That matters for one practical reason: an automated check does not read your privacy statement or your intentions. It looks at what your page actually does.
What a crawler can see, and what it can't
A scan can register whether a refuse option exists at the first layer, whether it looks like the accept button or like a small grey link, whether toggles are pre-checked, and whether tracking requests fire before any choice is made. All of that is visible from the outside, at scale, without a human being involved.
What a scan cannot see is your record of consent. That part only surfaces when someone asks you to demonstrate it, and under Article 7(1) GDPR the burden of proof sits with you, not with your visitor. A banner that looks correct in a crawl and has no log behind it is still a problem waiting for a slower, more expensive conversation.
The numbers say the visible part is still often wrong
Consumer organisation Consumentenbond checked 100 popular websites against the Dutch authority's rules in 2025 and found that 32 of the 84 sites with a banner, 38 percent, did not ask for consent properly. News and media sites did worse: of 20 media sites with a banner, 16 were not in order. The 2023 figure was higher at 61 percent, although the samples were only partly the same, so read the trend as direction, not as precision.
```cijfers
titel: Dutch banners that do not ask for consent correctly
eenheid: %
bron: https://www.consumentenbond.nl/acties-claims/nieuws/2025/onderzoek-cookies-nog-steeds-teveel-opgedrongen (Consumentenbond, cookie research 2025)
Sample 2023, all sites: 61
Sample 2025, all sites: 38
Sample 2025, news and media sites: 80
```
The chart shows something useful about risk: the average is improving, but if you run an ad-funded or media-heavy site, you are statistically in the worst-performing group and therefore the most likely to be flagged by an automated sweep.
Fines are no longer theoretical
Dutch enforcement has been slow in absolute terms. The same Consumentenbond piece notes only two cookie fines from the Dutch authority in 2024, following investigations that started in 2019 and 2020. France shows the other end of the scale. The CNIL reported that in 2025 it sanctioned 21 entities for tracker breaches and issued €486,839,500 in cumulative fines, including €325 million and €150 million against two large players, partly for not acting on refusal or withdrawal of consent.
What to do this week
Load your own homepage in a clean browser profile, open the network tab, and refuse everything. If requests to analytics or ad domains still go out, your banner is decoration. Then check whether refusing takes the same number of clicks as accepting. Then ask a simple question of your setup: if a letter arrives asking you to show consent for a specific date, can you produce it?
That last question is why PlainConsent logs consent with a real audit trail, in five languages, at one flat price per site with every feature included. Not because a log makes you compliant on its own, but because it is the only part of this an outside scan cannot check for you.