Dieter
Before you click: Data Protection Report 2026

Before you click

Most German websites pass on something about your visit before you can click anything. Very few of them mean to.

When you open a website, more happens in the first second than you can see. We wanted to know how much of it goes to third-party companies without any action on your part. So we automatically visited 10,389 German websites: medical practices, trade businesses, clubs and associations, law firms, shops, public authorities. We opened each one three times. Once without clicking anything. Once after a click on “Accept all”. And once after a click on “Reject”.

The result surprised us. Most of the data that flows out unasked is never analysed by anyone. It flows because a font is loaded from a third-party server.

Data collection 25 June to 9 August 2026 Method automated visits with a real browser Sample 15 sectors, 16 federal states Anonymous no names, no addresses
76 %
of websites with third-party services: clicking “Reject” changes nothing technically.
68 %
of websites pass something on to third-party servers before visitors can click anything.
21 %
of all websites report your visit to Google, purely because of fonts, maps or spam protection.
22.1 %
of the affected websites pass on only things that could be dropped without anyone noticing.

Test your website

You can run the same test as in this study yourself at any time: three states, all recipients, all cookies, the security settings. As a report that anyone can read without prior knowledge.

So that you know what your default settings do before someone else wants to know.

Check your website now

Dieter zeigt Daumen hoch
Why this matters right now.

Almost everyone finds cookie banners annoying. That is why the European Union is working on new rules. Two changes in particular are planned. First, there should be a few clearly defined purposes for which a website no longer has to ask at all. Second, anyone who has said “no” once should not be asked again for six months.

Both sound sensible. But both only work if a “no” actually gets through technically on the website. That is exactly what we measured. On roughly three out of four websites, it does not.

A third point is still being fought over. You could set the “no” once in your browser, and all websites would have to respect it. Then the banners would no longer be needed. Several governments, including the German one, and parts of the advertising industry are pushing to have this point removed. As of September 2026, nothing has been decided.

01Basics

What happens when you open a website

A few terms are needed to make the figures in this report understandable. If you already know them, skip straight to chapter 2.

A website is made of parts from many servers

When you type in an address, your browser fetches the page from the operator’s server. But that page usually doesn’t contain all of the content. It contains instructions like “fetch the font from this other address” or “show the map from that provider here”. Your browser follows these instructions immediately and without asking. So it opens connections to further companies. These companies are called third parties.

Each of these connections reveals something to the third-party company: your IP address, that is the number under which you can currently be reached on the internet, which page you are looking at, and technical details about your device. On its own, that is not much. Across many websites, it adds up to a picture.

Cookies are little sticky notes in your browser

A cookie is a piece of text that a website stores in your browser and can read again later. Some cookies are harmless and necessary, such as the one that remembers the contents of your shopping basket. Others contain an ID number that lets a provider recognise you across many sites. Under German law, cookies like that need your consent before they may be set.

We visited every website three times

This is exactly where our measurement comes in. For every website, we made three separate visits and each time noted which third-party servers were contacted and which cookies were set:

  • Before the click. The page is opened, nothing else. Everything that happens now happens without any consent.
  • After “Accept all”. The state a website is allowed to reach when visitors consent.
  • After “Reject”. The most interesting case. This is where it shows whether a no has any technical effect at all.

Comparing these three states is the core of this report. To our knowledge, there has been nothing of this breadth for Germany before.

A note on our own behalf.

The page you are reading right now loads nothing from third-party servers. The font is embedded in the document, the graphics are drawn in the document, and so is the data. In the top right you can see a counter. It reads zero, and your browser calculated it itself. This is what a website can look like.

02The normal case

What the typical German website looks like

We check every website on five points. That gives 32 possible results. In reality, only 24 of them occur.

The five checks are:

  1. Does the page stay quiet as long as the visitor hasn’t clicked anything? That is: no connections to third-party servers before the click.
  2. Is there no recognisable advertising or analytics tool running before consent?
  3. Does clicking “Reject” have a measurable effect?
  4. Can a privacy policy be found?
  5. Are the server’s basic security settings in place?

One result occurs particularly often. 23.1 % of all websites fall into the same pattern: they have a privacy policy. They use no advertising or analytics tool. And they still contact third-party servers before anyone could click. Clicking Reject changes nothing, and the security settings are missing.

These websites don’t want to watch anyone. They still give something away. That is the normal case on the German web, and it is the reason this report turns out differently from what we expected.

The pattern goes beyond this one result. If you add up all the websites that contact third-party servers without using an advertising or analytics tool themselves, you get just over half of all websites examined (5,490 of 10,389).

Key takeaway

Just over half of all German websites pass data on to third-party companies even though they don’t use any advertising or analytics tool at all.

The 24 patterns that actually occur

A filled square means: check passed. The order of the squares matches the order of the five checks above.
Share of all 10,389 websites examined. Patterns below 0.3 % are combined in the last row.

Two groups and little in between

To combine the five checks into a single number, we award points. A website that passes all checks scores 100. One that fails all of them scores 0. The average across all websites is 50.0 points.

This average, however, hardly describes any real website. The distribution has two clusters. A large group sits at 30 to 40 points. A second, smaller group sits at 80 to 90 points. In between, it is thin.

The reason is simple. If a website loads anything at all from third-party servers, it usually loads several things at once, and it does so before the click. If it doesn’t, it loads nothing at all. There is little middle ground. 8.2 % of websites pass all five checks at once.

How many points the websites score

All 10,389 websites, grouped in steps of ten.
Points: no third-party servers before the click 30 · no advertising or analytics tool 20 · Reject works 25 · privacy policy can be found 10 · security settings up to 15. Average 50.0, midpoint of the distribution (median) 38.
03Where the data goes

The most common reason for data flowing out is a font

Until now, most studies have counted how much flows out. We additionally checked what for.

Before the first click, the 10,389 websites open connections to 2,691 different recipients. We assigned the 300 most common of them by hand to a company, a country and a purpose. That covers around 86 % of all connections. The rest is a classic long tail, a very long list of recipients that each hardly ever appear: 69 % of all recipients show up on exactly one single website.

This assignment shifts the picture considerably. Advertising and analytics services, which is exactly what cookie banners are meant for, account for 15.8 % of all unrequested connections. The largest single block is a different one: 28.6 % go to Google, and they go there for fonts, for embedded maps or for the spam protection reCAPTCHA.

If you add further things of this kind, that is fonts from other providers, ready-made code libraries, embedded videos and small add-on widgets like rating stars, you get 40.4 % of all unrequested connections. A website can avoid this entire block without visitors noticing any difference. Chapter 10 explains how.

What the unrequested connections are made for

Share of all connections made before the first click.
The basis is a manually maintained list of the 300 most common recipients. “Avoidable” here means: the function is preserved if the file is served from the site’s own server or only loaded after a click. Anything we could not assign with certainty we counted as not avoidable.

Google learns of every third visit, usually unintentionally

37.1 % of websites contact a Google server before the first click. For most of them, there is no analysis behind it. 21 % of all websites examined, that is 57 % of all websites with Google contact, connect purely because of fonts, maps or reCAPTCHA. Nobody there wanted to measure anything. Google still learns that you opened that page.

A German court has already ruled on why this is no side issue. On 20 January 2022, the Regional Court of Munich I awarded a claimant 100 euros in damages because a website had loaded its font directly from Google and in doing so transmitted her IP address (case no. 3 O 17493/20). The court based its reasoning on exactly what our measurement shows: the operator could have served the font without any connection to Google. The ruling was followed by a wave of cease-and-desist letters, which courts later largely classed as abusive. That changes nothing about the technical finding. (Overview by the Berlin Chamber of Commerce (IHK))

Key takeaway

One in five German websites reports the visit to Google merely because it loads a font or a map from there. None of it is analysed.

The 15 most common recipients before the first click

Share of websites that contact this address before anyone can react.
We are allowed to name the recipients. They are the companies that receive the data, not the website operators we examined. We never name those anywhere.
04The counter-calculation

What would be left if you dropped the unnecessary

This question can be answered precisely for every single website.

For each of the 10,389 websites, we know which recipients it contacts before the first click and which purpose group each of them belongs to. So we can strike out a group hypothetically and count how many websites would then be completely quiet. Completely quiet means: not a single third-party server before the visitor has decided.

Before the calculation, that is 32.2 % of all websites. Strike out just one single group, namely Google’s fonts, maps and reCAPTCHA, and it is 41.3 %. One single change, and 9.1 % of all websites switch sides.

Strike out everything that is avoidable without losing any function, and it is 47.2 %. Put another way: for 22.1 % of the websites that currently pass on anything at all, the entire unrequested data flow consists of things like this. No business model depends on it. Nobody would lose out.

Do the maths yourself

Deselect what should disappear from the German web. The figure on the right is recalculated across all 10,389 individual measurements.
41.3 %
of websites would then be completely quiet until the visitor has decided
already quietwould be added
The calculation runs on the real measurements of every single website. A website counts as quiet if, after striking out the deselected groups, no recipient remains. The groups “advertising and analytics”, “website builder”, “hosting”, “business function” and “not assigned” deliberately cannot be deselected. Removing them would not be without consequences.

And who is left?

A reminder of the first figure in this report: today, 68 % of all websites pass something on before you can click. After the clean-up, it would be 52.8 %.

The websites that remain are about things that actually do something: advertising and analytics tools, website builders that don’t run without third-party servers, payment providers, appointment booking portals. That is what consent and cookie banners are meant for. The problem shrinks from widespread carelessness to a hard core.

Key takeaway

Just over one in five websites that currently pass on data could stop doing so completely, right away, without visitors noticing any difference.

In fairness.

This calculation shows what is technically possible. It doesn’t say that it is easy for everyone. If you rent a website from a website-builder provider, you often can’t change the font source yourself at all. That decision is made by the provider. That is exactly what this report is about.

05Prediction

Why you can’t tell by looking at a website

We tested four obvious explanations: sector, federal state, company size and the software used. A model that takes all four into account at once explains 3.4 % of the differences.

What does that mean? Imagine you have to guess how many points an unknown website scores. You are allowed to ask one question first. If you ask which federal state the company is based in, the answer improves your estimate hardly at all. The same goes for the sector, for the company size and, slightly less so, for the software used.

This is the most uncomfortable finding of this report, because it contradicts the most popular form of presentation, namely the ranking. Differences between sectors and federal states do exist, and we list them in full further down. They are just small compared to the differences within each group.

The most vivid test: we randomly pick two websites from the same sector and measure how far apart their scores are. On average, that is 30.2 points. Then we compare websites from two different sectors. Result: 30.2 points. The two values are identical.

In concrete terms: two medical practices are on average 30.0 points apart. A medical practice and an online shop are 30.5 points apart. So knowing which sector you have landed in hardly helps you judge.

How much do sector, region, size and software explain?

Share of the differences between websites that each characteristic can explain.
A characteristic that really explained something would score 30 % or more here. That is why the scale goes up to 30. On the right you can see how far apart the groups are on average. These gaps are real, they just disappear in the much larger spread within the groups. The four bars must not be added up, because the characteristics are related: a model with all four characteristics at once comes to 3.4 % (3.0 % after correcting for the number of characteristics, calculated on the 9,811 websites for which all four are available).

WordPress is Germany in miniature

This shows most clearly with the most widely used system. 57 % of our sample run on WordPress. Their average is 50.0 points and thus hits the national average exactly. The spread within this group is even slightly larger than that of the entire dataset.

35 % of WordPress sites are completely quiet before the first click. 14 % score 20 points or below. Same software, opposite result. So what a WordPress site does doesn’t depend on WordPress. It depends on which theme was installed, which plugins came with it and what their default settings say. As a rule, nobody makes these decisions consciously. They come with the installation and are never touched again.

Confidentiality obligations change nothing either

If anything ought to influence how a website behaves, it is the question of how sensitive the information a visit reveals is. Anyone who opens a psychotherapist’s website gives away a hint about their health. So we compared the websites of professions bound by confidentiality with all the others: doctors, dentists, psychotherapists, pharmacies, lawyers and tax advisers.

  • Contact with a US provider before the click: 46.2 % compared with 48.4 % in all other sectors
  • Advertising or analytics tool before consent: 11.8 % compared with 15.9 %
  • completely quiet: 32.4 % compared with 32.1 %

The gaps are so small that they practically do not exist. In the German web, a visit to a therapist is passed on in roughly the same way as a visit to a furniture store. On 9.9 % of healthcare websites a connection to an advertising or analytics corporation is running before any consent is given.

One group stands out in a different direction. Among law firms, on 8.8 % of websites no privacy policy can be found. Among sole practitioners the figure is 12.8 %, roughly one in eight websites. The average across all sectors is 5.7 %.

Takeaway

On average, two medical practices differ from each other in data protection just as much as a medical practice and an online shop.

The rankings and what they are worth

We show them in full because they are useful for regional and sector-specific context. The column Spread tells you how little the group value reveals about an individual website.
Score 0 to 100. “Quiet” means: no third-party server before the first click. “Reject ineffective” refers only to those websites in the group that use third-party services at all. We do not show groups of fewer than 40 websites; for systems the threshold is 50. The column Spread indicates how far the websites in a group deviate from the group value on average.
06The reject click

What clicking “Reject” does

On 76 % of websites with third-party services it has no measurable effect.

This is the finding most likely to stick from this report. After the previous chapters, though, it reads differently than usual. The reject button is rarely a deliberate deception. It is usually a control that was never wired up to anything, just as the font source was never changed and the plugin never configured.

Instead of a single percentage we show four groups. They make visible what really happens when someone presses “Reject”.

What actually happens after clicking “Reject”

All websites that load third-party services in at least one state.
The bottom two groups together make up the 76 % where the no has no technical effect. On 63.7 % of these websites the state after the no is even identical to the state after the yes in every single measurement.

Two figures from this deserve a mention of their own. 19.8 % of all websites contact more third-party servers after the no than on a plain visit without any click at all. So anyone who clicks nothing is better off there than someone who rejects. And across all websites, the reject click lowers the number of server contacts by 12.4 %.

Three states compared

Average number of contacts with third-party servers per website.
All 10,389 websites, each measured in three separate sessions.
Takeaway

On almost two thirds of websites with third-party services, exactly the same thing happens after a click on “Reject” as after “Accept all”. The button is there; it is just not connected.

A banner is not a good sign

9.2 % of the websites examined use a recognisable consent tool, meaning the software behind the cookie banner. You would expect these websites to be cleaner than the rest. Measured, it is the other way round. Before the click they contact 8.4 third-party servers on average, websites without a banner only 3.9. An advertising or analytics tool runs on 29.4 % of their pages before consent; without a banner it is 13.5 %.

It does not follow that banners do harm. It is a selection effect: whoever installs a banner has usually also installed something that needs one. It is still revealing, though. On 81.5 % of websites with a banner third-party services are already running while the banner asks for permission. For you as a visitor this means: a cookie banner does not show that a site takes care. It shows that there is something there to take care of.

The tools compared

How often the no remains ineffective varies a lot depending on the tool used. More interesting than the ranking is a pattern behind it. There are two designs. Some run as a plugin on the site’s own server, others are loaded as a service from a third-party server. Both designs fail in different places. The plugins let hardly anything through before consent, but then ignore the no especially often. The embedded services more often actually switch something off, but almost without exception let other services run beforehand.

How often “Reject” remains ineffective, by tool

Only websites that load third-party services at all. From 30 websites per tool.
We identified the tools by the provider address loaded or by the cookie names set. What is measured is whether fewer third-party servers are contacted after the no than after the yes. This assesses the set-up on the respective website. It does not assess what the product could do. A tool with good settings can be set up badly, and that is exactly what we observe here.
07Ghosts in the code

Some websites send data to services that no longer exist

The best evidence that nobody is looking comes from the tools that have long been running into the void.

Looking through the cookie names that are set before any consent, you come across fossils. 31 websites still set cookies with names like __utma or __utmz. That is the first generation of Google Analytics, which Google shut down years ago. 248 websites set _gid or _gat, the markers of the second generation. Google stopped processing data for it on 1 July 2023 and switched off the interface in 2024. And 7 websites still load AddThis, a service for share buttons that was discontinued in 2023.

These websites are not tracking anyone. Nobody collects the data. The connection is still established and the cookie still set. Legally, this is the same process as with a working tool: access to the visitor’s device without their consent. It is a data protection violation that benefits nobody.

Takeaway

31 German websites send data to a Google service that has not existed for years. Nothing is received any more. It is still stored on the visitor’s device.

Who sets the cookies that land in the browser before the click

Share of websites with the respective marker among the cookie names.
The name of a cookie reveals which system set it. What stands out is how often the source is a default setting. The module in the shop plugin WooCommerce that records where visitors come from is active after installation without any further action. Website builders set their session cookies out of the box. And on 206 websites it is the consent tool itself that sets its cookies before consent has been given.

Security is configured even less often than data protection

There is a second setting that stays untouched almost everywhere. A server can hand the browser a few rules that make attacks harder. These rules cost nothing and bother nobody. They only need to be set once.

65 % of websites get our worst security grade because these rules are missing. Even among the websites with the best data protection grade the figure is 66 %. So the two topics are not connected, except in one respect: both are a default setting that nobody has changed.

08Four afternoons

What a perfectly ordinary search triggers

Up to this point it has been about websites. Now it is about what this means for an individual person.

To do this we simulate everyday searches. We randomly draw websites from the matching sector of our sample, as if someone were opening them one after another, and count how many different companies learn of the visit along the way. Nothing is clicked anywhere. Each row below is based on 20,000 runs with real measurements.

Six everyday searches, each without a single click

Sorted by how likely it is that an advertising or analytics corporation learns that you were searching.
A thought experiment on real measurements. Websites are drawn uniformly from the respective sector of our sample. Anyone searching in real life lands more often on large, more heavily marketed websites. The figures are therefore calculated rather conservatively.

How rare a quiet site is

A second look at the same question. If you open any website from our sample, there is a 32.2 % probability that it is completely quiet. That sounds like a solid chance. But it shrinks quickly as soon as it becomes more than one site:

  • two sites in a row, both quiet: 10.4 %
  • three sites in a row: 3.3 %
  • five sites in a row: 0.35 %

Calculated the other way round, you get a pair of figures that sums up the whole report. Until Google learns of you for the first time, you need on average 2.7 page views. Until you come across a website that passes all five checks in this report, you need on average 12.1.

Takeaway

After three websites visited, Google knows on average that you are out and about. Five websites in a row without any data being passed on is something you experience with a probability of 0.35 percent.

How many companies learn about your afternoon?

Any websites from the entire sample, 8,000 runs each.
99.0 %
Probability that at least one Google server has learned of you
10.9
different companies learn of it on average
3.3
of which based in the USA
Same method as above, only without restriction to one sector.

Many recipients, one dominates

The connections are spread across 2,691 different recipients. That sounds like diversity and is not. 69 % of these recipients appear on exactly one single website. At the other end stands a single corporation: 42.4 % of all unrequested connections in the German web lead to Google. The reason is banal. Google runs the standard library of the web: the fonts, the maps, the spam protection, the videos.

This concentration has a consequence that is easy to overlook. No individual website operator sees more than their own site. Out of ten random German websites, Google sees 3.7 of them on average.

09Law and politics

Who is liable for a default setting they have never seen

The law has no category called “by accident”. It is addressed to the operator of the website, even where in fact the website builder provider or a plugin made the decision.

The rule

The decisive provision is Section 25 of the German Telecommunications Digital Services Data Protection Act, TDDDG for short. Put simply, it says: anyone who stores something on a visitor’s device or reads something that is already there needs the visitor’s consent. The only exception is what is strictly necessary for the service explicitly requested. For the transmission of the IP address to a third-party company, for instance when loading a font, the General Data Protection Regulation applies in addition.

What the courts have made of it

  • Regional Court of Munich I, January 2022. 100 euros in damages for an IP address transmitted to Google without consent when loading a font. Overview
  • German Federal Court of Justice (BGH), 18 November 2024. The mere loss of control over your own data can be a compensable harm. There is no need to prove that someone misused the data. BGH press release
  • CNIL, France, September 2025. Fine of 150 million euros against SHEIN, among other things because advertising cookies were set as soon as the page was opened. CNIL announcement

In Germany, enforcement rarely happens through fines. It happens through orders from the supervisory authorities and through cease-and-desist letters from competitors and associations.

What Brussels is currently negotiating

In November 2025 the EU Commission proposed a package that moves the cookie rules into the General Data Protection Regulation. Two points matter for website operators, a third is contested:

  • Fewer questions. For a short, exhaustive list of purposes, no consent would be needed at all. This includes technical transmission, a service explicitly requested, narrowly defined first-party audience measurement and the security of the service.
  • Quiet after the no. Anyone who has rejected once may not be asked again for the same purpose for six months.
  • The signal from the browser. The plan was that you set your answer once in the browser and all websites have to respect it. Several governments, including the German one, are working to have this point removed. A leaked paper from Google warned of 40 to 50 billion euros in economic damage. Report by netzpolitik.org

Our measurement has something to say on all three points. On the cooling-off period: it helps little as long as the first no technically does not get through on 76 % of the affected websites. Not being asked for six months while loading continues for six months does not improve the situation. On the browser signal: it would work precisely where the banner fails today, because it does not require a correct set-up on every single website.

On the list of exceptions: none of the four planned exceptions covers Google Fonts, embedded maps or videos. The largest block of unrequested connections in the German web would therefore still need consent after the reform. The debate about the form of the banner leaves the most common violation untouched.

Takeaway

The EU is arguing about how websites should ask for permission. On three out of four websites the answer is not technically evaluated at all.

10What helps

Five steps, sorted by impact

Because the problem is a default setting, the solution is a setting. The impact figures come from the counter-calculation in chapter 4.

Serve fonts and icons from your own server

Google Fonts, Font Awesome and similar font packages can be downloaded and stored on your own server. For visitors the site looks exactly the same. The loading time stays the same or improves. The effort is about half a day.

9.1 % of all websites would become quiet through this alone

Load maps, videos and spam protection only on click

Instead of embedding the map straight away, you show a preview image. The service is only loaded once someone clicks on it. Ready-made components for this exist for all common systems.

has an additional effect, see the counter-calculator

Check what your own banner really blocks

A banner that does not hold back scripts creates work without protection. You can check this in five minutes: open your own site in a private window, click “Reject”, then open the “Network” tab in the browser’s developer tools and see which third-party addresses still show up.

affects 76 % of websites with third-party services

Remove old tools instead of carrying them along

Decommissioned analytics accounts, discontinued services, remnants of old website rebuilds. They no longer deliver data to anyone and still create a legal risk.

31 websites still send data to a system shut down long ago

Set the server’s security settings

Four to five lines in the server configuration. This is the check that most otherwise clean websites in our data collection failed.

65 % of websites fail here today
To website builder providers and agencies

The default setting is the real lever

Whoever ships a theme, a plugin or a website builder decides for tens of thousands of websites at once. A website builder that serves fonts from its own server and loads maps only on click fixes more violations in one day than any wave of cease-and-desist letters. The reverse also applies: a customer who cannot change the font source of their rented website builder is liable for a decision they are not even allowed to make.

To supervisory authorities and legislators

Start with the manufacturer

Enforcement today targets individual operators, meaning practices, clubs and businesses that can neither know nor influence what their software does by default. It would be more effective to hold widely used systems, themes and website builders responsible. A binding signal from the browser would have the same advantage: it works regardless of whether the individual website is set up correctly. And, as this report shows, it usually is not.

11Methodology

How we measured

Selection of websites

The starting point is around 39,000 German legal notice (Impressum) pages from the open Common Crawl index. From these we derived the sector, business size, federal state and system used. Business size comes from the legal form and register entries, the federal state from the postcode. From this we drew a sample of 10,500 websites stratified by sector. We were able to measure 10,389 of them completely.

The scan

Each website was opened with a real, automatically controlled browser in three separate sessions: without any interaction, after a click on “Accept all” and after a click on “Reject”. For each state we recorded the third-party servers contacted and the cookies set, plus the security settings, the HTTPS status and whether a privacy policy could be found. The data collection period was 25 June to 9 August 2026, with the majority falling on 4 to 9 August.

Limitations, please read along

  • Stratified, not representative of the population. The sectors are deliberately more evenly populated than they are on the web. This makes comparisons between sectors robust. The overall average is slightly skewed compared with the real German web.
  • Ordinary websites from the long tail. Our sample consists of ordinary German websites. Studies of the most visited sites arrive at considerably higher tracker numbers. Both are true and describe different parts of the same web.
  • Snapshot. A website may have changed the day after the measurement. A single measurement does not prove a permanent state.
  • Technical, not legal. We establish what a website does. We do not establish legal violations. Whether a particular contact is “strictly necessary” cannot be measured. That is a matter for case-by-case examination.
  • Banner detection incomplete. We identify consent tools by known provider addresses and cookie names. Home-built banners without such traces escape us. The share of 9.2 % is therefore a lower bound.
  • Purpose assignment with fuzzy edges. We see the address of the recipient, not the complete request. Whether a connection to googleapis.com was a font, a map or reCAPTCHA in a particular case cannot be separated from that. For our calculation this does not matter, because all three fall into the same group and all three are avoidable. Everything we could not assign with certainty we counted as not avoidable. The counter-calculation is therefore rather too conservative.
  • Two definitions for the privacy policy. The fourth check of the score requires a link directly findable in the scan. The separately reported rate of missing privacy policies of 5.7 % additionally takes into account a follow-up check via the legal notice page. It is the more robust figure.

Other studies for comparison

  • University of Bamberg, 2022. 81 German-language websites with a banner. 79 % loaded trackers before consent, after “Accept” 18 trackers on average. The figures are well above ours because high-traffic sites were examined there. To the study
  • ETH Zurich, USENIX Security 2024. Around 97,000 websites heavily visited in the EU. On 65.4 % of sites with a reject option, data continued to be collected despite rejection. Our German figure of 76 % is in the same order of magnitude. Bouhoula et al., “Automated Large-Scale Analysis of Cookie Notice Compliance”
  • HTTP Archive, Web Almanac 2024. Worldwide, 95 % of websites embed at least one tracker, and the Google Analytics cookie _ga is found on 49 % of desktop sites. In our sample it is 6.1 %. The gap shows the difference between the large commercial websites and the long tail. “Privacy” chapter
  • Federation of German Consumer Organisations (vzbv). One in ten cookie banners is clearly unlawful. A different question, because the design was examined there and the technical effect in our case. The direction is the same. Press release

To our knowledge this is the first Germany-wide measurement of this breadth that compares all three consent states per website and additionally breaks down the recipients by purpose. Should there be an earlier one, we will gladly correct this.

Anonymisation

We name no domains, no operators and no agencies. This applies to the text, to the graphics and to all data we release. Only aggregated figures with a minimum group size are published. We may name the recipients because naming them exposes nobody.

Use

All figures in this report may be used freely with attribution. Suggested citation: simply Legal GmbH (2026): Before you click. Data Protection Report 2026, 10,389 German websites in a three-state scan. Data collection 25 June to 9 August 2026. Licence: CC BY 4.0 (attribution). Online: https://www.dieter-datenschutz.de/en/magazine/data-protection-report-2026

Raw data extracts and special analyses on request from [email protected].

Test your website

You can run the same test as in this study yourself at any time.

See for yourself

Website scanner

Three states, all recipients, all cookies, the security settings. As a report that you can read without prior knowledge. So that you know what your default setting does before someone else wants to know.

Check your website now

Dieter zeigt Daumen hoch