PERFMETRIX — in data we trust
All articles
Benchmarks17 September 2026·8 min read

We scanned 37 California court-ordered course sites. 81% had no CMP.

A behavioural scan of a regulated US education vertical. The failure rate matches our UK clinic benchmark. The composition behind it is the reverse.

DeBy Denis · Perfmetrix
fired trackers before any consent interaction
75%fired trackers before any consent interaction
ran no consent platform at all
81.3%ran no consent platform at all
sites readable, of 37 scanned
32sites readable, of 37 scanned
On this page
  1. Every site got a fresh browser and a full request log before any click
  2. The three headline numbers have three different denominators
  3. Absence was verified twice, because one check isn't enough
  4. Five sites were excluded, and that decision moves the number
  5. The scan ran from a European vantage, which under-detects geo-scoped banners
  6. The same failure rate describes two opposite markets
  7. A failure rate this high is a signal of low sophistication, not a queue of customers
  8. What we'd do with a site in this sample

Short answer: we scanned 37 California court-ordered online course providers on 16 September 2026. 32 could be read reliably, and 26 of those 32 — 81.3% — ran no consent management platform of any kind. 75% fired trackers before anyone interacted with a banner, but only 4 of the 24 leaking sites had a consent platform installed at all. That reverses what we found in UK clinics, where every leaking site already had a banner. This vertical isn't misconfigured. It hasn't started.

The distinction matters more than the failure rate does, and it's the part a benchmark usually buries.

Every site got a fresh browser and a full request log before any click

The method is the same one behind every number we publish, and it's deliberately boring.

Each domain loaded in its own browser context, with no cookies carried over from the previous site. Cross-contamination between scans is a real measurement trap, and it's why two people checking the same site in devtools get different answers. We recorded every cookie set and every network request made before any consent interaction — no clicking accept, no clicking reject, no dismissing anything. Then we fingerprinted the consent layer, if there was one.

Firing a tracker before any interaction is the observation. Everything else in this post is arithmetic on top of it.

The three headline numbers have three different denominators

Benchmarks get quoted without their denominators, so here are all three explicitly.

  • 75% fired trackers before any consent interaction. That's 24 sites out of the 32 usable ones.
  • 81.3% ran no consent platform at all. That's 26 sites out of the same 32.
  • 17% of the leaking sites had a consent platform installed. That's 4 out of 24 — a percentage of the leaking sites, not of the sample.

Those three don't stack, and reading them as if they did is the usual way this kind of data gets mangled. Six sites in the sample had a consent platform; four of them leaked anyway. Twenty of the leaking sites had nothing installed to leak past.

Absence was verified twice, because one check isn't enough

A scanner that reports "no consent platform" is often reporting "no consent platform I recognise." Those are different claims and only one of them is worth publishing.

So absence was confirmed two ways: once against the third-party CMP vendors the scanner fingerprints, and again against self-hosted consent plugins in the served HTML. A site only counts as having no consent layer when neither check finds one. The second pass is what separates a genuine absence from a gap in our detector — a site running a plugin we've never seen still leaves the plugin's markup in the page.

We've been caught by exactly this before, which is why the second check exists.

Five sites were excluded, and that decision moves the number

Five of the 37 scanned sites are not in any figure above. The scanner couldn't determine their consent layer either way — not present, not absent, unreadable.

Counting those five as failures would have pushed the headline rate up. It would also have been wrong, and it's the specific way this kind of benchmark gets inflated: an undetected consent layer looks identical to a missing one if you don't separate them. So they're excluded, the denominator is 32 rather than 37, and the exclusion is on the record.

If anyone publishes a per-vendor breakdown of a vertical like this, ask how they detected each platform and what they did with the ones they couldn't. We're not publishing one from this data.

The scan ran from a European vantage, which under-detects geo-scoped banners

This is the limit that constrains the finding most, so it goes in the post rather than a footnote.

Our scanner egresses from EU-West. These are US sites, and a site that serves a California banner only to US traffic may have shown us nothing while showing a visitor in Sacramento a perfectly good consent layer. That biases the "no CMP" figure upward by an amount we can't quantify from this run.

It cuts the other way too. A site that serves a European visitor a GDPR banner and a US visitor nothing would read as having a consent layer here, when the thing a Californian sees is bare. Both errors are live in this dataset. Fixing it needs US egress, which is an infrastructure change rather than a code one, and it's on our list.

Two further limits, stated plainly: this is one vertical in one state at one moment, so 81.3% is not a US figure and shouldn't be quoted as one. And we are not making a legal determination about any site we scanned. Whether the CCPA applies to a given business depends on revenue and data-volume thresholds we didn't measure. What we measured is what the tags did.

The same failure rate describes two opposite markets

Set this against the private UK clinics we scanned in July 2026. There, 37% of sites fired Google trackers before consent — and 100% of those already had a consent platform installed. The banner was bought, deployed, and never wired to the tags it was meant to control. That's a repair job: the parts are on site, someone has to connect them.

California court-ordered course providers produce a worse headline number and a completely different problem. 17% of the leaking sites had a consent platform. The other 83% had nothing at all.

You cannot repair a consent layer that was never installed, and the pitch that works on the clinics — your banner isn't doing what you think it's doing — lands on nobody here. Same measurement, same scanner, opposite conclusion. A benchmark that reported only the failure rate would have hidden that completely.

If you want to know which of those two descriptions fits your own site, the cookie scanner loads it in a real browser and reports what fires before any consent interaction, along with whether it can see a consent layer at all. It's the same pipeline these numbers came out of.

A failure rate this high is a signal of low sophistication, not a queue of customers

The commercially convenient reading of 81.3% is a large untapped market. We don't think that's what it says.

A site with no consent platform has usually not decided against one. It has not considered the question. There's no procurement, no vendor, no internal owner, and often no analytics setup worth protecting — several of these sites fired nothing at all, which is its own kind of answer. The businesses that show up as failures in a scan like this are, for the most part, businesses that haven't started measuring anything.

The 19% with a platform installed are a different conversation entirely, and a much shorter one. They've made the decision, spent the money, and in four cases out of six are getting nothing for it. Whether their consent rate is any good is a question they can actually act on; a business with no banner has no consent rate to improve.

That's also why we'd treat a drop in reported conversions here differently. On a site with a working banner, reported traffic falling after a consent layer goes in is the expected cost of the thing working. On a site in this sample, there's nothing yet to cause it.

Regulators are not waiting for the vertical to mature, for what that's worth. In September 2025 the California Privacy Protection Agency announced a joint investigative sweep with the Attorneys General of California, Colorado and Connecticut, contacting businesses that appeared not to be processing opt-out requests. That's enforcement attention on the mechanics of opting out, aimed at businesses that already have something to opt out of.

What we'd do with a site in this sample

For the 81%, the honest first step isn't a consent platform. It's working out whether the site sells or shares personal information in the sense Cal. Civ. Code § 1798.135 uses, because that's what determines whether an opt-out mechanism is required and what it has to do. Buying a banner before answering that produces a banner that satisfies nobody.

For the 19%, the work is the same as everywhere else: confirm the platform is wired to the tags, confirm the consent signals reach Google rather than stopping at the banner, and re-scan to prove the pre-consent requests are gone.

We'll keep scanning verticals and publishing the composition rather than just the headline. If you'd like the consent layer on your own estate checked properly — wired, signalling, and verified from the geography that matters — that's the work we do.

Sources

  1. 1.Perfmetrix scanner — behavioural scan of California court-mandated online education sites, n=32 usable of 37 scanned (our own data; method below) · 16 September 2026
  2. 2.Perfmetrix — UK private clinic consent benchmark (our own prior scan, for comparison) · 8 July 2026
  3. 3.California Privacy Protection Agency — joint investigative sweep with the Attorneys General of California, Colorado and Connecticut into businesses not honouring opt-out requests · 9 September 2025
  4. 4.Cal. Civ. Code § 1798.135 — methods of limiting sale, sharing and use of personal information · Checked 2026-09-17

Find out what your site leaks — in 30 seconds

Run the free consent checker on your own domain, or book a call and we'll walk your setup together.