Skip to main content

Who builds this

About ConsentMark

ConsentMark is an independent analytics governance scanner for regulated organisations across the EU, the EEA and the UK. It loads any site in a real browser before, after accepting and after rejecting consent, and issues a versioned, dated A-F grade. It is operated by Obscurity Ltd, and we have no stake in the answer.

What ConsentMark Does

ConsentMark is built for regulated organisations - insurance, fintech, energy and travel. A scan loads a site, works its consent banner, and returns an A-F governance grade with the findings behind it.

A scan covers consent enforcement, the tag inventory, where the data is sent, and how many third parties the page brings in. Each finding names the remediation it calls for. Monitor runs the same scan on a schedule against a subscribed domain and reports what changed between runs.

How a grade is scored

Every result is scored on the same five dimensions, listed here heaviest first:

  1. Technical Consent Controls - Whether a consent management platform is present, and whether the tags on the page honour an accept or a reject once it is given.
  2. Cross-Border Data Transfers - Which jurisdictions receive the data, and which of those transfers your records need to account for.
  3. Pre-Consent Data Leakage - Whether cookies, storage writes or identifiers leave the browser before the visitor has chosen. The scan records what left before the choice, and the time it left.
  4. Governance Controls - Whether tags are deployed through a tag manager with version history and review, or hand-placed in the page where no one can see the change.
  5. Third-Party Exposure - How many distinct third parties the page brings in. Each one is another recipient the controller has to identify, document and put a written arrangement in place for.

The framework behind it

What a grade measures is two layers of a five-layer model: the Analytics Governance Control Model sets out all five, and which of them a scan reads.

Built by Obscurity

ConsentMark is built and operated by Obscurity Ltd, an analytics governance practice in Dublin, Ireland, founded and led by Dónal Troddyn. Obscurity has worked on analytics governance for regulated organisations since 2018.

Advisory work - a Governance Posture Review, or an Obscurity Governance Retainer that operates the measurement layer month after month - is described at obscurity.ie.

Contact

Write to contact@consentmark.com.