61% fired at least one tracker before the visitor consented. Here is what our browser observed, which tools appeared most often, and how owners can verify their own sites.
We ran RegSentry's headless-browser scan against 3,891 small- and mid-sized business websites and watched exactly when each third-party script first contacted its server. On 2,391 of them (61%), at least one tracker fired before the visitor was given a consent choice. Across those sites we recorded 5,653 pre-consent technical findings, an average of 2.4 per affected site, and 780 sites were running three or more.
Under California Penal Code § 631 (with statutory damages set by § 637.2), plaintiffs may argue that an affected California visitor session is a separate violation worth up to $5,000. Applied to self-reported traffic, the directional median statutory ceiling in this dataset is $622K per site. That is a theoretical maximum used for risk context, not a prediction, legal conclusion, or estimate of what any site would owe.
The most common culprits are the everyday marketing and analytics tags almost every site installs — frequently added by a marketing team long after the consent banner was set up.
| Tracker | Found on | |
|---|---|---|
| Google Ads / DoubleClick | 1225 sites | |
| Meta Pixel | 1112 sites | |
| Microsoft Clarity | 484 sites | |
| LinkedIn Insight | 327 sites | |
| HubSpot Tracking | 250 sites | |
| Hotjar | 228 sites | |
| Microsoft Advertising (Bing UET) | 194 sites | |
| Sentry | 188 sites | |
| TikTok Pixel | 129 sites | |
| Sentry Session Replay | 101 sites | |
| Pinterest Tag | 95 sites | |
| VWO | 89 sites |
Read the ranked list with a technical explanation and next step for every tracker.
Violations clustered in verticals that pair high traffic with sensitive intake — but no category was clean.
| Vertical | Pre-consent violations |
|---|---|
| SaaS | 154 sites with a pre-consent violation |
| E-commerce | 95 sites with a pre-consent violation |
| Legal | 93 sites with a pre-consent violation |
| Martial arts studios | 66 sites with a pre-consent violation |
| Funeral homes | 66 sites with a pre-consent violation |
| Insurance | 62 sites with a pre-consent violation |
| Fintech | 61 sites with a pre-consent violation |
| Veterinary | 60 sites with a pre-consent violation |
| Home services (HVAC) | 57 sites with a pre-consent violation |
Nearly every site in this set had some consent setup — a banner, a cookie notice. The trackers fired anyway, because a banner only helps if it actually blocks scripts until a visitor clicks, and most are mis-configured or quietly bypassed by tags added later. The only way to know is to watch the network in a real browser.
See if your site fires trackers before consent — free, 30 seconds.
Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.
Methodology: figures reflect RegSentry automated scans of 3,891 business websites through August 2026, detecting third-party requests that fire before a consent signal. Exposure is the CIPA § 637.2 statutory ceiling ($5,000 per California session) applied to self-reported traffic, a directional maximum, not a prediction, and not legal advice. A tracker's presence is a technical finding and is not by itself proof of a legal violation.