The Cybernews Router Privacy Index 2026 assessed 22 consumer and business router brands against their published privacy policies, scoring each across data collection, geolocation practices, and policy transparency. Three additional brands were assessed under separate criteria, bringing the total to 25.
DNS logging is described by the researchers as one of the most revealing signals a router can produce, effectively a timestamped record of every website a household or office visits. The uniform opacity across all 25 vendors means consumers have no public basis for determining whether that data is retained or shared.
On geolocation, no brand in the study explicitly ruled out tracking precise device location. Seven confirmed doing so outright, six did so conditionally, and 12 failed to specify. For nearby Wi-Fi identifiers, 92% of brands either partially confirmed collection or left the question unanswered. The researchers note that SSID and BSSID harvesting can enable highly accurate physical location tracking without requiring GPS access.
D-Link, Omada, and Wyze received the highest risk scores in the assessment. In each case the primary driver was a corporate-wide privacy policy covering multiple product lines, which the researchers argue creates legal ambiguity around what network monitoring is actually taking place for router-specific traffic.
The study also found that relevant privacy terms are typically inaccessible before purchase, registration, or device setup, making it structurally difficult for consumers to compare policies before buying. Cybernews published the full ranking, data-handling charts, and privacy recommendations alongside the research.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter