How a scan works
How ConsentMark Works
ConsentMark records what a site sends in each consent state and grades it against a published set of severity gates. The scanner loads a site in headless Chromium, driven by Playwright from an Irish locale and timezone, and identifies itself in the user agent it sends. The grade runs from A to F, or is withheld as I where the scan could not observe enough to grade at all, and it names the methodology version behind it.
Three-Stage Scan
A scan runs in three stages, and the same URL runs the same way each time.
- 1
Discover
The scanner catalogues every tag, script, cookie and network request the page issues. Nothing is installed on your side and no code change is needed. The scan runs from an Irish vantage - an en-IE browser on Europe/Dublin time - as an automated visitor that identifies itself as one. Every result states the browser, region, viewport and capture window it ran from.
- 2
Consent
The scanner accepts the banner, rejects it, and leaves it untouched, recording which tags fire in each state. Whether a Consent Management Platform holds tags back until the visitor has chosen is settled from that record rather than from its configuration screen.
- 3
Score
Every finding is evaluated against compliance gates ordered by severity. When more than one gate fires on the same scan the strictest cap wins, and the letter is published with the evidence that produced it.
The five governance dimensions
The dimensions below are what a scan reports on, in the order they carry weight. The letter itself is set by the severity gates above.
Technical Consent Controls
Whether a consent management platform is present, and whether the tags on the page honour an accept or a reject once it is given.
Cross-Border Data Transfers
Which jurisdictions receive the data, and which of those transfers your records need to account for.
Pre-Consent Data Leakage
Whether cookies, storage writes or identifiers leave the browser before the visitor has chosen. The scan records what left before the choice, and the time it left.
Governance Controls
Whether tags are deployed through a tag manager with version history and review, or hand-placed in the page where no one can see the change.
Third-Party Exposure
How many distinct third parties the page brings in. Each one is another recipient the controller has to identify, document and put a written arrangement in place for.
What the Grades Mean
Grades are set by severity gates rather than by a points total, so strong behaviour in one dimension cannot offset a critical failure in another.
Strong governance
No measurement collection call before the visitor chose, whatever host would receive it. Advanced Consent Mode can send cookieless pings before consent, while basic mode blocks Google tags until consent is granted.
Good with minor gaps
Something was sent before the visitor chose, in a restricted or non-tracking form.
Material gaps
Rejecting consent is harder than accepting it, or data transfers reach jurisdictions without adequate safeguards.
Incomplete implementation
CMP blocking technology is deployed but not fully enforced.
Critical risk
There is no CMP, consent is not enforced, personal data is leaking, or a reject is ignored.
Insufficient data
The scan could not collect enough to score the site, so no A-F grade is issued for it. Book a Governance Posture Call and we will go through what the scan reached.
Regulatory Context
Article 5(2) of the GDPR puts the burden of demonstrating compliance on the controller. The Data Protection Commission and its counterparts across the EU have opened investigations into how websites track visitors, and what they ask for is what a site was doing on a given date.
A ConsentMark grade answers that with a dated record of what the site did on the day it ran. It is the same record a board needs to carry analytics tracking on its risk register.
Evidence and Versioning
A report sets out which tags were detected, what consent signals were observed, where data was sent, and how each dimension scored. The methodology carries a version number, and a grade names the version that produced it, so a scan can be compared with one taken months earlier.
A scan is one sample. ConsentMark Monitor repeats the capture every night on a site your organisation has proved it owns, and checks what it finds against the Tag Baseline you approved. Each night's verdict is signed, and no failure is reported to you until someone at Obscurity has looked at it. A site is a domain and its subdomains, up to 100 pages.