Dacoda
Sweden · www.dacoda.com · 5 vendors
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- CookieHub — Cybersecurity — Iceland
- Google LLC — Technology — United States
- Help Scout — Technology — United States
- and 2 more
Services catalogue
1 service in catalogue across 1 category; runs on 5 sub-vendors.
- Email Service
Insights
Last updated 2026-08-03 · revision 2
5 direct vendors, 114 subvendors
Direct vendors by controlling owner country (sample)
- United States: 3
- Denmark: 1
- Iceland: 1
Subvendors by controlling owner country (sample)
- Spain: 1
- United Kingdom: 4
- France: 3
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Dacoda exhibits a very high degree of migration readiness. The company's internal tech stack, featuring modern technologies like Next.js, React, Node.js, and a Headless CMS (Prismic), is inherently modular and cloud-native friendly. This architecture significantly eases the process of migrating to cloud environments or refactoring services into microservices. The most significant advantage for migration readiness is the reported 'Total Vendors: 0', indicating a complete absence of direct vendor lock-in. This drastically simplifies potential migration efforts by removing dependencies on specific vendor contracts, proprietary technologies, or complex exit clauses. Dacoda's strong expertise in GDPR, IAB TCF 2.3, and Google Consent Mode V2 also positions it well to navigate and ensure compliance with regulatory requirements during any migration process. While 'Vendor HQ Countries' and 'Vendor Geographic Diversity' are noted for 6 services, implying reliance on technologies originating from diverse regions (United States, Denmark, Iceland), the lack of direct vendor relationships reduces contractual complexity during migration. The main unknowns are specific data residency requirements, which could introduce complexity if strict rules apply, and financial stability data, which would confirm the ability to fund a significant migration project. However, the overwhelming strengths in technology and vendor independence make Dacoda highly prepared for migration.
Compliance
6 in-scope frameworks identified; showing 3.
Icelandic Consumer Protection Act — Assessment Required
Risk is Low because Dacoda is primarily a B2B software development company. Consumer protection obligations are more relevant to the e-commerce platforms Dacoda builds for clients than to Dacoda's own direct services. However, to the extent Dacoda offers any direct consumer-facing services, consumer protection rules would apply.
Evidence: https://www.dacoda.is/thjonusta/netverslanir, https://www.neytendastofa.is/
GDPR (source) — Assessment Required
GDPR risk is inherently high for any EEA-based company processing personal data. Dacoda is a software and digital solutions company headquartered in Iceland (an EEA member state), and explicitly references Icelandic Act No. 90/2018 (the national implementation of GDPR) in its privacy policy. As a software developer building booking engines, e-commerce platforms, service portals, and mobile apps for clients including a pension fund (Festa), an aviation authority (Isavia), and a fuel company (Olís), Dacoda almost certainly processes personal data both as a data controller (employee data, website visitor data, contact form submissions) and as a data processor on behalf of clients. Non-compliance penalties can reach €20M or 4% of global annual turnover. The risk level is High due to: (1) confirmed EEA jurisdiction, (2) confirmed personal data processing, (3) role as both controller and processor for client systems, (4) no publicly visible DPO appointment or formal GDPR compliance documentation beyond a basic privacy notice, and (5) the privacy policy is minimal and does not address all GDPR Article 13/14 requirements.
Evidence: https://www.dacoda.is/personuverndarstefna, https://www.althingi.is/lagas/nuna/2018090.html, https://www.personuvernd.is/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Icelandic Electronic Commerce Act — Assessment Required
Risk is Medium because Dacoda builds and operates e-commerce platforms and online service portals for clients, and as a provider of information society services itself (website, webmail, client portals), it must comply with Iceland's Electronic Commerce Act. Non-compliance could result in regulatory action by the Consumer Agency (Neytendastofa) or civil liability. The risk is moderated by the fact that Dacoda is primarily a B2B service provider rather than a direct consumer-facing e-commerce operator.
Evidence: https://www.dacoda.is/thjonusta/netverslanir, https://www.althingi.is/lagas/nuna/2002030.html
Financials
Financial Resilience Score: 6/10
Dacoda ehf. demonstrates qualitative resilience through its long operating history of over 22 years, having survived multiple economic shocks including the 2008 Icelandic banking crisis and the COVID-19 pandemic. The company maintains a blue-chip Icelandic client base including Isavia (state-owned airport operator), Olís, Festa pension fund, and major tourism/car-rental players, providing relatively stable revenue anchors. Its diversified service portfolio spanning booking systems, e-commerce, custom software, and integration work reduces dependency on any single product line, while a small, senior team of approximately 10-11 employees implies a lean cost base. However, significant risks temper this assessment. The company operates in Iceland's small domestic market (~390,000 inhabitants), capping organic growth potential. Client concentration risk is material given the small team size, and heavy exposure to Icelandic inbound tourism through clients like Blue Car Rental, Zero Car Rental, Nordic Visitor, Duty Free, and Isavia creates cyclical vulnerability. Additional pressures include tight Icelandic developer talent competition driving wage inflation, and ISK currency volatility affecting foreign-denominated tooling costs. No specific financial figures (revenue, EBIT, equity) were available as they sit behind paid Icelandic registries (Keldan.is, Creditinfo Iceland, Skatturinn ársreikningaskrá).
Key strengths: Long operating history of 22+ years surviving 2008 crisis and COVID-19, Blue-chip client base including Isavia, Olís, and Festa pension fund, Diversified service portfolio across booking, e-commerce, custom software, and integration, Lean team of ~10-11 senior staff implying low fixed cost base
Risk factors: Small Icelandic domestic market (~390,000 population) caps growth, Client concentration risk with only ~11 employees serving few large clients, Heavy exposure to cyclical Icelandic inbound tourism sector, Talent competition and wage inflation in tight Icelandic developer market, ISK currency volatility affecting foreign-denominated costs
Revenue by geography
- Iceland: 100%
Workforce by country
- Iceland: 11
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.