The Privacy Compliance Report: We Graded 3.3 Million Sites and 62% Fail Basic Data Protection

Update — 2026-06-29: Refreshed against LLMSE's current index of 3.34 million classified URLs (up from ~1.5M at first publication; the privacy-graded population specifically grew from the 148,360 sites in the original to 3,335,497). Privacy is now one of six graded quality dimensions. Every number is recomputed, and two things changed. First, the alignment: the original reported an "A or B" pass; this version follows the current standard where privacy pass = grades A-C (37.0%) and reports the strict A-or-B as a separate "strong pass" (now 5.4%, down from 6.5%). The outright-fail (F) rate rose from 58.6% to 62.0% as broader crawl coverage pulled in lower-quality sites. Second, the corrections: the original's hand-built per-site tables and its full SEO×privacy cross-tab were dropped in favor of reproducible aggregates, and under the current A-C standard Wix actually clears (60.1%, almost all of it C-grade) — leaving Squarespace, not the Wix/Squarespace pair the original named, as the true platform laggard. The thesis holds and hardens: privacy compliance is still the exception, not the norm.

Privacy regulation has teeth now. Cumulative GDPR penalties have passed €5.65 billion across more than 2,560 individual fines (CMS GDPR Enforcement Tracker, March 2025), California's CCPA gives consumers a right to opt out of the sale or sharing of their data, and regulators are fining named companies specifically for how their cookie banners behave. The question is no longer whether websites should comply — it is whether they actually do.

The prevailing assumption is that, a decade into GDPR, the basics are settled: surely most sites now show a consent banner, link a privacy policy, and gate their trackers. The legal text is unambiguous. Under the EU's ePrivacy rules a site must obtain prior consent before setting any non-essential cookie, implied consent does not count, and GDPR Article 7 requires that consent be demonstrable, freely given, and as easy to withdraw as to give. A compliant front page is not technically demanding.

It is also, in aggregate, rare. We graded 3,335,497 websites on the privacy signals a regulator, browser, or informed user would actually encounter — a cookie-consent mechanism, the presence of a privacy policy and a cookie policy, a CCPA "Do Not Sell" link, third-party tracker volume, whether tracking scripts are gated behind consent, and a visible data-processing disclosure. Every grade comes from LLMSE's automated privacy analyzer applied uniformly across the index, not a hand-picked sample of brands.

Only 37.0% of the web passes (grades A-C), 62.0% fails outright with an F, and just 5.4% earn an A or B. The distribution has a hollow middle: sites either do enough to land a C or do almost nothing and crash to F, with barely anyone in between. The pattern by sector and platform is consistent and revealing — the industries and tools that routinely handle payments and customer accounts protect data best, the ones that handle little protect it worst, and a site's search-optimization effort tells you almost nothing about its privacy posture.

The Data

Privacy is one of six quality dimensions LLMSE grades across the index. Positioning it against the others shows it is a middling-pass dimension — far above the near-universally-failed discovery axes (SEO, AEO), below trust and accessibility:

Dimension URLs graded (web-wide) Web pass rate
SEO 3,362,329 1.9%
AEO (AI answers) 3,337,419 1.5%
EEAT (trust) 3,358,303 45.4%
WCAG (accessibility) 3,341,342 43.8%
Readability 3,341,493 32.8%
Privacy 3,335,497 37.0%

Pass rates are computed over the population actually graded on each dimension — not every URL carries every grade, so the denominators differ. SEO, AEO, EEAT, WCAG, and Privacy pass at grades A-C; Readability passes at A-B. The privacy population (3.34M) is the largest single-dimension dataset this site has reported on. This post slices it three ways: by content category, by the CMS or framework the site runs, and against each site's SEO grade.

Methodology

This post makes quantitative claims, so the definitions and limits matter.

  • Grades and "pass." Each site is scored 0-100 by the privacy analyzer and graded A (90-100), B (80-89), C (70-79), D (60-69), or F (0-59) — there is no E grade. "Pass" means A+B+C (the current cross-dimension standard); we report the stricter A+B as a "strong pass" separately where it changes the story.
  • What the privacy grade measures. Scoring is deduction-based from a starting 100. The analyzer detects, and penalizes the absence of: a cookie-consent mechanism / CMP (the heaviest single signal), a privacy policy link (equally weighted), a dedicated cookie policy, a CCPA "Do Not Sell" link, third-party tracker volume (a penalty triggers at five or more tracking domains), whether tracking scripts are consent-gated, and a visible data-processing disclosure. The two heaviest signals — consent mechanism and privacy policy — carry the most weight; losing both drops a site to a C at best, and the secondary penalties (no cookie policy, no opt-out link, excessive trackers) are what push the majority into F. The grade reflects what is visible on the rendered page, the same posture a regulator or browser would observe.
  • Classification basis. Category membership is by LLM classification; the CMS/framework label is by automated technology fingerprinting; each grade is an independent automated analyzer. The privacy check is heuristic and front-page-oriented: it cannot read a privacy program, only its on-page evidence.
  • Cross-references are computed as set intersections (Redis ZINTERCARD) between a segment index (a category, an app-<CMS> index, or an seo-<grade> index) and the privacy grade indices. All counts are aggregate; no individual site is identified.
  • Known limits. Pass rates are over graded populations, smaller than raw segment size. The CCPA "Do Not Sell" signal is calibrated to a maximal multi-jurisdiction standard, so sites with no US/California audience are mechanically penalized for a link they have no legal obligation to show — read the absolute numbers as compliance with a strict superset, not with any single law. Flag small samples: the Wix (3,003 graded) and SEO grade-A (1,044 graded) buckets are below the ~10K threshold and are noted where used. Counts are a live snapshot and drift as classification continues. Russian-language sites are excluded from all breakdowns.
  • Why these numbers differ from the 2026-03 original. The index grew from ~1.5M to ~3.4M URLs, and this post's privacy-graded population grew from 148,360 to 3,335,497. Early grades skewed toward higher-quality, more-visible sites, so the outright-fail rate rose (58.6%→62.0%) as coverage broadened. The original also reported "A or B" as its pass bar (6.5%, now 5.4%); aligning to the current A-C standard puts the headline pass at 37.0%. Claims that depended on hand-picked site lists or a full grade×grade cross-tab were dropped and rebuilt as reproducible aggregates.

The Scorecard

Across the whole web, the privacy grade curve is bottom-heavy and bimodal:

Grade Sites Share
A (90-100) 64,528 1.9%
B (80-89) 115,137 3.5%
C (70-79) 1,053,403 31.6%
D (60-69) 33,733 1.0%
F (0-59) 2,068,696 62.0%

Distribution of privacy grades across 3.34M URLs: F dominates at 62.0%, C holds 31.6%, and A/B/D are slivers — a hollow middle between a thin top and a heavy bottom

The middle does not exist. Combined, the A, B, and D bands account for 6.4% of the web; the other 93.6% is split between a single basic-compliance tier (C, 31.6%) and outright failure (F, 62.0%). The shape is a fingerprint of how privacy actually gets implemented: a site either installs a consent mechanism and links a policy — which clears the C threshold — or it does effectively nothing and falls to F. The thin D band (1.0%) means almost no site lands "partway"; once an operator starts caring, it usually clears C, and the strong-pass A/B tier (5.4%) is where genuine consent-gating, complete policies, and tracker discipline live. The rest of this report card is the story of who occupies which tier, and it begins with Privacy by Industry.

Privacy by Industry: Commerce Protects, the Builders Don't

Ranking 16 mainstream sectors by privacy pass rate produces a clean gradient anchored by data sensitivity. The standout cell per column is bolded.

Sector Sites graded Privacy pass (A-C)
Shopping 41,036 60.6%
Health 76,254 52.7%
Beauty & Fitness 47,020 50.3%
Finance 18,019 49.1%
Food & Drink 42,680 48.4%
Law & Government 19,205 48.0%
Home & Garden 43,604 47.1%
Business & Industry 1,017,500 45.6%
Travel 31,356 45.3%
Sports 36,660 44.2%
Entertainment 222,984 43.1%
Automotive 65,908 41.7%
Education 121,404 40.9%
News & Media 70,377 40.1%
Real Estate 19,965 37.5%
Computer & Electronics 394,805 22.8%
Web average 3,335,497 37.0%

Privacy pass rate by industry: Shopping leads at 60.6%, the data-sensitive sectors cluster near 50%, and Computer & Electronics trails far below the 37.0% web average at 22.8%

Shopping leads privacy at 60.6% — the only sector clearing 60% — followed by a tight cluster of categories that routinely process personal and payment data: Health (52.7%), Beauty & Fitness (50.3%), Finance (49.1%), Food & Drink (48.4%). E-commerce has spent two decades treating consent banners and privacy policies as table stakes, because they sit on the same checkout pages that handle card data; only 38.4% of graded Shopping sites score F, the lowest failure rate on the board. This is consistent with the same Shopping-leads-privacy pattern reported in the companion cross-industry quality report card, and it points to a plausible mechanism rather than a proven one: where a sector handles sensitive user data, it invests in the visible privacy signals; where it doesn't, it doesn't bother.

Computer & Electronics is worst at 22.8% — roughly 14 points below the web average and the only sector under 30% — with 76.7% of its sites scoring F. The irony is hard to miss: the sector that builds tracking infrastructure is the least likely to gate it. Developer blogs, documentation, project pages, and forums collect little obvious data and disclose less, so they skip consent mechanisms and policy links that the grader rewards. Entertainment sits mid-pack (43.1%, 56.5% F) — ad-supported models and heavy third-party script loading drag it down despite scale. The gradient is not about money or regulatory attention in the abstract; it tracks how directly a sector touches a payment form.

Privacy by Platform: Shopify's Defaults, Squarespace's Gap

The CMS or framework a site runs is the single strongest predictor of its privacy grade in this dataset, because managed platforms ship defaults. Best cell per column bolded.

Platform Sites graded Pass (A-C) Strong (A-B) Grade F
Shopify 15,241 76.9% 12.8% 21.8%
Webflow 13,311 69.2% 19.5% 30.0%
Wix 3,003 60.1% 1.0% 39.0%
Drupal 34,954 56.7% 8.9% 42.0%
WordPress 1,046,377 47.2% 9.2% 51.4%
Joomla 28,081 38.1% 5.8% 60.3%
Next.js 20,757 31.8% 3.0% 66.9%
Squarespace 26,270 20.8% 0.9% 78.8%
Web average 3,335,497 37.0% 5.4% 62.0%

Privacy pass rate by platform: Shopify leads at 76.9%, Webflow and Wix follow, and Squarespace trails far below the web average at 20.8%

Shopify is the privacy leader at 76.9%, double the web average, with the lowest failure rate of any platform (21.8% F). Its hosted checkout and built-in cookie-consent tooling give every merchant baseline compliance out of the box — a default that no individual operator has to think about. Webflow (69.2%) and Drupal (56.7%) follow, both associated with professionally built sites.

The Wix result is the headline correction to the original report. Under the current A-C standard Wix passes at 60.1% — well above the web average — but almost all of it is C-grade: its strict A+B "strong pass" is just 1.0%. Wix reliably gets sites to a basic consent-banner-plus-policy floor and almost never beyond it. The original post, which counted only A+B as a pass, therefore called Wix a laggard; on the standard it is mid-field, but the strong-pass column shows the original was capturing something real — Wix privacy posture is shallow even when present.

Squarespace is the genuine laggard at 20.8% pass and 78.8% F — worse than the average on every measure. Despite being a "managed" platform, it does not push consent tooling the way Shopify does, and its largely small-business, marketing-site user base rarely adds it. WordPress sits mid-table at 47.2%, but its enormous footprint means its 51.4% F rate alone accounts for over half a million failing sites — and that F rate is sharply up from the 42% the original reported, as the broader crawl reached deeper into the long tail of abandoned and unmaintained WordPress installs. Next.js (31.8%) underperforms for the predictable reason that it is a developer framework, not a managed platform: privacy falls entirely on the build team and is clearly not a default priority.

The Consent Banner Is the Whole Ballgame

The single heaviest signal in the grade is the cookie-consent mechanism, and it is the one most of the failing web omits. That is not a stylistic preference — it is the precise behavior regulators are now fining. France's CNIL fined Google a total of €150 million and Facebook Ireland €60 million on 31 December 2021 for cookie banners that let users accept in one click but required several clicks to refuse, holding that a site must let users reject cookies as easily as accept them. The UK's ICO has pursued the same standard, reprimanding Sky Betting & Gaming in September 2024 for setting advertising cookies before obtaining consent. GDPR Article 7's requirement that consent be as easy to withdraw as to give is exactly the asymmetry these actions target. A site that loads trackers before showing a banner is not merely scoring poorly on our grade; it is doing the thing that has produced nine-figure penalties.

The browser-level backstop that was supposed to make this moot has weakened, which raises the stakes rather than lowering them. Safari's Intelligent Tracking Prevention blocks third-party cookies by default and Firefox's Total Cookie Protection partitions them, both on by default. But Chrome — the majority browser — reversed course in April 2025, declining to deprecate third-party cookies or even add a consent prompt, and Google wound down the Privacy Sandbox initiative later in 2025. The original version of this post argued that platform-level enforcement was quietly dismantling unconsented tracking; that prediction has reversed. With the dominant browser keeping third-party cookies alive, the burden of consent falls back where the law always put it — on the site operator — and the 62% F rate is the measure of how few have picked it up.

Does SEO Investment Predict Privacy? Barely

A reasonable hypothesis is that sites which invest in being found also invest in compliance — both are signs of an operator that takes its web presence seriously. The data only half-supports it. Cross-referencing every site's SEO grade against its privacy grade:

SEO grade Sites graded (privacy) Privacy pass (A-C) Privacy-F
A 1,044 46.6% 50.9%
B 13,075 48.8% 49.5%
C 49,922 48.7% 49.6%
D 120,805 48.7% 49.9%
F 3,146,872 36.2% 62.8%
Web average 3,335,497 37.0% 62.0%

Privacy pass rate by SEO grade: sites graded A through D on SEO cluster near 48%, but SEO-F sites drop to 36.2%, and even top-SEO sites fail privacy about half the time

The relationship is a single step, not a slope. Any site that clears SEO grading at all — A, B, C, or even D — passes privacy at a flat ~47-49%, roughly 12 points above the SEO-F majority (36.2%) and the web average. There is a real association at the coarse level: an operator who has done any SEO work is meaningfully more likely to have done privacy work too. But the slope within the passing bands is flat, and the top of the SEO ladder buys nothing extra — sites graded A on SEO pass privacy only 46.6% of the time and land in privacy-F 50.9% of the time (a small bucket of 1,044 sites, so treat the exact figure as indicative). In other words, being excellent at search optimization does not make a site any likelier to protect data than being merely competent at it. SEO and privacy are run by different teams against different incentives — crawlers versus regulators — and they rarely coordinate. A strong search reputation is no proxy for compliance, which is the practical reason to check both.

What's at Stake

  • 62% of the web fails an automated check that mirrors what regulators enforce — and the failures are concentrated in the heaviest-weighted signal (consent), the exact behavior behind CNIL's €210M in cookie fines and the ICO's reprimands. Most operators are one complaint away from being on the wrong side of a published enforcement standard.
  • Platform choice is destiny for small operators — a merchant on Shopify inherits a 76.9% pass posture for free, while a comparable site on Squarespace inherits a 20.8% one. The compliance gap between platforms is wider than the gap between most industries, and it is invisible to the operator until something goes wrong.
  • Low-privacy sectors are a latent liability, not a safe default — Computer & Electronics scores worst (22.8%) precisely because it collects little today, but the moment a documentation site adds a newsletter signup, analytics, or a support form, it inherits obligations its 76.7%-F infrastructure was never built to meet.
  • The browser backstop reversed — with Chrome keeping third-party cookies and the Privacy Sandbox shelved, unconsented tracking is no longer being deprecated out of existence. The legal exposure that operators were quietly relying on platforms to neutralize is back on their own books.

What Would Help

  1. Site owners: check privacy alongside the dimension you already track. Strong SEO predicts almost nothing about your privacy grade — top-SEO sites still fail privacy half the time. Run a full multi-dimension check at llmse.ai/classify rather than assuming a polished, well-ranked site is also compliant.
  2. Small businesses: let the platform carry compliance. The single highest-leverage privacy decision a non-technical operator makes is the CMS. Shopify and Webflow ship consent and policy defaults that clear the bar; if you are on Squarespace or a bare framework, adding a managed consent tool is the cheapest move available.
  3. Developers and technology publishers: add the consent layer you omit by default. Computer & Electronics and Next.js sites fail privacy together. A consent mechanism, a linked privacy and cookie policy, and gating analytics behind consent are a few hours of work that move a site from F to C — and bring it onto the right side of GDPR Article 7 and ePrivacy consent rules.
  4. Compliance teams: treat the consent banner as the control that matters. Enforcement is concentrated on cookie behavior — accept-as-easily-as-reject, no firing before consent. Audit that one interaction first; it is both the heaviest signal in the grade and the one regulators have repeatedly fined. See how your stack scores on the privacy analyzer.
  5. Platform and CMS vendors: ship consent on by default. The Shopify-versus-Squarespace gap shows that defaults, not user effort, determine aggregate compliance. Vendors who turn on a compliant consent mechanism out of the box would move millions of sites at once — far more than any amount of operator education.

This analysis was conducted using LLMSE, which has classified over 3.4 million websites across SEO, EEAT, AEO, WCAG accessibility, readability, GARM brand safety, and privacy dimensions. Privacy figures reflect the 3,335,497 sites graded on the privacy dimension as of June 2026. To analyze your own site across every dimension in this report, visit llmse.ai/classify.