Free scan
Data report · 2026

The state of website tracking: we scanned 3,891 small-business sites

61% fired at least one tracker before the visitor consented. Here is what our browser observed, which tools appeared most often, and how owners can verify their own sites.

3,891
SMB sites scanned with a real browser
61%
fired a tracker before consent
$622K
median statutory-ceiling exposure per site
68%
of technical findings were high-severity

What we found

We ran RegSentry's headless-browser scan against 3,891 small- and mid-sized business websites and watched exactly when each third-party script first contacted its server. On 2,391 of them (61%), at least one tracker fired before the visitor was given a consent choice. Across those sites we recorded 5,653 pre-consent technical findings, an average of 2.4 per affected site, and 780 sites were running three or more.

Under California Penal Code § 631 (with statutory damages set by § 637.2), plaintiffs may argue that an affected California visitor session is a separate violation worth up to $5,000. Applied to self-reported traffic, the directional median statutory ceiling in this dataset is $622K per site. That is a theoretical maximum used for risk context, not a prediction, legal conclusion, or estimate of what any site would owe.

The trackers firing before consent

The most common culprits are the everyday marketing and analytics tags almost every site installs — frequently added by a marketing team long after the consent banner was set up.

TrackerFound on
Google Ads / DoubleClick1225 sites
Meta Pixel1112 sites
Microsoft Clarity484 sites
LinkedIn Insight327 sites
HubSpot Tracking250 sites
Hotjar228 sites
Microsoft Advertising (Bing UET)194 sites
Sentry188 sites
TikTok Pixel129 sites
Sentry Session Replay101 sites
Pinterest Tag95 sites
VWO89 sites

Read the ranked list with a technical explanation and next step for every tracker.

Who is most exposed

Violations clustered in verticals that pair high traffic with sensitive intake — but no category was clean.

VerticalPre-consent violations
SaaS154 sites with a pre-consent violation
E-commerce95 sites with a pre-consent violation
Legal93 sites with a pre-consent violation
Martial arts studios66 sites with a pre-consent violation
Funeral homes66 sites with a pre-consent violation
Insurance62 sites with a pre-consent violation
Fintech61 sites with a pre-consent violation
Veterinary60 sites with a pre-consent violation
Home services (HVAC)57 sites with a pre-consent violation

The gap most owners miss

Nearly every site in this set had some consent setup — a banner, a cookie notice. The trackers fired anyway, because a banner only helps if it actually blocks scripts until a visitor clicks, and most are mis-configured or quietly bypassed by tags added later. The only way to know is to watch the network in a real browser.

See if your site fires trackers before consent — free, 30 seconds.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.

Methodology: figures reflect RegSentry automated scans of 3,891 business websites through August 2026, detecting third-party requests that fire before a consent signal. Exposure is the CIPA § 637.2 statutory ceiling ($5,000 per California session) applied to self-reported traffic, a directional maximum, not a prediction, and not legal advice. A tracker's presence is a technical finding and is not by itself proof of a legal violation.