We wanted to know how many real websites actually respect the consent rules they claim to follow. So we ran our free GDPR scanner on 1,834 domains and logged exactly what loaded before anyone clicked a thing.
The short version: most sites we looked at track visitors, very few have a working consent step, and having a cookie banner is no guarantee the tracking is actually gated. Here are the numbers, with a strict method so you can trust them. They update automatically as we scan more sites.
What did we measure, and what counts as a leak?
We count a site as leaking only when a tracker set a cookie before consent, or when a Google tag ran with consent granted. Cookieless tags, like Google Consent Mode in its denied state or privacy-first analytics such as Plausible, do not count as a leak. That is deliberate: cookieless, consent-respecting tracking is exactly the setup we want sites to move toward. It also makes the figures below a floor, not an exaggeration.
Our scanner loads a site the way a first-time visitor would, with no clicks and no consent given. It records which known trackers fire, which cookies get set, how many third-party domains receive a request, and whether it can detect a consent management platform (CMP).
Two honest caveats. First, this is not a random sample of the web. People scan a site because they suspect a problem, so the group skews toward sites with something to find. Second, we detect CMPs by their known scripts and the standard __tcfapi signal, so a custom-coded banner we cannot see will be missed. That means our no-CMP figure is an upper bound.
How many sites had no detectable consent tool?
On 82% of the 1,834 sites we could not detect any consent management platform. Only about 18% ran a CMP we recognized. Some of the rest use a custom or self-hosted banner we cannot see, so treat 82% as a ceiling. Even so, it points to a lot of sites with no visible consent layer at all.
A missing CMP only matters if the site actually tracks people. Plenty of sites we scanned were simple brochure pages with nothing to gate. That is why the next number matters more.
How many sites fire trackers before you consent?
On 30% of all sites we scanned, a real tracker fired before any consent was given. That is with our strict definition, where the tag either set a cookie or ran with consent granted. The timing is the violation: when a tracker sends identifying data on load, a banner that appears afterward is too late to matter.
The GDPR rules on cookies are clear on the order of operations. Non-essential trackers should not run until the visitor has made a real choice. The EDPB widened this in recent guidance to cover pixels and fingerprinting too, not just cookies.
Does having a cookie banner actually fix it?
Not on its own. Among the sites that did have a detectable CMP, 36% still fired a real tracker before consent. Among sites with no CMP, the figure was 28%. In other words, installing a banner correlated with more leaking, not less.
Two things explain that. Sites that bother installing a CMP tend to be the heavier-tracking sites in the first place, so they have more to leak. And a banner only works if it actually gates the tags. A CMP that loads after Google Analytics has already fired is decoration. If you use Google tags, you also need Google Consent Mode v2 wired to that banner, or consent state never reaches Google on EU traffic.
Which trackers show up most often?
Google runs the board. Trackers owned by Google appeared on 50% of all sites, far ahead of everyone else. Meta was next at 9%, then Microsoft at 7%, LinkedIn at 4%, and Matomo at 3%. No other single owner was close.
The most common tracker owners, by share of sites:
- Google (Analytics, Tag Manager, Ads): 50%
- Meta Platforms (Meta Pixel): 9%
- Microsoft (Clarity, Ads): 7%
- LinkedIn Insight: 4%
- Matomo: 3%
When we look only at trackers that actually set a tracking cookie before consent, Google led by a wide margin at 22% of all sites, with Meta next at 6%. Everything else sat in low single digits. These are the tags most sites forget to gate, because they get pasted in during setup and never touched again.
What kinds of trackers are these?
Analytics and advertising dominate. Analytics trackers showed up on 50% of sites and advertising trackers on 34%. Marketing tools and social widgets trailed far behind. So the typical risk is not some exotic script. It is the same analytics and ad tags nearly everyone installs.
That is good news in a way. If you handle Google Analytics, Google Ads, and Meta Pixel correctly, you have covered most of the risk we saw in the data.
How many trackers does the average site load?
The average site in our scan loaded 1.6 trackers. That sounds low until you remember many sites loaded zero. About 58% of sites ran at least one tracker, and among those the count climbs fast. The heaviest single site we scanned ran 16 separate trackers on one page.
Which consent tools do the compliant sites use?
Among the sites where we did detect a CMP, two names led by a wide margin: OneTrust on 122 sites and Cookiebot on 86. CookieYes, TrustArc, and Sourcepoint followed further back. So the paid enterprise tools own the visible consent market, even though a small, well-configured banner does the same job.
That gap is the whole reason we built Consentify. If you are weighing options, our Cookiebot alternative comparison breaks down where a lighter tool fits better, especially for smaller sites that do not need enterprise pricing.
What this means for your website
The pattern across 1,834 sites is consistent. Most sites track visitors, the trackers are almost always Google or Meta, and they often fire before any consent. The banner, when it exists, frequently loads too late to matter.
You cannot fix what you cannot see, so start by scanning your own site. It takes under a minute and shows exactly which trackers fire before consent, which is the number that actually gets sites in trouble.
Want to see where your site lands? Run a free GDPR scan, then fix it with Consentify: one domain free, no watermark, no time limit.