56% of Americans say they frequently skip reading a privacy policy before clicking agree, according to Pew Research Center's survey of 5,101 U.S. adults conducted in May 2023 and published that October. That gap between how many sites publish a privacy policy and how many visitors actually read one is the throughline connecting adoption, length, and trust data across every major study on the topic. Below is what the most-cited surveys and academic corpora say about how common privacy policies are, how long they have gotten, and whether anyone still trusts what they say.

What percentage of people read privacy policies?

Reading behavior has stayed strikingly low across every survey that has measured it in the last decade. Pew's May 2023 survey found that 56% of American adults frequently click "agree" on a privacy policy without reading it, and a further group only occasionally reads one, leaving a small minority who say they consistently read policies in full. The same survey found that 69% of respondents see privacy policies mainly as something to click past rather than a genuine disclosure, and 61% say the policies fail to clearly explain how their data will be used even when they do attempt to read them.

56 percent of Americans skip reading a privacy policy before agreeing to it 56% of Americans frequently skip readinga privacy policy before agreeing to it

A separate industry survey cited across multiple 2026 data-privacy roundups puts the share of consumers who read a privacy policy in full, when directly prompted to accept one, at just 22%, while 58% say they reviewed some privacy policy before making a purchase in the past year, suggesting many people skim rather than skip entirely. Both figures point the same direction: reading a full privacy policy top to bottom is the exception, not the norm, regardless of how the question is framed.

Figure 1: Self-reported reading habits among 5,101 U.S. adults. Source: Pew Research Center, "How Americans View Data Privacy" (October 2023).

How many websites actually have a privacy policy?

Adoption is a separate question from readership, and it splits sharply by site popularity. A large-scale academic crawl of 9.6 million archived homepages found a detectable privacy policy link on 37.2% of snapshots for sites ranked in the top 1,000 by traffic, falling to just 9.6% for sites ranked below 1 million, a gap covered in detail in our companion post on privacy policy adoption by site rank. That popularity gradient has held up since the earliest baseline measurement: in June 1998, the Federal Trade Commission found only 14% of a 674-site sample of commercial websites gave any notice of their data practices, and just 2% posted anything resembling a comprehensive policy.

Adoption looks very different once you leave the open web and look at regulated or enterprise-facing sectors. Large companies report a 94% rate of taking documented steps to meet privacy obligations, compared with 88% for small companies, according to compliance benchmarking cited in 2026 industry roundups, a gap that tracks the resourcing difference between a legal or compliance team and a solo founder shipping a landing page.

Figure 2: Adoption falls sharply as site popularity drops. Source: Princeton and KU Leuven, million-document privacy policy corpus study.

How long is the average privacy policy in 2026?

Privacy policies have gotten dramatically longer since the early 2000s, and the growth has not leveled off. A University of Basel study of privacy policies collected between 1996 and 2021, covering tens of thousands of unique documents, found that median policy length climbed from 876 words in 2009 to 1,522 words in 2019, and the researchers describe policies continuing to lengthen and grow harder to read through 2021, especially in the years immediately following new regulations such as GDPR and CCPA taking effect.

Length correlates with reading difficulty. Multiple independent readability analyses put the average privacy policy at roughly a 12th to 13th-grade reading level, well above the 8th-grade level the Plain Writing Act and most literacy researchers recommend for material intended for a general adult audience. One analysis of the 300 most popular websites found 96.76% of policies scored below the recommended Flesch Reading-Ease threshold of 60, meaning nearly every policy sampled required at least a high-school-plus reading level to parse on a first pass.

Figure 3: Median policy length nearly doubled in a decade. Source: University of Basel, "Privacy Policies Across the Ages" (2022, corpus spanning 1996 to 2021).

Longer is not automatically better for the reader, and it may not even be better for the business publishing it. A 2026 study examining privacy policy presentation and length found that an unusually long policy reduced participant trust compared with a short policy or no visible policy at all in a recommender-system trust experiment, a reminder that a privacy policy generated to cover every legal base still needs to stay navigable, not just complete. You can generate a clear, GDPR- and CCPA-ready privacy policy built from plain-language sections rather than one dense wall of legal text.

Do people trust companies with their data?

Trust is low and has stayed low across every recent measurement. Pew's 2023 survey found only about 1 in 5 Americans, roughly 20%, are very or somewhat confident that companies will handle their personal information responsibly, while 81% say they are concerned about how companies use the data they collect about them. The same survey found 77% of Americans say they have very little or no understanding of what the government does with their data, and 67% say the same about companies, alongside 73% who feel they have very little or no control over data companies collect on them.

That distrust has a measurable business cost on the other side of the ledger. 95% of respondents in Cisco's 2025 Data Privacy Benchmark Study said they would not make a purchase from a company if they were not confident their data was being protected properly, and separate 2026 brand-trust research finds 83% of consumers weigh whether they trust a company with their data before deciding to buy from it. Despite the distrust, privacy investment pays off on paper: Cisco's 2025 study of 2,600 privacy and security professionals across 12 countries found organizations report a median 1.6x return on privacy spending, with 96% saying the benefits outweigh the cost and 29% reporting a 2x return or higher.

MetricFigureSource
Americans who frequently skip reading a privacy policy56%Pew Research Center, May 2023
Americans confident companies handle data responsibly~20%Pew Research Center, May 2023
Median privacy policy length, 20191,522 wordsUniversity of Basel corpus, 2022
Organizations reporting positive ROI on privacy spend96%Cisco 2025 Data Privacy Benchmark Study
Consumers who would not buy without data protection confidence95%Cisco 2025 Data Privacy Benchmark Study

Figure 4: The gap between concern and confidence. Source: Pew Research Center, "How Americans View Data Privacy" (October 2023).

How has the privacy policy landscape changed since 1998?

The baseline the FTC set in 1998, just 2% of surveyed commercial sites posting a comprehensive policy, has been left far behind by raw adoption numbers, but the underlying tension between disclosure and comprehension has not gone away. It has arguably shifted from "does a policy exist" to "can anyone actually use the one that does."

Figure 5: Adoption grew from near-zero to standard practice as policy length began climbing ahead of GDPR. Source: FTC (1998), University of Basel (2022).

Figure 6: Policy length kept climbing post-GDPR while readership stayed flat. Source: University of Basel (2022), Pew Research Center (2023), Cisco (2025).

Regulation is the clearest driver of the length increase. The same University of Basel research links jumps in policy length and new mandatory disclosure sections directly to GDPR's 2018 effective date and to CCPA's rollout beginning in 2020, both of which require specific new categories of disclosure, such as data-sharing partners, retention periods, and consumer rights language, that older, shorter policies never had to include.

The Bottom Line

The numbers describe two trends moving in opposite directions at once: privacy policies keep getting longer and more legally thorough, while the share of people who actually read them stays flat at roughly half skipping entirely and only about a fifth confident in how their data gets handled. That gap is not an argument for skipping the disclosure work. Regulators, not readers, are the primary audience that actually checks a privacy policy line by line, and Cisco's 1.6x median ROI figure suggests getting it right pays for itself even when most visitors never open the page. The practical fix is not a shorter policy for its own sake, it is a policy structured so the sections regulators check and the sections a skimming visitor needs are both easy to find, which is exactly what a current, plain-language privacy policy built from a maintained template accomplishes better than a static document drafted once and left untouched for years.

Frequently Asked Questions

What percentage of people read privacy policies? 56% of Americans say they frequently click agree on a privacy policy without reading it, according to Pew Research Center's May 2023 survey of 5,101 U.S. adults. A separate industry survey found only 22% of consumers read a privacy policy in full when prompted to accept one.

How long is the average privacy policy? Median privacy policy length reached 1,522 words by 2019, up from 876 words in 2009, roughly doubling over a decade, according to a University of Basel longitudinal study covering privacy policies from 1996 through 2021 and drawing on a corpus of more than one million documents.

Do consumers trust companies to protect their data? Only about 1 in 5 Americans, roughly 20%, are very or somewhat confident that companies will handle their personal data responsibly, per Pew Research's 2023 survey. 81% say they are concerned about how companies use the data they collect.

Does having a privacy policy pay off financially? Yes. Organizations report a median 1.6x return on privacy investment, and 96% say the benefits of privacy spending outweigh the costs, according to Cisco's 2025 Data Privacy Benchmark Study of 2,600 privacy and security professionals across 12 countries.

Where the Numbers Come From

  1. Pew Research Center. (2023). "How Americans View Data Privacy." Survey of 5,101 U.S. adults, fielded 15 to 21 May 2023, published 18 October 2023.
  2. Wagner, I., University of Basel. (2022). "Privacy Policies Across the Ages: Content and Readability of Privacy Policies 1996 to 2021." Corpus of tens of thousands of unique policies; later published in ACM Transactions on Privacy and Security (2023).
  3. Cisco. (2025). "2025 Data Privacy Benchmark Study." Survey of 2,600 privacy and security professionals across 12 countries.
  4. Federal Trade Commission. (1998). Baseline commercial website privacy notice survey, 674-site random sample, cited in subsequent FTC privacy reports.
  5. Taylor and Francis, Behaviour and Information Technology. (2026). "The Effects of Privacy Policy Presentation and Length on Trust in Recommender Systems: An Online Experiment."
  6. SQ Magazine. (2026). "Customer Data Privacy Statistics 2026," aggregating third-party consumer survey figures on policy reading and purchase behavior. Included as a secondary aggregator; original underlying survey methodology not independently disclosed on the aggregator page.

Note: All figures verified as of July 2026. Adoption-by-rank figures are detailed further in our companion post on how many websites publish a privacy policy. Readership, trust, and ROI figures are refreshed at least twice a year to track new Pew and Cisco survey editions.