Our scanner has been running since April. It analysed 1,068 websites between 11 April and 5 September 2026, and today I am publishing what came out of it, as a barometer I intend to keep up every quarter.
The headline figure: at least 12.9% of those sites load tracking cookies without valid consent. Either no banner appears at all while trackers are being set (12.3%), or a banner is there but the trackers fire before the visitor has chosen (5.3%). Combined per site, because forty-four sites manage both.
Why that figure and not another
I had two other headlines first, and both were wrong.
The first said 13% of the sites tested had no legal documents at all. On checking, that 13% turned out to be our own score cap: our scanner caps any site without a privacy policy page at 45 out of 100, whatever its other merits. Forty per cent of recent sites land on that exact value. That is not a distribution, it is a ceiling, and its average means nothing.
The second compared France and Germany: 65% against 20% of sites with no privacy policy page. A forty-five point gap makes a fine headline. Except that our scanner detects pages, not clauses. A French site that informs its visitors inside its legal notice page, which is the convention there, is counted as having no privacy policy. Yet GDPR Article 13 requires the information to be provided, not to have a page of its own. Since the German convention is the separate page, the gap mostly measures two ways of presenting the same information.
What settled it: the two indicators that do not depend on page layout show only 4 and 5 points of difference between the two countries. A forty-five point gap on the one indicator sensitive to presentation is the signature of an instrument defect, not of a difference in practice. So I am publishing no country comparison this time, and fixing the scanner before the next edition.
The documents, with their caveat
Under that caveat, and using the tool’s exact wording rather than an interpretation of it:
- 46.3% of sites: no privacy policy page detected
- 40.5%: no cookie policy page detected
Both figures probably overstate the real problem, for the reason above. I am publishing them anyway, because leaving them out would have meant showing only what suits me.
What I do not know
A statistic quoted without its method is a statistic nobody can defend on my behalf. So, what this barometer cannot say:
The sample is not representative. These are sites someone came to test for compliance, so people already worried about their own. No weighting would change that, which is why the exact framing is “across 1,068 sites submitted to our scanner”, never “X% of European small businesses”.
Our country detection is wrong 8.5% of the time where it can be checked. I publish that because it is what made me keep the country domain rather than the inference.
The scanner changed mid-period, on 19 July. Every published rate was checked stable on both sides of that switch; the ones that were not have been removed rather than averaged — a rate that moves twenty points between two versions of the tool is the figure of neither half.
The dataset is open
The aggregated figures are downloadable as JSON, with the method inside the file. No personal data leaves: no domain, no address, no company name.
Next edition in December, adding the real market share of consent platforms among small sites — a measurement nobody publishes, because the existing studies cover the top million most-visited sites, which is to say not ours.
If you want to know where your own site stands, the scanner is free. And if trackers are your concern, I have written elsewhere about the 37 trackers a banner must block and what a site without a cookie policy risks.
Yann