Privacy Scorecard Methodology
version 1.0 · status stable · updated 2026-06-08
The Privacy Scorecard grades data-collection tools on a single question: can this tool give an operator real insight without compromising the people it measures? A high grade is not a verdict that you should stop measuring — it identifies tools that respect consent, minimize data, and stay transparent. A low grade is not an accusation of illegality — it describes documented behavior that increases privacy and compliance risk and that an operator must actively manage.
This page is the canonical, versioned definition of how grades are produced. Every entry on the scorecard links back here.
The five dimensions
Each tool is scored 0–5 on five dimensions. 0 means hostile to privacy; 5 means exemplary.
- Data minimization — How little personal data the tool collects by default, and whether collection is opt-in and scoped to a purpose. Tools that ship collecting only aggregate, non-identifying data score high; tools that vacuum up granular event and identity data by default score low.
- Consent honoring — Whether the tool blocks or limits collection until consent is granted, and whether it respects Global Privacy Control (GPC) and browser consent-signal APIs. Tools that model or recover data when consent is denied score low here even if they offer a consent mode.
- Identifier strategy — Cookieless versus persistent identifiers; whether the tool fingerprints; whether its identifiers cross sites or feed an advertising graph. First-party, rotating, or no identifiers score high; cross-site identity resolution and device fingerprinting score low.
- Residency & sharing — Whether the operator can self-host or pin data to a region, who ultimately controls the data, and whether data is shared with third parties. Self-hostable or EU-pinned, processor-only tools score high; tools that act as controllers and share with an ad ecosystem score low.
- Transparency — Open source, clear documentation of exactly what is collected, a processor-vs-controller posture stated in the DPA, and disclosed sub-processors. Verifiable behavior scores high; opaque or undocumented behavior scores low.
Score and grade bands
The score is the sum of the five dimensions multiplied by four, giving a 0–100 scale:
score = (dataMinimization + consentHonoring + identifierStrategy
+ residencyControl + transparency) × 4
Grades are assigned by band:
| Grade | Score | Reading |
|---|---|---|
| A | 85–100 | Privacy-respecting by design; safe default choice for most teams. |
| B | 70–84 | Strong, with one or two caveats to configure. |
| C | 55–69 | Workable only with deliberate governance and consent gating. |
| D | 40–54 | High-risk; collects or shares more than most teams realize. |
| F | 0–39 | Built for surveillance/ad-tech outcomes; treat all collection as high-risk. |
Sourcing and defensibility
A public scorecard that says a tool collects data or sidesteps tracking prevention is only credible — and only legally safe — if every claim is documented and reproducible. The rules:
- Documented, reproducible criteria only. A grade may rest on (a) the vendor’s own documentation, DPA, or privacy policy; (b) a live ad.rip scan showing the actual requests, cookies, and parameters the tool sends; or (c) published, reputable third-party research. No grade rests on rumor or opinion.
- Per-entry sourcing. Every entry lists the sources behind its grade and carries a “verified on” date. Behavior changes; grades are re-scored when it does.
- Factual framing of circumvention. Where a tool can defeat tracking prevention, we describe the mechanism factually and by its accepted name — for example CNAME cloaking (first-party subdomain masking a third-party endpoint), server-side tagging (moving collection off the client so blockers can’t see it), or consent-denied modeling (statistically reconstructing conversions when consent is refused). We state what the technique does and what it means for a visitor. We do not assert that any vendor is acting illegally — lawfulness depends on the operator’s implementation, jurisdiction, and consent posture.
- Vendor right-to-respond. Any vendor may request a correction — the intake process documents what evidence is accepted and the response timeline. Substantiated corrections are applied and the verified date is updated; the change is noted in the newsletter. Disagreements that aren’t factual errors are recorded as such.
- Implementation caveat. Many tools’ privacy outcomes depend on how they’re deployed. Where that’s true (e.g., enterprise analytics), the entry says so explicitly and grades the default, documented behavior, not a hardened edge case.
Affiliate disclosure
Some privacy-respecting vendors that score well are also tools we may have an affiliate relationship with. Affiliate status never affects a grade. Any entry tied to an affiliate link is flagged on its page, and the directory marks affiliate links independently. Grades are set before, and independently of, any commercial relationship.
Relationship to ad.rip
The scorecard is the editorial layer; ad.rip is the evidence layer. Where an entry is backed by a scan, the entry links to the ad.rip audit so anyone can see the raw collection behavior rather than taking the grade on faith. This is also the honest version of the funnel: the grades are free and citable, and the live audit of your own site — or a deeper audit of a specific vendor — is the paid product.