Research

ConsentStack Research

The State of Cookie Compliance

We ran 229 live websites through our free compliance scanner and watched what actually happened before, during, and after the consent choice.

By Ben Churchill · Published July 2026 · Behavioral research, not legal advice

67%

showed no consent banner at all

154 of 229 sites

3.7%

were fully clean under an EU consent test

8 of 217 with a conclusive verdict

13%

passed under both EU and US visitor tests

29 of 229 sites

43%

of banner sites still leaked after Reject

30 of 70 where Reject was clickable

Between June 21, 2026 and July 14, 2026, 229 live websites were checked with ConsentStack's free compliance scanner. The scanner loads a site twice, once as an EU visitor and once as a US visitor, and records every request that fires on page load and after the visitor clicks Accept and Reject. This is what it saw.

One thing up front, because it shapes everything below. These are sites whose owners chose to run a scan. They are not a random sample of the web, and they skew toward US, tech, and marketing-heavy businesses. Read the numbers as sites that checked themselves, not the web. Every figure carries the exact count it is based on.

Who we scanned, and who we did not

The corpus is 229 unique websites, one scan per site (the most recent), production sites only. 97% of the scans were started from a US network, and the most common domains were .com, .ai, .co, and .io, with a heavy business-software presence. That is the population that tends to both evaluate a consent tool and run a dense marketing stack, which is worth remembering when the leak rates look high.

Because the sample chose itself, treat this as a health check of sites motivated enough to look, not a census of the internet. To check how much that skews the picture, we also scanned a neutral control the same way. The next section puts the two side by side.

How this compares to the web's most-visited sites

The obvious objection to everything above is self-selection: maybe the sites that run a compliance scan are the ones already worried they have a problem. So we ran a neutral control. We started from the Tranco research ranking (a standard top-sites list built to resist gaming), using a fixed, published snapshot (list GQ4LK). Before any scan ran, so no result could influence the cut, we removed pure plumbing that serves no webpage (CDNs, DNS services, ad-delivery endpoints), keeping any domain we were unsure about. We scanned the top 250 that remained, the exact same way as everything above.

Of those 250, 70 could not be scanned: mostly non-website infrastructure, plus about a dozen large sites that block automated visitors (nytimes.com, epicgames.com, vimeo.com and similar), which almost certainly do run a banner, so if anything their absence flatters the control. Of the 180 that returned a scan, a closer look found 34 more that were infrastructure endpoints rather than real webpages (ad-serving domains, image hosts, link shorteners, hosting suffixes), which we set aside the same way. That leaves 146 real websites, 137 with a conclusive verdict.

What the scanner sawSites that ran our scannerMost-visited sites (control)
No consent banner67%70%
No banner while running trackers that need consent54%46%
Tracking fired before consent78-83%75%
Clean under both EU and US tests13%16%
Failed the EU consent test86%77%

The first four rows are shares of all sites that completed a scan (229 that ran our scanner; 146 control). "Failed the EU consent test" is a share of sites with a conclusive verdict (217 and 137). At these sample sizes, differences of roughly 8 to 10 points can fall within the margin of error. Banner detection is signature-based and can miss unusual custom or full-page consent flows, which the very biggest sites are the most likely to use, so the control's no-banner share is an upper bound. The control's reject-after-click behavior is not shown: only 39 control sites showed a Reject the scanner could click, and unlike our main figure we did not hand-check those against the request logs, so the two are not comparable.

The two lists tell almost the same story. On four of the five measures the gap is within the margin of error: whichever list you look at, roughly 7 in 10 show no banner, three-quarters or more fire a tracker before consent, and fewer than 1 in 6 are clean under both tests. The one real difference is the overall EU test, where the most-visited sites do better (77% fail versus 86%), which fits: they have more resources behind their privacy programs. But even setting our strict pre-consent standard aside entirely, 46% of the most-visited sites ran trackers that need consent with no banner in front of them. If anything, the comparison shrinks the self-selection worry. The sites that scanned themselves come out somewhat worse, but the two lists fail the same tests at close to the same rates.

One more honest note. The top-sites list includes domains with little or no European audience, and as everywhere in this study a verdict describes what an EU visitor's browser experiences at a domain, not a ruling that any particular law applies to whoever runs it.

Most sites have no consent banner at all

The single biggest finding is also the simplest. 154 of 229 sites (67%) showed no recognizable consent banner. And 124 of those sites, which is 54% of all 229, were tracking visitors before consent with nothing in front of it: 111 ran an analytics or marketing tracker before any banner appeared, and the rest set tracking cookies or ran other non-essential third-party scripts. Over half the sample has no consent mechanism guarding tracking that calls for one.

A fair caveat on that headline: 8 of the 154 were bot-walled scans (the site blocked our automated browser) where no banner could be observed either way. Among the 221 sites the scanner could fully load, 146 (66%) confirmed no banner. The figure barely moves, which is why it is worth stating. If you are putting a first banner in front of your own trackers, our cookie banner examples gallery covers what the design should say and the mistakes that cause most of the failures below.

Here is how all 229 sites split when tested as an EU visitor. The chart groups every site by what the scanner saw, so the sites that are fine (including the ones that correctly show no banner because they run only essential scripts) sit on the passing side.

How 229 sites split under an EU-visitor test
  • No banner shown, but running trackers that need consenta125 · 55%Fails
  • Has a consent tool, Reject works, but a tracker fires before the visitor answers33 · 14%Fails
  • Has a consent tool, but it leaks or gives no way to reject29 · 13%Fails
  • No banner, and none required (no trackers that need consent)22 · 10%Passes
  • Blocked or scan-limited (no conclusive verdict)12 · 5%Unclear
  • Has a consent tool that passes the test8 · 3%Passes
Fails an EU-visitor testPassesNo conclusive verdictShare of 229 scanned sites.

a Counted from what the EU visitor saw. The site-level count is 124 (54%), differing by one site that showed a banner only to the US visitor. Overall, 30 sites earned a passing EU verdict, 187 failed, and 12 could not be scored. Only 8 of the passing sites were clean of every flagged issue under the stricter zero-issues test, which is the 3.7% figure in the summary above.

Installing a consent tool is not the same as being compliant

Only 75 of the 229 sites (33%) ran any consent tool at all. Among those 75, 84% still failed the EU test, almost always in the same way: a third-party request went out before the banner was answered. Buying the tool did not stop the data leaving.

We cannot tell you why it went out. The scanner records requests and their timing, not page source, so a tag placed above the consent gate, a tracker the tool's blocking list does not recognize, and automatic blocking left switched off all look the same to it. We name none of them, and in particular we do not default to blaming the site owner. The verdict is the same either way, and it is a failure. We are also not publishing per-vendor pass rates here, because no named tool appeared on more than about ten sites and a branded scoreboard at that size would be anecdote dressed as data. A separate study re-scans each vendor's installed base at a larger scale: Cookie Compliance by Consent Tool.

The banner is often theater, and Reject does not always work

A banner is only worth something if clicking Reject actually stops the tracking. Of the 70 banner sites where the scanner could reach and click Reject, 30 (43%) kept a genuine third-party tracker firing afterward. The two most common were Microsoft Clarity, which records sessions, and the Meta Pixel, which sits at the center of the pixel and wiretap lawsuits.

Trackers still firing after the visitor clicked Reject
  • Microsoft Clarity12 sites · 17%
  • Meta Pixel11 sites · 16%
  • HubSpot Marketing Hub6 sites · 9%
  • PostHog5 sites · 7%
  • Share of 70 sites where Reject was clickable.

Charted are the trackers seen leaking on five or more sites. A smaller tail (X Ads, Reddit Pixel, and Intercom) kept firing on a few sites each.

We publish the conservative count. The scanner flagged 35 sites leaking after Reject, and we hand-checked every one against the saved request logs: all 35 requests were really there. We then set 5 aside because the request that fired was a consent tool's own call to record the rejection, or an accessibility widget, rather than tracking. The 30 above are the unambiguous cases.

How we tested

Every result here is behavioral. The scanner describes what fired and when, not what a court would decide. For each site it opens a fresh browser, loads the page as an EU visitor and again as a US visitor, and records the third-party requests on page load and after clicking Accept and Reject. A region is marked non-compliant when there is no banner in front of trackers that need consent, when a tracker fires before the banner is answered, or when Reject does not stop tracking.

A few things worth stating plainly about where and how the scan runs. Each site is loaded from two real vantage points, both DigitalOcean servers on AS14061: a European one in Frankfurt, Germany (FRA1) and a US one in San Francisco, California (SFO3). The US vantage is a genuine California IP, so a notice a site shows only to California visitors is one we would actually see. Even so, the US figures are not a formal CCPA compliance rate: California law is opt-out, meaning a tracker may fire before the visitor chooses and only has to stop if they opt out, so we hold the strict opt-in standard to the EU verdict only. The scanner also does not send Global Privacy Control signals, the one opt-out channel California actually mandates, so that channel is out of scope here. And banner detection can miss an unusual custom or shadow-DOM banner, which would show up as a false "no banner."

We hand-checked the verdicts against the saved request logs before publishing: all 35 reject-leak verdicts (every one, not a sample) and a random 25-site sample of the no-banner verdicts. Every flagged request was present in the logs; the audit is what moved the reject-leak count to its conservative 30. The exact rules the scanner applies to reach each verdict are written out in full just below, and we scanned a neutral control of the web's most-visited sites the same way (see the section on the web's most-visited sites).

Every figure on this page names its exact count and denominator, so you can check the arithmetic yourself. If you want the method in one line: we tested 229 self-selected sites the way a visitor experiences them, and reported the aggregates.

How a verdict is decided

Every verdict on this page comes from a fixed set of rules, the same ones the public scanner applies to any site. Here they are in full, so you can trace how any single result was reached.

What counts as tracking that needs consent. A request to a third party, or a cookie, in an analytics, advertising, or marketing category. Strictly-necessary things are exempt and never count against a site: its own first-party cookies, security and anti-abuse cookies (Cloudflare's bot-management cookies, Google reCAPTCHA), and the consent tool's own files. A site running only those is treated as having nothing to consent about.

A region is marked non-compliant when any one of these is true
  1. There is no consent banner, and the site runs tracking that needs consent.
  2. A consent tool is present but gives the visitor no way to reject.
  3. A tracker that needs consent keeps firing after the visitor clicks Reject (the tool leaks), or the tool blocks everything even after Accept (it is broken).
  4. EU test only: any tracker that needs consent fires before the visitor answers the banner.

A region passes when a banner holds tracking until the visitor chooses and honors Reject, or when there is no banner because the site runs nothing that needs consent. A tool that is stricter than the law requires (it blocks even after Accept, or runs an opt-in flow in the US where opt-out would allow tracking by default) is treated as a usability quirk, not a violation, and is not counted against the site.

Why EU and US verdicts differ. The EU test is opt-in: nothing that needs consent may fire before the visitor agrees. The US test follows California's opt-out model, where a tracker may fire before the choice and only has to stop once the visitor opts out, so only trackers that keep firing after Reject count against a site. The same site can pass one test and fail the other, which is why we never turn the US results into a CCPA compliance rate.

What this means for your site

A banner that shows up is not the same as a banner that works. If you are not sure which one you have, the same scanner behind this study will check your site in a minute or two and show you exactly which trackers fire before consent and which keep firing after Reject. No signup, no email.

Questions and answers

Limitations

  • Self-selected sample. Sites whose owners chose to run a free scan, skewed US and tech. Generalize only to sites that get scanned. The neutral top-sites control above shows how much that skew moves the numbers: only modestly, and the most-visited sites fail most of the same tests too.
  • Small overall, tiny per tool. 229 sites in total, at most about ten sites per named consent tool. Aggregate patterns are strong; per-vendor numbers are not published.
  • A snapshot, not a trend. about three and a half weeks of scans. The recurring version will track change over time.
  • Behavioral, not legal. The scanner cannot see the legal bases a site may claim, private processor agreements, or server-side consent. It reports what happened. For cookies and device access, EU law requires consent before they load regardless of the basis claimed (the EU Court of Justice Planet49 ruling and European Data Protection Board guidance), which is why the pre-consent findings are on solid ground.
  • US and GPC scope. Our US vantage is a California IP, but California law is opt-out and Global Privacy Control is not tested, so the US findings are behavioral, not a formal CCPA compliance rate.

This is a behavioral research study, not legal advice, and no individual site was reviewed by a lawyer. Legal statements are attributed to primary sources such as the EU Court of Justice, the European Data Protection Board, and state regulators. For your own obligations, talk to qualified counsel.

See where your site leaks consent

Run a free compliance scan against EU and US rules. No signup required.

2,886 sites scanned and counting

Just want the cookie list? Run the free cookie checker to see every cookie and tracker a site sets, and which ones fire before consent.

100+ happy customers

AN
ML
LP
DM
JT

Find out where your site stands

Run the same scanner behind this study against your own site. See which trackers fire before consent and which ignore Reject, in a minute or two, with no signup.

Get started free