Our 2026 pre-consent tracking report analyzes 45 leading India and global websites to measure cookie tracking, third-party trackers, and security practices before users give consent.
of websites fired trackers before consent
31 of 45 sites loaded analytics or ad trackers on the public homepage before any choice was made.
of websites were missing a security header
44 of 45 sites were missing at least one of CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy or Permissions-Policy.
cookies set before consent (average)
Set on the initial public page load, before a consent choice.
third-party domains contacted before consent (average)
Distinct external domains contacted per site on load.
/100 average privacy and tracking risk score
xScan-AI composite of tracking, headers, TLS and third-party exposure.
69% of the sites scanned (31 of 45) fired analytics or advertising trackers on the public homepage before the visitor made any consent choice.
98% of the sites scanned (44 of 45) were missing at least one of CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy or Permissions-Policy.
Sites set 12 cookies on average on the initial public page load - before a consent choice was recorded.
Each site contacted 17 distinct external domains on average before consent, and the composite risk score across the sample averaged 48 out of 100.
Showing a cookie banner and actually blocking non-essential tracking are two different things. Most sites that displayed a banner still fired their trackers on the first page view, before the visitor clicked anything - the banner collected a choice, but the tags had already run. Under GDPR and India's DPDPA, non-essential trackers are supposed to stay blocked until consent is given, which requires the scripts themselves to be held back rather than simply asked about.
Nearly every site was missing at least one standard response security header. These defend against clickjacking, XSS and protocol downgrade, and their absence is an easy, visible signal of under-investment in basic web hygiene.
On average each site contacted 17 external domains and set a dozen cookies before consent - every one a place personal data can flow without a recorded choice.
Pre-consent tracking can create privacy and compliance risks when non-essential cookies, analytics, or advertising trackers load before a user makes a consent choice. Organizations should ensure that consent preferences are enforced before non-essential tracking begins, which is what prior-script blocking in a ConsentX consent management platform deployment is designed to do.
The patterns in this scan point to a short list of checks worth running against your own site.
The ConsentX cookie scanner runs the same checks used in this study against your own pages.
To measure pre-consent tracking and cookie consent behavior, ConsentX analyzed the public homepages of 45 leading India and global websites (news, ecommerce, BFSI, SaaS, travel and health) using the Cloudflare URL Scanner via ConsentX's xScan-AI, in June 2026. For each site we recorded the cookies set, scripts and third-party domains contacted before any consent choice, the response security headers and the TLS configuration, then derived a 0-100 risk score.
This is an indicative snapshot of 45 leading sites, not a statistical census of the web, and automated checks at scan time are advisory rather than a legal determination. We plan to widen the sample in future updates.
Run the same xScan-AI scan on your own site, free. See what fires before consent and how to fix it.