Skip to main content

September 2026 · Methodology v7.8

The Analytics Governance Benchmark - 2026 edition

We approached 1,656 regulated organisations across the EU, the EEA, the United Kingdom and Switzerland, and set out what the run could and could not grade. The figures froze on 6th September 2026.

Scored under methodology v7.8. Letters are not comparable across methodology versions, and the rules that produced these ones are set out below.

Grade distribution

555 of the 1,022 organisations graded A to F were graded F, and 123 were graded A. Every share on this chart is a share of the 1,022 graded.

Share of the 1,022 graded A to F

Grade distribution over the 1,022 organisations graded A to F
GradeOrganisations
Graded A123 of 1,022 graded (12%)
Graded B115 of 1,022 graded (11%)
Graded C66 of 1,022 graded (6%)
Graded D163 of 1,022 graded (16%)
Graded F555 of 1,022 graded (54%)

An F means one of the v7.8 F-gates fired: personal data in a tracking request, tracking with no consent controls, collection before consent, tracking after a rejection, or contradictory consent signals. The gates are published in full at methodology v7.8.

The distribution is the finding. Every score the scan produces is one of five per-grade constants, so a mean over them restates this grade mix on a 0 to 100 scale rather than measuring anything further, and no mean, median or sector average is published.

What changed in the grading rules

These letters were produced by rules that moved since the version an earlier run of the same list was scored under. Each change is published in full at methodology v7.8.

Grading rule changes between v1.2 and v7.8
RuleUnder v1.2Under v7.8Effect
Post-rejection capA leak after a rejection was found only when post-reject requests exceeded pre-consent by 10 in absolute terms and by a tenth in relative terms, and a severity ladder then set the ceiling at C, D or F by the size of the difference.One tracking request on a fresh load after a rejection, or one tracking cookie that survives it, is the finding. There is no threshold and no ladder.Letters down
Pre-consent measurement capThe ceiling turned on evidenced storage or an identifier before consent. A measurement call to an endpoint on the site's own domain was outside it.A measurement collection call before consent sets the ceiling at B whatever endpoint receives it, the site's own tag server included.Letters down
Transfer capA destination the registry had never characterised fired the cap, and so did one whose own record documented a safeguard.A destination whose record documents a safeguard never fires the cap, and one the registry has never characterised fires nothing either way.Letters up
Consent state exercisedA scan was graded on what it observed, whether or not it drove a consent control.A letter requires that at least one consent state was exercised. Where the scan drove no consent control, the letter is withheld and the reason names the cause.New rule - 63 letters withheld

Results by sector

Grade counts across regulated sectors. A sector with fewer than 10 graded organisations is not shown, and a grade count of 1 to 4 inside a published row is withheld: at sector level, a count of one or two is close to naming the organisations behind it. Nothing withheld here can be recovered from another figure in this edition.

Where an F is likelier

Share of each sector's own graded population that was graded F, worst first.

Each bar is a share of that sector's own graded population, printed beside it as the F count over that population. Sectors below the cohort floor are not drawn at all.
Share of each sector's graded population that was graded F
SectorGraded F
Property12 of 14 graded (85.7%)
Gambling49 of 69 graded (71.0%)
Automotive16 of 23 graded (69.6%)
Transport20 of 30 graded (66.7%)
Investment36 of 60 graded (60.0%)
Energy60 of 102 graded (58.8%)
Pharma34 of 58 graded (58.6%)
Telecoms46 of 79 graded (58.2%)
Insurance103 of 197 graded (52.3%)
Legal15 of 29 graded (51.7%)
Healthcare21 of 41 graded (51.2%)
Fintech33 of 65 graded (50.8%)
Credit Union23 of 48 graded (47.9%)
Aviation7 of 15 graded (46.7%)
Banking61 of 152 graded (40.1%)
  • Banking

    Approached
    284
    Graded
    152
    Graded A
    31
    Graded F
    61
  • Insurance

    Approached
    277
    Graded
    197
    Graded A
    27
    Graded F
    103
  • Energy

    Approached
    156
    Graded
    102
    Graded A
    12
    Graded F
    60
  • Gambling

    Approached
    129
    Graded
    69
    Graded A
    fewer than 5
    Graded F
    49
  • Telecoms

    Approached
    112
    Graded
    79
    Graded A
    8
    Graded F
    46
  • Fintech

    Approached
    108
    Graded
    65
    Graded A
    fewer than 5
    Graded F
    33
  • Credit Union

    Approached
    91
    Graded
    48
    Graded A
    0
    Graded F
    23
  • Investment

    Approached
    87
    Graded
    60
    Graded A
    7
    Graded F
    36
  • Pharma

    Approached
    79
    Graded
    58
    Graded A
    14
    Graded F
    34
  • Healthcare

    Approached
    78
    Graded
    41
    Graded A
    5
    Graded F
    21
  • Transport

    Approached
    52
    Graded
    30
    Graded A
    fewer than 5
    Graded F
    20
  • Aviation

    Approached
    37
    Graded
    15
    Graded A
    fewer than 5
    Graded F
    7
  • Automotive

    Approached
    36
    Graded
    23
    Graded A
    0
    Graded F
    16
  • Legal

    Approached
    36
    Graded
    29
    Graded A
    fewer than 5
    Graded F
    15
  • Property

    Approached
    23
    Graded
    14
    Graded A
    0
    Graded F
    12

What the run could grade

1,022 of the 1,656 organisations approached carry a letter. Every share on this chart is a share of the 1,656.

A withheld letter is withheld and not low - nothing here records how those 454 sites behave once a visitor makes a consent choice, the 180 that returned nothing appear in no grade or sector figure above, and each reason keeps its full label and a sentence saying what it means at /benchmark/2026.json.
How each of the 1,656 organisations approached was dispositioned
DispositionOrganisations
Graded A to F1,022 of 1,656 (61.7%)
Grade withheld454 of 1,656 (27.4%)
Grade withheld - Inconclusive for other reasons272 of 1,656 (16.4%)
Grade withheld - Edge protection blocked the scan119 of 1,656 (7.2%)
Grade withheld - No consent state could be exercised63 of 1,656 (3.8%)
Returned nothing180 of 1,656 (10.9%)

1,022 graded, 454 withheld and 180 with no result account for the 1,656 approached. The three withhold reasons are exclusive of one another and sum to the 454.

Methodology

Each organisation was scanned using ConsentMark's automated governance scanner. The scanner loads a site in headless Chromium, driven by Playwright from an Irish locale and timezone, and identifies itself in the user agent it sends. It loaded the homepage, observed all network requests before and after consent interactions, and evaluated five weighted dimensions. The scans ran on 5th and 6th September 2026 and were scored under methodology v7.8. Organisations were selected from publicly available regulatory registers across the EU, the EEA, the United Kingdom and Switzerland.

This Analytics Governance benchmark measures observable, external signals only. It does not assess internal policies, contractual arrangements, or server-side processing that is not visible from the browser.

What this scan cannot see

Server-side tag management is invisible from the browser by construction: the whole point of it is that the request goes to a first-party endpoint. A container the scan never sees is not a container that is not there, so no adoption figure for it is reported here. Session replay tooling was not matched against a signature set in this run, so no rate is reported for it either. Neither absence is a finding about the organisations scanned.

Cite this edition
BibTeX
@misc{consentmark-benchmark-2026,
  author       = {{ConsentMark}},
  year         = {2026},
  title        = {The Analytics Governance Benchmark, 2026 edition, methodology v7.8},
  howpublished = {\url{https://www.consentmark.com/benchmark/2026}},
  note         = {ConsentMark methodology v7.8}
}
APA
ConsentMark. (2026, September 6). The Analytics Governance Benchmark, 2026 edition, methodology v7.8. Methodology v7.8. https://www.consentmark.com/benchmark/2026
Markdown
[The Analytics Governance Benchmark, 2026 edition, methodology v7.8 - ConsentMark](https://www.consentmark.com/benchmark/2026)
Plain text
The Analytics Governance Benchmark, 2026 edition, methodology v7.8 - ConsentMark, 2026-09-06, methodology v7.8, https://www.consentmark.com/benchmark/2026

Programmatic access

This edition as data: /benchmark/2026.json and /benchmark/2026.csv. Both carry the edition, methodology v7.8, the date the figures froze, the run they were scored from and the disclosure threshold inside the file. The figures are the figures on this page: the page and the files render from one source. Cached for one hour.

Scan your site now

See how your organisation compares to the benchmark. Free, instant, no login required.