Cirv Cookie Index

Report · 2026

The State of EU E-commerce Cookie Compliance

We scanned 45 European online stores for cookie/consent signals — the GDPR + ePrivacy basics. Here's what we found (a conservative floor).

View the open data  Updated 2026-08-10 · CC-BY-4.0

45stores analysed
69/100average score
31%graded D or F
31%fail cookie notice

The headline

Many of Europe's online stores ship trackers with no visible consent. The average homepage scores 69/100, and 31% are graded D or F — a conservative floor, since JS-injected trackers are invisible to static scanning. The single most common failure is cookie notice, affecting 31% of the stores we could scan. Under GDPR and the ePrivacy Directive, loading trackers before consent is a real enforcement risk.

Grade distribution

Grade A23
Grade B0
Grade C8
Grade D0
Grade F14

The most common failures

Share of scanned stores failing each cookie/consent check (homepage):

Cookie notice14
Consent platform14
Tracker gating14

Best and worst

Best in class

Needs the most work

What this means under GDPR

GDPR and the ePrivacy Directive require consent before non-essential trackers load. Fines reach into the millions. This index reads only static markup, so it under-counts (JS-injected trackers are invisible) — a low score is a near-certain red flag, and a high score still warrants a real audit.

Check your own store in seconds.
Run the free scanner, or pull the full dataset via the API.
Get API access  Get API access →

Method: static cookie/consent scan of each store's public homepage (a conservative floor). See methodology. Citable data: data.json. Not legal advice.