person. Not a team, not a vendor, not a shared mailbox. A person who can be asked and can answer.
  2. A written answer to one question: when a visitor declines, what do we send? If the answer is a product name, nobody has answered the question.
  3. The check placed in whichever review happens more often. Consent state breaks on publishes, not on calendar quarters, so an annual review will always be looking at a different site than the one that broke.

Two checks, both free

  1. Fresh private window. Decline everything. Then open one Google request in the network tab and read the whole query string. You are not looking for whether the tag fired. You are looking for whether any consent parameters are present at all. A tag that fires with no consent state looks identical to a correct one in most tag debuggers.
  2. Ask whoever owns the container: when a visitor declines, what do we send Google? A vendor name is not an answer. A description of what happens to the request is.

The reframe

The question in most rooms is which consent platform to buy. On these numbers that was never the part in doubt. The question is whose name goes next to the signal, and it is answerable this afternoon without spending anything.

Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Every US Privacy Enforcement Action So Far Comes Down to One Broken Link

US state privacy enforcement hasn't hinged on missing policies or big data breaches. It keeps coming back to one thing: the opt-out. Broken "Do Not Sell" links, ignored GPC signals, and consent UIs that make declining harder than accepting.

July 2026 Read →
Privacy Research
More Than A Third Of Cookie Banners Do Not Block Anything

Of 18,524 sites we scored, 1,024 showed a cookie banner and 387 of those tracked the visitor anyway. The problem is not the sites with no consent tooling. It is the ones that bought it, deployed it, and are protected by none of it.

August 2026 Read →