18 Signal Loss Statistics That Define 2026
Every marketing dashboard tells a story. The problem in 2026 is how much of that story is missing before it ever reaches you. Ad blockers strip events at the browser. iOS withholds the identifiers that used to tie conversions to people. Browsers that already block third-party cookies quietly shrink your addressable audience. And regulators are now fining companies nine figures for collecting data the wrong way.
We pulled together the numbers that actually define this landscape — 18 of them, each traced back to its original source, with the disagreements between sources noted rather than hidden. Where the popular figure is wrong or oversimplified, we say so. This is the reference we wish existed when we started explaining signal loss to marketers.
Every statistic below links to its primary source. Use them, cite them, and check them.
How much data are you actually losing at the browser?
Client-side tracking depends on a browser cooperating: loading the script, storing the cookie, and completing the request before the visitor leaves. A growing share of visitors have opted out of that arrangement entirely.
-
Roughly 1.77 billion people — about 29.5% of internet users worldwide — used an ad blocker at least sometimes as of Q2 2025. That figure comes from GWI, reported through DataReportal. It's worth being precise here: aggregators cite numbers ranging from 29.5% all the way to 42.7%, depending on how they define "ad blocker" and which panel they use. We anchor to GWI because it's the primary source with a transparent methodology; treat anything higher as a specific vendor's cut, not the consensus.
-
Ad blocking was forecast to cost publishers around $54 billion in 2024 — roughly 8% of global ad spend. From eyeo's Ad-Filtering Report. That's the publisher-side revenue loss; for advertisers, the cost shows up differently, as attribution gaps that make good channels look bad.
-
When asked why they block, users cite "too many ads" (63.5%), "ads get in the way" (53.5%), and "to protect my privacy" (42.4%). Also GWI via DataReportal, Q2 2025. The privacy motivation matters most for measurement teams: these users are deliberately opting out of being tracked, and no amount of client-side cleverness changes that.
The takeaway isn't "ad blockers are rising" — adoption has actually plateaued. It's that a large, stable minority of your traffic is structurally invisible to browser-based tracking, and the only fix is to move collection somewhere the browser can't intercept it. That's the entire premise of server-side tracking.
Are third-party cookies actually going away?
This is the most misreported topic in martech, and getting it right is a fast way to tell a credible source from one recycling old headlines.
-
Google ended its plan to deprecate third-party cookies in Chrome. After six years and repeated delays, the phaseout was walked back — announced in July 2024 and confirmed abandoned in 2025, per reporting from the IAPP. Chrome will keep third-party cookies. If a blog post still tells you cookies "die in 2025," it hasn't been updated.
-
Google shut down most of the Privacy Sandbox APIs in October 2025. The Topics, Protected Audience, and Attribution Reporting APIs — the intended replacements for cookies — were deprecated. Six years of industry investment in the "cookieless" replacement stack was effectively retired.
-
Even so, roughly 17–20% of global traffic is already cookieless by default. Safari, Firefox, and Brave block third-party cookies regardless of what Chrome does (per Consenteo's 2026 analysis). This is the point everyone misses: the "cookieless future" as a Chrome-led event was cancelled, but a cookieless present has quietly existed for years for one in five of your visitors.
So the honest framing for 2026 is not "prepare for cookie deprecation." It's "cookies never fully worked, Chrome's reversal changes nothing about the fifth of your traffic that already blocks them, and durable first-party identity is the answer either way."
What did iOS actually do to your attribution?
Apple's App Tracking Transparency (ATT) removed the default device identifier that powered mobile attribution. Four years on, the picture is more nuanced than "everyone opts out."
-
Global iOS ATT opt-in averaged about 35% in Q2 2025, rising toward 38% by early 2026 (Adjust) — while AppsFlyer reports closer to 50% consent among users who saw the prompt. Both are real; they measure different denominators. Adjust's figure spans a broader base, AppsFlyer's counts prompted users. The practical read: somewhere between a third and a half of iOS users will share the identifier if you ask well — and the rest are permanently dark to user-level tracking.
-
iOS ad spend grew 26% from 2023 to 2024, outpacing Android's 10%. From AppsFlyer's post-ATT analysis. This is the counter-narrative worth internalizing: spend recovered because marketers rebuilt around consent-based and server-side signal, not despite ATT. The teams that adapted are spending more, not less.
-
France's competition authority fined Apple €150 million over its ATT implementation in 2025. A reminder that even the privacy frameworks themselves are now under regulatory scrutiny — the rules are still moving.
If mobile attribution is where your numbers fell apart, the mechanics of the fix are covered in our breakdown of how iOS changes break attribution and how to repair it.
Does server-side tracking actually improve performance?
Collection is only half the story. The other half is whether the ad platforms can use what you send them — which comes down to match quality.
-
Brands report 15–20% average campaign performance improvement with full Conversions API implementation. This figure is widely cited to Meta's own developer documentation. It's an average across advertisers, not a guarantee — but it's Meta's own number, not a vendor's.
-
Event Match Quality (EMQ) is scored 1–10; most stores sit at 4–6, and 7+ is the target. EMQ measures how reliably Meta can match your server-sent events to real accounts. Below 5, Meta can match only about half your events — the rest are invisible to its optimization.
-
The parameters you send drive the score: email alone lands around 5.5–6.5; adding phone pushes it to 7.5–8; adding the fbp and fbc browser parameters reaches 8.5–9; adding name and address gets you past 9. This is practitioner-observed across production CAPI setups, not an official Meta table — but it's consistent enough across sources to plan around. The lesson: match quality is a function of how much clean, consented first-party data you can attach to each event.
-
Improving EMQ from 8.6 to 9.3 has been associated with roughly 18% lower CPA (CustomerLabs). We attribute this to CustomerLabs specifically rather than presenting it as universal, but it illustrates the point: match quality isn't a vanity score — it maps to acquisition cost.
Getting these numbers right is exactly what our Meta CAPI implementation guide walks through, deduplication and all.
What does getting consent wrong actually cost?
Server-side collection done carelessly is a compliance liability, not an asset. The enforcement numbers have moved from theoretical to material.
-
Cumulative GDPR fines reached approximately €5.6 billion by the end of 2025, with about €1.4 billion issued in 2025 alone (CMS GDPR Enforcement Tracker / EDPB data). Some trackers put the mid-2026 cumulative figure higher, above €7 billion; the exact total depends on which appeals and annulments a tracker counts.
-
France's CNIL alone issued €486.8 million in fines in 2025, with cookies among the top subjects of enforcement. Straight from the CNIL's own year-end reporting. Five years after its cookie guidelines, tracker violations are still the regulator's most common target.
-
In September 2025, the CNIL fined Google €325 million — split €200 million to Google LLC and €125 million to Google Ireland — for cookie-consent failures and inserting ads into Gmail without valid consent.
-
The same month, SHEIN was fined €150 million for placing advertising cookies without consent and running a broken opt-out that kept reading cookies after users clicked "reject."
-
Google's French cookie fines have escalated: €100 million in 2020, €150 million in 2021, €325 million in 2025. The pattern is the point — repeat non-compliance compounds, and the penalties grow with it.
The throughline: the value of server-side infrastructure isn't only that it captures more data. It's that it captures data on the same consent state as your client-side tags, so the events you recover are events you're actually allowed to have. That's the difference between traffic integrity as an asset and a lawsuit waiting to happen.
What we see across our own implementations
Everything above is public, sourced industry data. This section is different, and we're labeling it clearly: these are our own observations from deploying server-side infrastructure across our customer base, offered as commentary — not as peer-reviewed benchmarks.
Across the stores we work with, the single most common surprise is how low the starting event-capture rate is once you actually measure it. Teams assume their tracking "works" because tags fire in preview mode; the gap only becomes visible when server-side collection runs in parallel and the two counts diverge. The second recurring pattern is EMQ: most stores arrive at 4–6 and are genuinely shocked, because nobody told them the score existed. And the third is that the teams who treat consent as a first-class part of the architecture — rather than a banner bolted on afterward — are the ones who never end up in the enforcement statistics above.
If you want to know your own numbers rather than the industry's, that's the honest place to start: measure your real capture rate and your EMQ before you change anything. Everything else follows from those two figures.
Frequently asked questions
What percentage of users block ads in 2026?
About 29.5% of internet users worldwide use an ad blocker at least sometimes, per GWI/DataReportal (Q2 2025). Estimates from other aggregators run higher, up to ~42%, depending on methodology.
Are third-party cookies going away in 2026?
No — Google reversed its plan to deprecate third-party cookies in Chrome and retired the Privacy Sandbox replacement APIs in October 2025. However, Safari, Firefox, and Brave still block third-party cookies by default, leaving roughly 17–20% of traffic cookieless regardless of Chrome.
What is a good Event Match Quality (EMQ) score?
EMQ is scored 1–10. Most stores land at 4–6; 7 or above is the practical target. The score rises with each additional clean, hashed parameter you send (email, phone, name, address, and the fbp/fbc browser identifiers).
How much can server-side tracking improve ad performance?
Meta's own documentation is widely cited for a 15–20% average campaign performance improvement with full Conversions API implementation. Results vary by how complete and consented your event data is.
Is server-side tracking GDPR compliant?
It can be — but it isn't automatically. Server-side collection must run on the same consent state as your client-side tags. Done wrong, it's a liability: cookie-consent failures drove CNIL fines of €325M (Google) and €150M (SHEIN) in September 2025 alone.
The Ingest Labs platform
The four layers behind clean, compliant, AI-ready data:
Ingest IQ — server-side collection, capturing events the browser drops.
Ingest ID — durable, cookieless first-party identity.
Event IQ — unified analytics and AI on data you can trust.
Ad Shield — real-time traffic quality and integrity.
The AI-Ready Customer Data Infrastructure.