CookieFirst
Netherlands · cookiefirst.com · 19 vendors
Resilience scores
- Digital Sovereignty: 53
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- SPF-Report.com — Cybersecurity — United States
- Stripe, Inc. — Financial Services — United States
- Tapfiliate — Technology — Netherlands
- and 16 more
Services catalogue
1 service in catalogue across 1 category; runs on 19 sub-vendors.
- CookieFirst
Insights
Last updated 2026-08-15 · revision 1
19 direct vendors, 209 subvendors
Direct vendors by controlling owner country (sample)
- Slovenia: 1
- United States: 8
- Bulgaria: 1
Subvendors by controlling owner country (sample)
- South Korea: 1
- Israel: 1
- Ireland: 3
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
CookieFirst exhibits medium migration readiness, scoring 55. The company benefits from a modern core technology stack, including React for its consent banner and REST APIs for integrations, and already leverages cloud infrastructure with OVH and a CDN (BunnyWay/BunnyCDN), including geo-replication and load balancing. This suggests a degree of architectural flexibility that could facilitate migration. However, several factors introduce significant challenges and uncertainties. A critical missing piece of information is "Data Residency Requirements," which can heavily influence migration strategies and available cloud providers. The "Vendor Lock-in Risk" is also unknown; with 23 services and vendors across 9 countries, understanding the contractual terms and ease of transitioning away from critical vendors is paramount. While vendor diversity aids resilience, managing a migration involving numerous distinct services and their respective integrations could be complex and resource-intensive. The extensive regulatory compliance (GDPR, CCPA, etc.) means any migration would need to meticulously ensure continued adherence, potentially increasing the scope and cost. Furthermore, the use of WordPress for the marketing website, while common, might require re-platforming if a full cloud-native migration is pursued. The absence of data on financial stability also means the company's capacity to fund a potentially large-scale migration is unknown. These unknowns and complexities place its migration readiness in the moderate range.
Compliance
8 in-scope frameworks identified; showing 3.
Dutch Telecommunications Act — Assessment Required
As a Netherlands-based company, CookieFirst is subject to the Dutch Telecommunicatiewet (implementing the ePrivacy Directive), enforced by the Autoriteit Consument & Markt (ACM). The ACM has been an active enforcer of cookie consent requirements in the Netherlands, issuing fines to major companies. CookieFirst's own website must comply with these requirements. Risk is Medium because: (1) ACM is an active enforcer; (2) CookieFirst's own website uses analytics and advertising cookies from US providers; (3) as a compliance tool provider, any non-compliance on its own site would be reputationally damaging; (4) no independent audit of CookieFirst's own Dutch cookie compliance has been found.
Evidence: https://cookiefirst.com/legal/cookie-declaration/, https://cookiefirst.com/legal/privacy-policy/
GDPR (source) — Partially Compliant
CookieFirst is headquartered in the Netherlands (EU), operates as both a data controller (for its own website/customers) and a data processor (processing end-user consent data on behalf of customers), and explicitly builds its entire product around GDPR compliance. Strong indicators of compliance exist: a named DPO (Tom van den Bos), a published privacy policy referencing GDPR Articles 6(1)(a)/(b)/(c), a Data Processing Agreement framework, EEA-only primary data storage, 72-hour breach notification procedures, and full data subject rights documentation. However, the status is 'Partially Compliant' rather than 'Compliant' because: (1) no independent third-party GDPR audit or certification has been publicly disclosed; (2) some sub-processors (Google, Microsoft, LinkedIn, Stripe) are US-based, creating ongoing Schrems II / Chapter V transfer risk that requires active SCCs/adequacy monitoring; (3) the privacy policy was last updated March 2023, predating some regulatory developments; (4) company size means formal DPIA documentation and Records of Processing Activities (RoPA) completeness cannot be externally verified. Risk is Medium rather than High because the company's core business is GDPR compliance tooling, creating strong reputational and commercial incentives for compliance, and the Dutch DPA (Autoriteit Persoonsgegevens) is an active enforcer.
Evidence: https://cookiefirst.com/legal/privacy-policy/, https://cookiefirst.com/legal/general-terms-conditions/, https://cookiefirst.com/dsar/, https://cookiefirst.com/cookie-consent-gdpr/, https://cookiefirst.com/vulnerability-reporting/
CPRA — Assessment Required
CookieFirst explicitly supports CCPA compliance as a product feature and serves US-based customers. As a Netherlands-based company, CCPA applies to CookieFirst only if it meets the thresholds: (1) annual gross revenue >$25M; (2) buys/sells/receives/shares personal information of 100,000+ California consumers/households annually; or (3) derives 50%+ of annual revenue from selling/sharing California consumers' personal information. CookieFirst's pricing (starting at €9/month) and SME profile suggest it likely does not meet the $25M revenue threshold. However, as a CMP processing consent data for potentially thousands of websites with California visitors, threshold (2) may be relevant. Risk is Low because: (1) company is Netherlands-based with Dutch law governing; (2) likely below revenue thresholds; (3) the company already has CCPA-oriented product features ('Don't sell my data' link on its own website); (4) enforcement against small EU-based SaaS providers is limited.
Evidence: https://cookiefirst.com/ccpa-compliance/, https://cookiefirst.com
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
CookieFirst (Digital Data Solutions B.V.) is a small Dutch privacy-tech SaaS company with no publicly disclosed financial figures. As a small/micro Dutch B.V., it is only required to file abridged balance sheets with the KVK, so revenue, EBIT and equity are not accessible via open sources. Qualitatively, the business model rests on recurring SaaS subscriptions (€9-€19/month plus Enterprise tier) supporting revenue visibility, and the company benefits from strong regulatory tailwinds from GDPR, CCPA, LGPD, Quebec Law 25, PDPA and Google Consent Mode v2 requirements. The company has secured enterprise-grade reference customers including Vogue, Aegon, Berenberg Bank, Amnesty International, the Swiss Army, Hyundai Ireland, InterContinental Hotels, Elsevier and Stena Line, providing credibility and sales traction. Google-certified CMP status and IAB TCF 2.2 support serve as important ecosystem qualifications that gate enterprise contracts. Most importantly, CookieFirst was acquired by iubenda in 2024/2025 (announced March 2026), which is itself part of team.blue group, ultimately owned by HgCapital. This M&A backing brings capital, distribution, cross-sell opportunities and product R&D scale, materially improving financial resilience. However, the competitive landscape is intense (Cookiebot, Usercentrics, OneTrust, Osano, CookieYes, Axeptio) with commoditization pressure at the low end, and there is some post-acquisition brand consolidation risk as iubenda has its own consent solution.
Key strengths: Recurring SaaS subscription revenue model with automatic renewal, Regulatory tailwinds from GDPR, CCPA, LGPD, Quebec Law 25, PDPA, Google-certified CMP and IAB TCF 2.2 support, Enterprise-grade reference customers (Vogue, Aegon, Hyundai, Amnesty International, Elsevier, Swiss Army), M&A backing by iubenda / team.blue group (HgCapital-owned), Reseller/affiliate channel with 30% commission structure, Product localization in 14+ languages
Risk factors: Highly competitive CMP category with larger, better-funded rivals (Cookiebot, Usercentrics, OneTrust), Commoditization pressure with entry-level pricing at €9/month, Regulatory dependency; browser-level consent signals (GPC) are long-term product risk, Concentration risk on Google ecosystem integrations, Limited public financial disclosure as small Dutch B.V., Post-acquisition integration risk with iubenda's overlapping consent solution
Revenue by geography
- Rest of World (Brazil, US, Canada, Thailand): 0%
- Europe (DACH-heavy, incl. Netherlands, Germany, UK, Switzerland, Sweden, Ireland, Italy): 0%
Revenue by product/service
- CookieFirst CMP Subscription (Free/Basic/Plus/Enterprise): 100%
Workforce by country
- Netherlands: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.