Consent Theater: 93% of Sites With Cookie Banners Start Tracking Before You Click Anything
The State of Consumer-Web Surveillance & Compliance, 2026 — a Public Vector data report
The headline finding
The cookie banner has become the web's most visible privacy ritual — and, our data shows, its emptiest one.
Between February and May 2026, we crawled 5,431 consumer-facing websites with an instrumented browser that never clicked a consent banner: no "Accept," no "Reject," no interaction at all. Of the 997 sites that displayed a cookie-consent banner, 925 — 92.8% — fired non-essential third-party trackers anyway, before the visitor touched the banner. Advertising pixels, analytics beacons, data-broker calls, and session-recording scripts were already transmitting by the time the banner finished rendering.
The banner, in other words, is theater. The tracking decision was made before the question was asked.
How we measured this. Public Vector operates an automated compliance crawler built on an instrumented Chromium browser (Playwright). It captures every network request a page makes — not cookies alone, not JavaScript tags alone, but actual outbound traffic — and matches each request against a registry of known tracking services compiled from Exodus Privacy, Disconnect, and DuckDuckGo Tracker Radar signatures.
Sample: 9,165 completed crawls of 5,431 distinct sites (drawn primarily from the Tranco popularity list), February 20 – May 21, 2026. Crawls that loaded zero pages (network failures, bot walls) were excluded — 766 of 9,931 total crawls. Crawls used no consent interaction, so every tracker observed fired without consent. Cookie-banner analysis completed on a 2,763-site subset. "Non-essential" trackers means the advertising, analytics, data-broker, session-replay, marketing, A/B-testing, and click-tracking categories — CDN, security, and infrastructure services are excluded.
Accessibility: separately, 253 consumer e-commerce sites were audited with axe-core 4.10.2 against WCAG 2.1 Level AA (tags wcag2a/wcag2aa/wcag21a/wcag21aa), May 18 – June 10, 2026.
Full per-statistic SQL, denominators, and caveats are available on request.
Finding 1: The banner is privacy theater — 92.8% track first, ask second
Of 2,763 analyzed sites, 997 (36.1%) displayed a consent banner. Among those 997 banner-showing sites, 925 (92.8%) fired at least one non-essential third-party tracker during the same crawl in which the banner appeared, with zero consent given. A consent banner on today's web is less a gate than a notification that tracking has already begun.
A second, independent measurement agrees: in 182 deeper agent-driven site audits that timestamped every network request against the moment the banner was dismissed, 137 sites (75.3%) fired non-essential trackers before dismissal — a mean of 6.7 distinct tracking services per site already running pre-consent.
Finding 2: The "Reject" option is rare
Of the 997 sites showing a banner, only 179 (18.0%) presented a visible reject or decline button. 393 (39.4%) exhibited at least one consent dark pattern — most commonly a hidden or absent reject option, or non-essential cookie categories pre-checked by default. For four out of five banner-showing sites, the only one-click choice offered is "yes."
Finding 3: Even without a banner, the tracking is on by default
Across all 5,431 sites — banner or not — 2,349 (43.2%) fired non-essential trackers with no consent interaction of any kind, and 2,679 (49.3%) made at least one detectable third-party tracking call. The reach of the largest platforms is striking: Google-owned tracking services appeared on 2,291 sites (42.2% of everything we crawled), Meta/Facebook trackers on 981 sites (18.1%), and TikTok's pixel on 262 sites (4.8%).
Finding 4: One in eight sites is recording your session
685 sites (12.6%) loaded session-replay software — tools that capture mouse movement, scrolling, keystrokes, and form interactions for later playback. Microsoft Clarity led (404 sites), followed by Hotjar (205), Crazy Egg (97), and FullStory (53). Separately, 1,879 sites (34.6%) transmitted hash-format identifiers (MD5/SHA-256 tokens consistent with hashed-email or user-ID matching) to third parties, and 99 sites sent a plaintext email address or phone number to a third-party endpoint.
Finding 5: 88.5% of audited e-commerce sites fail WCAG 2.1 AA at a serious level
Of 253 consumer e-commerce sites where our axe-core accessibility audit ran, 224 (88.5%) had at least one serious or critical WCAG 2.1 AA violation, and 137 (54.2%) had at least one critical violation. We found a mean of 10.4 serious or critical failing page elements per site (median 5; the worst, 90). The most widespread failures were insufficient color contrast (107 sites), links with no discernible name for screen readers (85 sites), and images missing alt text (59 sites). The audit shows the basics failing at scale, a decade-plus after WCAG 2.0 became the de facto ADA Title III benchmark.
What this means for litigation
Each of these findings maps onto an active theory of liability.
- Wiretap and interception claims. Session-replay tools and pixels that capture communications before any consent are the core fact pattern in California Invasion of Privacy Act (CIPA) litigation and other state analogues. Our data puts that fact pattern on roughly one in eight sites — running pre-consent on nearly all of them.
- Consent that doesn't consent. A banner that appears after tracking has begun, hides its reject option, or pre-checks non-essential categories is weak evidence of voluntary, informed agreement — relevant both to privacy claims and to whether consent-based defenses hold up.
- Sensitive-data exposure. Hashed and plaintext identifiers flowing to advertising endpoints implicate state comprehensive privacy laws, the FTC's health-and-data-broker enforcement posture, and, where health contexts are involved, HIPAA-adjacent theories.
- ADA Title III. With 88.5% of audited e-commerce sites failing WCAG 2.1 AA at serious-or-critical severity, digital-accessibility exposure remains effectively the rule, not the exception.
About Public Vector
Public Vector is a privacy-compliance intelligence platform. We crawl consumer websites and analyze mobile apps with browser-level network capture to detect tracking pixels, PII/PHI leakage, broken consent flows, dark patterns, and accessibility failures — then measure the gap between what a site actually does and what its policies say it does. We make our findings, methodology, and underlying data available to researchers, journalists, and counsel on request at publicvector.io.
— The Public Vector team
Working a case on one of these theories? Pre-vetted defendants with sealed, hash-chained evidence reports are live on our marketplace — or test any site yourself with our free scanner.
Browse the marketplace → Run a free scan →