State of EU/UK Retail Cookie Compliance 2026

We scanned the homepages of large EU and UK online retailers — no logins, no clicks, one visit each — and measured the three cookie-consent failures European regulators actually fine for. Results are reported in aggregate; the full site list and method are published below.

Scanned 2026-07-28 · 79 of 166 attempted retailers measured

Findings

How to read these numbers

The scanner identifies itself honestly — a PrivacyForgeResearch user-agent linking back to this page — and never bypasses bot defences, rate limits or challenge pages.

That has a cost: 87 of the 166 retailers we attempted could not be measured — 76 refused the scanner outright and 11 were unreachable, timed out or returned nothing. Every rate below is computed over the 79 sites that could be measured — and how much of large EU/UK retail is closed to an honestly-identified compliance scanner is itself one of this study’s findings.

Banners with no first-layer reject option10.1%

Share of the homepages that showed a banner.

Sites firing third-party trackers before any consent65.8%

Share of all measured sites.

Sites showing a cookie banner on the homepage87.3%

Share of all measured sites.

Consent Mode set to deny by default100%

Share of the sites where Google Consent Mode was detected (14 of 79 measured sites).

CountryMeasuredFirst-layer rejectTrackers before consent
DE1662.5%31.3%
ES3Percentage suppressed: fewer than 10 measured sites.Percentage suppressed: fewer than 10 measured sites.
FR9Percentage suppressed: fewer than 10 measured sites.Percentage suppressed: fewer than 10 measured sites.
IT1050%90%
NL1190.9%54.5%
UK3093.3%86.7%

Percentages are suppressed for countries with fewer than 10 measured sites — the sample is too small to carry a rate. Their measured counts are shown for completeness.

Reuse this data: the aggregates on this page are licensed CC BY 4.0 — cite “PrivacyForge, State of EU/UK Retail Cookie Compliance 2026” with a link.

Methodology

  1. Sample: the 166 attempted sites published in the appendix below — large online retailers in the UK, Germany, France, Spain, Italy and the Netherlands (150 hand-curated primaries plus a 16-site spare tranche promoted in full), with one storefront per retail brand: no brand appears twice or in two markets, though a large retail group may appear through several of its brands. The country tag is the storefront’s home market.
  2. Instrument: a Playwright (headless Chromium) scanner visiting each homepage once with a fresh browser profile, en-GB locale, and an identifying research user-agent (PrivacyForgeResearch). The scanner never interacts with consent controls — it loads the page, waits six seconds, and reads. The scan ran on 27–28 July 2026 from a UK vantage point.
  3. Measure (a) — first-layer reject: whether the visible consent banner contains a reject/refuse/only-necessary control at its first layer, matched against a six-language lexicon. A "settings" or "preferences" door does not count — that is the pattern CNIL fined Google €150M and Facebook €60M for.
  4. Measure (b) — pre-consent tracking: whether any request to a known third-party tracking host fired before any consent interaction, matched against a published list of tracker domains. The Google Tag Manager loader itself is deliberately not counted.
  5. Measure (c) — Consent Mode default: where Google Consent Mode is present, whether ad_storage and analytics_storage default to denied before interaction.
  6. Aggregate-only reporting: per-site results are not published. Rates are computed over the 79 sites that could be measured. The scanner identifies itself honestly and never bypasses bot defences, rate limits or challenge pages, so a site that refuses it is recorded as an exclusion rather than worked around: of the 87 excluded sites, 76 were bot-blocked (a 4xx/5xx bot response — HTTP 400, 403, 429 or 503 — or a challenge page), 7 failed with a protocol or interrupted-navigation error, 2 no longer resolve, 1 returned an empty page and 1 timed out.
  7. Limitations: one homepage visit per site from a UK vantage point; JavaScript rendered for six seconds; banners served only on inner pages, geo-targeted variants, and post-consent behaviour are out of scope. Detection heuristics were verified against the viewport screenshot captured for every scanned site: a random audit of sites recorded as showing a banner agreed on 9 of 10, and every site recorded as showing no banner was screenshot-checked individually, as was every site re-scanned after an instrument fix.
  8. Limitation — banner detection is a floor: a banner counts as present only when its first layer exposes readable control labels, so notice-only banners and icon-only controls are not counted, and a consent-management container that is mounted in the page but never shown to the visitor does not count as a banner shown. The true share of sites presenting some form of cookie notice is therefore at least the figure reported here.

Appendix: the published site list

  • amazon.co.uk (UK)
  • argos.co.uk (UK)
  • tesco.com (UK)
  • sainsburys.co.uk (UK)
  • asda.com (UK)
  • next.co.uk (UK)
  • marksandspencer.com (UK)
  • johnlewis.com (UK)
  • currys.co.uk (UK)
  • asos.com (UK)
  • boohoo.com (UK)
  • jdsports.co.uk (UK)
  • sportsdirect.com (UK)
  • boots.com (UK)
  • superdrug.com (UK)
  • screwfix.com (UK)
  • wickes.co.uk (UK)
  • diy.com (UK)
  • dunelm.com (UK)
  • matalan.co.uk (UK)
  • riverisland.com (UK)
  • newlook.com (UK)
  • very.co.uk (UK)
  • ao.com (UK)
  • ebay.co.uk (UK)
  • hollandandbarrett.com (UK)
  • lookfantastic.com (UK)
  • gymshark.com (UK)
  • wayfair.co.uk (UK)
  • notonthehighstreet.com (UK)
  • halfords.com (UK)
  • toolstation.com (UK)
  • waterstones.com (UK)
  • therange.co.uk (UK)
  • clarks.com (UK)
  • schuh.co.uk (UK)
  • size.co.uk (UK)
  • footasylum.com (UK)
  • mountainwarehouse.com (UK)
  • gooutdoors.co.uk (UK)
  • lakeland.co.uk (UK)
  • petsathome.com (UK)
  • thebodyshop.com (UK)
  • spacenk.com (UK)
  • cultbeauty.co.uk (UK)
  • beautybay.com (UK)
  • selfridges.com (UK)
  • harrods.com (UK)
  • fatface.com (UK)
  • whitestuff.com (UK)
  • otto.de (DE)
  • zalando.de (DE)
  • mediamarkt.de (DE)
  • saturn.de (DE)
  • lidl.de (DE)
  • kaufland.de (DE)
  • obi.de (DE)
  • hornbach.de (DE)
  • dm.de (DE)
  • rossmann.de (DE)
  • douglas.de (DE)
  • thomann.de (DE)
  • conrad.de (DE)
  • cyberport.de (DE)
  • notebooksbilliger.de (DE)
  • bonprix.de (DE)
  • baur.de (DE)
  • breuninger.com (DE)
  • aboutyou.de (DE)
  • home24.de (DE)
  • westwing.de (DE)
  • fressnapf.de (DE)
  • deichmann.de (DE)
  • tchibo.de (DE)
  • alternate.de (DE)
  • reuter.de (DE)
  • shop-apotheke.com (DE)
  • flaconi.de (DE)
  • fnac.com (FR)
  • darty.com (FR)
  • cdiscount.com (FR)
  • leroymerlin.fr (FR)
  • castorama.fr (FR)
  • boulanger.com (FR)
  • laredoute.fr (FR)
  • galerieslafayette.com (FR)
  • printemps.com (FR)
  • sephora.fr (FR)
  • decathlon.fr (FR)
  • veepee.fr (FR)
  • showroomprive.com (FR)
  • but.fr (FR)
  • conforama.fr (FR)
  • auchan.fr (FR)
  • carrefour.fr (FR)
  • e.leclerc (FR)
  • manomano.fr (FR)
  • oscaro.com (FR)
  • sarenza.com (FR)
  • spartoo.com (FR)
  • micromania.fr (FR)
  • nocibe.fr (FR)
  • elcorteingles.es (ES)
  • pccomponentes.com (ES)
  • zara.com (ES)
  • mango.com (ES)
  • bershka.com (ES)
  • stradivarius.com (ES)
  • pullandbear.com (ES)
  • desigual.com (ES)
  • sprinter.es (ES)
  • tradeinn.com (ES)
  • worten.es (ES)
  • phonehouse.es (ES)
  • druni.es (ES)
  • primor.eu (ES)
  • kiabi.es (ES)
  • decimas.com (ES)
  • unieuro.it (IT)
  • euronics.it (IT)
  • mediaworld.it (IT)
  • eprice.it (IT)
  • calzedonia.com (IT)
  • intimissimi.com (IT)
  • ovs.it (IT)
  • coin.it (IT)
  • ibs.it (IT)
  • mondadoristore.it (IT)
  • tannico.it (IT)
  • yoox.com (IT)
  • luisaviaroma.com (IT)
  • bottegaverde.it (IT)
  • kasanova.com (IT)
  • arcaplanet.it (IT)
  • bol.com (NL)
  • coolblue.nl (NL)
  • wehkamp.nl (NL)
  • hema.nl (NL)
  • debijenkorf.nl (NL)
  • blokker.nl (NL)
  • gamma.nl (NL)
  • praxis.nl (NL)
  • intertoys.nl (NL)
  • fonq.nl (NL)
  • bever.nl (NL)
  • ranzijn.nl (NL)
  • expert.nl (NL)
  • kwantum.nl (NL)
  • leenbakker.nl (NL)
  • etos.nl (NL)
  • moonpig.com (UK)
  • robertdyas.co.uk (UK)
  • oliverbonas.com (UK)
  • seasaltcornwall.com (UK)
  • mytheresa.com (DE)
  • galaxus.de (DE)
  • medion.com (DE)
  • rueducommerce.fr (FR)
  • ldlc.com (FR)
  • blancheporte.fr (FR)
  • shein.es (ES)
  • aliexpress.es (ES)
  • notino.it (IT)
  • maxizoo.it (IT)
  • bax-shop.nl (NL)
  • bruna.nl (NL)

Frequently asked questions

What did the study measure?
Three checks on each retailer’s homepage, before any consent interaction: whether the cookie banner offers a first-layer reject option, whether third-party tracking requests fire before consent, and whether Google Consent Mode (where present) defaults to denied. All three map to failures European regulators have actually enforced against.
Why does a missing first-layer reject button matter?
Because making refusal harder than acceptance is the exact pattern the French regulator CNIL fined Google €150 million and Facebook €60 million for in its decisions of late 2021, announced January 2022. The UK ICO, working with the CMA, warned the operators of the UK’s most-visited websites about the same pattern in November 2023, and the EDPB’s cookie-banner taskforce report (January 2023) set out the common enforcement position.
Why could nearly half the sample not be measured?
Because the scanner plays fair. It identifies itself as PrivacyForgeResearch, visits each homepage once, and never rotates identities, solves challenges or otherwise evades bot defences. 87 of the 166 retailers we attempted therefore could not be measured — 76 refused the scanner outright (a 4xx/5xx bot response — HTTP 400, 403, 429 or 503 — or a challenge page) and 11 were unreachable, timed out or returned nothing. Those sites are classified, counted and disclosed here rather than worked around, and every rate on this page is computed over the 79 sites that could be measured. The block rate is a finding in its own right: to an honestly-identified compliance scanner, roughly half of large EU/UK retail is not auditable at all.
Which sites were scanned?
The full site list is published in the methodology appendix on this page. Results are reported in aggregate only — this study names the failure rates, not individual shops.
Why are individual retailers not named?
The purpose is to measure how common these failures are across the market, not to accuse specific operators on the basis of an automated heuristic. Automated detection has error bars; aggregates are robust to them, individual accusations are not.
How does this compare to US enforcement?
US regulators enforce adjacent failures under state privacy laws: Sephora paid $1.2M (2022) for ignoring opt-out signals, American Honda $632,500 (2025) partly for consent flows that made opting out harder than opting in, and California’s CPPA fined retailer Todd Snyder $345,178 (2025) after a misconfigured consent banner failed to process opt-outs for 40 days.
Can I reuse these figures?
Yes — the aggregate data on this page is licensed CC BY 4.0. Cite “PrivacyForge, State of EU/UK Retail Cookie Compliance 2026” with a link to this page.

Fixing these failures is covered step-by-step in our complete GDPR compliance guide and the cookie consent best-practices guide.