Skip to content
CLOUD Act flagged on every listing
EU VETTED
INSIGHT

The state of US exposure in European cookie-consent platforms, 2026

We verified 5 European consent management platforms against their published ownership records and infrastructure disclosures. 1 operates with no US exposure anywhere in the consent data path.

By EU Vetted Editorial Published DISCLOSURE Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Of 5 European consent platforms, 1 is fully clear of US exposure

Consent management platforms exist for one reason: to document that a website processes personal data lawfully. That makes their own data path worth reading closely, and it is not as European as the category's branding suggests. We checked every consent platform in our directory against its published ownership records and infrastructure disclosures, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct).

CLOUD Act exposure Platforms
None 1
Minor 1
Material 3
Direct 0
Any exposure 4

Every platform, and where the exposure enters

Platform Country Ownership Hosting CLOUD Act exposure Where it enters
ConsentManager Germany EU-owned Germany None Public DPA names the whole chain and none of it is US-owned: Plusserver (Germany) and UpCloud (Finland) for data centres, DataCamp (UK) for the CDN; IAB TCF v2 CMP, and a subsidiary of Iubenda, the next row in this table
Iubenda Italy EU-owned Ireland Minor Parent Team.blue (Belgium) is European-controlled and the DPA is public and current, last updated 15 December 2025; the residual caution is disclosure, since the sub-processor list is available only on request
Didomi France EU-owned Not published Material Paris-based and funded by EU and French investors with no US parent identified, but its own French legal notice names Amazon Web Services LLC (Seattle) as the host and publishes no EU region; DPA and sub-processor list are not published openly
Cookiebot Denmark EU HQ, US-funded Ireland Material Danish operating entity that runs no infrastructure of its own: the DPA puts the consent databases on Microsoft Azure in Ireland and names Akamai (US) as the CDN serving the consent script, holding a database in the US. Merged with Usercentrics in September 2021
Usercentrics Germany EU HQ, US-funded Germany Material Munich-headquartered, ISO 27001 certified and SOC 2 Type 2 attested, but the DPA places the CMP on Google Cloud, with APIs and databases primarily in Frankfurt and Belgium under a US-owned hyperscaler

Consolidation is the category's defining fact, though not in the form we recorded last time. Usercentrics and Cybot, the maker of Cookiebot, merged in September 2021 and the group now runs much of the DACH consent market, while Iubenda lists ConsentManager as a subsidiary. Four of the five platforms in the table therefore sit under two groups rather than five independent vendors. We previously reported that Vista Equity Partners had acquired Usercentrics in 2024. That could not be substantiated on re-verification: Usercentrics' own about-us page describes the company as backed by venture investors including Full In Partners, ALSTIN and Cavalry Ventures, with €27.2M raised in total, and neither the imprint nor the commercial register (AG München HRB 241272) names a private-equity parent. We have withdrawn the claim.

The French and Italian platforms in the middle of the table start from the same place, European ownership with limited public disclosure, and end up in different bands. Iubenda classifies as minor because a verification that cannot read a published sub-processor list has to leave room for what it cannot see. Didomi classifies as material for a documented reason rather than an unread one: its own legal notice names a US-incorporated host.

Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). One method note applies in this category: where a vendor does not publish its sub-processor list, we do not award the none classification, however European the rest of the picture looks. For consent platforms the data path we read is specific: where the banner script is served from, where consent logs are stored, and who ultimately owns the operator.

Sources are the vendors' own published documents: sub-processor lists where available, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; all listings with per-platform detail are on the cookie-consent category page.

The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference.

Frequently asked questions

Which European cookie-consent platforms have no US sub-processors in 2026?
Of the 5 European consent management platforms we verified, 1 operates with no US parent and no US layer in the consent data path: ConsentManager (Germany, CLOUD Act exposure None), whose public DPA names its whole chain: Plusserver (Germany) and UpCloud (Finland) for data centres, DataCamp (United Kingdom) for the CDN, none of them US-owned. The full per-platform breakdown is in the table on this page.
Does a consent banner itself send data to US infrastructure?
It can. The banner script is served from somewhere, the consent logs that prove compliance are stored somewhere, and the vendor itself is owned by someone. Cookiebot's own DPA names Akamai Technologies, Inc. as the CDN that serves its consent script, with a database in the US, and puts the consent databases on Microsoft Azure in Ireland; Usercentrics' DPA names Google Cloud as the hosting sub-processor, with APIs and databases primarily in Frankfurt and Belgium. Both classify as material on our scale even though both operating companies are European.
How is this data verified and how often is it updated?
Each platform is checked against its own published sub-processor list, DPA and ownership records, and re-verified quarterly. Figures on this page render live from the dataset, so they update when a re-verification changes a classification.
METHODOLOGY

For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →