Statable scan finds third-party trackers firing before EU consent banners load
A scan of 1,186 websites across ten European countries found that most sent data to third-party servers before any visitor interaction, often within 419 milliseconds of page load. The results also showed wide country-by-country gaps and uneven performance from consent banners that are meant to block tracking until users agree.
Why it matters: - The scan suggests many European sites may be collecting or sharing data before users can meaningfully respond to consent prompts. - The findings matter for privacy compliance, user trust and how consent tools are implemented in practice. - Statable measured the issue technically, not as a legal ruling on any site.
What happened: - Statable scanned 1,186 websites across ten European countries on 29 July 2026. - The company loaded each site in a real browser, intercepted outgoing network requests and timestamped them against page load. - The median time to the first third-party request was 419 milliseconds. - In this study, “before consent” meant before any pointer, keyboard or touch interaction with the page. - The crawler identified itself as StatableScanner, followed robots.txt and recorded blocked domains as not scanned.
The details: - Polish sites had the highest rate of trackers firing before any interaction at 64.9% among countries with samples of 100 sites or more. - Spain followed at 60.0%, and Belgium at 55.3%. - German sites had the lowest rate at 40.0%. - Thirty percent of German sites contacted no third party at all before interaction. - In Belgium, that figure was 2.3%, or three sites out of 132. - Of the European sites carrying a recognisable consent management platform, 75.5% still sent data to trackers before any interaction. - Google’s Funding Choices appeared on 13 sites, and none blocked tracking beforehand. - OneTrust leaked on 81.8% of installations. - Cookiebot leaked on 77.6% of installations. - Complianz performed best among the named platforms but still leaked on 49.1% of installations. - A scan of 186 Dutch medical clinics found 78.5% fired trackers before interaction. - In a broader Dutch sample of 817 sites, 49.9% fired trackers before interaction. - Three in four Dutch medical clinics contacted Google-owned hosts before any interaction. - Across the full sample, 2,609 distinct third-party hosts received requests before interaction. - One European retailer set a cookie that expired more than a thousand years in the future. - A single page load on that retailer’s site set 511 separate cookies. - The sample was drawn deterministically from a hash of each domain name, allowing independent reconstruction. - To test stability, Statable scanned 1,040 domains twice, two days apart. - The pre-consent tracking result matched on 97.9% of those domains. - Source lists were Majestic Million, licensed under CC BY 3.0, and OpenStreetMap, licensed under ODbL.
Between the lines: - The results point to a gap between having a consent banner and actually stopping network traffic before consent. - The country spread suggests implementation quality varies widely across Europe. - The consent platform results imply that banners alone do not guarantee blocking unless sites configure them to stop trackers. - The medical clinic sample stands out because health-related sites can handle especially sensitive visitor data.
What's next: - Statable says its GDPR Checker browser extension is available for Chrome, Firefox and Edge. - The extension reports trackers, cookies and embedded resources that load before interaction and lists remediation steps. - In validation across 1,000 European websites, the extension classified 42% as red, 38% as amber and 20% as green. - The extension reports technical measurements and does not provide legal advice. - Statable says its analytics product remains free for sites on .edu, .github.io and .gitlab.io domains, with no pageview cap. - Statable is operated by Key Arg B.V., registered in the Netherlands.
The bottom line: - Across a large European sample, trackers often loaded before users could do anything, and many consent banners did not stop them.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
European News Update
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.