{
  "schemaVersion": "1.0",
  "corpus": "benchmark",
  "title": "The Analytics Governance Benchmark - 2026 edition, methodology v7.8",
  "version": "2026",
  "canonicalUrl": "https://www.consentmark.com/benchmark/2026.json",
  "humanUrl": "https://www.consentmark.com/benchmark/2026",
  "publisher": {
    "name": "Obscurity Ltd",
    "cro": "622475",
    "jurisdiction": "Ireland",
    "url": "https://obscurity.ie"
  },
  "licence": {
    "name": "ConsentMark corpus compilation licence 1.0",
    "summary": "You may quote, cite and redistribute this corpus, in whole or in part, for any purpose, provided you attribute it to Obscurity Ltd and cite the canonical URL and the asOf date. You may not re-characterise it: presenting a value, a grade band, a gate or a consent state as saying something this corpus does not say, or presenting a derived work as the published corpus, is outside these terms.",
    "attributionRequired": true,
    "derivativeReCharacterisation": "not permitted"
  },
  "citeAs": "ConsentMark. (2026, September 6). The Analytics Governance Benchmark - 2026 edition, methodology v7.8. Obscurity Ltd (CRO 622475). https://www.consentmark.com/benchmark/2026",
  "asOf": "2026-09-06",
  "generatedAt": "2026-09-07T13:13:07.203Z",
  "frozenAtPublication": "Frozen at publication. This edition is the record of the run it reports, as it stood on its asOf date. A re-measurement is published as its own dated edition at its own URL.",
  "series": "The Analytics Governance Benchmark",
  "edition": "2026",
  "methodologyVersion": "v7.8",
  "methodologyUrl": "https://www.consentmark.com/methodology/v7.8",
  "frozenAt": "2026-09-06",
  "dateMeaning": "frozenAt is the date of the run these figures come from, and asOf is the same date: the edition is frozen at its run and is never restated in place. A re-measurement is published as its own dated edition at its own URL.",
  "csvUrl": "https://www.consentmark.com/benchmark/2026.csv",
  "observation": {
    "period": "September 2026",
    "runDate": "2026-09-06",
    "marketCount": 31,
    "sectorCount": 23,
    "comparability": "Scored under methodology v7.8. Figures are not comparable across methodology versions, and this edition will not be restated under a later one."
  },
  "provenance": {
    "sourceRun": "benchmark-1656-results-2026-09-06.json",
    "ruleCommit": "c191cdc05",
    "rowsWithheldByNoStateRule": 63,
    "note": "sourceRun is the scan run these figures were scored from, and ruleCommit is the commit of the scoring rules they were scored under. rowsWithheldByNoStateRule is how many rows the v7.8 no-state rule moved from a letter to a withheld letter."
  },
  "disclosure": {
    "minimumSectorCohort": 10,
    "minimumCellCount": 5,
    "suppressedLabel": "fewer than 5",
    "rule": "A sector publishes a row only when at least 10 of its organisations were graded A to F. Inside a published row, a grade count of 1 to 4 is withheld and reported as suppressed. A count of zero is published as zero, because it identifies nobody. The threshold applies to the graded population, never to the approached one. No sector-by-market breakdown is published at any size.",
    "withheld": {
      "sectors": 8,
      "approached": 71,
      "returnedAResult": 55,
      "gradedAToF": 40,
      "note": "The sectors held back by the cohort floor, as one aggregate. Published so the reconciliation still closes without naming a sector too small to name: the published sector rows plus this block account for every organisation approached."
    }
  },
  "populations": {
    "approached": 1656,
    "returnedAResult": 1476,
    "gradedAToF": 1022,
    "gradeWithheld": 454,
    "returnedNothing": 180,
    "reconciliation": "approached = returnedAResult + returnedNothing. returnedAResult = gradedAToF + gradeWithheld. gradeWithheldByReason sums to gradeWithheld. Every percentage in this corpus names the population it is a share of: percentageOfGraded has gradedAToF as its denominator, percentageOfApproached has approached."
  },
  "gradeWithheldByReason": [
    {
      "id": "other-inconclusive",
      "label": "Inconclusive for other reasons",
      "description": "The scan returned a result it could not grade with confidence: too little observable behaviour, or a consent flow it could not complete.",
      "count": 272,
      "percentageOfApproached": 16.4
    },
    {
      "id": "edge-protection-blocked",
      "label": "Edge protection blocked the scan",
      "description": "The site's edge protection refused the request or served a challenge page instead of the site. Nothing about the site's own tags was observed.",
      "count": 119,
      "percentageOfApproached": 7.2
    },
    {
      "id": "no-consent-state-exercised",
      "label": "No consent state could be exercised",
      "description": "The scan found no consent control it could drive, so neither accepting nor rejecting consent was attempted. Under v7.8 a letter requires that at least one consent state was exercised.",
      "count": 63,
      "percentageOfApproached": 3.8
    }
  ],
  "scores": {
    "meanOfGraded": 45.9,
    "medianOfGraded": 22,
    "denominator": "gradedAToF",
    "denominatorCount": 1022,
    "scale": "0 to 100, higher is better.",
    "note": "The mean and the median of the 1022 graded rows, and of nothing else. A withheld row carries no score and is in neither figure. No minimum, maximum, ranking or named performer is published, at any level of aggregation."
  },
  "gradeDistribution": [
    {
      "grade": "A",
      "count": 123,
      "percentageOfGraded": 12
    },
    {
      "grade": "B",
      "count": 115,
      "percentageOfGraded": 11
    },
    {
      "grade": "C",
      "count": 66,
      "percentageOfGraded": 6
    },
    {
      "grade": "D",
      "count": 163,
      "percentageOfGraded": 16
    },
    {
      "grade": "F",
      "count": 555,
      "percentageOfGraded": 54
    }
  ],
  "gradeMeaning": [
    "An F means one of the v7.8 F-gates fired: personal data in a tracking request, tracking with no consent controls, collection before consent, tracking after a rejection, or contradictory consent signals. The gates are published in full at /methodology/v7.8.",
    "A letter requires that at least one consent state was exercised. Where none was, the letter is withheld rather than set low.",
    "A grade is a governance assessment of observable behaviour on one page load. It is not a certification and not a legal conclusion."
  ],
  "sectors": [
    {
      "sector": "banking",
      "displayName": "Banking",
      "approached": 284,
      "returnedAResult": 260,
      "gradedAToF": 152,
      "meanScoreOfGraded": 54,
      "gradeACount": 31,
      "gradeFCount": 61,
      "suppressedCells": []
    },
    {
      "sector": "insurance",
      "displayName": "Insurance",
      "approached": 277,
      "returnedAResult": 252,
      "gradedAToF": 197,
      "meanScoreOfGraded": 47,
      "gradeACount": 27,
      "gradeFCount": 103,
      "suppressedCells": []
    },
    {
      "sector": "energy",
      "displayName": "Energy",
      "approached": 156,
      "returnedAResult": 141,
      "gradedAToF": 102,
      "meanScoreOfGraded": 42,
      "gradeACount": 12,
      "gradeFCount": 60,
      "suppressedCells": []
    },
    {
      "sector": "gambling",
      "displayName": "Gambling",
      "approached": 129,
      "returnedAResult": 118,
      "gradedAToF": 69,
      "meanScoreOfGraded": 37,
      "gradeACount": null,
      "gradeFCount": 49,
      "suppressedCells": [
        "gradeACount"
      ]
    },
    {
      "sector": "telecoms",
      "displayName": "Telecoms",
      "approached": 112,
      "returnedAResult": 105,
      "gradedAToF": 79,
      "meanScoreOfGraded": 42,
      "gradeACount": 8,
      "gradeFCount": 46,
      "suppressedCells": []
    },
    {
      "sector": "fintech",
      "displayName": "Fintech",
      "approached": 108,
      "returnedAResult": 103,
      "gradedAToF": 65,
      "meanScoreOfGraded": 45,
      "gradeACount": null,
      "gradeFCount": 33,
      "suppressedCells": [
        "gradeACount"
      ]
    },
    {
      "sector": "credit-union",
      "displayName": "Credit Union",
      "approached": 91,
      "returnedAResult": 58,
      "gradedAToF": 48,
      "meanScoreOfGraded": 51,
      "gradeACount": 0,
      "gradeFCount": 23,
      "suppressedCells": []
    },
    {
      "sector": "investment",
      "displayName": "Investment",
      "approached": 87,
      "returnedAResult": 76,
      "gradedAToF": 60,
      "meanScoreOfGraded": 46,
      "gradeACount": 7,
      "gradeFCount": 36,
      "suppressedCells": []
    },
    {
      "sector": "pharma",
      "displayName": "Pharma",
      "approached": 79,
      "returnedAResult": 71,
      "gradedAToF": 58,
      "meanScoreOfGraded": 48,
      "gradeACount": 14,
      "gradeFCount": 34,
      "suppressedCells": []
    },
    {
      "sector": "healthcare",
      "displayName": "Healthcare",
      "approached": 78,
      "returnedAResult": 69,
      "gradedAToF": 41,
      "meanScoreOfGraded": 46,
      "gradeACount": 5,
      "gradeFCount": 21,
      "suppressedCells": []
    },
    {
      "sector": "transport",
      "displayName": "Transport",
      "approached": 52,
      "returnedAResult": 48,
      "gradedAToF": 30,
      "meanScoreOfGraded": 39,
      "gradeACount": null,
      "gradeFCount": 20,
      "suppressedCells": [
        "gradeACount"
      ]
    },
    {
      "sector": "aviation",
      "displayName": "Aviation",
      "approached": 37,
      "returnedAResult": 33,
      "gradedAToF": 15,
      "meanScoreOfGraded": 52,
      "gradeACount": null,
      "gradeFCount": 7,
      "suppressedCells": [
        "gradeACount"
      ]
    },
    {
      "sector": "automotive",
      "displayName": "Automotive",
      "approached": 36,
      "returnedAResult": 34,
      "gradedAToF": 23,
      "meanScoreOfGraded": 37,
      "gradeACount": 0,
      "gradeFCount": 16,
      "suppressedCells": []
    },
    {
      "sector": "legal",
      "displayName": "Legal",
      "approached": 36,
      "returnedAResult": 33,
      "gradedAToF": 29,
      "meanScoreOfGraded": 47,
      "gradeACount": null,
      "gradeFCount": 15,
      "suppressedCells": [
        "gradeACount"
      ]
    },
    {
      "sector": "property",
      "displayName": "Property",
      "approached": 23,
      "returnedAResult": 20,
      "gradedAToF": 14,
      "meanScoreOfGraded": 26,
      "gradeACount": 0,
      "gradeFCount": 12,
      "suppressedCells": []
    }
  ],
  "limits": [
    "Server-side tag management is invisible from a browser by construction, so no adoption rate for it is reported. A container the scan never sees is not a container that is not there.",
    "Session replay tooling was not matched against a signature set in this run, so no rate is reported for it either.",
    "Only observable, external governance signals are measured. Internal policies, contractual arrangements and server-side processing are outside what a browser check can see.",
    "The edition reports one run. It is a dated record, not a current measurement, and it is not restated under a later methodology: a re-measurement is published as its own edition.",
    "The 454 withheld letters are withheld, not low. Nothing in this corpus records how a withheld site behaves once a visitor makes a consent choice."
  ],
  "omits": [
    "Every organisation scanned. No domain, no hostname, no organisation name and no per-organisation row appears in this corpus, in any field, at any grade.",
    "Any sector-by-market breakdown. Markets are published as a count only. A sector crossed with a market is small enough at this population to name the organisation sitting in it.",
    "Extremes. The corpus publishes distributions - counts, shares, a mean and a median - and no minimum, maximum, ranking, best or worst performer.",
    "Cells below the disclosure threshold. A grade count of 1 to 4 inside a published sector row is withheld, and a sector with fewer than 10 graded organisations publishes no row at all.",
    "Any comparison with an edition scored under a different methodology version. Letters produced under different grading rules are not comparable, so no comparison is drawn.",
    "Any obligation on a controller. The corpus records what was observed and how it was scored. What follows for a given organisation is not in this file."
  ]
}
