Free scan
Data report · 2026

The state of website tracking: we scanned 1,943 small-business sites

57% fired at least one tracker before the visitor consented. Here is what our browser observed, which tools appeared most often, and how owners can verify their own sites.

1,943
SMB sites scanned with a real browser
57%
fired a tracker before consent
$880K
median statutory-ceiling exposure per site
67%
of technical findings were high-severity

What we found

We ran RegSentry's headless-browser scan against 1,943 small- and mid-sized business websites and watched exactly when each third-party script first contacted its server. On 1,106 of them (57%), at least one tracker fired before the visitor was given a consent choice. Across those sites we recorded 2,511 pre-consent technical findings, an average of 2.3 per affected site, and 351 sites were running three or more.

Under California Penal Code § 631 (with statutory damages set by § 637.2), plaintiffs may argue that an affected California visitor session is a separate violation worth up to $5,000. Applied to self-reported traffic, the directional median statutory ceiling in this dataset is $880K per site. That is a theoretical maximum used for risk context, not a prediction, legal conclusion, or estimate of what any site would owe.

The trackers firing before consent

The most common culprits are the everyday marketing and analytics tags almost every site installs — frequently added by a marketing team long after the consent banner was set up.

TrackerFound on
Meta Pixel458 sites
Microsoft Clarity255 sites
LinkedIn Insight221 sites
Sentry188 sites
Google Ads / DoubleClick180 sites
HubSpot Tracking134 sites
Hotjar132 sites
TikTok Pixel80 sites
VWO70 sites
Datadog RUM62 sites
Pinterest Tag57 sites
Twitter Pixel55 sites

Read the ranked list with a technical explanation and next step for every tracker.

Who is most exposed

Violations clustered in verticals that pair high traffic with sensitive intake — but no category was clean.

VerticalPre-consent violations
SaaS154 sites with a pre-consent violation
E-commerce95 sites with a pre-consent violation
Fintech61 sites with a pre-consent violation
Legal39 sites with a pre-consent violation
Healthcare38 sites with a pre-consent violation
Home services (HVAC)35 sites with a pre-consent violation

The gap most owners miss

Nearly every site in this set had some consent setup — a banner, a cookie notice. The trackers fired anyway, because a banner only helps if it actually blocks scripts until a visitor clicks, and most are mis-configured or quietly bypassed by tags added later. The only way to know is to watch the network in a real browser.

See if your site fires trackers before consent — free, 30 seconds.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.

Methodology: figures reflect RegSentry automated scans of 1,943 business websites through July 2026, detecting third-party requests that fire before a consent signal. Exposure is the CIPA § 637.2 statutory ceiling ($5,000 per California session) applied to self-reported traffic, a directional maximum, not a prediction, and not legal advice. A tracker's presence is a technical finding and is not by itself proof of a legal violation.