Skip to main content

September 2026 · Methodology v7.8

The Analytics Governance Benchmark - 2026 edition

We approached 1,656 regulated organisations across the EU, the EEA, the United Kingdom and Switzerland, and set out what the run could and could not grade. The figures froze on 6th September 2026.

Scored under methodology v7.8. Letters are not comparable across methodology versions, and the rules that produced these ones are set out below.

What the run could grade

1,022 of the 1,656 organisations approached carry a letter. Every share on this chart is a share of the 1,656.

  • Graded A to F: 1,022 of 1,656 (61.7%)

    The scan drove a consent control, observed what the site did on either side of the choice, and the run scored it.

  • Grade withheld: 454 of 1,656 (27.4%)

    The scan returned a result the run would not put a letter on. A withheld letter is withheld, not low, and nothing here records how these sites behave once a visitor makes a consent choice.

  • Inconclusive for other reasons: 272 of 1,656 (16.4%)

    The scan returned a result it could not grade with confidence: too little observable behaviour, or a consent flow it could not complete.

  • Edge protection blocked the scan: 119 of 1,656 (7.2%)

    The site's edge protection refused the request or served a challenge page instead of the site. Nothing about the site's own tags was observed.

  • No consent state could be exercised: 63 of 1,656 (3.8%)

    The scan found no consent control it could drive, so neither accepting nor rejecting consent was attempted. Under v7.8 a letter requires that at least one consent state was exercised.

  • Returned nothing: 180 of 1,656 (10.9%)

    The scan could not load the site at all: a network error, a protocol error or a timeout. These sites appear in no grade or sector figure below.

1,022 graded, 454 withheld and 180 with no result account for the 1,656 approached. The three withhold reasons are exclusive of one another and sum to the 454.

Grade distribution

Of the 1,022 organisations graded A to F, 555 were graded F and 123 were graded A.

Share of the 1,022 graded A to F

A
123(12%)
B
115(11%)
C
66(6%)
D
163(16%)
F
555(54%)

An F means one of the v7.8 F-gates fired: personal data in a tracking request, tracking with no consent controls, collection before consent, tracking after a rejection, or contradictory consent signals. The gates are published in full at methodology v7.8.

The mean score is 45.9 and the median 22, both over the 1,022 graded sites. A withheld letter carries no score and is in neither figure.

What changed in the grading rules

These letters were produced by rules that moved since the version an earlier run of the same list was scored under. Each change is published in full at methodology v7.8.

Grading rule changes between v1.2 and v7.8
RuleUnder v1.2Under v7.8Effect
Post-rejection capA leak after a rejection was found only when post-reject requests exceeded pre-consent by 10 in absolute terms and by a tenth in relative terms, and a severity ladder then set the ceiling at C, D or F by the size of the difference.One tracking request on a fresh load after a rejection, or one tracking cookie that survives it, is the finding. There is no threshold and no ladder.Letters down
Pre-consent measurement capThe ceiling turned on evidenced storage or an identifier before consent. A measurement call to an endpoint on the site's own domain was outside it.A measurement collection call before consent sets the ceiling at B whatever endpoint receives it, the site's own tag server included.Letters down
Transfer capA destination the registry had never characterised fired the cap, and so did one whose own record documented a safeguard.A destination whose record documents a safeguard never fires the cap, and one the registry has never characterised fires nothing either way.Letters up
Consent state exercisedA scan was graded on what it observed, whether or not it drove a consent control.A letter requires that at least one consent state was exercised. Where the scan drove no consent control, the letter is withheld and the reason names the cause.New rule - 63 letters withheld

Results by sector

Mean score and grade counts across regulated sectors. A sector with fewer than 10 graded organisations is not shown, and a grade count of 1 to 4 inside a published row is withheld: at sector level, a count of one or two is close to naming the organisations behind it. Nothing withheld here can be recovered from another figure in this edition.

  • Banking

    Approached
    284
    Graded
    152
    Mean score
    54
    Graded A
    31
    Graded F
    61
  • Insurance

    Approached
    277
    Graded
    197
    Mean score
    47
    Graded A
    27
    Graded F
    103
  • Energy

    Approached
    156
    Graded
    102
    Mean score
    42
    Graded A
    12
    Graded F
    60
  • Gambling

    Approached
    129
    Graded
    69
    Mean score
    37
    Graded A
    fewer than 5
    Graded F
    49
  • Telecoms

    Approached
    112
    Graded
    79
    Mean score
    42
    Graded A
    8
    Graded F
    46
  • Fintech

    Approached
    108
    Graded
    65
    Mean score
    45
    Graded A
    fewer than 5
    Graded F
    33
  • Credit Union

    Approached
    91
    Graded
    48
    Mean score
    51
    Graded A
    0
    Graded F
    23
  • Investment

    Approached
    87
    Graded
    60
    Mean score
    46
    Graded A
    7
    Graded F
    36
  • Pharma

    Approached
    79
    Graded
    58
    Mean score
    48
    Graded A
    14
    Graded F
    34
  • Healthcare

    Approached
    78
    Graded
    41
    Mean score
    46
    Graded A
    5
    Graded F
    21
  • Transport

    Approached
    52
    Graded
    30
    Mean score
    39
    Graded A
    fewer than 5
    Graded F
    20
  • Aviation

    Approached
    37
    Graded
    15
    Mean score
    52
    Graded A
    fewer than 5
    Graded F
    7
  • Automotive

    Approached
    36
    Graded
    23
    Mean score
    37
    Graded A
    0
    Graded F
    16
  • Legal

    Approached
    36
    Graded
    29
    Mean score
    47
    Graded A
    fewer than 5
    Graded F
    15
  • Property

    Approached
    23
    Graded
    14
    Mean score
    26
    Graded A
    0
    Graded F
    12

Methodology

Each organisation was scanned using ConsentMark's automated governance scanner. The scanner loads a site in headless Chromium, driven by Playwright from an Irish locale and timezone, and identifies itself in the user agent it sends. It loaded the homepage, observed all network requests before and after consent interactions, and evaluated five weighted dimensions. The scans ran on 5th and 6th September 2026 and were scored under methodology v7.8. Organisations were selected from publicly available regulatory registers across the EU, the EEA, the United Kingdom and Switzerland.

This Analytics Governance benchmark measures observable, external signals only. It does not assess internal policies, contractual arrangements, or server-side processing that is not visible from the browser.

What this scan cannot see

Server-side tag management is invisible from the browser by construction: the whole point of it is that the request goes to a first-party endpoint. A container the scan never sees is not a container that is not there, so no adoption figure for it is reported here. Session replay tooling was not matched against a signature set in this run, so no rate is reported for it either. Neither absence is a finding about the organisations scanned.

Cite this edition
BibTeX
@misc{consentmark-benchmark-2026,
  author       = {{ConsentMark}},
  year         = {2026},
  title        = {The Analytics Governance Benchmark, 2026 edition, methodology v7.8},
  howpublished = {\url{https://www.consentmark.com/benchmark/2026}},
  note         = {ConsentMark methodology v7.8}
}
APA
ConsentMark. (2026, September 6). The Analytics Governance Benchmark, 2026 edition, methodology v7.8. Methodology v7.8. https://www.consentmark.com/benchmark/2026
Markdown
[The Analytics Governance Benchmark, 2026 edition, methodology v7.8 - ConsentMark](https://www.consentmark.com/benchmark/2026)
Plain text
The Analytics Governance Benchmark, 2026 edition, methodology v7.8 - ConsentMark, 2026-09-06, methodology v7.8, https://www.consentmark.com/benchmark/2026

Programmatic access

This edition as data: /benchmark/2026.json and /benchmark/2026.csv. Both carry the edition, methodology v7.8, the date the figures froze, the run they were scored from and the disclosure threshold inside the file. The figures are the figures on this page: the page and the files render from one source. Cached for one hour.

Scan your site now

See how your organisation compares to the benchmark. Free, instant, no login required.