Proprietary Data
State of GDPR Website Compliance: What 636 Real Scans Found
Actual numbers from GetGDPRScan's free GDPR scanner, not estimates.
Quick answer
An analysis of 636 completed GetGDPRScan free GDPR scans found that about a third of sites (32.7%) had no issues flagged at all, 3.3% were missing a privacy policy the scan determined was actually required, and tracking scripts firing without consent appeared in 2.0% of scans. Among sites with a cookie banner, the large majority (95.5%) included a working reject option rather than an accept-only design. Tracking-related concerns were the most frequently flagged category, appearing in about one in five scans.
By GetGDPRScan Editorial · Last updated 2026-07-24
Most compliance content makes claims about "most websites" without ever showing a number. This article is the opposite: real counts from real scans, run through GetGDPRScan's free GDPR checker.
Two caveats matter for reading this honestly. First, this reflects the GDPR module only — AI Act and accessibility versions will follow once a comparable volume of scan data exists for those modules. Second, this sample is self-selected: people who ran a free GDPR scanner are, on average, more privacy-conscious than the median website owner, so real-world violation rates across the wider web are plausibly higher than what's reported here.
Where this data comes from
Every number below is drawn from 636 completed scans (out of 641 attempted — a 99.2% completion rate) run through GetGDPRScan's GDPR module. Each scan renders the target page, extracts structured signals, and evaluates them against a fixed set of GDPR-related checks — the same mechanism described in How Website Compliance Scanning Actually Works. No scan target URLs, IP addresses, or other identifying information are included in or derivable from this report — only aggregate counts.
The most common real violations
Filtering out informational and "not applicable to this site" findings, these are the actual compliance gaps that showed up most often:
Real flagged violations, by share of scans (n=636)
| Issue | Severity | % of scans |
|---|---|---|
| Form collects personal data with no consent checkbox | Medium | 9.6% |
| Tracking scripts detected (needs DPA / consent review) | Medium | 8.0% |
| Google reCAPTCHA in use (needs privacy policy disclosure) | Medium | 3.6% |
| Privacy policy missing (required for this site) | High | 3.3% |
| Tracking scripts firing without consent | High | 2.0% |
| Personal data submitted via a GET request (URL leakage) | Medium | 1.7% |
| Cookie banner present but no reject option | Medium | 1.3% |
How GetGDPRScan checks this: These figures come directly from GetGDPRScan's GDPR module's automated detection logic — the same checks every free scan runs.
What's actually rare vs. what just looks common
Two findings are easy to misread if you only look at raw frequency. "No cookie banner detected" showed up on 23.3% of sites — but the scan flagged this as informational in almost all of those cases, meaning it determined a banner wasn't required because the site wasn't setting non-essential cookies in the first place. The real violation — a cookie banner that's required but missing — was notably rarer, appearing on well under 2% of sites.
Similarly, "no privacy policy" appears twice in the data with opposite meanings: 5.3% of sites had no privacy policy but the scan determined none was required for that site's data practices (informational), while a separate 3.3% were missing a privacy policy the scan determined actually was required — that second number is the one that represents real exposure.
Positive signals: what sites are getting right
About a third of scans (32.7%) found no issues at all. Of the 177 sites where a cookie banner was detected, 95.5% included a working reject option rather than an accept-only design — accept-only banners, a well-known dark pattern, were the minority, not the norm, in this sample. A small number of sites (1.9%) were specifically confirmed to have tracking scripts correctly blocked pending consent, which the scan treats as the compliant reference behavior, not a flaw.
Which categories of concern come up most?
Grouping flagged items by category (not every flagged item carries a category tag, so these percentages are a lower bound): transparency-related issues appeared in 35.8% of scans, data-collection issues in 26.1%, third-party service disclosures (fonts, reCAPTCHA, and similar) in 23.1%, and tracking-related issues in 19.8%.
Average risk sub-scores, on a 1–10 scale where higher means more risk factors triggered, stayed low across the board: 2.0 for tracking, 2.0 for data collection, and 1.6 for transparency — consistent with most sites triggering only one or two risk factors rather than accumulating many.
How often does a scan need a full browser render?
12.3% of completed scans required a full Playwright browser render rather than a simpler HTML fetch — typically triggered by JavaScript-heavy pages, bot-blocking, or low-confidence results from the faster path. See How Website Compliance Scanning Actually Works for why that distinction exists.
Key takeaways
- •32.7% of 636 completed scans had no GDPR issues flagged at all.
- •Real violations were less common than raw "no banner / no policy" counts suggest — most of those cases were informational ("not required for this site"), not actual gaps.
- •A missing required privacy policy (3.3%) and trackers firing without consent (2.0%) were the most serious, if less frequent, findings.
- •95.5% of sites with a cookie banner included a working reject option — accept-only banners were the minority.
- •This is a self-selected sample of free-scanner users, not a random sample of the web — real-world rates elsewhere are plausibly higher.
FAQ
Related
What Is a Website Compliance Platform?
The category this data comes from — one scan, multiple compliance modules.
GDPR Compliance for Websites: The Complete Guide
What GDPR actually requires, behind the numbers in this report.
Website Compliance Checklist
The most common issues across GDPR, AI Act, and accessibility, and how to prioritize fixes.
GDPR compliance scan
Run a free GDPR compliance scan of your own website.