How many companies does your cookie banner actually share data with? A new complaint counted 1,741
When you click "Accept" on a cookie banner, how many separate companies just got permission to process your data? On one site a privacy group counted 1,741. That number comes from a GDPR complaint filed on 30 July 2026 by the Austrian non-profit noyb (Max Schrems' organisation) with the Austrian data-protection authority. Its argument is simple: consent to 1,741 companies in a single click cannot possibly be informed, so it isn't valid consent at all.
If you run a website and you're trying to figure out which analytics setup keeps you on the right side of that, here's the shortcut the complaint hands you. The thing that decides whether the whole consent problem even applies to you is one number: how many third parties your analytics shares visitor data with. Bundle your traffic stats into an advertising stack and that number runs into the hundreds or thousands, and you inherit exactly the consent problem noyb is attacking. Use a cookieless, first-party analytics tool and the number is zero — no advertising vendors, no data brokers, nothing to disclose, and so nothing to (invalidly) ask consent for. This post is about why that number is the one worth watching, and how honest the "zero" really is.
What the complaint actually says
noyb's target was dict.cc, a popular German-English dictionary site. On visiting, users were shown a standard consent banner. Clicking to accept, noyb says, handed data-processing permission to 1,741 partner companies at once. To give consent that GDPR would recognise as informed, a visitor would need to understand what each of those companies does with their data — which means reading 1,741 privacy policies. noyb's estimate: at least 170 hours, "even if you just scan each policy for 6 minutes" — more than a full working week spent reading, for a single "Accept" click on a dictionary lookup.
GDPR (Article 4(11)) requires consent to be freely given, specific, informed, and unambiguous. noyb's contention is that the "informed" limb collapses at 1,741 recipients: nobody in the real world reads 170 hours of policies, so nobody clicking "Accept" actually knows what they agreed to. The complaint asks the regulator to order the unlawfully processed data deleted, to have every downstream recipient notified of that deletion, and to impose a fine. noyb names dict.cc as the lead case but points to the same pattern on Repubblica.it, Bergfex.de and FIFA.com — this isn't one badly-configured site.
Two honest caveats. First, this is a complaint, not a ruling — the Austrian DPA hasn't decided it, and noyb files a lot of complaints. Second, the specific count is dict.cc's; your favourite site might show 300 or 800 rather than 1,741. But the direction of travel here is not speculative. Belgium's data-protection authority found GDPR infringements in the IAB Europe Transparency and Consent Framework — the industry plumbing that generates these multi-hundred-vendor banners — back in 2022, opening years of still-unresolved litigation. Parts of that original decision were later annulled on appeal, but its core survived: the EU Court of Justice confirmed in 2024 that the framework's consent signal is itself personal data and that IAB Europe is a joint controller for it. The 1,741 figure is a fresh, vivid data point on a problem the courts have been circling for years, not a novel theory.
Why the number is structural, not a design choice
It's tempting to read this as a UX failure — a banner with too many checkboxes. It isn't. The vendor count is baked into how programmatic advertising works. When a page monetises through real-time bidding, the ad slot is auctioned to a chain of ad exchanges, demand-side platforms, data-management platforms and "data enrichment" partners, each of which wants — and, under the TCF, is listed as a recipient of — signals about the visitor. The banner isn't padded with 1,741 companies by accident; those are the companies in the pipeline. You can't meaningfully shrink the list without leaving the ad ecosystem that produced it.
That's why "just show a shorter banner" doesn't fix it, and why the number is the right thing to measure. It tells you, in one integer, how far your visitors' data travels:
| Your analytics setup | Advertising / data-broker partners in the data path | Is informed consent even possible? |
|---|---|---|
| GA4 wired into an ad stack behind a TCF banner | hundreds to 1,700+ | No — that's noyb's whole argument |
| Cookieless, first-party analytics (Simplytics, Plausible, Fathom, Simple Analytics) | 0 | Moot — no personal data shared, so nothing to consent to |
The second row is the interesting one for a site owner. If the count is zero, the consent question doesn't get answered differently — it never comes up. There's no vendor list to render on a banner because there are no vendors.
This is a different point from "you might be exempt"
We've written before about the ways cookieless analytics can let you drop the banner: the EU Digital Omnibus proposal that would carve out first-party audience measurement, and France's CNIL exemption that already does, if your tool passes its test. Those posts make a legal argument: under this rule, you're exempt from having to ask.
The vendor-count argument is a level below that, and sturdier. Exemptions are conditional — they depend on a specific regulation, in a specific country, that could be rewritten. "We share your data with zero advertising companies" doesn't depend on any exemption surviving a trilogue. There's simply no third party in the picture, so there's no disclosure to get wrong and no consent to be found invalid two years later. The exemption says you don't have to ask; the zero-vendor design says there's nothing to ask about. The second is a better place to stand.
How honest is "zero"?
Here's where a vendor blog would plant a flag and claim its tool is uniquely clean. It isn't, and the whole point of a privacy-first product is undercut the moment it starts overclaiming. So, precisely:
Zero refers to advertising and data-broker third parties in the visitor-data path. Simplytics sets no cookies, runs no ad SDK, and joins no ad exchange, so a visitor's page view is never auctioned, brokered, sold, or handed to a marketing "partner." There is no TCF vendor list because there are no vendors. That's the number that matters for the consent problem above, and for Simplytics it is genuinely zero.
What Simplytics does rely on are infrastructure processors, and those are a different thing. The product runs on Cloudflare's network with its database in the EU (Warsaw); billing goes through Dodo Payments; account emails go through Resend. Those companies process data to deliver the service you asked for — they don't receive your visitors for their own advertising, and they aren't in the analytics data path. Calling that "zero third parties, full stop" would be dishonest; the honest claim is zero advertising third parties, plus a short, named list of sub-processors doing the plumbing. Every serious tool has the second list. The consent scandal is entirely about the first.
And no, this isn't unique to us. Any properly cookieless, first-party tool — Plausible, Fathom, Simple Analytics — clears the same bar: they don't feed your visitors into an ad auction either. If your only goal is "zero advertising vendors," several tools get you there. Where Simplytics is different is the rest of the deal: it does the same job for $1/month instead of the $9–15/month those hosted privacy tools charge, wipes raw records nightly and keeps aggregates forever, and stores its data in the EU. A lot of functionality for a lot less money — and a vendor count of zero either way.
The tool that can't get to zero is Google Analytics. GA4 exists to feed Google's advertising and audience products; that data flow is the feature, not a misconfiguration. GA4 on its own isn't the thing that renders a 1,741-vendor banner — that list is generated by the ad-exchange stack and its consent-management tool — but GA4 is the analytics layer that belongs to that world rather than standing outside it. Of the mainstream tools, it's the one whose data points toward the ad ecosystem instead of away from it. (We go through the rest of the trade-offs in our Simplytics vs Google Analytics comparison.)
The bottom line
The next time you look at a cookie banner — on your own site or someone else's — ask the one question that actually predicts your legal exposure: how many companies does clicking "Accept" share data with? A July 2026 complaint says one site's answer was 1,741, and that no human could give informed consent to a list that long. The cleanest way to never have that argument is to make the number zero: pick analytics that shares visitor data with no advertising partners at all. Cookieless first-party tools do that by design — and the cheapest privacy-friendly Google Analytics alternative that does it, cookieless and EU-hosted, is $1/month.