This is a technical scan report, not legal advice. It documents third-party network activity observed on your site and maps it to publicly-filed litigation patterns. It makes no compliance guarantee and no prediction about any legal outcome. Consult a qualified attorney for legal questions.
Original research · scanned July 21–22, 2026

We scanned 252 top US e‑commerce sites the way plaintiff law firms do. 87% failed the first test.

A plaintiff-firm scanner runs three checks: what fires before anyone touches the consent banner, what keeps firing after “Reject All,” and what a Global Privacy Control signal changes. We ran exactly that sequence against 252 prominent US e‑commerce, DTC, and consumer-health sites. This is what the bots that generate demand letters actually see.

87%of measurable sites fired trackers pre-consent
5.7named trackers firing, average per site
82%kept firing with GPC signalled
16 of 19kept firing after “Reject All” was clicked
1site out of 169 earned an A
Of 252 sites scanned, 169 were measurable; 51 blocked our scanner (counted inconclusive, never clean) and 32 were dead or errored. Among the measurable: 147 fired at least one named tracker before any consent interaction. Of the 69 with a detectable consent banner, 58 fired before anyone touched it. Grades: 131 F, 14 D, 15 C, 8 B — and exactly one A.
Why this matters

There is a working industry built on exactly this measurement. Plaintiff law firms run automated scanners using a documented, disarmingly simple method: open a site in a fresh browser session, watch the network tab, and log every third-party request that fires before the consent banner is touched. That log becomes “Exhibit A” in a demand letter — alongside a cover letter alleging wiretapping under the California Invasion of Privacy Act (§631) and/or its pen-register provision (§638.51), a draft complaint, and a 14–30 day deadline. CIPA carries $5,000-per-violation statutory damages, no proof of harm required, no company-size threshold. Published redacted letters demand from $5,000 per violation up to $460,000 per claimant — arithmetic, not damages assessment: trackers × statutes × $5,000.

The volume is not hypothetical: by industry tallies, roughly 675 CIPA suits were filed in 2024 and over 800 in 2025 — and filings are the tip; counting unfiled demand letters, estimates run to 50,000–100,000 total claims since 2022. Pre-suit settlements are commonly reported at $10,000–$30,000, and small businesses settle because the math says to. We wanted to know: against the exact first test those scanners run, how do the biggest, best-resourced consumer sites in the country do? So we pointed our scanner — built to replicate that method — at 252 of them.

What we tested, and how

Each site got the same three-pass sequence our free scan runs, which mirrors the plaintiff-firm method:

  1. Baseline pass: a fresh Playwright browser profile — no cookies, no storage, no prior visits — loads the homepage from a single US residential IP and logs every third-party request through a 7-second dwell, before any consent interaction.
  2. Reject pass: in the same session, the scanner looks for a “Reject All” (or equivalent) control, clicks it if found, and logs what keeps firing.
  3. GPC pass: a second identical fresh profile loads the page with a Global Privacy Control signal announced; we diff which trackers still fire.

Requests are classified against our database of 30 litigated trackers in 5 severity classes; each site gets a grade. Hard cap: 240 seconds per site.

Honest limits, up front. This is one automated pass on the homepage only, from one vantage point, in a single run, with a 7-second dwell — not a site-wide audit; behavior can differ by page, geography, and day. Banner detection is best-effort: a banner our scanner failed to recognize counts as “none.” Reject-button detection is deliberately conservative: finding a clickable reject on 11% of sites does not mean only 11% have one — it means an automated visitor (like a plaintiff-firm bot) could find and click one on 11%. And the 51 sites that blocked our scanner tell us nothing either way; we report them as inconclusive, never as clean.
The numbers
CheckpointSitesShare
Measurable sites169
Fired ≥1 named tracker pre-consent14787%
Consent banner detected6941%
— of those, fired before any interaction anyway58 of 6984%
No banner detected, and fired8953% of all measurable
Kept firing with GPC signalled13982%
Reject button found and clicked1911%
— of those, kept firing after “Reject All”16 of 1984%

The average measurable site fired 5.7 named trackers pre-consent (6.5 among sites that fired at all; median firing site: 7; worst: 13). Session-replay-class tools — the category behind roughly 65% of filed complaints — were firing pre-consent on 75 of 169 sites (44%). The failures were not concentrated in one corner of the market: apparel, beauty, health and wellness, and big retail all graded much the same.

The trackers doing the firing

Site counts are pre-consent firings among the 169 measurable sites, with our severity class (Class A = ad/identity pixels, the demand-letter headliners; Class B = session replay; Class D = identity resolution). Each tracker links to its litigation profile.

TrackerSitesClass
Google Ads / DoubleClick126A — ad/identity
Google Analytics 4101A — ad/identity
Microsoft UET / Bing Ads90A — ad/identity
Pinterest Tag80A — ad/identity
TikTok Pixel76A — §638.51 wave leader: 100+ class actions in a year
Meta Pixel67A — the most-named tracker in demand letters
Snap Pixel53A — named in the $5M European Wax Center pixel suit
The Trade Desk52A — ad/identity
Reddit Pixel47A — ad/identity
Microsoft Clarity39B — session replay
Klaviyo34D — identity resolution
LinkedIn Insight Tag24A — also named in the EWC pixel suit

Full per-tracker litigation profiles: the tracker index.

Where courts are split — the part the letters leave out

A tracker firing pre-consent is a network observation, not a finding of liability, and courts are genuinely divided on whether it is even actionable. On the dominant §638.51 “pen register” theory, plaintiffs have survived early dismissal challenges in Heiting v. IHOP, Price v. Entravision, and Camplisson v. Adidas (pixels can be pen registers) — but defendants have won in Sanchez v. Cars.com, Rodriguez v. Plivo (an IP address alone held insufficient), and Licea v. Hickory Farms. Session-replay rulings diverge the same way: Torres v. Prudential ended in summary judgment for the defense (replay readable only after transmission is not real-time interception), while the Ninth Circuit in Mikulsky v. Bloomingdale’s (2025) revived a §631 session-replay claim, holding the “contents” of website communications were plausibly disclosed. And our numbers carry the limits stated above — one homepage pass, one vantage point, conservative detection, 51 bot-blocked sites about which we claim nothing. What the dataset shows is narrower: the network behavior demand letters are built on is the default state of prominent US consumer sites, and the mitigations that would change the log — banner gating, reject handling, GPC — mostly are not changing it.

What a site owner should actually do

Know what your own site sends before someone else logs it for you. The starting point is your current pre-consent log: which trackers fire before consent, whether they stop after “Reject,” and whether a GPC signal changes anything. You can do this manually with a fresh browser profile and the DevTools network tab, or run our free scan, which produces the same timestamped artifact a plaintiff-firm scanner produces, classified against the litigation record. Remove what you don’t need; gate what you do behind consent, verify the gate actually holds, and keep dated evidence of the change. None of this is legal advice: we report technical observations of network behavior, and what any of it means for your business is a question for a qualified attorney.

See what your site sends before consent

The same three-pass scan this study ran — pre-consent log, reject test, GPC test — free, on any site you own or advise.

Run a free scan Free scan, no signup to start. This is a technical scan report, not legal advice. Scan only sites you own or advise.

Method: fresh-profile homepage scans of 252 US e-commerce/DTC/consumer-health sites, July 21–22, 2026, single US residential vantage point. Aggregates only; no site is named. Press and researchers: write to reports@cipascanner.com for questions about the method.

Related reading