Didomi
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Cette fiche Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Paris-based enterprise CMP (founded 2017); ISO 27001, Google-certified CMP; clients include Volvo, Michelin, Yahoo.
Didomi propose un hébergement européen en France, mais une maison mère ou un sous-traitant américain laisse une exposition matérielle au CLOUD Act. Référencé dans la catégorie Consentement cookies.
Notes d’évaluation
Didomi SAS (137 Boulevard de Sébastopol, Paris FR, RCS Paris 831 722 756, founded 2017) is ISO/IEC 27001:2022 certified, a Google-certified CMP and an enterprise-grade platform (Volvo / Yahoo / Michelin / Lacoste / Rakuten), and its cap table remains European (Breega, Elaia, BPI France, Smartfin) with no identified US majority, so ownership_signal stays eu_owned. The infrastructure is a different story: Didomi's own French legal notice names its hébergeur as Amazon Web Services LLC, Seattle WA, United States, its trust centre states that data is hosted primarily at Amazon Web Services data centers, and both sdk.privacy-center.org (the SDK every visitor loads) and api.privacy-center.org (where consents are posted) resolve into AWS CloudFront. Core consent data therefore rests with a US-owned provider with no published EU region, which moves cloud_act_exposure from minor to material. No DPA is published and no sub-processor list is readable, which caps the score at 3.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Cette fiche Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
Autre Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- — non divulgué
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Non
-
Sous-traitants divulgués: Oui
-
Clients open source: Non
-
Certification tierce: Oui
Aller à
À propos de Didomi
Didomi (Paris, France, founded 2017) is an enterprise-grade Consent Management Platform with a strong roster of European brands: Volvo, Yahoo, Michelin, Lacoste, Rakuten. ISO 27001 certified, Google Certified CMP partner, IAPP Bronze Member. The platform covers consent collection, Preference Management, Privacy Request automation, Compliance Monitoring, and server-side tagging, broader than pure cookie-banner vendors. Cap table is mostly European (Breega, Elaia, BPI France, Smartfin), no US PE majority identified at time of research. Infrastructure is the counterweight: Didomi's French legal notice names its hébergeur as Amazon Web Services LLC (Seattle, WA, United States), the trust centre states data is hosted primarily at Amazon Web Services data centres, and both sdk.privacy-center.org (the SDK every visitor loads) and api.privacy-center.org (where consents are posted) resolve into AWS CloudFront, with no EU region published anywhere. Core consent data therefore rests with a US-owned provider, which is why exposure is recorded as Significative; no DPA is published and no sub-processor list is readable. Public pricing has also been withdrawn and buyers are routed to contact sales. For French and European procurement audiences Didomi is the broadest enterprise CMP in the catalogue on features rather than the cleanest on infrastructure.
Carte des sous-traitants · non divulgué
Référentiels & certifications
Matrice de fonctionnalités
Tableau 1Fonctionnalités de Didomi
Intégration & accès
Conformité & gouvernance
Documents publics
-
manquantContrat de sous-traitance (DPA)— manquant
-
OuvrirListe des sous-traitantstrust.didomi.io/subprocessors…
Alternatives dans cette catégorie
-
Allemagne · 23 €/moisSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Danemark · 7 €/moisHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
Italie · 5.99 €/moisBasé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Non Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
23 €/mois |
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
7 €/mois |
|
|
Basé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Non
Open source: Non
|
5.99 €/mois |