GDPR Compliance Statistics
Aggregate data from 442 website scans — tracking consent violations, third-party trackers, and compliance scores across the web.
Data recalculated daily.
442
Websites scanned
72/100
Avg compliance score
0 = worst · 100 = best
7%
Fire trackers before consent
44%
Fully compliant
How many websites are GDPR compliant?
Compliance level assigned to each scanned website based on the severity and number of issues detected.
What percentage of websites track users before consent?
A tracker “fires before consent” when it sends a network data request within the first 500ms of page load — before the user has seen or interacted with a consent banner.
7%
Fire trackers before consent
32 of 442 sites
20%
Missing a reject option
87 of 442 sites
15%
Have no consent banner
68 of 442 sites
Under GDPR, any tracking technology that collects or transmits personal data requires prior informed consent. The EU's “reject must be as easy as accept” requirement means a site cannot offer only an Accept button.
What are the most common GDPR violations?
Ranked by the number of scanned websites where each issue was detected.
| # | Violation | Affected sites |
|---|---|---|
| 1 | Tag manager present — verify all tags respect consent | 256(58%) |
| 2 | Advertising / remarketing trackers detected | 196(44%) |
| 3 | Long-lived cookies detected | 166(38%) |
| 4 | Third-party cookies detected | 160(36%) |
| 5 | Consent banner missing reject option | 87(20%) |
| 6 | No cookie consent banner detected | 68(15%) |
| 7 | Tag manager detected with no consent mechanism | 48(11%) |
| 8 | Google Conversion Linker tracking cookie present — verify consent gating | 37(8%) |
| 9 | Cookies set before consent | 30(7%) |
| 10 | Reject button could not be verified — cross-origin CMP iframe | 17(4%) |
Which trackers are most commonly found?
Number of scanned websites where each third-party tracking technology was detected. Includes trackers found both before and after consent.
How are compliance scores distributed?
Each website receives a 0–100 compliance score. A score above 80 indicates good compliance; below 40 indicates significant active violations.
Scan activity — last 12 weeks
Number of completed website scans per week.
Browse by industry
See how GDPR compliance compares across different sectors.
Methodology
- What is a scanned website?
- A unique domain that has been scanned at least once using the ConsentLens Playwright-based scanner. Statistics reflect the most recently completed scan per domain.
- How is the compliance score calculated?
- Each website receives a 0–100 score composed of four equally-weighted sub-scores: cookie consent handling, tracking transparency, third-party script management, and consent option availability.
- What does 'fires before consent' mean?
- Any tracker that sends a data-collection network request (XHR, fetch, beacon, or image pixel) within the first 500ms of page load, before the user has had the opportunity to interact with a consent interface.
- Data freshness
- Statistics are recalculated from the live database once per day. The timestamp at the top of this page shows when data was last computed.
Based on 442 completed scans.
Scan your website →