The DPC's final decision against IAB Europe, issued in May 2022 and confirmed on appeal in 2025, made clear that a TCF banner in a regulated organisation needs controller-level evidence. The CMP cannot supply that evidence about itself. Code agents and release automation are changing tracking surfaces faster than a manual review cycle covers them. Obscurity gives boards and data protection officers the independent, timestamped evidence that demonstrates ongoing control of what a site ships.
Governance Posture Call, Review and Retainer
An engagement opens with a Governance Posture Call, a scoped conversation about where your tracking exposes you. It usually leads to a Governance Posture Review, which sets down in writing, on a date, what your tracking does. Beyond that, an Obscurity Governance Retainer operates the measurement layer month after month under one named contact. Scope and fees are set in the conversation.
What a retained month contains
A retained month is continuous work. After each release your journeys are run again through their consent states - accept, reject, and the partial states in between. A change that alters what a page sends is caught while the release is still fresh.
Every tag change we make is staged as a version in your own container and published on your side, under your change process. The record says what changed and why. When something breaks, the evidence is captured as it happens - what fired, on which page, under which consent state - rather than reconstructed afterwards.
A written report goes out each month covering what ran, what changed and what is still open. The report names the person who ran the month, and they answer your board's or your data protection officer's questions on it when asked.
Scope of service
- Included
- We find what your sites are sending and remediate the tags and the containers behind it. We quantify it from the analytics data we can reach, and document it so the finding stands up on its own. This work runs under the agreed scope, without waiting for a request each time.
- On request
- We brief your data protection officer, your legal team or your board on what we found, and we present the record in person. We supply the factual material and the method behind it to support a response to a regulator. Preserving or extracting data from the systems we can reach falls here too, as does an analysis deeper than the month called for. You ask, we scope it, and it is quoted separately.
We do not decide whether it is notifiable. A finding is only useful to your DPO if the people who produced it had no interest in the answer.
Professional indemnity insurance is held, and at the end of an engagement your evidence is returned to you in an open format within 90 days.
Security and due diligence questions are answered on the ConsentMark security page.
How we deliver
Every engagement follows a five-stage governance lifecycle. ConsentMark provides the evidence layer: automated scans, each kept as a record.
Regulated industries with complex digital properties
We work in sectors where a supervisory authority can ask what a website measures and expect a documented answer.
Every engagement is led by the founder. The work turns on technical detail and regulatory context at the same time, and on the judgement to say what a finding means for a compliance posture.
ConsentMark, our own scanning and monitoring platform, carries the measurement. It runs on a daily schedule, so the time goes on reading what a scan found rather than on collecting it.
The Governance Posture Call
The call runs 45 minutes and there is nothing to prepare. We use it to work out whether analytics governance is a priority for your organisation, and whether we are the people to do it.