Didomi
France · www.didomi.io · 15 vendors
Didomi develops a consent management platform (CMP) and data governance solutions that help businesses comply with international privacy regulations. The company enables organizations to collect, store, and activate user choices across multiple channels, aiming to balance marketing performance with user trust and reduce compliance risk.
Resilience scores
- Digital Sovereignty: 13
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Demandware — Technology — United States
- HubSpot, Inc. — Technology — United States
- and 12 more
Services catalogue
2 services in catalogue across 2 categories; runs on 15 sub-vendors.
- Didomi
- Personal Data Processing
Insights
Last updated 2026-07-22 · revision 2
15 direct vendors, 270 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Denmark: 1
- Unknown: 1
Subvendors by controlling owner country (sample)
- United States: 190
- Sweden: 10
- Denmark: 4
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Didomi's migration readiness benefits from a modern, distributed, and API-driven tech stack, including REST APIs, SDKs, and Server-Side Tagging (Addingwell by Didomi). This architecture suggests a degree of modularity and flexibility conducive to migration. Their deep expertise in managing complex and diverse regulatory compliance (GDPR, CCPA, IAB TCF v2.2, etc.) is a strength, as they are well-equipped to navigate the compliance challenges inherent in any data migration. However, several critical data gaps and inherent complexities significantly lower the migration readiness score. The most impactful unknowns are data residency requirements and financial stability (ability to fund a migration), both of which are not specified and could pose major challenges or blockers. While the internal tech stack lists specific vendors like HubSpot, Webflow, Vimeo, and Google Tag Manager, and 'Total Services: 22' are identified from vendors across 5 countries, the total number of distinct vendors and the specific vendor lock-in risk remain unknown. This ambiguity, coupled with the potential complexity of migrating or re-integrating 22 external services, presents a significant hurdle. The extensive regulatory environment, while managed expertly, inherently adds layers of complexity to any migration effort, requiring meticulous planning and execution to maintain compliance. The score reflects a capable technical foundation but is heavily tempered by significant business and operational unknowns that could impede a successful migration.
Compliance
9 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, often applied in the context of privacy and data protection audits (e.g., ISAE 3000 Type I/II reports on data processing controls). As a data processor for 2,500+ enterprise clients, Didomi could benefit from an ISAE 3000 assurance report to provide independent third-party assurance to clients about their data processing controls. However, the risk is Low because: (1) ISAE 3000 is not a mandatory regulatory requirement for Didomi's industry; (2) their ISO 27001:2022 certification provides substantial equivalent assurance; (3) ISAE 3000 is more commonly required in financial services and audit contexts; (4) no evidence of ISAE 3000 engagement was found, but this is not unusual for a technology company of Didomi's profile.
Evidence: https://www.didomi.io/security
CPRA — Compliant
Didomi explicitly supports CCPA/CPRA compliance as a core product feature, serving US-based clients and operating in 35+ countries including the United States. The risk is Medium because: (1) Didomi has US operations and serves US clients who require CCPA-compliant consent management; (2) Didomi's own data processing activities involving California residents' data may trigger CCPA obligations depending on revenue and data volume thresholds; (3) Didomi actively markets CCPA compliance solutions, indicating awareness and product-level support; (4) the CPRA (effective 2023) introduced additional requirements including the California Privacy Protection Agency (CPPA) enforcement. The risk is not High because Didomi's primary establishment is in France (not California), and their role is primarily as a service provider (processor) rather than a business under CCPA.
Evidence: https://www.didomi.io/regulations/ccpa, https://www.didomi.io/regulations/us-privacy-laws, https://www.didomi.io/regulations/gpc-compliance, https://www.didomi.io/regulations/gpp
French Data Protection Law — Compliant
As a French-registered company (Didomi SAS, RCS Paris n°831 722 756), Didomi is subject to French data protection law, which implements GDPR and includes additional national provisions enforced by the CNIL. The risk is Medium because: (1) CNIL is one of the most active and technically sophisticated EU DPAs, with a specific focus on cookie consent and CMP compliance; (2) CNIL has issued detailed guidelines on cookie consent banners that directly affect CMP providers like Didomi; (3) CNIL has fined major companies (Google, Facebook, Amazon) for cookie consent violations; (4) Didomi's platform is used by thousands of French companies to achieve CNIL compliance, creating reputational risk if their CMP is found non-compliant; (5) however, Didomi's core business is CNIL compliance, and they actively monitor and implement CNIL guidance.
Evidence: https://www.didomi.io/legal-notice, https://www.didomi.io/privacy-policy, https://www.didomi.io/cookie-policy, https://www.didomi.io/blog/didomi-european-cmp-association
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Didomi is a well-funded mid-stage French SaaS scale-up with a strong cash position following its $40M Series B in June 2022 (led by Elephant, with Breega and Partech), on top of ~$11M raised in earlier rounds. This provides multi-year runway and a solid balance sheet for a company of its size. The recurring SaaS revenue model, with high gross margins, multi-year contracts and low churn once integrated into a customer's stack, supports revenue predictability. Reported ARR growth of ~3x year-on-year at the time of the Series B further underscores commercial momentum. However, as a privately held French SAS, Didomi does not publicly disclose audited revenue, EBIT or equity, limiting transparency. Profitability is unknown and, as a growth-stage VC-backed SaaS, the company is likely still prioritizing growth over EBIT. The CMP market is highly competitive with well-funded players (OneTrust, Usercentrics/Cookiebot, Sourcepoint, TrustArc, Osano) and increasing bundling by large platforms (Google, Adobe). Regulatory tailwinds (GDPR, CCPA, Law 25, LGPD, Google Consent Mode v2) continue to expand the addressable market, but potential simplification under the EU 'Digital Omnibus' could commoditize stand-alone consent banners. Overall resilience is above average but tempered by opacity and competitive/regulatory concentration risk.
Key strengths: $40M Series B (June 2022) led by Elephant plus ~$11M in prior rounds, providing multi-year runway, Recurring SaaS revenue model with high gross margins and low churn, Regulatory tailwinds expanding TAM (GDPR, CCPA, Law 25, LGPD, Google Consent Mode v2), 2,500+ customers across 35+ countries providing diversified customer base, Product suite expansion beyond CMP (Preference Management, Compliance Scanning, Addingwell server-side tagging, DSAR automation) increasing ACV and stickiness, Blue-chip customer base across media, banking, retail and pharma (Europcar, Chantelle, La Poste Mobile, OUIGO, Planity)
Risk factors: Intense competition from OneTrust, Usercentrics/Cookiebot, Sourcepoint, TrustArc, Osano and bundled offerings from Google/Adobe, Regulatory single-point exposure: EU 'Digital Omnibus' GDPR simplification could reduce demand for stand-alone CMPs, Profitability unknown; likely still prioritizing growth over EBIT, Market consolidation risk (Usercentrics+Cookiebot merger, OneTrust divestitures); integration execution risk with Addingwell acquisition and Sourcepoint tie-up, Limited financial transparency as a private SAS
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.