57% fired at least one tracker before the visitor consented. Here is what our browser observed, which tools appeared most often, and how owners can verify their own sites.
We ran RegSentry's headless-browser scan against 1,943 small- and mid-sized business websites and watched exactly when each third-party script first contacted its server. On 1,106 of them (57%), at least one tracker fired before the visitor was given a consent choice. Across those sites we recorded 2,511 pre-consent technical findings, an average of 2.3 per affected site, and 351 sites were running three or more.
Under California Penal Code § 631 (with statutory damages set by § 637.2), plaintiffs may argue that an affected California visitor session is a separate violation worth up to $5,000. Applied to self-reported traffic, the directional median statutory ceiling in this dataset is $880K per site. That is a theoretical maximum used for risk context, not a prediction, legal conclusion, or estimate of what any site would owe.
The most common culprits are the everyday marketing and analytics tags almost every site installs — frequently added by a marketing team long after the consent banner was set up.
| Tracker | Found on | |
|---|---|---|
| Meta Pixel | 458 sites | |
| Microsoft Clarity | 255 sites | |
| LinkedIn Insight | 221 sites | |
| Sentry | 188 sites | |
| Google Ads / DoubleClick | 180 sites | |
| HubSpot Tracking | 134 sites | |
| Hotjar | 132 sites | |
| TikTok Pixel | 80 sites | |
| VWO | 70 sites | |
| Datadog RUM | 62 sites | |
| Pinterest Tag | 57 sites | |
| Twitter Pixel | 55 sites |
Read the ranked list with a technical explanation and next step for every tracker.
Violations clustered in verticals that pair high traffic with sensitive intake — but no category was clean.
| Vertical | Pre-consent violations |
|---|---|
| SaaS | 154 sites with a pre-consent violation |
| E-commerce | 95 sites with a pre-consent violation |
| Fintech | 61 sites with a pre-consent violation |
| Legal | 39 sites with a pre-consent violation |
| Healthcare | 38 sites with a pre-consent violation |
| Home services (HVAC) | 35 sites with a pre-consent violation |
Nearly every site in this set had some consent setup — a banner, a cookie notice. The trackers fired anyway, because a banner only helps if it actually blocks scripts until a visitor clicks, and most are mis-configured or quietly bypassed by tags added later. The only way to know is to watch the network in a real browser.
See if your site fires trackers before consent — free, 30 seconds.
Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.
Methodology: figures reflect RegSentry automated scans of 1,943 business websites through July 2026, detecting third-party requests that fire before a consent signal. Exposure is the CIPA § 637.2 statutory ceiling ($5,000 per California session) applied to self-reported traffic, a directional maximum, not a prediction, and not legal advice. A tracker's presence is a technical finding and is not by itself proof of a legal violation.