Cookiebot
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Danish cookie consent (est. 2012, operated by Usercentrics A/S); ISO 27001 + ISO 27701 + SOC 2 Type 2; merged with Usercentrics in September 2021; CMP runs on Microsoft Azure Ireland.
Cookiebot offers EU hosting in Ireland, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Cookie consent.
Assessment notes
Cookiebot is operated by Usercentrics A/S (Havnegade 39, Copenhagen DK, CVR DK34624607 — the renamed Cybot A/S, following the September 2021 Usercentrics/Cybot merger), ISO 27001 + ISO 27701 certified and SOC 2 Type 2 attested since August 2025. It runs no infrastructure of its own: Annex 2 of the publicly readable DPA puts the consent databases in Microsoft Azure, Ireland (Microsoft Ireland Operations Ltd, hot fail-over to Amsterdam) and names Akamai Technologies, Inc. (Cambridge MA, US) as the CDN that serves the consent script, holding a database in the US; the EU CDN alternative (BunnyWay, SI) applies only to customers who actively select it. Two US-owned processors therefore sit in the path of every consent event, so cloud_act_exposure stays material. The previously recorded Vista Equity Partners acquisition of the group could not be substantiated on re-verification — see verification_notes.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded This listing EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Cookiebot
Cookiebot (operated by Usercentrics A/S, Havnegade 39, Copenhagen, CVR DK34624607, the renamed Cybot A/S, founded 2012) is one of the largest consent management platforms in Europe: 2.4M websites, 8.8B monthly consents, 600K+ customers, Google-certified Gold-tier CMP partner, ISO 27001 + ISO 27701 certified and SOC 2 Type 2 attested since August 2025. Cybot and Usercentrics merged in September 2021. A Vista Equity Partners acquisition of the group was recorded on this listing in May 2026 and could not be substantiated on re-verification: Usercentrics' own about-us page describes the company as backed by venture investors (Full In Partners, ALSTIN, Cavalry Ventures) against total funding of €27.2M, and neither imprint nor the Handelsregister record (AG München HRB 241272) names a private-equity parent. This listing therefore asserts no acquirer and records ownership as EU HQ, US-funded, a flag that still needs a paid-database check of the cap table. The procurement-grade caveat is infrastructure rather than ownership: Cookiebot runs no Danish infrastructure of its own, its DPA states the group does not operate its own server resources, and Annex 2 puts the consent databases on Microsoft Azure in Ireland with hot fail-over to Amsterdam. The consent script every visitor loads is served by Akamai Technologies, Inc. (Cambridge, MA), whose Annex 2 entry records a database in the US, and the EU CDN alternative (BunnyWay, Slovenia) applies only to customers who actively select it. For a CMP the script path is the whole product, which is why exposure is recorded as Material.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Cookiebot
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Germany · €23/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
-
Italy · €5.99/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€23/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€5.99/mo |