Cookie Information ApS

Denmark · owned by Independent (Denmark) · cookieinformation.com · 21 vendors

Cookie Information is a Danish company that provides a Consent Management Platform (CMP) designed to help businesses achieve cookie compliance with GDPR, ePrivacy, and other data privacy regulations. Their platform enables marketers and website owners to manage user consent for cookies and tracking technologies in a compliant and user-friendly way. They offer tools for cookie scanning, consent collection, and reporting across websites and apps.

Resilience scores

Disruption prediction

Cookie Information ApS has an estimated 11% probability of disruption in the next 6 months.

11 of Cookie Information ApS's 21 vendors monitored for disruptions.

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 21 sub-vendors.

Insights

Last updated 2026-09-13 · revision 3

21 direct vendors, 291 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Cookie Information ApS exhibits a high level of migration readiness, primarily driven by its highly modern and cloud-native internal tech stack. The use of AWS, Docker, Kubernetes, Node.js, and Terraform signifies an architecture that is inherently portable, containerized, and managed with infrastructure-as-code principles. This significantly reduces technical barriers and complexity for potential migrations. Their deep expertise in navigating complex data privacy regulations like GDPR and ePrivacy, central to their product offerings, is a substantial advantage for managing compliance requirements during any migration, especially concerning data residency and cross-border data flows. The main challenges to migration readiness stem from the missing financial data, which makes it impossible to assess the company's capacity to fund a significant migration effort. 'Data Residency Requirements' are not specified, which could introduce unknown complexities if strict rules are discovered. The ambiguity surrounding 'Total Vendors: 0' versus 'Total Services: 32' and 'Vendor Lock-in Risk: Unknown' prevents a precise assessment of vendor-related migration challenges, although the cloud-native nature of their stack generally suggests lower inherent lock-in compared to legacy systems.

Compliance

5 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applicability depends on whether Cookie Information qualifies as a digital service provider or ICT service management entity under the directive. If they provide consent management platforms or privacy technology services that qualify as digital services, and meet the size threshold (50+ employees or €10M+ turnover), NIS2 would apply. Medium risk as technology companies often fall under NIS2 scope, but specific classification needs verification.

ISO 27001 (source) — Assessment Required

ISO 27001 is highly relevant for technology companies handling personal data and providing privacy-related services. For a consent management provider, information security management is crucial for maintaining customer trust and protecting processed data. Medium risk as it's often required by enterprise customers and supports GDPR compliance efforts.

ISAE 3000 (source) — Assessment Required

ISAE 3000 applies to assurance services and reporting. Relevance depends on whether Cookie Information provides assurance services or requires third-party assurance reporting for their privacy/consent management services. Low risk as it's typically not a primary regulatory requirement for technology service providers.

Financials

Three-year financials

Financial Resilience Score: 6/10

Cookie Information ApS operates in a regulation-driven market where demand for Consent Management Platforms (CMPs) is largely non-discretionary due to GDPR, ePrivacy, the Danish Data Protection Act, the EU Digital Services Act, and Google Consent Mode v2 requirements. This regulatory tailwind provides a structural demand floor, and the SaaS subscription model typically delivers recurring revenue with high gross margins (commonly 70-85% among CMP peers). The company reportedly received growth-equity backing from Verdane in 2022, which likely strengthened its balance sheet and supported international expansion. However, the company faces intense competition from much larger players including OneTrust (multi-billion USD valuation), Usercentrics/Cookiebot (post-merger), and Didomi, creating pricing pressure. As a small private ApS with limited public transparency, it likely has customer concentration in the EU/Nordic region and may depend on a few large enterprise contracts. Regulatory dependency is double-edged: softening enforcement or browser-native consent controls (e.g., Global Privacy Control) could erode demand. FX exposure between DKK costs and EUR/GBP/USD revenue adds additional risk. Without access to filed annual reports, a precise quantitative resilience assessment is not possible.

Key strengths: Regulation-driven, non-discretionary demand (GDPR, ePrivacy, DSA, Google Consent Mode v2), Recurring SaaS subscription revenue model with typically high gross margins, Growth-equity backing from Verdane (reported 2022), Strong brand recognition in Nordic market, European data-sovereignty positioning differentiates vs. US competitors

Risk factors: Intense competition from larger players (OneTrust, Usercentrics/Cookiebot, Didomi) creating pricing pressure, Geographic concentration in EU/Nordics, Regulatory dependency — softening enforcement or browser-native consent could erode demand, Small private ApS with limited public transparency and potential customer concentration, FX exposure (DKK costs vs. EUR/GBP/USD revenue)

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report