We expected a curve
Before the first crawl finished we assumed the privacy scores would form something like a bell: a few sites doing everything, a few doing nothing, and most somewhere in the middle muddling through.
Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026. 18,550 scored zero out of 100. The mean came out at 13.5.
That is not a curve. It is a pile at the bottom with a thin tail leading away from it, and the shape itself is the finding.
What a zero actually means
A zero means the scan observed tracking behaviour with nothing in front of it. No consent platform detected, no consent signal, requests going out to analytics and ad endpoints before any visitor had agreed to anything.
It is worth being precise about what it does not mean.
- It does not mean the site is breaking a law. Many of these sites are not subject to any consent requirement at all, and that is counsel's determination rather than ours.
- It does not mean there is no privacy policy. There usually is one, linked in the footer, describing choices the site does not actually offer.
- It does not mean anyone acted badly. In almost every case nobody decided anything. The tags arrived one at a time, with a booking widget, a chat tool, a remarketing pixel added for a campaign three years ago.
A zero is an ownership outcome, not a technical failure. Nobody was ever asked the question.
Why the middle is empty
The score is built from states a browser can observe, and those states are close to binary. A tag either waits for a consent signal or it does not. There is no half-wired condition that earns half the points, because from outside the browser a half-wired site and an unwired site produce the same observation: tracking happened.
So the distribution has a pile at zero, a thin scattering through the middle, and a small cluster at the top. We took that shape apart in more detail in privacy scores do not have a middle.
Restaurants are the worst-scoring group, and it is not carelessness
The restaurant cut is the deepest in the index: 31,167 sites at a mean of 9.9, with 82.4% in the Unprotected tier, meaning neither a consent platform nor a privacy preferences link was detected.
The reason is structural rather than cultural. A restaurant website is rarely one website. It is a template from a hospitality vendor, an ordering widget from a second vendor, a reservation system from a third, a loyalty script from a fourth, and a marketing pixel added by whoever ran the last campaign. Each of those arrives with its own tags, and no single party has edit access to all of them. We wrote that up at length in why restaurant websites score worst on privacy.
Three checks, ten minutes, no tooling
- Fresh private window, network tab open before the page loads, touch nothing. Filter for anything going to an analytics or advertising domain. Everything you see here fired before the visitor agreed to anything.
- If a banner appeared, decline it, reload and browse two or three pages. Look again. This is the check that catches the most common failure, and it is the one almost nobody runs.
- Open one Google request and read the whole query string. If there is no consent state in it, no signal is being transmitted, regardless of what any dashboard says.
Ten minutes gets you a defensible answer about your own site. Nothing in that procedure needs a licence, an account or a vendor.
What a good result looks like
A good result is not a green badge. It is a short, testable sentence: no analytics or advertising request leaves this site before a visitor makes a choice, and none leaves after a refusal.
Which is also why "our consent platform handles it" is not a result. A consent platform renders a choice and records an answer. Something in your own tag container still has to read that answer and act on it, and that part is configuration nobody else can do for you. The category distinction is in a cookie banner is not a consent tool.
Of the 1,475 sites in this index where a consent platform was detected, 620 still tracked before consent or after a refusal. Having the tool was not the same as the tool doing anything.
Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.