Privacy Research

Why 18,550 Websites Scored Zero On Privacy, And What That Actually Means

By Rawsoft Team | September 2026 | 8 min read

We expected a curve

Before the first crawl finished we assumed the privacy scores would form something like a bell: a few sites doing everything, a few doing nothing, and most somewhere in the middle muddling through.

Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026. 18,550 scored zero out of 100. The mean came out at 13.5.

That is not a curve. It is a pile at the bottom with a thin tail leading away from it, and the shape itself is the finding.

What a zero actually means

A zero means the scan observed tracking behaviour with nothing in front of it. No consent platform detected, no consent signal, requests going out to analytics and ad endpoints before any visitor had agreed to anything.

It is worth being precise about what it does not mean.

A zero is an ownership outcome, not a technical failure. Nobody was ever asked the question.

Why the middle is empty

The score is built from states a browser can observe, and those states are close to binary. A tag either waits for a consent signal or it does not. There is no half-wired condition that earns half the points, because from outside the browser a half-wired site and an unwired site produce the same observation: tracking happened.

So the distribution has a pile at zero, a thin scattering through the middle, and a small cluster at the top. We took that shape apart in more detail in privacy scores do not have a middle.

Restaurants are the worst-scoring group, and it is not carelessness

The restaurant cut is the deepest in the index: 31,167 sites at a mean of 9.9, with 82.4% in the Unprotected tier, meaning neither a consent platform nor a privacy preferences link was detected.

The reason is structural rather than cultural. A restaurant website is rarely one website. It is a template from a hospitality vendor, an ordering widget from a second vendor, a reservation system from a third, a loyalty script from a fourth, and a marketing pixel added by whoever ran the last campaign. Each of those arrives with its own tags, and no single party has edit access to all of them. We wrote that up at length in why restaurant websites score worst on privacy.

Three checks, ten minutes, no tooling

  1. Fresh private window, network tab open before the page loads, touch nothing. Filter for anything going to an analytics or advertising domain. Everything you see here fired before the visitor agreed to anything.
  2. If a banner appeared, decline it, reload and browse two or three pages. Look again. This is the check that catches the most common failure, and it is the one almost nobody runs.
  3. Open one Google request and read the whole query string. If there is no consent state in it, no signal is being transmitted, regardless of what any dashboard says.

Ten minutes gets you a defensible answer about your own site. Nothing in that procedure needs a licence, an account or a vendor.

What a good result looks like

A good result is not a green badge. It is a short, testable sentence: no analytics or advertising request leaves this site before a visitor makes a choice, and none leaves after a refusal.

Which is also why "our consent platform handles it" is not a result. A consent platform renders a choice and records an answer. Something in your own tag container still has to read that answer and act on it, and that part is configuration nobody else can do for you. The category distinction is in a cookie banner is not a consent tool.

Of the 1,475 sites in this index where a consent platform was detected, 620 still tracked before consent or after a refusal. Having the tool was not the same as the tool doing anything.

Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy Research
Why Restaurant Websites Score Worst On Privacy, And It Is Not Carelessness

Across 18,524 scored sites, restaurants averaged 9.8 out of 100 on privacy and ecommerce averaged 22.8. The gap is not effort. It is how much of a restaurant funnel runs on domains the brand does not own.

August 2026 Read →
Privacy
Cookie Banner vs. Consent Tool: Why "We Have a Banner" Fails a 2026 Audit

A banner is a UI. A consent tool is enforcement. The three banner types we see in audits, a two-minute Global Privacy Control test, and the state-by-state reason the implied-consent notice no longer holds.

July 2026 Read →