
Most German websites pass on something about your visit before you can click anything. Very few of them mean to.
When you open a website, more happens in the first second than you can see. We wanted to know how much of it goes to third-party companies without any action on your part. So we automatically visited 10,389 German websites: medical practices, trade businesses, clubs and associations, law firms, shops, public authorities. We opened each one three times. Once without clicking anything. Once after a click on “Accept all”. And once after a click on “Reject”.
The result surprised us. Most of the data that flows out unasked is never analysed by anyone. It flows because a font is loaded from a third-party server.
You can run the same test as in this study yourself at any time: three states, all recipients, all cookies, the security settings. As a report that anyone can read without prior knowledge.
So that you know what your default settings do before someone else wants to know.
Almost everyone finds cookie banners annoying. That is why the European Union is working on new rules. Two changes in particular are planned. First, there should be a few clearly defined purposes for which a website no longer has to ask at all. Second, anyone who has said “no” once should not be asked again for six months.
Both sound sensible. But both only work if a “no” actually gets through technically on the website. That is exactly what we measured. On roughly three out of four websites, it does not.
A third point is still being fought over. You could set the “no” once in your browser, and all websites would have to respect it. Then the banners would no longer be needed. Several governments, including the German one, and parts of the advertising industry are pushing to have this point removed. As of September 2026, nothing has been decided.
A few terms are needed to make the figures in this report understandable. If you already know them, skip straight to chapter 2.
When you type in an address, your browser fetches the page from the operator’s server. But that page usually doesn’t contain all of the content. It contains instructions like “fetch the font from this other address” or “show the map from that provider here”. Your browser follows these instructions immediately and without asking. So it opens connections to further companies. These companies are called third parties.
Each of these connections reveals something to the third-party company: your IP address, that is the number under which you can currently be reached on the internet, which page you are looking at, and technical details about your device. On its own, that is not much. Across many websites, it adds up to a picture.
A cookie is a piece of text that a website stores in your browser and can read again later. Some cookies are harmless and necessary, such as the one that remembers the contents of your shopping basket. Others contain an ID number that lets a provider recognise you across many sites. Under German law, cookies like that need your consent before they may be set.
This is exactly where our measurement comes in. For every website, we made three separate visits and each time noted which third-party servers were contacted and which cookies were set:
Comparing these three states is the core of this report. To our knowledge, there has been nothing of this breadth for Germany before.
The page you are reading right now loads nothing from third-party servers. The font is embedded in the document, the graphics are drawn in the document, and so is the data. In the top right you can see a counter. It reads zero, and your browser calculated it itself. This is what a website can look like.
We check every website on five points. That gives 32 possible results. In reality, only 24 of them occur.
The five checks are:
One result occurs particularly often. 23.1 % of all websites fall into the same pattern: they have a privacy policy. They use no advertising or analytics tool. And they still contact third-party servers before anyone could click. Clicking Reject changes nothing, and the security settings are missing.
These websites don’t want to watch anyone. They still give something away. That is the normal case on the German web, and it is the reason this report turns out differently from what we expected.
The pattern goes beyond this one result. If you add up all the websites that contact third-party servers without using an advertising or analytics tool themselves, you get just over half of all websites examined (5,490 of 10,389).
Just over half of all German websites pass data on to third-party companies even though they don’t use any advertising or analytics tool at all.
To combine the five checks into a single number, we award points. A website that passes all checks scores 100. One that fails all of them scores 0. The average across all websites is 50.0 points.
This average, however, hardly describes any real website. The distribution has two clusters. A large group sits at 30 to 40 points. A second, smaller group sits at 80 to 90 points. In between, it is thin.
The reason is simple. If a website loads anything at all from third-party servers, it usually loads several things at once, and it does so before the click. If it doesn’t, it loads nothing at all. There is little middle ground. 8.2 % of websites pass all five checks at once.
Until now, most studies have counted how much flows out. We additionally checked what for.
Before the first click, the 10,389 websites open connections to 2,691 different recipients. We assigned the 300 most common of them by hand to a company, a country and a purpose. That covers around 86 % of all connections. The rest is a classic long tail, a very long list of recipients that each hardly ever appear: 69 % of all recipients show up on exactly one single website.
This assignment shifts the picture considerably. Advertising and analytics services, which is exactly what cookie banners are meant for, account for 15.8 % of all unrequested connections. The largest single block is a different one: 28.6 % go to Google, and they go there for fonts, for embedded maps or for the spam protection reCAPTCHA.
If you add further things of this kind, that is fonts from other providers, ready-made code libraries, embedded videos and small add-on widgets like rating stars, you get 40.4 % of all unrequested connections. A website can avoid this entire block without visitors noticing any difference. Chapter 10 explains how.
37.1 % of websites contact a Google server before the first click. For most of them, there is no analysis behind it. 21 % of all websites examined, that is 57 % of all websites with Google contact, connect purely because of fonts, maps or reCAPTCHA. Nobody there wanted to measure anything. Google still learns that you opened that page.
A German court has already ruled on why this is no side issue. On 20 January 2022, the Regional Court of Munich I awarded a claimant 100 euros in damages because a website had loaded its font directly from Google and in doing so transmitted her IP address (case no. 3 O 17493/20). The court based its reasoning on exactly what our measurement shows: the operator could have served the font without any connection to Google. The ruling was followed by a wave of cease-and-desist letters, which courts later largely classed as abusive. That changes nothing about the technical finding. (Overview by the Berlin Chamber of Commerce (IHK))
One in five German websites reports the visit to Google merely because it loads a font or a map from there. None of it is analysed.
This question can be answered precisely for every single website.
For each of the 10,389 websites, we know which recipients it contacts before the first click and which purpose group each of them belongs to. So we can strike out a group hypothetically and count how many websites would then be completely quiet. Completely quiet means: not a single third-party server before the visitor has decided.
Before the calculation, that is 32.2 % of all websites. Strike out just one single group, namely Google’s fonts, maps and reCAPTCHA, and it is 41.3 %. One single change, and 9.1 % of all websites switch sides.
Strike out everything that is avoidable without losing any function, and it is 47.2 %. Put another way: for 22.1 % of the websites that currently pass on anything at all, the entire unrequested data flow consists of things like this. No business model depends on it. Nobody would lose out.
A reminder of the first figure in this report: today, 68 % of all websites pass something on before you can click. After the clean-up, it would be 52.8 %.
The websites that remain are about things that actually do something: advertising and analytics tools, website builders that don’t run without third-party servers, payment providers, appointment booking portals. That is what consent and cookie banners are meant for. The problem shrinks from widespread carelessness to a hard core.
Just over one in five websites that currently pass on data could stop doing so completely, right away, without visitors noticing any difference.
This calculation shows what is technically possible. It doesn’t say that it is easy for everyone. If you rent a website from a website-builder provider, you often can’t change the font source yourself at all. That decision is made by the provider. That is exactly what this report is about.
We tested four obvious explanations: sector, federal state, company size and the software used. A model that takes all four into account at once explains 3.4 % of the differences.
What does that mean? Imagine you have to guess how many points an unknown website scores. You are allowed to ask one question first. If you ask which federal state the company is based in, the answer improves your estimate hardly at all. The same goes for the sector, for the company size and, slightly less so, for the software used.
This is the most uncomfortable finding of this report, because it contradicts the most popular form of presentation, namely the ranking. Differences between sectors and federal states do exist, and we list them in full further down. They are just small compared to the differences within each group.
The most vivid test: we randomly pick two websites from the same sector and measure how far apart their scores are. On average, that is 30.2 points. Then we compare websites from two different sectors. Result: 30.2 points. The two values are identical.
In concrete terms: two medical practices are on average 30.0 points apart. A medical practice and an online shop are 30.5 points apart. So knowing which sector you have landed in hardly helps you judge.
This shows most clearly with the most widely used system. 57 % of our sample run on WordPress. Their average is 50.0 points and thus hits the national average exactly. The spread within this group is even slightly larger than that of the entire dataset.
35 % of WordPress sites are completely quiet before the first click. 14 % score 20 points or below. Same software, opposite result. So what a WordPress site does doesn’t depend on WordPress. It depends on which theme was installed, which plugins came with it and what their default settings say. As a rule, nobody makes these decisions consciously. They come with the installation and are never touched again.
If anything ought to influence how a website behaves, it is the question of how sensitive the information a visit reveals is. Anyone who opens a psychotherapist’s website gives away a hint about their health. So we compared the websites of professions bound by confidentiality with all the others: doctors, dentists, psychotherapists, pharmacies, lawyers and tax advisers.
The gaps are so small that they practically do not exist. In the German web, a visit to a therapist is passed on in roughly the same way as a visit to a furniture store. On 9.9 % of healthcare websites a connection to an advertising or analytics corporation is running before any consent is given.
One group stands out in a different direction. Among law firms, on 8.8 % of websites no privacy policy can be found. Among sole practitioners the figure is 12.8 %, roughly one in eight websites. The average across all sectors is 5.7 %.
On average, two medical practices differ from each other in data protection just as much as a medical practice and an online shop.
On 76 % of websites with third-party services it has no measurable effect.
This is the finding most likely to stick from this report. After the previous chapters, though, it reads differently than usual. The reject button is rarely a deliberate deception. It is usually a control that was never wired up to anything, just as the font source was never changed and the plugin never configured.
Instead of a single percentage we show four groups. They make visible what really happens when someone presses “Reject”.
Two figures from this deserve a mention of their own. 19.8 % of all websites contact more third-party servers after the no than on a plain visit without any click at all. So anyone who clicks nothing is better off there than someone who rejects. And across all websites, the reject click lowers the number of server contacts by 12.4 %.
On almost two thirds of websites with third-party services, exactly the same thing happens after a click on “Reject” as after “Accept all”. The button is there; it is just not connected.
9.2 % of the websites examined use a recognisable consent tool, meaning the software behind the cookie banner. You would expect these websites to be cleaner than the rest. Measured, it is the other way round. Before the click they contact 8.4 third-party servers on average, websites without a banner only 3.9. An advertising or analytics tool runs on 29.4 % of their pages before consent; without a banner it is 13.5 %.
It does not follow that banners do harm. It is a selection effect: whoever installs a banner has usually also installed something that needs one. It is still revealing, though. On 81.5 % of websites with a banner third-party services are already running while the banner asks for permission. For you as a visitor this means: a cookie banner does not show that a site takes care. It shows that there is something there to take care of.
How often the no remains ineffective varies a lot depending on the tool used. More interesting than the ranking is a pattern behind it. There are two designs. Some run as a plugin on the site’s own server, others are loaded as a service from a third-party server. Both designs fail in different places. The plugins let hardly anything through before consent, but then ignore the no especially often. The embedded services more often actually switch something off, but almost without exception let other services run beforehand.
The best evidence that nobody is looking comes from the tools that have long been running into the void.
Looking through the cookie names that are set before any consent, you come
across fossils. 31 websites still set cookies with names like __utma
or __utmz. That is the first generation of Google Analytics, which Google
shut down years ago. 248 websites set _gid or
_gat, the markers of the second generation. Google stopped processing
data for it on 1 July 2023 and switched off the interface in 2024. And
7 websites still load AddThis, a service for share buttons that was
discontinued in 2023.
These websites are not tracking anyone. Nobody collects the data. The connection is still established and the cookie still set. Legally, this is the same process as with a working tool: access to the visitor’s device without their consent. It is a data protection violation that benefits nobody.
31 German websites send data to a Google service that has not existed for years. Nothing is received any more. It is still stored on the visitor’s device.
There is a second setting that stays untouched almost everywhere. A server can hand the browser a few rules that make attacks harder. These rules cost nothing and bother nobody. They only need to be set once.
65 % of websites get our worst security grade because these rules are missing. Even among the websites with the best data protection grade the figure is 66 %. So the two topics are not connected, except in one respect: both are a default setting that nobody has changed.
Up to this point it has been about websites. Now it is about what this means for an individual person.
To do this we simulate everyday searches. We randomly draw websites from the matching sector of our sample, as if someone were opening them one after another, and count how many different companies learn of the visit along the way. Nothing is clicked anywhere. Each row below is based on 20,000 runs with real measurements.
A second look at the same question. If you open any website from our sample, there is a 32.2 % probability that it is completely quiet. That sounds like a solid chance. But it shrinks quickly as soon as it becomes more than one site:
Calculated the other way round, you get a pair of figures that sums up the whole report. Until Google learns of you for the first time, you need on average 2.7 page views. Until you come across a website that passes all five checks in this report, you need on average 12.1.
After three websites visited, Google knows on average that you are out and about. Five websites in a row without any data being passed on is something you experience with a probability of 0.35 percent.
The connections are spread across 2,691 different recipients. That sounds like diversity and is not. 69 % of these recipients appear on exactly one single website. At the other end stands a single corporation: 42.4 % of all unrequested connections in the German web lead to Google. The reason is banal. Google runs the standard library of the web: the fonts, the maps, the spam protection, the videos.
This concentration has a consequence that is easy to overlook. No individual website operator sees more than their own site. Out of ten random German websites, Google sees 3.7 of them on average.
The law has no category called “by accident”. It is addressed to the operator of the website, even where in fact the website builder provider or a plugin made the decision.
The decisive provision is Section 25 of the German Telecommunications Digital Services Data Protection Act, TDDDG for short. Put simply, it says: anyone who stores something on a visitor’s device or reads something that is already there needs the visitor’s consent. The only exception is what is strictly necessary for the service explicitly requested. For the transmission of the IP address to a third-party company, for instance when loading a font, the General Data Protection Regulation applies in addition.
In Germany, enforcement rarely happens through fines. It happens through orders from the supervisory authorities and through cease-and-desist letters from competitors and associations.
In November 2025 the EU Commission proposed a package that moves the cookie rules into the General Data Protection Regulation. Two points matter for website operators, a third is contested:
Our measurement has something to say on all three points. On the cooling-off period: it helps little as long as the first no technically does not get through on 76 % of the affected websites. Not being asked for six months while loading continues for six months does not improve the situation. On the browser signal: it would work precisely where the banner fails today, because it does not require a correct set-up on every single website.
On the list of exceptions: none of the four planned exceptions covers Google Fonts, embedded maps or videos. The largest block of unrequested connections in the German web would therefore still need consent after the reform. The debate about the form of the banner leaves the most common violation untouched.
The EU is arguing about how websites should ask for permission. On three out of four websites the answer is not technically evaluated at all.
Because the problem is a default setting, the solution is a setting. The impact figures come from the counter-calculation in chapter 4.
Google Fonts, Font Awesome and similar font packages can be downloaded and stored on your own server. For visitors the site looks exactly the same. The loading time stays the same or improves. The effort is about half a day.
9.1 % of all websites would become quiet through this aloneInstead of embedding the map straight away, you show a preview image. The service is only loaded once someone clicks on it. Ready-made components for this exist for all common systems.
has an additional effect, see the counter-calculatorA banner that does not hold back scripts creates work without protection. You can check this in five minutes: open your own site in a private window, click “Reject”, then open the “Network” tab in the browser’s developer tools and see which third-party addresses still show up.
affects 76 % of websites with third-party servicesDecommissioned analytics accounts, discontinued services, remnants of old website rebuilds. They no longer deliver data to anyone and still create a legal risk.
31 websites still send data to a system shut down long agoFour to five lines in the server configuration. This is the check that most otherwise clean websites in our data collection failed.
65 % of websites fail here todayWhoever ships a theme, a plugin or a website builder decides for tens of thousands of websites at once. A website builder that serves fonts from its own server and loads maps only on click fixes more violations in one day than any wave of cease-and-desist letters. The reverse also applies: a customer who cannot change the font source of their rented website builder is liable for a decision they are not even allowed to make.
Enforcement today targets individual operators, meaning practices, clubs and businesses that can neither know nor influence what their software does by default. It would be more effective to hold widely used systems, themes and website builders responsible. A binding signal from the browser would have the same advantage: it works regardless of whether the individual website is set up correctly. And, as this report shows, it usually is not.
The starting point is around 39,000 German legal notice (Impressum) pages from the open Common Crawl index. From these we derived the sector, business size, federal state and system used. Business size comes from the legal form and register entries, the federal state from the postcode. From this we drew a sample of 10,500 websites stratified by sector. We were able to measure 10,389 of them completely.
Each website was opened with a real, automatically controlled browser in three separate sessions: without any interaction, after a click on “Accept all” and after a click on “Reject”. For each state we recorded the third-party servers contacted and the cookies set, plus the security settings, the HTTPS status and whether a privacy policy could be found. The data collection period was 25 June to 9 August 2026, with the majority falling on 4 to 9 August.
googleapis.com was a font, a map or reCAPTCHA in a particular case
cannot be separated from that. For our calculation this does not matter, because all
three fall into the same group and all three are avoidable. Everything we could not
assign with certainty we counted as not avoidable. The counter-calculation is therefore
rather too conservative._ga is found on
49 % of desktop sites. In our sample it is 6.1 %. The gap shows the
difference between the large commercial websites and the long tail.
“Privacy” chapterTo our knowledge this is the first Germany-wide measurement of this breadth that compares all three consent states per website and additionally breaks down the recipients by purpose. Should there be an earlier one, we will gladly correct this.
We name no domains, no operators and no agencies. This applies to the text, to the graphics and to all data we release. Only aggregated figures with a minimum group size are published. We may name the recipients because naming them exposes nobody.
All figures in this report may be used freely with attribution. Suggested citation: simply Legal GmbH (2026): Before you click. Data Protection Report 2026, 10,389 German websites in a three-state scan. Data collection 25 June to 9 August 2026. Licence: CC BY 4.0 (attribution). Online: https://www.dieter-datenschutz.de/en/magazine/data-protection-report-2026
Raw data extracts and special analyses on request from [email protected].
You can run the same test as in this study yourself at any time.
Three states, all recipients, all cookies, the security settings. As a report that you can read without prior knowledge. So that you know what your default setting does before someone else wants to know.