Research

ConsentStack Research

Cookie Compliance by Consent Tool

We scanned 912 live sites running the four most common consent tools. Across all four, roughly 9 in 10 fired a tracker before the visitor answered the banner. Installing a tool is not the same as being compliant.

By Ben Churchill · Published July 2026 · Behavioral research, not legal advice

91%

fired a third-party tracker before the visitor answered the banner

829 of 912 sites, excluding the tool's own SDK

24%

kept a tracker firing after the visitor clicked Reject

178 of 741 sites where Reject was clickable (20% of all 912)

92%

failed an EU consent test

820 of 891 sites with a conclusive verdict

6%

were clean under both EU and US visitor tests

52 of 912 sites

A common assumption is that once you install a cookie consent tool, the compliance part is handled. So we tested it. We took 912 live sites that we had confirmed were running one of the four most common consent tools, Cookiebot, OneTrust, Ketch, and CookieYes, and ran each one through ConsentStack's free compliance scanner the way an EU visitor experiences it. This is what we found.

One framing note up front, because it shapes everything below. This is a study of deployments, not products. The question is not whether a tool can block trackers correctly, it is what actually happens on the sites that run it, as they are configured. And the sites we sampled are a specific slice: businesses that fit our own customer profile, in English, with large enterprise deployments excluded. Read the numbers as "the kind of sites we sampled, as configured," not "every customer of these tools." Every figure carries the exact count it is based on.

Who we scanned, and who we did not

We started from lists of sites we had already confirmed were running each tool, then scanned a balanced group of roughly 250 per tool: 241 on Cookiebot, 241 on OneTrust, 244 on Ketch, and 186 on CookieYes. Of 951 sites we tried, 912 returned a complete scan and 39 (4.1%) could not be reached or blocked our automated browser, which we set aside rather than count. The sites skew toward the United States and United Kingdom, in English.

Two things this cohort is not. It is not a random sample of any tool's customer base: these are sales-style lists matched to the kind of business we sell to, so they lean small and mid-sized and marketing-heavy, and they leave out the large enterprise deployments that tend to have a dedicated privacy team. If anything, that pushes the fail rates up relative to each tool's whole base. And it is not a product review: every number describes what a site did as it was configured, which is a deployment question, not a verdict on the tool.

Installing a consent tool is not the same as being compliant

The clearest way to see this: unlike the web at large, almost every site here has a working banner. And it usually does not help. 91% of the 912 sites (829) fired a third-party tracker before the visitor answered the banner, even after setting aside the consent tool's own scripts. On the sites where our scanner independently re-confirmed the tool was running, the figure is higher still, between 93% and 97%.

Here is how all 912 sites split when tested as an EU visitor. The single largest group, on every one of the four tools, is the same: a consent tool is present and Reject works, but a tracking tag is placed above the consent gate and fires before the banner is answered. That is a deployment problem, not a broken tool.

How 912 sites on the four tools split under an EU-visitor test
  • Has a consent tool, Reject works, but a tracker fires before the visitor answers545 · 60%Fails
  • Has a consent tool, but a tracker keeps firing after Reject (or there is no way to reject)192 · 21%Fails
  • No banner shown, but running trackers that need consenta83 · 9%Fails
  • Has a consent tool that passes the test42 · 5%Passes
  • No banner, and none required (no trackers that need consent)29 · 3%Passes
  • Blocked or scan-limited (no conclusive verdict)21 · 2%Unclear
Fails an EU-visitor testPassesNo conclusive verdictShare of 912 scanned sites.

a "No banner shown" is a lower bound here. Signature-based detection can miss a banner rendered inline by a plugin or in the shadow DOM, so some of these sites do run a banner the scanner did not recognize. We do not treat the no-banner rate as a headline figure for that reason (see Limitations).

How the four tools compare

This is the table most people want, so here it is, with the neutral web-wide control beside it for scale. Two things to read carefully. First, the four tools land close together: on both measures the widest gap between them is not statistically significant, which is exactly why we do not crown a "worst" tool. Second, the control (the most-visited sites on the web) fails for a different reason, so it is context, not a like-for-like match: it fails mostly by having no banner at all, while the tool sites almost all have a banner and fail anyway.

Consent toolSitesFailed the EU testFired a tracker before consent
Cookiebot24192%91%
OneTrust24194%92%
Ketch24492%91%
CookieYes18689%89%
All four combined91292%91%
Most-visited sites (control)14677%75%

"Failed the EU test" is a share of sites with a conclusive verdict; "fired a tracker before consent" is a share of all of a tool's sites and excludes the tool's own SDK. The control is the web's most-visited sites (the Tranco research ranking, list GQ4LK), scanned the same way; only 30% of them run any consent tool at all, so its failures are mostly "no banner," a different mechanism from the tool sites. Cookiebot is part of Usercentrics, so this row also reflects Usercentrics deployments.

We report the reject-behavior and clean-both figures pooled across all four tools rather than tool by tool, on purpose. Broken out per tool the counts get small and the differences stop being meaningful, and a per-tool reject leaderboard on a self-selected slice would imply a precision the data does not support. The pooled numbers are in the sections that follow.

The banner is often theater, and Reject does not always work

A banner is only worth something if clicking Reject actually stops the tracking. Of the 741 sites across all four tools where the scanner could reach and click Reject, 178 (24%) kept a genuine third-party tracker firing afterward, which is 20% of all 912 sites we scanned. We report this figure pooled across the four tools, not tool by tool.

One tracker stands out. A request to Microsoft Clarity's endpoint was observed after Reject on 92 sites, more than three times the next most common (Meta Pixel, on 26), and it was the most common after-reject tracker on every one of the four tools individually. Clarity records session replays; the Meta Pixel sits at the center of the pixel and wiretap lawsuits. This describes what the sites did; it is not a claim about Microsoft or Meta.

Trackers still firing after the visitor clicked Reject
  • Microsoft Clarity92 sites · 12%
  • Meta Pixel26 sites · 4%
  • Microsoft Advertising (UET)10 sites · 1%
  • Shopify Pixel10 sites · 1%
  • HubSpot9 sites · 1%
  • TikTok Pixel9 sites · 1%
  • PostHog9 sites · 1%
  • Share of 741 sites where Reject was clickable.

Charted are the trackers seen leaking on five or more sites. A smaller tail (Klaviyo, ZoomInfo, Google Ads, LinkedIn Insight Tag, and Reddit Pixel) kept firing on a few sites each.

We publish the conservative count. We checked every one of the 597 flagged after-reject requests against the saved network logs, and all 597 were really there, not inert or blocked scripts miscounted as fired. We then set aside anything that was the consent tool's own call to record the rejection, an accessibility or chat widget, a video embed, or performance monitoring, and counted only genuine analytics and marketing trackers. The 178 above are the unambiguous cases.

Did the scanner actually see the tool?

Because we started from lists of confirmed installs, we can check the scanner against a known answer. When it loaded each site fresh, it independently re-detected the same tool on 73% to 86% of them, a strong agreement floor. That is also what makes the pre-consent numbers hard to wave away: on the sites where the scanner confirmed the tool with its own eyes, the pre-consent rate is 93% to 97%, so "you counted sites that don't really run the tool" does not explain the result.

Where the scanner did not see a banner on a site we knew had a tool installed, the honest reading is mixed: some are genuine deployment gaps (installed but not gating), and some are banners rendered in a way signature detection misses. We spot-checked and found both, so we keep the no-banner rate out of the headline numbers and treat it as an upper bound.

How we tested

Every result here is behavioral. The scanner describes what fired and when, not what a court would decide. For each site it opens a fresh browser, loads the page as an EU visitor and again as a US visitor, and records the third-party requests on page load and after clicking Accept and Reject. A region is marked non-compliant when there is no banner in front of trackers that need consent, when a tracker fires before the banner is answered, or when Reject does not stop tracking. It is the same scanner, with the same rules, behind our public tool and our earlier State of Cookie Compliance census.

Each site is loaded from two real vantage points, both DigitalOcean servers on AS14061: a European one in Frankfurt, Germany (FRA1) and a US one in San Francisco, California (SFO3). The US vantage is a genuine California IP. Even so, the US figures are not a formal CCPA compliance rate: California law is opt-out, and the scanner does not send Global Privacy Control signals, so we hold the strict opt-in standard to the EU verdict only and the clean-under- both figure is behavioral.

Before publishing, we re-derived every headline number from the scanner's stored output on three separate code paths and got the same figures each time, and we checked all 597 after-reject flags against the raw network logs. Every figure on this page names its exact count and denominator, so you can check the arithmetic yourself.

How a verdict is decided

Every verdict on this page comes from a fixed set of rules, the same ones the public scanner applies to any site. Here they are in full, so you can trace how any single result was reached.

What counts as tracking that needs consent. A request to a third party, or a cookie, in an analytics, advertising, or marketing category. Strictly-necessary things are exempt and never count against a site: its own first-party cookies, security and anti-abuse cookies, and the consent tool's own files. A site running only those is treated as having nothing to consent about.

A region is marked non-compliant when any one of these is true
  1. There is no consent banner, and the site runs tracking that needs consent.
  2. A consent tool is present but gives the visitor no way to reject.
  3. A tracker that needs consent keeps firing after the visitor clicks Reject (the tool leaks), or the tool blocks everything even after Accept (it is broken).
  4. EU test only: any tracker that needs consent fires before the visitor answers the banner.

A region passes when a banner holds tracking until the visitor chooses and honors Reject, or when there is no banner because the site runs nothing that needs consent. A tool that is stricter than the law requires (it blocks even after Accept, or runs an opt-in flow in the US where opt-out would allow tracking by default) is treated as a usability quirk, not a violation, and is not counted against the site.

What this means for your site

Your consent tool showing a banner is not the same as your consent tool working. The same scanner behind this study will check your site in a minute or two and show you exactly which trackers fire before consent and which keep firing after Reject. No signup, no email.

Questions and answers

Limitations

  • A sampled slice, not a tool's customer base. The sites are matched to our own customer profile, in English, with enterprise deployments excluded, so they are not a random sample of any tool's installs. Generalize only to sites like these. The skew tends to push fail rates up, which we state so it is not read the other way.
  • Deployments, not products. Every number describes what a site did as configured. A tool that blocks correctly on Reject can still let a tag fire on page load if the tag sits above the consent gate. Nothing here is a verdict on a tool's capabilities.
  • No per-tool ranking. The four cluster close together and the failures are deployment- driven, so we pool reject-behavior and clean-both figures across all four rather than crowning a worst tool.
  • The no-banner rate is an upper bound. Signature-based banner detection can miss a banner rendered inline by a plugin or in the shadow DOM. A spot-check found that some no-banner sites do run a banner the scanner did not recognize, which is why we keep that figure out of the headlines.
  • Behavioral, not legal. The scanner cannot see the legal bases a site may claim, private processor agreements, or server-side consent. It reports what happened. For cookies and device access, EU law requires consent before they load regardless of the basis claimed (the EU Court of Justice Planet49 ruling and European Data Protection Board guidance), which is why the pre-consent findings are on solid ground.
  • US and GPC scope. Our US vantage is a California IP, but California law is opt-out and Global Privacy Control is not tested, so the US findings are behavioral, not a formal CCPA compliance rate.

For transparency, we ran our own customers through the identical test: 5 of 5 came out clean under both the EU and US tests. That is far too small a number to rate, and it is self-selected in our favor, so we report it only as a raw count and keep it out of the comparison above. We include it because a study that measures everyone else should measure itself too.

This is a behavioral research study, not legal advice, and no individual site was reviewed by a lawyer. Legal statements are attributed to primary sources such as the EU Court of Justice, the European Data Protection Board, and state regulators. For your own obligations, talk to qualified counsel.

See where your site leaks consent

Run a free compliance scan against EU and US rules. No signup required.

2,476 sites scanned and counting

100+ happy customers

AN
ML
LP
DM
JT

Find out where your site stands

Run the same scanner behind this study against your own site. See which trackers fire before consent and which ignore Reject, in a minute or two, with no signup.

Get started free