The cookie banner is up. Google's cookies got there first.
Elevates opened the websites of 21 EU affairs think tanks in a clean browser and clicked nothing. Five stored Google Analytics cookies at once, before the visitor chose anything. Four of those five had a cookie notice on screen while it happened. A notice is not consent.
QUICK ANSWER
Elevates opened the websites of 21 EU affairs think tanks in a clean browser and clicked nothing. Five stored Google Analytics cookies at once, before the visitor chose anything. Four of those five had a cookie notice on screen while it happened. A notice is not consent. You can run the same check on your own site in two minutes.
If you run communications at a policy institute, there is a good chance the cookie notice went up in 2022, after someone on the board asked about GDPR. It appeared, the question went away, and nobody has opened the site in a clean browser since.
Elevates did, for every member of the Trans European Policy Studies Association that runs a website of its own. The result is not that institutes ignore the rules. Most of them get this right. It is that on a quarter of the sites, the notice and the tracking have nothing to do with each other: the notice asks, and the cookies are already set.
Elevates checked 21 institutes the way an inspector would
TEPSA describes itself as 51 member and associate institutes in 37 European countries. Its member guide links to each one. Twenty nine publish on a domain of their own. The rest sit inside a university's website, where the cookies belong to the university, so they were left out.
On 19 September 2026 Elevates loaded each of the 29 homepages in a fresh, empty browser profile, waited eight seconds, clicked nothing and scrolled nothing, then listed every cookie the page had stored. Twenty six loaded. Twenty one of those are based in the EU or the EEA, and those 21 are the count below.
That moment, before the visitor has done anything, is the one the rule is about.
Figure 1First visit
Twenty one institutes. Five track you on arrival.
Each mark is one think tank based in the EU or EEA, loaded once in a clean browser with nothing clicked.
Five set Google's cookies before the visitor chose anything
Five of the 21 stored Google Analytics cookies, _ga and its companions, on arrival. Two of the five also set cookies for Meta or LinkedIn.
None of the five told Google whether the visitor had agreed. Google's tags carry a consent signal when a site is set up to send one. It was missing from every analytics request these five sites sent.
Every positive was run a second time. The cookie count came back identical on all of them.
Four of the five had a cookie notice on screen at the time
Figure 2Before the click
The notices ranged from a single Accept button to a full consent tool with a Details panel. None of that mattered, because the cookies were written before any button was pressed.
This is the pattern for which France's data regulator fined Shein 150 million euros on 1 September 2025: cookies placed on visitors' devices "as soon as they arrived on the site". Shein is not a think tank and nobody is suggesting a fine of that size. The point is the mechanism. A regulator looks at what happens before the click, which is exactly what this check looked at.
A notice is not consent, and the rule asks for consent first
The rule is Article 5(3) of the ePrivacy Directive. Storing information on a visitor's device is "only allowed on condition that the subscriber or user concerned has given his or her consent". The exception is storage that is strictly necessary to deliver what the visitor asked for.
Analytics can fall inside that exception only on narrow terms. France's regulator, in its guidance on audience measurement, requires the purpose to be audience measurement alone, the output to be anonymous statistics, and no reuse of the data by the provider for its own ends. Whether a given setup qualifies is for the site to show, not for the visitor to assume.
These institutes are based in the EU, so the question of whether European rules reach them does not arise. For a business outside the EU it does, and it turns on who the business sells to, not where it sits.
Four institutes show what correct looks like
Four of the 21 load Google Analytics and still store nothing until the visitor chooses. Their analytics requests carry Google's consent signal, set to denied.
That is Google's own consent mode. When analytics storage is denied, Google's documentation says the tag neither reads nor writes its analytics cookies, and sends measurements without them instead. The site still gets a basic count, and the cookies wait for a yes. Setting it up means declaring a default of denied before any tag loads, and letting the consent tool change it.
The remaining twelve set no tracking cookies on arrival at all.
Three of the five also run tags for a product Google shut down
Three of the five set cookies named _gat_gtag_UA_ followed by an account number. Those come from Universal Analytics, which stopped processing data on 1 July 2023. Access to its reports and its API closed a year later.
So these tags write cookies onto visitors' devices to feed reports that no longer exist. A tag left running two years after its product closed usually means nobody currently owns the site's tagging. That is an inference, but it is the likeliest reading.
Check your own site in two minutes
- Open a private window and go to your homepage. Click nothing, including the notice.
- Open the developer tools: F12 on Windows, Cmd Option I on a Mac.
- In Chrome, go to Application, then Cookies, then your domain. In Firefox it is Storage, then Cookies.
- Look for
_ga,_gid,_gcl_au,_fbp, or anything starting_gat_gtag_UA_.
If any of those are there before you clicked, the notice on your site is decoration. If one starts _gat_gtag_UA_, there is also a dead tag to remove.
When it fails, the fix is in how the tags load
Sometimes the repair is small. If your tags live in Google Tag Manager, it can be one setting: a default of denied, and a consent tool that updates it when the visitor chooses. That is an afternoon, and you can do it yourself without paying anyone.
Often it is not that tidy. The analytics tag was pasted into the theme years ago. A plugin added its own. An embedded video or a LinkedIn feed brings more. The notice was installed on top of all of it, and none of those tags were ever told to wait for it. Fixing that means finding every tag, making each one wait for the answer, removing the dead ones, and checking again after the next plugin update, because that is when it breaks.
That is the work Elevates does. The same clean browser check you ran above, on every page type your site has, a list of every tag and who put it there, and the repair made in your tag manager or your theme's code, then checked again. For an institute whose standing in Brussels rests on reading European rules carefully, this is the kind of thing a journalist with a browser can find in a minute.
If your site passed the two minute check, you are done, and you are in the majority. If it did not, the notice on your homepage is promising visitors something the site is not doing.