DataVow
Consent Register — 2026-09
A versioned, timestamped, record-level dataset of how public websites handle consent, built by the same scanner that powers the free Consent Checker. Each record says what one site's homepage served on the day it was scanned — which consent mechanism loaded, which trackers were present, and whether any of it preceded a consent mechanism.
A register like this is how a data or AI team documents the provenance of a source: not a supplier's attestation, but a dated measurement you can cite with a timestamp.
Vintage 2026-09 — summary
What the current vintage contains.
The top 1,100 domains by global rank (Majestic Million, retrieved 2026-09-23), one homepage scan per domain with the Consent Checker engine — a static HTML first pass. Scanned 2026-09-23 03:29 to 2026-09-23 03:31 UTC. Percentages are over the 1008 delivered records. Every number below is computed from the vintage itself — no projection, no extrapolation.
1008
Records in this vintage
1100
Domains attempted
19%
A CMP was detected
29%
A banner was detected
19%
Trackers with no consent mechanism
40%
No privacy-policy link found
66%
No recognized CMP and no banner
Field dictionary
Every field, and what it can and cannot tell you.
The register states findings and their limits. A static scan cannot prove compliance — it records what was measurable on one page, at one timestamp.
| Field | Type | What it records |
|---|---|---|
| domain | text | The scanned domain, as it appears in the source ranking list. |
| rank | integer | The domain's global rank in the source ranking list at retrieval time. |
| scanned_at | timestamp (ISO 8601, UTC) | When the scan ran. This is the timestamp that makes each record citable. |
| cmp_detected | text, nullable | Which consent management platform the page loads, if any (Cookiebot, OneTrust, Axeptio, Didomi, tarteaucitron, Osano, Usercentrics, TrustArc, Iubenda, Consentmanager, Civic Cookie Control). Null means none was detected in the page HTML. |
| banner_present | boolean | Whether consent-banner markup or copy was found in the initial HTML. Asynchronous banners can be missed by a static scan. |
| trackers | list of text | Named tracking scripts present in the page source: Google Analytics (GA4), Google Tag Manager, Meta/Facebook Pixel, LinkedIn Insight, Hotjar, Mixpanel. |
| tracker_count | integer | How many of the named trackers were detected. |
| trackers_without_consent | boolean | True when at least one tracker is present in the page source and no consent mechanism (CMP or banner) was detected. This is the strongest single signal of tracking before consent. |
| privacy_policy | boolean, nullable | Whether a privacy-policy link or reference was detected on the scanned page (GDPR Article 13/14). Null when the page could not be fetched. |
| https | boolean | Whether the scanned URL is served over HTTPS. |
| fetch_ok | boolean | Whether the scan returned page HTML. Failed attempts are kept in the vintage for completeness and excluded from register counts and the sample. |
| fetch_error | text, nullable | For failed attempts only: why the scan could not fetch the page. |
Method and limits
How a vintage is produced.
- One homepage scan per domain, run with the Consent Checker engine: the page HTML is fetched with a declared research user agent and pattern-matched for CMP scripts, banner markup, named trackers, privacy-policy references and HTTPS. Scans run in parallel batches of 12; most pages complete in seconds, slow sites time out after 12 seconds and are recorded as failed attempts.
- Domains come from a public global ranking list, retrieved on the day the vintage is built, in descending rank order.
- A static scan reads the initial HTML. Banners and CMPs injected later by JavaScript can be missed, and a detected script is not proof that it fired before consent. The register records what was measurable, not a verdict (GDPR Article 6; CCPA §1798.100).
- Each vintage is immutable once published. Disputes about a record are answered with the stored scan, not with a correction in place.
Sample
Inspect the vintage before you licence it.
A 500-record CSV sample from vintage 2026-09, with the full field dictionary — the first 500 delivered records by rank. No email required.
Download the sample CSV →Register Licence — $2,500
One-time licence to the full vintage.
- The complete vintage, record level, delivered as CSV.
- A signed vintage manifest: source list, scan window, record count, method.
- The next vintage at no additional cost, to version your citations over time.
Prefer to evaluate over 30 days? Dataset passes give 30-day access from $99 — ask for a pass.