Consent, tracking and breaches,
measured and sourced.
Original studies run with our own scanner, reported in aggregate with the method published, and breach case studies built only from official sources.
Latest study: cookie consent on Indian websites, 2026
We loaded the homepages of 401 of India's most-visited websites and major brands twice: once with no consent and once after accepting. 76% stored tracking identifiers before the visitor chose anything, a typical site passed data to 3 tracking companies, and only 16.5% showed a consent banner at all.
Tracking identifiers stored before consent, by sector
Share of measured sites in each sector. Sectors with fewer than ten measured sites are not shown.
Breach case studies
Eight well-documented security breaches, from Uber in 2016 to MOVEit Transfer in 2023: what happened, the root cause, the regulatory outcome and the control that addresses it, with SOC 2 and ISO 27001 references. Every figure links to a regulator, government advisory, court filing or the company's own disclosure.
- Capital One, 2019: cloud configuration and an $80 million OCC penalty
- Equifax, 2017: an unpatched Apache Struts flaw
- Uber, 2016: an access key in code and a year before disclosure
- Colonial Pipeline, 2021: a VPN profile with no second factor
- SolarWinds, 2020: a compromised build system
- MOVEit Transfer, 2023: a vendor's zero-day
- CircleCI, 2023: a stolen session and customer secrets
- Optus, 2022: 9.5 million Australians and a case before the court
How we measure
- A public sample. Sites are drawn from the Tranco research ranking, with the list ID published, plus named sector groups of major brands
- Two passes, like a real visitor. Each page is loaded once with no consent and once after accepting, so what runs before the choice is separated from what runs after
- A conservative count. Only identifiers from known analytics and advertising providers count; tag managers, CDNs, bot protection and performance monitoring never do
- Unmeasurable is not compliant. Sites that fail to load or block automated browsers are excluded and reported, never counted as clean
- Independent checks. A random sample is re-checked without our scanner's code before anything is published
For journalists
Figures may be republished with a link to the study. Per-site results are available for verification on request, not for publication, through our contact page. Our team can explain the method and what the DPDP Act requires from May 2027.
The things people ask us
Who runs this research?
TryTrustable, using the same scanner that powers our free cookie scan and the consent platform. Every study states its sample, method, exclusions and limits, and is checked independently before publication.
Do you name the websites you scan?
No. Scan studies report aggregate and sector figures only. Per-site data is kept for verification and shared with journalists on request. The breach case studies are different: they name companies only for incidents already public through a regulator, a court, a government advisory or the company's own disclosure.
Can I use the figures?
Yes, with a link to the study.
How often is the research repeated?
We plan to repeat the consent study before the DPDP duties begin on 13 May 2027 and again after, so the change can be measured on the same method.
See what your own site does before consent.
Run the same two-pass scan on your site in about a minute, then fix what fires early.