September 2026 edition · measured April 11, 2026 to September 5, 2026

At least 12.9% of the sites we scan load trackers without valid consent

Across 1068 sites submitted to our scanner, 918 of which returned a usable detailed report.

These sites are not a sample of European small businesses. They are sites someone came to test — so people already worried about their own compliance. No weighting would make this sample representative, and I would rather say so here than in a footnote.

The figure that holds: what the site does, not what it displays

Two failings are measured in the browser, against tracking cookies actually being set. They depend on no presentation convention, and they are the only ones I will build a headline on.

Combined per site rather than added up — one site can carry both — that comes to 12.9%. Read it as a floor: the scanner does not accuse when the headless browser failed to run.

Missing documents, with the caveat that belongs to them

The scanner detects pages, not clauses. A site that informs its visitors inside its legal notice page is counted here as having no privacy policy page, whereas GDPR Article 13 requires the information to be provided, not to have a page of its own. That is a limitation of our tool, it penalises one country's presentation conventions more than another's, and it is why I publish no country comparison in this edition. It will be fixed before the next one.

What I do not know, and would rather write down

Method and data

The aggregated dataset is open, and it carries its method with it — a figure quoted without its method is a figure no one can defend.

Dataset, September 2026 edition (JSON)

If you cite it, the exact framing is: “across 1068 sites submitted to WebLegal.ai's scanner, between April 11, 2026 and September 5, 2026”. Next edition due December 2026, adding consent-platform market share.