Iubenda
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Italian privacy-compliance toolkit (Milan, est. 2011); 150K+ customers; subject to direction of Team.blue NV (Belgium); now also the parent of consentmanager.
Iubenda is a European service hosted in Ireland, with at most minor, transient US exposure under the CLOUD Act. It is listed under Cookie consent.
Assessment notes
Iubenda s.r.l. (Via San Raffaele 1, Milan IT, founded 2011) carries an ISO/IEC 27001 certification mark, is IAB TCF validated (CMP ID 123) and a Google-certified CMP, and is part of the team.blue group (Ghent, Belgium), backed as of the last cap-table check by Hg Capital (UK) and CPP Investments (Canada) with no US PE majority; ownership_signal eu_owned. Decisively for a consent platform, the script every visitor loads is served from an EU-owned CDN — cdn.iubenda.com and cs.iubenda.com both resolve to bunny.net (BunnyWay d.o.o., Slovenia) — and the DPA commits that all data processing activities carried out by the Processor shall be executed within the territories of the European Union / European Economic Area. The DPA is public and current (last updated 15 December 2025); the remaining gap is that the sub-processor list is available only on request, so sub_processors_url stays null and the score is capped below 5. iubenda is now also the parent of consentmanager, which it lists as a subsidiary.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Iubenda
Iubenda (Milan, Italy, founded 2011) is a 15-year-old privacy-compliance toolkit covering cookie consent, privacy policy generator, terms generator, accessibility widget, and advanced compliance solutions. It has 150,000+ customers across 400,000+ sites and apps. In-house legal team monitors regulations and updates the templates accordingly. Google-certified CMP partner, IAB TCF 2.2 validated, ISO 27001 aligned. Parent company is Team.blue NV (Ghent, Belgium), a European hosting and SaaS consolidator backed, as of the last confirmed cap-table check, by Hg Capital (UK) and CPP Investments (Canada Pension); team.blue's own about-us discloses no shareholders, so that position is carried forward rather than re-verified, and no material US private-equity majority is on record. Iubenda is now also the parent of consentmanager, which its imprint lists as a subsidiary, so two of the five listings in this category share an owner and should not be read as independent picks. For procurement buyers Iubenda remains one of the cleanest cookie-consent options in the catalogue: an EU-owned chain running from Milan to Ghent, a public and current DPA, and a consent script served from an EU-owned CDN. The remaining gap is that the sub-processor list is available only on request.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Iubenda
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
OpenData Processing Addendum (DPA)www.iubenda.com/terms-and-conditions…
-
missingSub-processors list— missing
Alternatives in this category
-
Germany · €23/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Denmark · €7/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€23/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€7/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
— |