Skip to main content

March 2026

Analytics Governance Benchmark 2026

We scanned 1,022 regulated organisations across 19 EU/EEA markets and 14 sectors to measure the state of analytics governance in regulated industries.

1,022
Organisations scanned
19
EU/EEA markets
14
Regulated sectors
85
Average score (of 100)

Grade Distribution

Of the 654 organisations that returned a conclusive scan, the majority scored well - but a significant minority have serious governance gaps.

A
338
338 (39%)
B
202
202 (23%)
C
71
71 (8%)
D
3 (<1%)
F
40 (5%)
Inconclusive
213 (25%)

Sites that blocked automated scanning, returned errors, or had insufficient data for a reliable grade.

Key Findings

Root cause analysis across all organisations that scored below an A grade.

49%

Non-EU data transfers

Nearly half of all root cause analyses identified non-EU data transfers as the primary governance weakness. Tags sending data to US-based processors without adequate transfer mechanisms remain the most common issue.

43%

Consent not enforced

Consent management platforms are present but not properly enforcing consent signals. Tags fire before or regardless of user consent choices, undermining the entire consent architecture.

6%

No consent infrastructure

A small but notable group of regulated organisations have no consent management platform deployed at all. All tags fire unconditionally on page load.

12%

Session replay detected

106 organisations were found to be running session replay tools, which capture detailed user interactions and raise significant data protection questions under GDPR.

3%

Server-side GTM adoption

Only 27 organisations have adopted server-side Google Tag Manager, a key mitigation for cross-border data transfer risks. Adoption remains extremely low.

Performance by Sector

Average governance scores and grade distribution across 14 regulated sectors.

SectorOrganisationsAvg. ScoreAF
Insurance16387987
Banking120836213
Energy8483457
Telecoms6585292
Fintech3886232
Credit Union3686232
Healthcare3481134
Pharma288813
Investment218711
Utilities147951
Legal14875
Gambling148331
Transport138571
Property10841

Scoring Dimensions

Each organisation is scored across five weighted dimensions.

Technical Consent Controls
Weight: 40% 91/100
Cross-Border Data Transfers
Weight: 20% 79/100
Pre-Consent Data Leakage
Weight: 15% 91/100
Governance Controls
Weight: 15% 85/100
Third-Party Exposure
Weight: 10% 83/100

Methodology

Each organisation was scanned using Obscurity's automated governance scanner, which loads the homepage in a headless browser, observes all network requests before and after consent interactions, and evaluates five governance dimensions. Scans were conducted over a two-week period in March 2026. Organisations were selected from publicly available regulatory registers across 19 EU/EEA jurisdictions.

This benchmark measures observable, external governance signals only. It does not assess internal policies, contractual arrangements, or server-side processing that is not visible from the browser.

Already been scanned?

Enter your website URL to see if your organisation was included in the benchmark.

Check your organisation's governance score

Run an instant, free governance scan to see how your organisation compares to the benchmark.