The state of US exposure in European cookie-consent platforms, 2026
We verified 5 European consent management platforms against their published ownership records and infrastructure disclosures. 1 operates with no US exposure anywhere in the consent data path.
Of 5 European consent platforms, 1 is fully clear of US exposure
Consent management platforms exist for one reason: to document that a website processes personal data lawfully. That makes their own data path worth reading closely, and it is not as European as the category's branding suggests. We checked every consent platform in our directory against its published ownership records and infrastructure disclosures, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct).
| CLOUD Act exposure | Platforms |
|---|---|
| None | 1 |
| Minor | 2 |
| Material | 2 |
| Direct | 0 |
| Any exposure | 4 |
Every platform, and where the exposure enters
| Platform | Country | Ownership | Hosting | CLOUD Act exposure | Where it enters |
|---|---|---|---|---|---|
| ConsentManager | Germany | EU-owned | Germany | None | German-operated on its own European data centres rather than a hyperscaler; ISO 27001 certified, IAB TCF v2 CMP |
| Iubenda | Italy | EU-owned | Ireland | Minor | Parent Team.blue (Belgium) is European-controlled; the residual caution is disclosure, since a public sub-processor list and DPA URL are not surfaced |
| Didomi | France | EU-owned | France | Minor | Paris-based and funded by EU and French investors with no US parent identified; DPA and sub-processor list are not published openly |
| Cookiebot | Denmark | EU HQ, US-funded | Denmark | Material | Danish product on Danish infrastructure, but acquired by Usercentrics in 2022, whose own acquirer since 2024 is Vista Equity Partners (US private equity) |
| Usercentrics | Germany | EU HQ, US-funded | Germany | Material | Munich-operated and ISO 27001 certified, but acquired by Vista Equity Partners (US private equity) in 2024, together with its Cookiebot subsidiary |
The consolidation story is the category's defining fact. Usercentrics bought Cookiebot in 2022 and now runs much of the DACH consent market; Vista Equity Partners bought Usercentrics in 2024. Two of the most widely deployed European consent platforms therefore answer, through their ownership chain, to a US ultimate parent, while their operations, certifications and hosting remain German and Danish. Neither vendor hides this, but it rarely appears in the category's marketing.
The two French and Italian platforms in the middle of the table show a different pattern: European ownership with limited public disclosure. Both classify as minor rather than none because a verification that cannot read a published sub-processor list has to leave room for what it cannot see.
Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). One method note applies in this category: where a vendor does not publish its sub-processor list, we do not award the none classification, however European the rest of the picture looks. For consent platforms the data path we read is specific: where the banner script is served from, where consent logs are stored, and who ultimately owns the operator.
Sources are the vendors' own published documents: sub-processor lists where available, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; all listings with per-platform detail are on the cookie-consent category page.
The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference.
Frequently asked questions
- Which European cookie-consent platforms have no US sub-processors in 2026?
- Of the 5 European consent management platforms we verified, 1 operates with no US parent and no US layer in the consent data path: ConsentManager (Germany, CLOUD Act exposure None), which runs on its own European data centres. The full per-platform breakdown is in the table on this page.
- Does a consent banner itself send data to US infrastructure?
- It can. The banner script is served from somewhere, the consent logs that prove compliance are stored somewhere, and the vendor itself is owned by someone. Two of the best-known European consent platforms, Usercentrics and its Cookiebot subsidiary, have sat under a US private-equity parent since 2024, which places the consent records they hold under US extraterritorial reach as we classify it.
- How is this data verified and how often is it updated?
- Each platform is checked against its own published sub-processor list, DPA and ownership records, and re-verified quarterly. Figures on this page render live from the dataset, so they update when a re-verification changes a classification.
For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.