For the Chief Financial Officer

Own the disclosure. Defend the number.

Digital operations sit inside your Scope 3 line and inside your PECR/GDPR contingency, and most finance teams cannot substantiate either. Since 5 February 2026, the Data (Use and Access) Act applies UK GDPR-level fines directly to pre-consent tracking. Pipelit gives you one evidence base that satisfies both, priced in the currency you already report in.

PECR maximum fine £500,000 £17.5M / 4% global turnover DUAA 2025 · in force 5 Feb 2026

25-minute briefing. Bring your CSO, General Counsel, or Head of Investor Relations.

The problem finance owns

Three lines you cannot yet substantiate. Same root cause.

These are the disclosures your team is going to be asked to defend in 2026, and the exposures your General Counsel is quietly tracking. All three trace back to the same measurement gap.

Line in the disclosure
What auditors will ask
P&L / contingency
Scope 3, Cat. 1 & 8
CSRD ESRS E1
"Show us the source data for digital operations emissions. How did you calculate this, is the method reproducible? Is it fit for limited assurance?"
£0 measured today
most digital-first firms
Material Scope 1 / 2
SEC 2026
"Is any part of this material for financial statement disclosure? What is the expenditure impact on P&L or capex from remediation?"
Material threshold
judgement call, needs data
Environmental claims
UK SDR
"Every public sustainability claim must be substantiated. Can you evidence 'net zero digital operations' or similar language currently on the site?"
Reputational + FCA
no fixed cap
Legal contingency
PECR Reg. 6 · via DUAA 2025
"Pre-consent tracking is active enforcement, and since 5 February 2026 the DUAA applies UK GDPR-level fines to PECR directly — including tracking 'instigated' through a tag manager. What is the current stock of unlawful data collection on our public estate?"
£17.5M or 4% turnover
whichever higher · was £500k pre-Feb 2026
How Pipelit closes it

One measurement. Four disclosures.

Because the root cause is one event, digital assets running before consent, a single evidence base substantiates all four lines at once, in the format your auditor expects.

01 · Evidence

Raw, not modelled

Every figure is a real byte count from a real browser session, multiplied by the live grid intensity where the request landed. No industry averages, no estimation multipliers, auditor-defensible on the first read.

02 · Currency

Priced in GBP, USD, EUR

Every kilogram of CO2e comes with a currency figure your finance stack already understands: the operational cost of the wasted transfer, the enforcement exposure, and the remediation cost. One number for two boardrooms.

03 · Method

Open & reproducible

SWDM v4, published under CC-BY, with the calculation trail on every scan. An external assurance provider can rerun the entire figure with the same inputs, nothing about the calculation depends on trusting Pipelit.

In practice · evidence, not endorsement
Worked example · from the published Ghost Carbon Report
datadoghq.com · scanned across 3 engines
pre-consent payload 2,087 KB / visit · 19 critical findings
× 100,000 visits/mo floor × 12 → 240 kg CO2e/yr
at estimated real traffic (30M/mo) → ~72 t CO2e/yr
every step reproducible · SWDM v4 · CC-BY
Public finding from the Ghost Carbon Report (June 2026, 46 UK sites). Deliberately conservative: homepage only, UK IP only, 100k-visit floor. Rerun it yourself — the method is open.

What a typical enterprise scan surfaces, before a single line of code is touched.

0.0t
CO2e / year in pre-consent digital waste on the public estate, priced at £42k in operational spend.
0-0
Distinct trackers firing before consent on the homepage, giving a defensible PECR Reg. 6 breach point in most cases.
0
Configuration change, usually inside the tag manager, closes both.

Bring one URL to the briefing. Leave with a number your auditor can defend.