Methodology · version 4.1 · June 2026

The method, in the open.

Every Pipelit figure, the compliance grade, the carbon number, the pound figure, is produced by a method you can rerun, audit, and challenge. Published under CC-BY.

01 · Principles

Pipelit is built on four principles that determine every design choice we make.

  • Measured, not modelled. Every figure begins as a real byte count in a real browser session. No industry averages, no estimation multipliers.
  • Reproducible from the source. Anyone with the raw inputs and the published method should reach the same number we do.
  • Actionable, not just descriptive. Every finding is a remediation, not a rating. Reduction is the outcome.
  • Open licence, external review. Method and dataset published under CC-BY. Any qualified external assurance provider can independently verify the calculation.

02 · What we measure

Pipelit measures bytes moved by trackers firing before the user has been given a lawful basis to accept them, that is, before an active consent event under PECR Reg. 6 and GDPR Art. 6.

We do not measure legitimate page content, images that render the user experience, or scripts that fire only after consent is granted. Only the pre-consent tracker payload is inside scope. This keeps the figure conservative and defensible: it is the waste no framework currently captures and no reasonable interpretation would justify.

Inside scope Pre-consent third-party requests: analytics, ad tech, session replay, tag manager scripts firing before a consent event, first-party trackers that set identifiers before consent.
Outside scope Post-consent analytics, first-party page content, images, fonts, essential scripts, service workers, functional cookies with legitimate interest legal basis correctly established.

03 · Measurement

Each scan runs the target URL in three real browser engines, Chromium, Gecko (Firefox), and WebKit (Safari), because tracker behaviour differs materially by engine.

Every network request is captured at the browser level with its full timing, byte count, origin, and cookies set. Requests are classified by an updated Disconnect / EasyList taxonomy to identify tracker categories, then filtered to include only those firing before an active consent event.

  • Sample size: a single scan captures roughly 1,200 request events across three engines.
  • Classification: tracker taxonomy is refreshed weekly and versioned; every finding cites the taxonomy version.
  • Consent detection: the scanner treats the visitor as a first-time visitor with no prior consent record.

04 · Emissions calculation

We apply the Sustainable Web Design Model v4 (SWDM v4) to convert measured bytes into kWh, then multiply by the live grid intensity at the visitor's jurisdiction.

carbon / visit =
  pre-consent bytes (GB)
  × 0.194 kWh/GB  // SWDM v4 operational energy intensity
  × grid intensity (gCO2e/kWh)  // Open Grid, live per jurisdiction

Operational emissions only. Embodied emissions are excluded from the visit-level figure because they are fixed and unaffected by the calculation's key variable (which trackers run, on which grid). Embodied emissions of the infrastructure are handled separately in the Scope 3 Category 8 line, not this one.

05 · Grid intensity

Grid intensity comes from the Open Grid, a per-jurisdiction feed published under CC-BY.

  • UK: live, sourced from the National Energy System Operator (NESO).
  • EU-27: Q3 2026, sourced from ENTSO-E Transparency Platform.
  • US: Q4 2026, sourced from EIA-930 hourly data by balancing authority.
  • Australia, Canada, Ireland: phased through 2026, AEMO, IESO, EirGrid respectively.

Intensity is captured at the second the scan runs, and every result records the timestamp and source so the calculation is fully reproducible.

06 · Compliance layer

Each pre-consent tracker is scored against three jurisdictions and returned with a specific citation. This gives the CFO and General Counsel a defensible line, and gives the developer a specific remediation.

  • UK PECR Reg. 6: requires user consent before storage or access on the user's terminal equipment. Firing before consent is a breach.
  • EU GDPR Art. 6: requires a valid lawful basis for processing. Absent consent, no other basis reasonably applies to marketing trackers.
  • US CCPA / CPRA: where a tracker sells or shares personal information, the "Do Not Sell" signal must be respected before firing.

07 · Assurance

Every scan produces a two-part evidence package designed for a limited assurance engagement.

  • Report (PDF): the figure, method version, calculation trail, grid intensity used at measurement time, and jurisdictional compliance summary.
  • Raw dataset (CSV/JSON): every request captured, byte count, tracker classification, cookies set, timings across all three engines, and the grid intensity at capture.

Because the method is open, an external assurance provider can independently rerun the entire figure with the same inputs. Nothing about the calculation depends on trusting Pipelit.

08 · Licence & contact

The methodology and Open Grid feeds are published under Creative Commons Attribution 4.0 International (CC-BY 4.0). You may use, redistribute, and build on them, provided you cite the source.

UK grid intensity is sourced live from the National Energy System Operator (NESO). Every intensity figure carries its timestamp and source so external assurance providers can independently verify each calculation.

Contact the research team Questions about the methodology, requests for the raw datasets, or research collaboration, research@pipelit.co.uk

See the method in action. Scan a URL.