Didomi
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Paris-based enterprise CMP (founded 2017); ISO 27001, Google-certified CMP; clients include Volvo, Michelin, Yahoo.
Didomi offers EU hosting in France, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Cookie consent.
Assessment notes
Didomi SAS (137 Boulevard de Sébastopol, Paris FR, RCS Paris 831 722 756, founded 2017) is ISO/IEC 27001:2022 certified, a Google-certified CMP and an enterprise-grade platform (Volvo / Yahoo / Michelin / Lacoste / Rakuten), and its cap table remains European (Breega, Elaia, BPI France, Smartfin) with no identified US majority, so ownership_signal stays eu_owned. The infrastructure is a different story: Didomi's own French legal notice names its hébergeur as Amazon Web Services LLC, Seattle WA, United States, its trust centre states that data is hosted primarily at Amazon Web Services data centers, and both sdk.privacy-center.org (the SDK every visitor loads) and api.privacy-center.org (where consents are posted) resolve into AWS CloudFront. Core consent data therefore rests with a US-owned provider with no published EU region, which moves cloud_act_exposure from minor to material. No DPA is published and no sub-processor list is readable, which caps the score at 3.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Didomi
Didomi (Paris, France, founded 2017) is an enterprise-grade Consent Management Platform with a strong roster of European brands: Volvo, Yahoo, Michelin, Lacoste, Rakuten. ISO 27001 certified, Google Certified CMP partner, IAPP Bronze Member. The platform covers consent collection, Preference Management, Privacy Request automation, Compliance Monitoring, and server-side tagging, broader than pure cookie-banner vendors. Cap table is mostly European (Breega, Elaia, BPI France, Smartfin), no US PE majority identified at time of research. Infrastructure is the counterweight: Didomi's French legal notice names its hébergeur as Amazon Web Services LLC (Seattle, WA, United States), the trust centre states data is hosted primarily at Amazon Web Services data centres, and both sdk.privacy-center.org (the SDK every visitor loads) and api.privacy-center.org (where consents are posted) resolve into AWS CloudFront, with no EU region published anywhere. Core consent data therefore rests with a US-owned provider, which is why exposure is recorded as Material; no DPA is published and no sub-processor list is readable. Public pricing has also been withdrawn and buyers are routed to contact sales. For French and European procurement audiences Didomi is the broadest enterprise CMP in the catalogue on features rather than the cleanest on infrastructure.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Didomi
Integration & access
Compliance & governance
Public documents
-
missingData Processing Addendum (DPA)— missing
-
OpenSub-processors listtrust.didomi.io/subprocessors…
Alternatives in this category
-
Germany · €23/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Denmark · €7/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Italy · €5.99/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€23/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€7/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€5.99/mo |