What 1,845 European websites did before anyone clicked anything
By Yevhen Skrypets, founder of Statable
On 29 July 2026 we loaded 1,845 European websites in an instrumented browser and wrote down everything that left the page before a visitor could have made any choice about it. Not before clicking “Reject”. Before clicking anything at all.
On 641 of them, a tracker had already fired.
The median site made its first request to a third-party server 419 milliseconds after the scan began — quicker than most people can locate a cookie dialog, let alone read it. By the time the banner finished rendering, the conversation with Google had happened.
This article is a summary of a longer technical write-up. Every number below comes from the same single-day run, and the full study, with all limitations and the tables we did not have room for here, is published openly.

Trackers firing before any visitor interaction, by country: Poland 64.9% of 134 domains down to Germany 40.0% of 100. Denmark (57.1% of 77) appears in the table further down.
The headline number, and what it divides by
Of the 1,845 domains attempted, 1,761 produced a usable capture, 1,314 either loaded cleanly or produced a detection, and 1,186 produced at least one detection. That last figure — 1,186 — is the denominator for every percentage in this article, and we state it every time because studies of this kind usually do not.
On that base, 641 sites (54.0%) contacted a tracker before any interaction. On the wider base of 1,314 loaded rows the same finding reads 48.8%. Neither number is the “real” one; they answer slightly different questions, and both are published.
The verdict split on the 1,186:
| Verdict | Sites | Share | Meaning |
| Red | 531 | 44.8% | a tracker fired before interaction |
| Amber | 345 | 29.1% | no tracker, but fonts, maps or embeds transmitted the visitor’s IP |
| Unknown | 178 | 15.0% | insufficient evidence to classify |
| Green | 132 | 11.1% | nothing of concern before interaction |
Genuinely quiet pages are rare. Only 124 of the 1,186 sites (10.5%) contacted no third-party host of any kind before interaction — fonts, maps and video embeds included.

Funnel from 1,845 domains attempted down to the 641 that tracked before interaction
Same regulation, different plumbing
Splitting the corpus by country top-level domain, and keeping every country with at least 77 domains in the set, produces a spread of nearly 25 percentage points across states operating under one regulation.
| Country | Domains with detections | Tracker before interaction | Zero third-party contact |
| Poland | 134 | 64.9% | 7.5% |
| Spain | 100 | 60.0% | 10.0% |
| Denmark | 77 | 57.1% | 6.5% |
| Belgium | 132 | 55.3% | 9.1% |
| Italy | 136 | 53.7% | 15.4% |
| France | 106 | 52.8% | 4.7% |
| Sweden | 152 | 50.0% | 9.9% |
| Austria | 112 | 43.8% | 15.2% |
| Germany | 100 | 40.0% | 21.0% |
The two columns measure different things and are worth reading side by side. German sites were the least likely to fire a tracker, and roughly three times as likely as Polish ones to keep the first page load free of third-party contact altogether — 21 of 100 against 10 of 134. But 40.0% of them still fired a tracker, and a site can pass the tracker test while handing an IP address to a font server before the visitor has moved.
We did not test why the countries differ, and we are not going to pretend otherwise. What the data supports is narrower: results cluster by country in a way a shared legal text does not explain. The likely variables are local — which CMS themes the regional agencies ship, whether those themes hotlink Google Fonts or self-host them, which consent vendor is the regional default, what the popular hosting bundle installs by default. Reading this corpus per country is mostly reading local engineering habit.
A banner on the page does not mean the page is waiting
We recognised a consent management platform on 351 of the 1,186 sites (29.6%). On 265 of those 351 — 75.5% — trackers still fired before any interaction. Three out of four sites that had bought a consent tool were running it next to the traffic rather than in front of it.

Leak rate by consent platform: Google Funding Choices 100% of 13 sites down to Complianz 49.1% of 55
| Consent platform | Sites detected | Leaked before interaction | Share |
| Google Funding Choices | 13 | 13 | 100.0% |
| Didomi | 25 | 23 | 92.0% |
| Axeptio | 9 | 8 | 88.9% |
| consentmanager | 14 | 12 | 85.7% |
| CookieFirst | 7 | 6 | 85.7% |
| OneTrust | 55 | 45 | 81.8% |
| CookieYes | 18 | 14 | 77.8% |
| Cookiebot | 98 | 76 | 77.6% |
| iubenda | 23 | 17 | 73.9% |
| Cookie Information | 18 | 13 | 72.2% |
| Usercentrics | 15 | 10 | 66.7% |
| Complianz | 55 | 27 | 49.1% |
Read the sample column before the percentage column. Google Funding Choices at 13 of 13 and CookieFirst at 6 of 7 are too small to rank vendors by; one site moving swings those rows by several points. Three rows carry enough sites to mean something: Cookiebot at 76 of 98, OneTrust at 45 of 55, and Complianz at 27 of 55. The last two have exactly the same sample size and land 33 points apart, so the choice of tool is not irrelevant — but most vendors cluster between 66% and 92%, a band narrow enough that picking a different name off the list usually does not change the outcome.
A consent banner is a user interface. Whether anything behind it is actually blocked is a separate engineering problem, and the two are only connected when somebody does that work deliberately, script by script. On this sample, that work had mostly not been done.
Google Consent Mode has two distinct failure shapes, and we counted them separately because they mean different things. In the hard case — an identifier left the browser before any interaction and can be joined to the visitor later — we saw a cookie go out on 305 of 1,186 sites (25.7%). In the soft case, the page fired a cookieless ping carrying gcs=G100, the signal that says consent has not been granted; that is roughly what Consent Mode is designed to look like in this window, and we saw it on 177 sites (14.9%). Forty-four sites did both, which usually means two tags on one page disagreeing with each other: something running with the denied default, and something older that never got the memo.
Half a second, and the page has already talked to Google
Against the 419 ms median, the mean was 945.6 ms across the 1,062 sites we could time, dragged upward by a long tail rather than by the typical site. Of those, 57.8% had contacted a third party within half a second and 79.8% within one second.

Time to first third-party request, peaking in the 250–500 ms bin at 31.8% of 1,062 sites
What arrives in that window is remarkably boring.
| Signature fired pre-interaction | Sites | Share of 1,186 |
| Google Fonts | 542 | 45.7% |
| Google Analytics 4 | 443 | 37.4% |
| Google Tag Manager | 330 | 27.8% |
| Google Ads | 325 | 27.4% |
| Google Maps | 171 | 14.4% |
Counted from the network side rather than by signature, googletagmanager.com was contacted by 544 domains, fonts.gstatic.com by 490 and fonts.googleapis.com by 476. The largest non-Google host in the corpus, connect.facebook.net, appears on 139. The fast half of the European web is not doing anything exotic; it is loading a tag manager and a font file.
The variety lives in the tail: 2,609 distinct third-party hosts received a request before interaction, most of them on a handful of sites each. The tail also holds the one result we still find hard to look at. A single European retailer — we are not naming it — set 511 cookies in one page load, one of which carried a lifetime of roughly 1,083 years. That is one site, not a pattern, and we report it as a curiosity rather than a trend.
Sector matters more than any outlier. In a separate scan of 186 Dutch medical clinics on 21 July 2026, 146 (78.5%) fired a tracker before interaction, against 54.0% across the EU corpus. Their median time to first third-party contact was 741 ms, about 1.77 times slower than the EU median — slower, but not safer: the Google Analytics family alone fired before interaction on 141 of those 186 sites.
How it was measured
This is the part a reader is entitled to check, so it is longer than the results.
Two instruments, one classifier. The corpus was scanned with a Playwright crawler driving headless Chromium (engine 0.2.0, ruleset 1.3.0, commit 2badab8). It was cross-checked with Statable GDPR Checker, our free browser extension, which runs the same 101 signatures in a real browser through its own, separate measurement layer. They share a classifier and no measuring code, which is the point: agreement between them is evidence about the measurement, not an independent check of the signature list.
The browser context. Every domain gets a fresh context — no cookies, no storage, no warm cache carried over. Locale nl-NL, timezone Europe/Amsterdam, viewport 1366×900, service workers blocked. Requests are captured at initiation rather than on response, so a request blocked by a content security policy still counts as an attempt to contact a third party. The user agent is StatableScanner/0.1 with a contact address inside the string, robots.txt is fetched and parsed before a domain is touched, and disallowed domains are recorded as blocked rather than loaded.
The budgets. Two seconds between domains, a 45-second navigation timeout, 15 seconds of watching after load, a hard 90-second per-domain deadline, six domains in parallel. The 15-second window is not a guess: 96.29% of all third-party requests we recorded arrived inside it. The remaining 3.7% — lazy pixels, scroll-triggered tags, late chat widgets — is outside our view, so a site whose only tracker fires at 20 seconds reads as clean here.
The one thing readers should know before believing any of this. The scanner performs three input events on every page: two mouse moves and one wheel scroll. Never a click, never a keypress, never any contact with a banner control. The reason is deferred loading — LiteSpeed Delay JS, WP Rocket, Perfmatters and NitroPack all attach the site’s real tags to the first mouse or touch event, several with no timer fallback at all, so a scanner sitting perfectly still records a clean page on a site that fires its tag manager the moment a human twitches. It follows that “before consent” in this dataset means before any click, keypress or banner choice — not before any pointer event whatsoever. Summaries that state it more tightly than that overstate what the crawler warrants, including one of our own.
Where the sample came from. Every candidate domain name is hashed, and selection comes from that hash, so the same source list and seed reproduce the same domain list on any machine — anyone can rebuild it before running a single request. The source lists are public and stay under their own licences: Majestic Million (CC BY 3.0) for ranked sites, OpenStreetMap (ODbL) for location-derived sets such as the clinic scan.
Does it come out the same twice. We re-ran it. On the 1,040 domains scanned by the crawler on two consecutive days that produced detections in both runs, the pre-consent verdict was identical on 1,018 (97.9%). The extension, run twice on the same 1,037 domains two hours and twenty minutes apart, agreed on 1,033 (99.6%), and its full four-way verdict matched on 1,024 (98.7%). We would not read the 2.1% of crawler domains that flipped as noise alone — a day passed, and sites deploy tags on their own schedule.
The mass validation. The extension’s own run covered 1,997 unique domains and produced a verdict on 1,682: red 695 (41.3%), amber 621 (36.9%), green 333 (19.8%), unknown 33 (2.0%). It also saw a different web than the crawler did. On the domains both looked at, the extension completed where the crawler could not on 17.3%, against 1.5% the other way. A declared user agent on a datacentre IP gets turned away by bot walls that a real browser walks straight past, which means a corpus built this way is skewed toward sites without aggressive bot defence, and we cannot say whether the blind spots track more or less than the rest.
What this study does not do. It never accepts, never rejects and never opens a preference centre, so it says nothing about whether banners honour a later “reject all”. It measures the home page only, and article pages, checkout flows and account areas typically carry more third parties, so treat every figure here as a floor rather than an average. Its first-party/third-party boundary is drawn by a hand-rolled heuristic in the crawler rather than the Public Suffix List, which errs in both directions. And it is a behavioural measurement of what browsers loaded on one day. It is not a legal assessment of any site or vendor.
What a site owner can do about it in ten minutes
The uncomfortable part of this dataset is how cheaply most of it could have been avoided. Self-hosting fonts removes the single most common pre-consent signature in the corpus. Loading the tag manager from inside the consent callback, rather than from the document head with the banner drawn over it, removes most of the rest. Neither is a legal exercise; both are twenty-minute engineering tasks that nobody was assigned.
Checking your own site takes less. Install Statable GDPR Checker — it is free, and also published for Firefox and Edge — open the page you are responsible for, and read what fired before you touched anything. It runs the same 101 signatures this study ran, its observation window opens at navigationStart and closes at your first real click or keypress, and it lists what to change. It reports technical measurements and does not provide legal advice.
Data and citation
The dataset is available under CC BY 4.0. It is not posted for download yet, because the rows carry domain names and we would rather decide how to handle that than publish first and think later; write to support@statable.com and we will send it. To cite the study itself:
Statable, EU pre-consent tracking scan, run pilot-fresh-20260729, scanned 29 July 2026, engine 0.2.0, ruleset 1.3.0, commit 2badab8. CC BY 4.0.
About Statable
Statable is cookieless web analytics, built and hosted in the European Union. It reports visitors, traffic sources, campaigns, goals and funnels without setting cookies or storing persistent identifiers: visitor counting uses a keyed server-side hash rotated every midnight UTC, and IP addresses are read at ingest to derive approximate location without being stored. The tracking script ranges from 504 to 1,855 bytes compressed, depending on which features a site turns on. Analytics are permanently free for sites on .edu, .github.io and .gitlab.io domains, with no pageview cap. Statable is operated by Key Arg B.V., registered in the Netherlands.
Media contact: Viktoriia Storozhchuk, Product Manager — support@statable.com, +31 6 45 54 72 37
