Median time to the first third-party request was 419 milliseconds. German sites were three times as likely to be clean as Polish ones.

A consent banner is a user interface. Whether anything behind it is actually blocked is a separate engineering problem. On this sample, that work had mostly not been done.”

— Yevhen Skrypets, Founder of Statable

THE HAGUE, ZUID-HOLLAND, NETHERLANDS, August 21, 2026 /EINPresswire.com/ — A technical scan of 1,186 websites across ten European countries found that most of them contact third-party servers before a visitor has interacted with the page in any way, typically 419 milliseconds after the page begins to load.

The scan was conducted on 29 July 2026 by Statable, a cookieless web analytics company registered in the Netherlands. Each site was loaded in a real browser, every outgoing network request was intercepted, and each request was timestamped relative to page load. The crawler identified itself as StatableScanner and followed robots.txt, and domains that disallowed it were recorded as blocked rather than scanned. In this study, “before consent” means strictly before any pointer, keyboard or touch interaction with the page. The measurement is technical and is not a legal assessment of any site.

Results differed sharply by country. Among samples of 100 sites or more, Polish sites showed the highest rate of trackers firing before any interaction at 64.9 percent, followed by Spain at 60.0 percent and Belgium at 55.3 percent. German sites showed the lowest rate at 40.0 percent.

The gap widens on a stricter measure. Thirty percent of German sites in the sample contacted no third party at all before interaction. In Belgium that figure was 2.3 percent, or three sites out of 132.

Consent banners made little difference. Of the European sites carrying a recognisable consent management platform, 75.5 percent still sent data to trackers before any interaction. Results varied by vendor: Google’s Funding Choices was found on 13 sites and none of them blocked tracking beforehand, while OneTrust leaked on 81.8 percent of installations and Cookiebot on 77.6 percent. The strongest performer, Complianz, still leaked on 49.1 percent.

“A consent banner is a user interface,” said Yevhen Skrypets, founder of Statable. “Whether anything behind it is actually blocked is a separate engineering problem, and the two are only connected when someone does that work deliberately, script by script. On this sample, that work had mostly not been done.”

A scan of 186 Dutch medical clinics found 78.5 percent fired trackers before interaction, against 49.9 percent across a broader Dutch sample of 817 sites. Three in four contacted Google-owned hosts before any interaction.

The scan also recorded outliers suggesting limited oversight. One European retailer set a cookie expiring more than a thousand years in the future, and a single page load on that site set 511 separate cookies. Across the sample, 2,609 distinct third-party hosts received requests before interaction.

The sample was drawn deterministically from a hash of each domain name, allowing independent reconstruction. To test stability, 1,040 domains were scanned twice, two days apart, and the pre-consent tracking result was identical on 97.9 percent of them. Source lists were Majestic Million, licensed under CC BY 3.0, and OpenStreetMap, licensed under ODbL.

The measurement engine used in the study is available to the public as a free browser extension, Statable GDPR Checker, published in the Chrome, Firefox and Edge extension stores. It reports which trackers, cookies and embedded resources loaded before interaction, and lists remediation steps. In validation across 1,000 European websites, the extension classified 42 percent of sites as red, meaning a tracker fired before interaction, 38 percent as amber, where only fonts, maps or video embeds transmitted the visitor’s IP address, and 20 percent as green. The extension reports technical measurements and does not provide legal advice.

About Statable

Statable is cookieless web analytics built and hosted in the European Union. It reports visitors, traffic sources, campaigns, goals and funnels without setting cookies or storing persistent identifiers. Visitor counting uses a keyed server-side hash rotated every midnight UTC, and IP addresses are read at ingest to derive approximate location without being stored. The tracking script ranges from 504 to 1,855 bytes compressed, depending on which features a site enables. Analytics are permanently free for sites on .edu, .github.io and .gitlab.io domains, with no pageview cap. Statable is operated by Key Arg B.V., registered in the Netherlands.

Viktoriia Storozhchuk
Statable
+31 6 45547237
support@statable.com
Visit us on social media:
LinkedIn
YouTube
X

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Media gallery

About The Author