← Public Vector

Data report — June 2026

Consent Theater: 93% of Sites With Cookie Banners Start Tracking Before You Click Anything

The State of Consumer-Web Surveillance & Compliance, 2026 — a Public Vector data report

The headline finding

The cookie banner has become the web's most visible privacy ritual — and, our data shows, its emptiest one.

Between February and May 2026, we crawled 5,431 consumer-facing websites with an instrumented browser that never clicked a consent banner: no "Accept," no "Reject," no interaction at all. Of the 997 sites that displayed a cookie-consent banner, 925 — 92.8% — fired non-essential third-party trackers anyway, before the visitor touched the banner. Advertising pixels, analytics beacons, data-broker calls, and session-recording scripts were already transmitting by the time the banner finished rendering.

The banner, in other words, is theater. The tracking decision was made before the question was asked.

How we measured this. Public Vector operates an automated compliance crawler built on an instrumented Chromium browser (Playwright). It captures every network request a page makes — not cookies alone, not JavaScript tags alone, but actual outbound traffic — and matches each request against a registry of known tracking services compiled from Exodus Privacy, Disconnect, and DuckDuckGo Tracker Radar signatures.

Sample: 9,165 completed crawls of 5,431 distinct sites (drawn primarily from the Tranco popularity list), February 20 – May 21, 2026. Crawls that loaded zero pages (network failures, bot walls) were excluded — 766 of 9,931 total crawls. Crawls used no consent interaction, so every tracker observed fired without consent. Cookie-banner analysis completed on a 2,763-site subset. "Non-essential" trackers means the advertising, analytics, data-broker, session-replay, marketing, A/B-testing, and click-tracking categories — CDN, security, and infrastructure services are excluded.

Accessibility: separately, 253 consumer e-commerce sites were audited with axe-core 4.10.2 against WCAG 2.1 Level AA (tags wcag2a/wcag2aa/wcag21a/wcag21aa), May 18 – June 10, 2026.

Full per-statistic SQL, denominators, and caveats are available on request.

Finding 1: The banner is privacy theater — 92.8% track first, ask second

Of 2,763 analyzed sites, 997 (36.1%) displayed a consent banner. Among those 997 banner-showing sites, 925 (92.8%) fired at least one non-essential third-party tracker during the same crawl in which the banner appeared, with zero consent given. A consent banner on today's web is less a gate than a notification that tracking has already begun.

A second, independent measurement agrees: in 182 deeper agent-driven site audits that timestamped every network request against the moment the banner was dismissed, 137 sites (75.3%) fired non-essential trackers before dismissal — a mean of 6.7 distinct tracking services per site already running pre-consent.

Finding 2: The "Reject" option is rare

Of the 997 sites showing a banner, only 179 (18.0%) presented a visible reject or decline button. 393 (39.4%) exhibited at least one consent dark pattern — most commonly a hidden or absent reject option, or non-essential cookie categories pre-checked by default. For four out of five banner-showing sites, the only one-click choice offered is "yes."

Finding 3: Even without a banner, the tracking is on by default

Across all 5,431 sites — banner or not — 2,349 (43.2%) fired non-essential trackers with no consent interaction of any kind, and 2,679 (49.3%) made at least one detectable third-party tracking call. The reach of the largest platforms is striking: Google-owned tracking services appeared on 2,291 sites (42.2% of everything we crawled), Meta/Facebook trackers on 981 sites (18.1%), and TikTok's pixel on 262 sites (4.8%).

Finding 4: One in eight sites is recording your session

685 sites (12.6%) loaded session-replay software — tools that capture mouse movement, scrolling, keystrokes, and form interactions for later playback. Microsoft Clarity led (404 sites), followed by Hotjar (205), Crazy Egg (97), and FullStory (53). Separately, 1,879 sites (34.6%) transmitted hash-format identifiers (MD5/SHA-256 tokens consistent with hashed-email or user-ID matching) to third parties, and 99 sites sent a plaintext email address or phone number to a third-party endpoint.

Finding 5: 88.5% of audited e-commerce sites fail WCAG 2.1 AA at a serious level

Of 253 consumer e-commerce sites where our axe-core accessibility audit ran, 224 (88.5%) had at least one serious or critical WCAG 2.1 AA violation, and 137 (54.2%) had at least one critical violation. We found a mean of 10.4 serious or critical failing page elements per site (median 5; the worst, 90). The most widespread failures were insufficient color contrast (107 sites), links with no discernible name for screen readers (85 sites), and images missing alt text (59 sites). The audit shows the basics failing at scale, a decade-plus after WCAG 2.0 became the de facto ADA Title III benchmark.

What this means for litigation

Each of these findings maps onto an active theory of liability.

About Public Vector

Public Vector is a privacy-compliance intelligence platform. We crawl consumer websites and analyze mobile apps with browser-level network capture to detect tracking pixels, PII/PHI leakage, broken consent flows, dark patterns, and accessibility failures — then measure the gap between what a site actually does and what its policies say it does. We make our findings, methodology, and underlying data available to researchers, journalists, and counsel on request at publicvector.io.

— The Public Vector team

Working a case on one of these theories? Pre-vetted defendants with sealed, hash-chained evidence reports are live on our marketplace — or test any site yourself with our free scanner.

Browse the marketplace →  Run a free scan →