Cookie Reports
United Kingdom · cookiereports.com · 13 vendors
Resilience scores
- Digital Sovereignty: 15
- Digital Resilience: 3
- Financial Resilience: 6
Technology vendors
- Google LLC — Technology — United States
- Looker — Technology — United States
- Veeva Systems Inc. — Technology — United States
- and 11 more
Services catalogue
1 service in catalogue across 1 category; runs on 13 sub-vendors.
- Cookie Reports
Insights
Last updated 2026-08-14 · revision 2
13 direct vendors, 107 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 1
- United States: 7
- Canada: 1
Subvendors by controlling owner country (sample)
- Finland: 1
- Ireland: 1
- Sweden: 5
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Cookie Reports exhibits moderate migration readiness. A key challenge lies in the proprietary nature of its "Intelligent web scanning/crawling technology," whose underlying architecture (e.g., cloud-native, containerized, microservices) is not specified, making its migration complexity an unknown factor. The integration with "Veeva Vault PromoMats" represents a significant external dependency and potential vendor lock-in, which could complicate migration efforts. The absence of financial stability data (revenue concentration, growth history) also makes it difficult to assess the company's capacity to fund a substantial migration project. While the "Vendor Relationships" data states "Total Vendors: 0", this is contradicted by the Veeva integration, indicating at least one critical vendor relationship that requires careful management during any migration. Data residency requirements are also unspecified, potentially introducing unforeseen constraints. On the positive side, the company's deep expertise in regulatory compliance, as evidenced by its product offerings, is a significant asset. This internal capability is crucial for ensuring that any migration adheres to stringent compliance requirements, particularly for their highly regulated client base. The company website's use of WordPress is generally straightforward to migrate.
Compliance
8 in-scope frameworks identified; showing 3.
FDA 21 CFR Part 11 — Assessment Required
FDA 21 CFR Part 11 governs electronic records and electronic signatures in FDA-regulated industries. While DCR is a UK company and not directly subject to FDA regulation, its pharmaceutical clients (particularly US-operating ones like Alexion/AstraZeneca, Perrigo) may require DCR's platform to meet 21 CFR Part 11 requirements as part of their validated computer system infrastructure. GxP (Good Practice) guidelines from EMA and FDA require pharmaceutical companies to validate computerised systems used in regulated activities. If DCR's platform is used in GxP-regulated workflows, clients may require DCR to provide validation documentation (IQ/OQ/PQ). Risk is Medium because non-compliance with client validation requirements could result in contract loss or client regulatory findings.
Evidence: https://www.digitalcontrolroom.com/, https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11, https://www.ema.europa.eu/en/documents/scientific-guideline/annex-11-computerised-systems-eudralex-volume-4_en.pdf
GDPR (source) — Partially Compliant
Digital Control Room Limited (DCR) is a UK-based technology company that processes personal data of website visitors, clients, and potentially employees. As a SaaS/compliance platform provider serving pharmaceutical clients including global enterprises (AstraZeneca, Sanofi, Perrigo), DCR acts as both a data controller (for its own website and business operations) and potentially a data processor (for client data scanned through its platform). The UK GDPR and Data Protection Act 2018 apply fully. Risk is rated High because: (1) the privacy policy is notably sparse — it lacks explicit lawful bases for processing, no mention of Data Protection Officer (DPO), no data retention periods, no details on international data transfers, and no reference to UK ICO registration; (2) the company processes data for pharmaceutical clients who themselves handle sensitive health-adjacent data; (3) enforcement by the UK ICO has been active, with fines up to £17.5 million or 4% of global annual turnover; (4) the privacy policy was last modified May 2026 but remains thin on required disclosures. The gap between regulatory requirements and disclosed compliance measures elevates risk.
Evidence: https://www.digitalcontrolroom.com/privacy-policy/, https://www.digitalcontrolroom.com/legal-terms-conditions/, https://www.digitalcontrolroom.com/cookie-policy/, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/, https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted
ISO 27001 (source) — Assessment Required
ISO 27001 certification is not legally mandated but is a critical trust signal for technology companies serving regulated industries. DCR provides a platform that accesses client websites including password-protected HCP portals, meaning it handles potentially sensitive pharmaceutical and health-related digital content. Major pharmaceutical clients (AstraZeneca, Sanofi) typically require ISO 27001 certification from technology vendors as part of their information security vendor assessment processes. Risk is Medium because: (1) without ISO 27001, DCR may face challenges in enterprise procurement processes; (2) the company's security posture cannot be independently verified from public sources; (3) pharmaceutical industry vendor qualification processes (e.g., GxP vendor qualification) often require ISO 27001 or equivalent; (4) the King's Award for Enterprise Innovation suggests business credibility but does not address information security.
Evidence: https://www.digitalcontrolroom.com/privacy-policy/, https://www.iso.org/standard/27001, https://www.digitalcontrolroom.com/vulnerability-response-programme/
Financials
Financial Resilience Score: 6/10
Digital Control Room Limited (operating cookiereports.com) demonstrates qualitative signs of a resilient niche business, though specific financial figures are not publicly available in this research. The company serves a blue-chip pharmaceutical client base including AstraZeneca, Sanofi, Perrigo, and Alexion, which typically implies recurring enterprise SaaS-style revenue with high switching costs once integrated into regulated compliance workflows. External validation via The King's Awards for Enterprise: Innovation and long-tenured customer testimonials suggest an established business (likely 10+ years old) with sustained commercial traction. However, as a UK private limited company, financial visibility is limited. The company likely files under small or medium-sized company exemptions per FRS 102 Section 1A, which often omit turnover and profit disclosures. Key risks include customer concentration (a small number of large pharma clients likely drive disproportionate revenue), vertical concentration in pharma/life sciences, and potential substitution risk from larger platforms such as Veeva that could bundle competing compliance functionality. Access to growth capital for international expansion may also be constrained given SME scale. Overall, the qualitative signals point to a stable, defensible niche business benefiting from regulatory tailwinds (ABPI Code enforcement, FTC actions, DoJ False Claims Act settlements), but the lack of disclosed financials prevents a higher confidence score.
Key strengths: Blue-chip pharma client base (AstraZeneca, Sanofi, Perrigo, Alexion), Recurring enterprise SaaS-style revenue with high switching costs, Regulatory tailwind driving demand for compliance monitoring, Niche technical differentiation (HCP portal scanning, multilingual, image-embedded claims), King's Award for Enterprise Innovation recognition, Long-tenured customer relationships indicating strong retention
Risk factors: Customer concentration risk from small number of large pharma clients, Limited public financial disclosure as a UK SME, Regulatory/technology substitution risk from larger platforms like Veeva, Heavy vertical concentration in pharma/life sciences, Constrained access to capital for international expansion, Single-sector procurement freeze exposure
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.