ConsentStack Research
The State of Cookie Compliance
We ran 229 live websites through our free compliance scanner and watched what actually happened before, during, and after the consent choice.
By Ben Churchill · Published July 2026 · Behavioral research, not legal advice
showed no consent banner at all
154 of 229 sites
were fully clean under an EU consent test
8 of 217 with a conclusive verdict
passed under both EU and US visitor tests
29 of 229 sites
of banner sites still leaked after Reject
30 of 70 where Reject was clickable
Between June 21, 2026 and July 14, 2026, 229 live websites were checked with ConsentStack's free compliance scanner. The scanner loads a site twice, once as an EU visitor and once as a US visitor, and records every request that fires on page load and after the visitor clicks Accept and Reject. This is what it saw.
One thing up front, because it shapes everything below. These are sites whose owners chose to run a scan. They are not a random sample of the web, and they skew toward US, tech, and marketing-heavy businesses. Read the numbers as sites that checked themselves, not the web. Every figure carries the exact count it is based on.
On this page
Who we scanned, and who we did not
The corpus is 229 unique websites, one scan per site (the most recent), production sites only. 97% of the scans were started from a US network, and the most common domains were .com, .ai, .co, and .io, with a heavy business-software presence. That is the population that tends to both evaluate a consent tool and run a dense marketing stack, which is worth remembering when the leak rates look high.
Because the sample chose itself, treat this as a health check of sites motivated enough to look, not a census of the internet. To check how much that skews the picture, we also scanned a neutral control the same way. The next section puts the two side by side.
How this compares to the web's most-visited sites
The obvious objection to everything above is self-selection: maybe the sites that run a compliance scan are the ones already worried they have a problem. So we ran a neutral control. We started from the Tranco research ranking (a standard top-sites list built to resist gaming), using a fixed, published snapshot (list GQ4LK). Before any scan ran, so no result could influence the cut, we removed pure plumbing that serves no webpage (CDNs, DNS services, ad-delivery endpoints), keeping any domain we were unsure about. We scanned the top 250 that remained, the exact same way as everything above.
Of those 250, 70 could not be scanned: mostly non-website infrastructure, plus about a dozen large sites that block automated visitors (nytimes.com, epicgames.com, vimeo.com and similar), which almost certainly do run a banner, so if anything their absence flatters the control. Of the 180 that returned a scan, a closer look found 34 more that were infrastructure endpoints rather than real webpages (ad-serving domains, image hosts, link shorteners, hosting suffixes), which we set aside the same way. That leaves 146 real websites, 137 with a conclusive verdict.
| What the scanner saw | Sites that ran our scanner | Most-visited sites (control) |
|---|---|---|
| No consent banner | 67% | 70% |
| No banner while running trackers that need consent | 54% | 46% |
| Tracking fired before consent | 78-83% | 75% |
| Clean under both EU and US tests | 13% | 16% |
| Failed the EU consent test | 86% | 77% |
The first four rows are shares of all sites that completed a scan (229 that ran our scanner; 146 control). "Failed the EU consent test" is a share of sites with a conclusive verdict (217 and 137). At these sample sizes, differences of roughly 8 to 10 points can fall within the margin of error. Banner detection is signature-based and can miss unusual custom or full-page consent flows, which the very biggest sites are the most likely to use, so the control's no-banner share is an upper bound. The control's reject-after-click behavior is not shown: only 39 control sites showed a Reject the scanner could click, and unlike our main figure we did not hand-check those against the request logs, so the two are not comparable.
The two lists tell almost the same story. On four of the five measures the gap is within the margin of error: whichever list you look at, roughly 7 in 10 show no banner, three-quarters or more fire a tracker before consent, and fewer than 1 in 6 are clean under both tests. The one real difference is the overall EU test, where the most-visited sites do better (77% fail versus 86%), which fits: they have more resources behind their privacy programs. But even setting our strict pre-consent standard aside entirely, 46% of the most-visited sites ran trackers that need consent with no banner in front of them. If anything, the comparison shrinks the self-selection worry. The sites that scanned themselves come out somewhat worse, but the two lists fail the same tests at close to the same rates.
One more honest note. The top-sites list includes domains with little or no European audience, and as everywhere in this study a verdict describes what an EU visitor's browser experiences at a domain, not a ruling that any particular law applies to whoever runs it.
Installing a consent tool is not the same as being compliant
Only 75 of the 229 sites (33%) ran any consent tool at all. Among those 75, 84% still failed the EU test, almost always in the same way: a third-party request went out before the banner was answered. Buying the tool did not stop the data leaving.
We cannot tell you why it went out. The scanner records requests and their timing, not page source, so a tag placed above the consent gate, a tracker the tool's blocking list does not recognize, and automatic blocking left switched off all look the same to it. We name none of them, and in particular we do not default to blaming the site owner. The verdict is the same either way, and it is a failure. We are also not publishing per-vendor pass rates here, because no named tool appeared on more than about ten sites and a branded scoreboard at that size would be anecdote dressed as data. A separate study re-scans each vendor's installed base at a larger scale: Cookie Compliance by Consent Tool.
Tracking usually fires before anyone chooses
Between 78% and 83% of sites, which is 179 to 189 of the 229 (the range comes from two ways of counting the same thing, the scanner's own findings versus re-deriving from the raw per-tracker flags), fired a third-party request that needs consent before the visitor gave it. Here is the standard behind that number, and we hold it on purpose.
We count any third-party request made before consent as a problem, even when the tag is set up for Google Consent Mode and sends a cookieless "denied" ping. The reason is simple: the request still travels to the third party, and it carries the visitor's IP address. Under EU law an IP address is personal data (the EU Court of Justice said so in the Breyer case), so data has already left before anyone agreed. The cookieless "denied" state changes what the third party may store; it does not stop the connection. Some vendors argue a denied ping is fine. We disagree, and enforcement is moving in our direction: the European regulators' Google Analytics decisions focused on visitor data reaching the third party at all, and the pixel-wiretap lawsuits are built on the theory that the connection itself is the interception.
These are the trackers most often firing before consent. Google Tag Manager tops the list, but a container load is a weaker example than an actual measurement or advertising call, so the sharpest cases are Google Analytics and the Meta Pixel just below it.
- Google Tag Managerb156 sites · 68%
- Google Analytics98 sites · 43%
- Meta Pixel76 sites · 33%
- Google Ad Manager76 sites · 33%
- LinkedIn Insight Tag59 sites · 26%
- HubSpot Forms44 sites · 19%
- HubSpot Marketing43 sites · 19%
- HubSpot Analytics40 sites · 17%
- Microsoft Clarity37 sites · 16%
- Google Ads28 sites · 12%
- Share of 229 scanned sites.
b Google Tag Manager is a container rather than a tracker in itself. Its load is still a third-party request to Google that carries the visitor's IP, but read the analytics and advertising rows below it as the sharper examples.
The banner is often theater, and Reject does not always work
A banner is only worth something if clicking Reject actually stops the tracking. Of the 70 banner sites where the scanner could reach and click Reject, 30 (43%) kept a genuine third-party tracker firing afterward. The two most common were Microsoft Clarity, which records sessions, and the Meta Pixel, which sits at the center of the pixel and wiretap lawsuits.
- Microsoft Clarity12 sites · 17%
- Meta Pixel11 sites · 16%
- HubSpot Marketing Hub6 sites · 9%
- PostHog5 sites · 7%
- Share of 70 sites where Reject was clickable.
Charted are the trackers seen leaking on five or more sites. A smaller tail (X Ads, Reddit Pixel, and Intercom) kept firing on a few sites each.
We publish the conservative count. The scanner flagged 35 sites leaking after Reject, and we hand-checked every one against the saved request logs: all 35 requests were really there. We then set 5 aside because the request that fired was a consent tool's own call to record the rejection, or an accessibility widget, rather than tracking. The 30 above are the unambiguous cases.
How we tested
Every result here is behavioral. The scanner describes what fired and when, not what a court would decide. For each site it opens a fresh browser, loads the page as an EU visitor and again as a US visitor, and records the third-party requests on page load and after clicking Accept and Reject. A region is marked non-compliant when there is no banner in front of trackers that need consent, when a tracker fires before the banner is answered, or when Reject does not stop tracking.
A few things worth stating plainly about where and how the scan runs. Each site is loaded from two real vantage points, both DigitalOcean servers on AS14061: a European one in Frankfurt, Germany (FRA1) and a US one in San Francisco, California (SFO3). The US vantage is a genuine California IP, so a notice a site shows only to California visitors is one we would actually see. Even so, the US figures are not a formal CCPA compliance rate: California law is opt-out, meaning a tracker may fire before the visitor chooses and only has to stop if they opt out, so we hold the strict opt-in standard to the EU verdict only. The scanner also does not send Global Privacy Control signals, the one opt-out channel California actually mandates, so that channel is out of scope here. And banner detection can miss an unusual custom or shadow-DOM banner, which would show up as a false "no banner."
We hand-checked the verdicts against the saved request logs before publishing: all 35 reject-leak verdicts (every one, not a sample) and a random 25-site sample of the no-banner verdicts. Every flagged request was present in the logs; the audit is what moved the reject-leak count to its conservative 30. The exact rules the scanner applies to reach each verdict are written out in full just below, and we scanned a neutral control of the web's most-visited sites the same way (see the section on the web's most-visited sites).
Every figure on this page names its exact count and denominator, so you can check the arithmetic yourself. If you want the method in one line: we tested 229 self-selected sites the way a visitor experiences them, and reported the aggregates.
How a verdict is decided
Every verdict on this page comes from a fixed set of rules, the same ones the public scanner applies to any site. Here they are in full, so you can trace how any single result was reached.
What counts as tracking that needs consent. A request to a third party, or a cookie, in an analytics, advertising, or marketing category. Strictly-necessary things are exempt and never count against a site: its own first-party cookies, security and anti-abuse cookies (Cloudflare's bot-management cookies, Google reCAPTCHA), and the consent tool's own files. A site running only those is treated as having nothing to consent about.
- There is no consent banner, and the site runs tracking that needs consent.
- A consent tool is present but gives the visitor no way to reject.
- A tracker that needs consent keeps firing after the visitor clicks Reject (the tool leaks), or the tool blocks everything even after Accept (it is broken).
- EU test only: any tracker that needs consent fires before the visitor answers the banner.
A region passes when a banner holds tracking until the visitor chooses and honors Reject, or when there is no banner because the site runs nothing that needs consent. A tool that is stricter than the law requires (it blocks even after Accept, or runs an opt-in flow in the US where opt-out would allow tracking by default) is treated as a usability quirk, not a violation, and is not counted against the site.
Why EU and US verdicts differ. The EU test is opt-in: nothing that needs consent may fire before the visitor agrees. The US test follows California's opt-out model, where a tracker may fire before the choice and only has to stop once the visitor opts out, so only trackers that keep firing after Reject count against a site. The same site can pass one test and fail the other, which is why we never turn the US results into a CCPA compliance rate.
What this means for your site
A banner that shows up is not the same as a banner that works. If you are not sure which one you have, the same scanner behind this study will check your site in a minute or two and show you exactly which trackers fire before consent and which keep firing after Reject. No signup, no email.
Questions and answers
Limitations
- Self-selected sample. Sites whose owners chose to run a free scan, skewed US and tech. Generalize only to sites that get scanned. The neutral top-sites control above shows how much that skew moves the numbers: only modestly, and the most-visited sites fail most of the same tests too.
- Small overall, tiny per tool. 229 sites in total, at most about ten sites per named consent tool. Aggregate patterns are strong; per-vendor numbers are not published.
- A snapshot, not a trend. about three and a half weeks of scans. The recurring version will track change over time.
- Behavioral, not legal. The scanner cannot see the legal bases a site may claim, private processor agreements, or server-side consent. It reports what happened. For cookies and device access, EU law requires consent before they load regardless of the basis claimed (the EU Court of Justice Planet49 ruling and European Data Protection Board guidance), which is why the pre-consent findings are on solid ground.
- US and GPC scope. Our US vantage is a California IP, but California law is opt-out and Global Privacy Control is not tested, so the US findings are behavioral, not a formal CCPA compliance rate.
This is a behavioral research study, not legal advice, and no individual site was reviewed by a lawyer. Legal statements are attributed to primary sources such as the EU Court of Justice, the European Data Protection Board, and state regulators. For your own obligations, talk to qualified counsel.
See where your site leaks consent
Run a free compliance scan against EU and US rules. No signup required.
Just want the cookie list? Run the free cookie checker to see every cookie and tracker a site sets, and which ones fire before consent.
100+ happy customers
Find out where your site stands
Run the same scanner behind this study against your own site. See which trackers fire before consent and which ignore Reject, in a minute or two, with no signup.