Datawrapper
Germany · www.datawrapper.de · 15 vendors
Resilience scores
- Digital Sovereignty: 13
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Chargebee Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 12 more
Services catalogue
1 service in catalogue across 1 category; runs on 15 sub-vendors.
- Datawrapper
Insights
Last updated 2026-08-03 · revision 1
15 direct vendors, 225 subvendors
Direct vendors by controlling owner country (sample)
- United States: 13
- Lithuania: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Norway: 2
- Japan: 3
- Belgium: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Datawrapper exhibits a moderate to high level of migration readiness, primarily driven by its modern tech stack and existing cloud adoption. The use of Amazon Web Services (AWS) as part of its internal infrastructure suggests familiarity and experience with cloud environments. The tech stack, featuring TypeScript, JavaScript, Svelte, Node.js, and a REST API, is well-suited for cloud-native architectures, microservices, and containerization, even though explicit mention of containerization is missing. The 'Datawrapper Enterprise (Self-Hosting)' offering implies that their core application has a degree of portability, which is a significant advantage for migration. Compliance with GDPR and ISO 27001, while requiring careful planning during migration, also indicates mature processes that can support a structured move. Key challenges and unknowns include the presence of PHP in the tech stack, which might indicate some legacy components requiring modernization. Crucially, 'Data Residency Requirements' are not specified, which is a critical factor that could significantly impact migration strategy, complexity, and cost. Similarly, 'Financial stability' to fund a major migration is unknown. The 'Vendor Lock-in Risk' is also unknown, and while specific major vendors like AWS, Cloudflare, Sentry, and GitHub are used, the overall vendor landscape is not fully clear due to contradictory data ('Total Vendors: 0').
Compliance
5 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Datawrapper GmbH is headquartered in Berlin, Germany — a core EU jurisdiction — making GDPR unconditionally applicable. The company processes personal data of its users (account data, usage data, employee data) and serves a global customer base including EU residents. Positive indicators include: data hosted exclusively in the EEA (AWS Frankfurt and Stockholm), explicit TLS encryption at rest and in transit, principle of least privilege access controls, and a published Privacy Policy. However, the full compliance status cannot be confirmed as 'Compliant' without access to the actual Privacy Policy content, a confirmed DPO appointment, documented DPIA processes, and verified data processing agreements with sub-processors. Risk is Medium rather than High because the company has demonstrably invested in privacy-by-design infrastructure (EEA-only hosting, encryption, access controls) and is ISO 27001 certified, which supports GDPR technical measures. German DPA (Berliner Beauftragte für Datenschutz und Informationsfreiheit) is the lead supervisory authority.
Evidence: https://www.datawrapper.de/security, https://www.datawrapper.de/imprint, https://www.datawrapper.de/privacy, https://assets.datawrapper.de/Datawrapper%20ISO-27001%20Certificate.pdf
SOC 2 (source) — Assessment Required
Datawrapper is a cloud-based SaaS platform serving enterprise customers including major global media organisations (NYT, Reuters, AP, Washington Post), the United Nations, and financial firms (Stripe, Gallup). Enterprise SaaS providers of this profile are routinely expected by enterprise customers to hold SOC 2 Type II reports as part of vendor due diligence and procurement requirements. No SOC 2 report or attestation is publicly referenced on Datawrapper's website. The company does hold ISO 27001 certification (which covers overlapping security controls), but ISO 27001 and SOC 2 are distinct frameworks. Risk is Medium because: (1) the absence of a publicly disclosed SOC 2 report may create friction in enterprise sales cycles and procurement processes; (2) enterprise customers in regulated industries (finance, media, government) increasingly mandate SOC 2 Type II; (3) the company's ISO 27001 certification demonstrates security maturity but does not substitute for SOC 2 in US-centric procurement contexts.
Evidence: https://www.datawrapper.de/security, https://assets.datawrapper.de/Datawrapper%20ISO-27001%20Certificate.pdf
NIS2 (source) — Assessment Required
Datawrapper is a German-based SaaS/cloud platform providing data visualisation tools to a global customer base including major media organisations, UN agencies, and financial institutions. Under NIS2 Directive (EU) 2022/2555, 'digital providers' — specifically online marketplaces, online search engines, and cloud computing service providers — are classified as Important Entities. Datawrapper operates as a cloud-based SaaS tool, which may qualify it as a 'cloud computing service provider' under NIS2 Annex II. The size threshold (50+ employees or €10M+ annual turnover) is uncertain from public sources. If Datawrapper meets the size threshold, NIS2 obligations would apply, requiring: cybersecurity risk management measures, incident reporting to BSI (Germany's national NIS2 authority), supply chain security, and registration. Risk is Medium because: (1) the sector classification as a digital provider is plausible but not definitively confirmed, (2) company size relative to NIS2 thresholds is unknown, and (3) Germany's BSI has been actively implementing NIS2 (BSIG amendment). The ISO 27001 certification partially mitigates technical risk.
Evidence: https://www.datawrapper.de/security, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/NIS-2/nis-2_node.html, https://www.datawrapper.de/imprint
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Datawrapper GmbH appears to be a financially resilient small SaaS company despite the absence of publicly disclosed financial figures. The company has operated for over 13 years (founded 2012) without any known major venture funding rounds, suggesting a bootstrapped or lightly-funded model that implies operational profitability and disciplined cost management—a strong signal of self-sustaining economics unusual for a European SaaS of this size. The customer base is a major strength: high-profile, sticky clients including The New York Times, Reuters, Associated Press, The Washington Post, The Guardian, United Nations, and Stripe, indicating recurring subscription revenue with likely low churn among newsroom customers. The SaaS subscription model typically delivers high gross margins, and diversification across media, government/NGOs, financial services, think tanks, and universities reduces single-vertical risk. However, the company's small absolute scale (~30 employees) limits resilience to key-person departures or the loss of a few large accounts. Concentration in the media/journalism vertical—itself under structural budgetary pressure—and rising competition from free/open-source alternatives, general BI tools, and AI-driven auto-charting features present material risks. Private-company opacity also prevents external verification of liquidity, debt, or profitability.
Key strengths: High-profile, sticky customer base (NYT, Reuters, AP, WaPo, Guardian, UN, Stripe), Bootstrapped/founder-led profile with no known major VC rounds over 13 years, implying profitability, Recurring SaaS subscription revenue with high typical gross margins, Product-market fit and category leadership in newsroom-grade data visualization, Diversified end-markets across media, government, tech, think tanks, and academia, Low-cost organic customer acquisition driven by widespread journalism/education usage
Risk factors: Small absolute scale (~30 employees) limits resilience to key-person or large-customer losses, Concentration in media/journalism vertical facing structural budget pressure, Competition from free/open-source tools (Flourish, Observable, D3) and BI platforms (Tableau, Power BI), AI disruption risk from LLM-driven auto-charting in ChatGPT, Excel Copilot, Notion, etc., Private-company opacity prevents verification of liquidity, debt, or profitability, FX exposure: USD/GBP revenues vs. EUR-denominated cost base
Workforce by country
- Germany: 20
- France: 2
- United Kingdom: 2
- Italy: 1
- Finland: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.