Consenter Risk Assessments

Privacy Badges

Understand how Consenter attributes the privacy+ and caution badge.

This work is licensed under CC BY-SA 4.0

This framework for attributing badges to third party service providers (TPP) is being constantly adapted according to the evolving state of technology, the changing legal framework, and most importantly, feedback from technology providers, experts and authorities. We want to keep the process as open as possible. If you disagree with parameters of our attribution framework, please let us know - either by contacting us directly or opening a new issue in our GitHub repository.

Badge Attribution

Criteria for Privacy+, No badge, and Caution attribution to third-party service providers | v2.2 — 31/08/2026

1. Badge model

Each third-party service provider is assigned one of three badges reflecting its default deployment risk — the privacy profile presented in a standard integration without special controller action.

BadgeMeaningDefault outcome?
✅ Privacy+Clearly privacy-friendly by design and by default. No red flags. Strong performance against tracking, profiling, and international transfer criteria. No own-purpose advertising or profiling.No — awarded only where all criteria are met
⬜ No badgeMixed or average risk profile. The service can be deployed compliantly through standard controller measures (including a consent banner that gates tracking until consent is given). This is also the default outcome where information is insufficient.Yes — default outcome
⚠️ CautionOne or more red flags present (RF1, RF3, or RF4), or elevated privacy risk indicators that cannot be resolved by standard controller measures. Requires heightened due diligence.No — requires specific findings

2. What constitutes normal tracking behaviour

The following behaviour does NOT, by itself, lead to a Caution badge:

Tracking or data collection that begins on page load before user consent has been obtained, where this behaviour can be fully resolved by deploying a standard consent banner (CMP) that gates the tool until consent is given.

This applies to analytics tools, session recording tools, heatmap tools, A/B testing tools, and any other tracking technology whose entire data collection can be switched off until the user grants consent. Because this issue is universal across virtually all third-party tracking tools and fully resolvable by standard controller measures (CMP integration), it does not alone constitute an elevated risk indicator warranting a Caution badge.

3. Attribution method — decision tree

Apply this sequence before consulting the aggregate score:

Step 1 — Red flags RF1, RF3, RF4

  • Any of RF1, RF3, or RF4 present? → Caution.
  • None present → continue to Step 2.

Step 2 — International transfer risk (RF2)

RF2 (high-risk third-country exposure) does not by itself lead to Caution. Where a lawful transfer mechanism exists — such as an EU adequacy decision, participation in the EU–US Data Privacy Framework (DPF), or Standard Contractual Clauses (SCCs) — GDPR treats the transfer as compliant and the risk is addressed through the domain E score rather than an automatic badge override.

RF2 is recorded where present and significantly lowers the domain E score:

Transfer situationDomain E score
Processing limited to EU/EEA or adequate jurisdictions; no meaningful government-access risk2
Some third-country exposure; lawful mechanism in place (DPF, SCCs); moderate access risk1
Transfer to high-risk third country (e.g. Russia, China) without any lawful mechanism or meaningful supplementary measures; or documented DPA enforcement finding that the specific transfer is unlawful0

A domain E score of 0 — combined with other low scores — may still result in Caution via the weighted-average or two-core-domain-zeros thresholds. It prevents Privacy+ in all cases.

Note: The presence of RF2 should always be disclosed in the reasoning and factored into the domain E score, even where it does not alone trigger Caution. Controllers must assess whether supplementary measures are adequate for the specific provider and deployment context.

Step 3 — Structural elevated-risk indicators

Are there concrete elevated privacy risk indicators that cannot be resolved by standard controller measures?

Indicators that may qualify (see Section 7 for full table):

  • Own-purpose data use (advertising, cross-service profiling, data brokering)
  • Problematic cross-publisher or cross-device profiling without adequate legal basis
  • Restrictive or manipulative consent mechanisms (dark patterns, forced consent)
  • Opaque onward data sharing with unnamed 'partners' for their own purposes

Indicators that do NOT qualify on their own (treated as normal — Section 2):

  • Tracking or session recording that fires before consent but is resolvable by a CMP
  • Cookies or persistent identifiers that are fully gatable via a consent banner
  • IP address collection forming part of normal web server operation
  • Third-country transfers covered by a lawful mechanism (DPF, SCCs, adequacy decision)
  • Concrete structural elevated-risk indicator present → Caution.
  • No structural elevated-risk indicator → continue to Step 4.

Step 4 — Domain B and E strength

  • Are domains B (tracking/profiling) and E (international transfers) both strong?
    • No → cannot receive Privacy+; go to Step 6.
    • Yes → continue to Step 5.

Step 5 — Overall profile

  • Is the provider's profile consistently high across core domains?
    • Yes → Privacy+.
    • No → continue to Step 6.

Step 6 — Default outcome

  • Mixed / average / configurable, no red flags (RF1/RF3/RF4), no unresolvable elevated risk → No badge (default).

4. Scoring model

Each domain is scored 0–2:

ScoreMeaning
2Privacy-friendly
1Mixed / average / configurable
0Elevated risk / poor privacy posture
DomainScoring questionWeight
A — Role & purpose limitationDoes the provider process strictly on the customer's behalf, or also for its own purposes?1.0×
B — Tracking, profiling & advertisingHow intrusive is the service's identifier, tracking, and profiling model? (See revised B guidance below)1.5×
C — Default settings & configurabilityAre privacy-friendly settings the default, or does compliance depend on active reconfiguration?1.0×
D — Minimisation, retention & deletionDoes the service limit collection and retention to what is necessary?1.0×
E — International transfers & gov. accessWhat is the provider's exposure to third-country transfers and access risks? (See RF2 guidance in Section 3)1.5×
F — Transparency & documentationCan the controller clearly understand and document the processing?1.0×
G — Data subject rights & consentCan the service be deployed in a way that respects consent and data subject rights?1.0×
H — Sub-processors & onward sharingIs the processing chain transparent, limited, and controlled?1.0×

Revised guidance for domain B (v2.1): A tool that records sessions or collects data before consent fires in its default configuration does NOT automatically score B = 0. B = 0 is reserved for structurally embedded non-essential tracking that cannot be effectively disabled by the controller — such as a retargeting DSP or DMP whose cross-publisher profiling is intrinsic to its function. A session recording or analytics tool that can be fully gated by a CMP scores B = 1 at minimum.

5. Attribution thresholds

✅ Privacy+ — all of the following must hold:

  • No red flags (RF1, RF3, RF4)
  • No RF2 (or if RF2 present: E must still score 2, which requires an adequacy decision or equivalent strong mitigation — in practice this means no RF2 can coexist with E = 2)
  • B ≥ 1
  • C = 2
  • E = 2
  • Weighted average score ≥ 1.4
  • No domain scored 0 in A, B, C, D or E

⚠️ Caution — any one of the following triggers it:

  • RF1 present (own advertising or cross-service profiling)
  • RF3 present (broad onward sharing for others' own purposes)
  • RF4 present (significant opacity)
  • Weighted average < 0.9
  • Two or more core domains (A–E) score 0
  • Concrete elevated-risk pattern present that is NOT resolvable by standard controller measures (e.g. own-purpose advertising use, cross-publisher profiling structural to the tool's business model, opaque onward sharing)

RF2 alone does not trigger Caution. Where a lawful transfer mechanism exists (adequacy decision, DPF, SCCs), GDPR treats the transfer as compliant. RF2 is reflected in a lower domain E score (E = 1 for standard DPF/SCCs; E = 0 for transfers to high-risk countries without any lawful mechanism), which reduces the weighted average and prevents Privacy+, but does not by itself result in Caution.

Not Caution on its own: tracking that fires before consent but is fully resolvable by deploying a CMP. This is treated as normal tracking behaviour (Section 2).

⬜ No badge — default:

  • No red flags (RF1, RF3, RF4) — RF2 may be present
  • Privacy+ threshold not met
  • Overall picture is mixed / average / configurable
  • All elevated-risk indicators, if any, are resolvable by standard controller measures

6. Red flags

RF1, RF3, and RF4 are hard overrides: any one present results directly in Caution. RF2 is a significant risk factor that is reflected in the domain E score but does not alone override the badge.

Red flagDefinitionEffect on badge
RF1 — Own advertising or cross-service profilingThe provider uses personal data FOR ITS OWN advertising, retargeting, audience building, or cross-service profiling, especially across unrelated customer contexts.Hard override → Caution
RF2 — High-risk third-country exposurePersonal data is processed in, accessed from, or exposed to a high-risk third country. Assessed against: whether a lawful transfer mechanism exists (adequacy decision, DPF, SCCs) and whether supplementary measures are meaningful.Significant E-score reduction; does NOT alone trigger Caution
RF3 — Broad onward sharing for others' own purposesThe privacy terms allow data sharing with 'partners', 'affiliates', or ecosystem participants for their own purposes (analytics, advertising, enrichment), making purpose limitation and controller oversight materially harder.Hard override → Caution
RF4 — Significant opacityThe provider does not disclose sufficient information on purposes, tracking technologies, transfer destinations, sub-processors, or retention periods to allow a controller to meaningfully assess compliance.Hard override → Caution

7. Elevated risk indicators (non-red-flag)

Where no formal red flag (RF1, RF3, RF4) is triggered, the following indicators may still support a Caution badge — but only if the risk is structural (inherent to the tool's business model and not addressable by controller configuration).

Indicator→ Caution if...→ NOT Caution if...
Own-purpose data useProvider uses visitor data for its own commercial analytics, data products, or advertising — not controllable by the deploying controllerProvider uses only aggregated/anonymised data for service improvement, with controller ability to opt out
Intrusive trackingTracking is structurally embedded and cannot be disabled without removing the tool (e.g. cross-publisher identity graph intrinsic to the product)Tracking fires before consent by default but is FULLY blockable by a CMP — this is NORMAL and does not lead to Caution
Problematic profilingCross-publisher or cross-device profiling without a clear legal basis, structural to the tool's functionOn-site behavioural analysis (session recording, heatmaps) scoped to the controller's own domain and fully gatable by a CMP
Manipulative consent mechanismsDark patterns, forced consent, or mechanisms that structurally undermine user choiceStandard consent flow configurable to be GDPR-compliant by the controller
Opaque onward sharingBroad sharing with unnamed 'partners' or 'affiliates' for their own purposes without meaningful transparencyNamed, disclosed sub-processors processing on the controller's behalf under DPA/SCCs
High-risk international transfersTransfer to a high-risk third country without any lawful mechanism, AND no meaningful supplementary measures; or a specific DPA enforcement finding that this provider's transfers are unlawfulTransfer covered by DPF, SCCs, or adequacy decision — reflected in domain E score (E = 0 or 1) but does not alone result in Caution

8. Domain scoring guidance

Full scoring criteria per domain. Consult the provider's privacy policy, DPA, Terms of Service, and supervisory authority decisions.

Domain B — Tracking, profiling, and advertising (revised v2.1)

ScoreCriteria
2No non-essential tracking in default EU deployment. No behavioural profiling. No advertising or ad-tech components. Analytics, if present, is aggregate or strongly minimised.
1Uses identifiers (cookies, SDKs) but these can be disabled or withheld without disproportionate effort — including by deploying a CMP. Limited profiling for product analytics only. Configurable and not inherently incompatible with compliant deployment. Includes tools that record sessions or fire tracking by default, where the tool can be fully blocked by a CMP until consent is obtained.
0Non-essential tracking is structurally embedded and cannot be effectively disabled by the controller. Cross-site or cross-service tracking intrinsic to the tool's function (e.g. retargeting DSP, DMP with cross-publisher profile building). Advertising functionality is structurally embedded and not separable. Note: a tool that tracks before consent but can be gated by a CMP does NOT score B = 0.

Domain E — International transfers and government access (revised v2.2)

ScoreCriteria
2Processing limited to EU/EEA or adequate jurisdictions (Art. 45 GDPR adequacy decision); or transfers are exceptional, well-controlled, and supported by strong technical safeguards. No meaningful government-access risk from a high-risk third country.
1Some exposure to the US or another third country. Lawful transfer mechanism in place (DPF, SCCs). Supplementary safeguards exist but are not particularly strong. Overall risk is moderate but not clearly severe. This is the typical score for standard US-based SaaS with DPF/SCCs.
0Transfer to a high-risk third country (e.g. Russia, China) without any lawful transfer mechanism or meaningful supplementary measures; or a DPA enforcement finding that specifically declares this provider's transfers unlawful. Reliance on contractual safeguards alone where technical measures are clearly required.

Domains A, C, D, F, G, H: scoring criteria unchanged from v1 — see the Consenter Manager Badge Attribution assessment tool (Google Apps Script) for full domain-level scoring rubrics.


Consenter Manager | v2.2 — 31/08/2026 |

Shape Consenter Together

Consenter is built on an open and participatory process that grows through community collaboration. Whether you share feedback, improve the documentation, or contribute to the Risk Configuration Guides or Technical Integration Guides, your expertise helps make Consenter more privacy-friendly, interoperable, and useful for everyone—including your own users and services: Get finally your benefits and control the risks when sharing personal data.

Last updated on

On this page