Merkle
United States · www.merkleinc.com · 12 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Looker — Technology — United States
- and 9 more
Services catalogue
1 service in catalogue across 1 category; runs on 12 sub-vendors.
- Merkury
Insights
Last updated 2026-08-16 · revision 1
12 direct vendors, 194 subvendors
Direct vendors by controlling owner country (sample)
- United States: 10
- France: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Belgium: 3
- Unknown: 1
- Sweden: 4
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Merkle exhibits a high degree of migration readiness, primarily driven by its extensive adoption of major cloud platforms (AWS, GCP) and a clear focus on 'Cloud Architecture' and 'Cloud strategy' within its services. This indicates a strong cloud-native approach and a multi-cloud strategy, enhancing flexibility and reducing single-cloud lock-in. The company's use of modern technologies like Customer Data Platforms (CDP), Identity Resolution, Machine Learning, and Generative AI suggests an architecture designed for agility and modern deployment practices. Furthermore, Merkle's 'Platforms & Engineering' services, which include 'Cloud strategy, architecture, commerce platforms, content management, and Customer Data Platform (CDP) engineering services,' demonstrate significant internal capability and experience in managing and migrating complex cloud environments. The absence of specified 'Data Residency Requirements' and 'Regulatory Environment' details also suggests fewer explicit constraints that would complicate migration efforts. However, a significant challenge lies in the large number of distinct internal technology vendors (at least 16 platforms), which implies a highly integrated and potentially complex ecosystem. Migrating such an environment could involve substantial effort in disentangling dependencies, managing multiple vendor contracts, and ensuring data consistency across various platforms. While vendor diversity reduces single-vendor lock-in, the sheer volume of integrations could lead to 'integration lock-in,' making it difficult to swap out core components without extensive re-engineering. The 'Vendor lock-in risk: Unknown' highlights this uncertainty. Additionally, the lack of data on financial stability (revenue concentration, growth) prevents an assessment of Merkle's capacity to fund large-scale migration projects.
Compliance
12 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
Merkle is a large global data and technology company processing sensitive consumer data at scale across 30+ countries. ISO 27001 certification is increasingly expected by enterprise clients, particularly in regulated industries and EU markets where it demonstrates systematic information security management. The risk is MEDIUM because: (1) Merkle's data broker activities and identity resolution platforms handle millions of consumer records, making information security critical; (2) EU clients and regulated-industry clients (financial services, healthcare) frequently require ISO 27001 as a vendor qualification criterion; (3) Without certification, Merkle may face procurement barriers; (4) Dentsu (parent company) has pursued ISO 27001 in some markets. No public ISO 27001 certificate was found for Merkle specifically.
Evidence: https://www.merkle.com/en/privacy-policy.html, https://www.merkle.com/en/about-us.html
CPRA — Partially Compliant
Merkle is explicitly registered as a data broker in California, Oregon, Texas, and Vermont. As a data broker and large-scale consumer data processor, CCPA/CPRA is a primary regulatory obligation. The risk is HIGH because: (1) Merkle's core business involves collecting, processing, and selling/sharing consumer personal data — the exact activities most heavily regulated by CCPA/CPRA; (2) Merkle's Merkury platform and data products involve selling and sharing consumer data with third parties; (3) CPRA established the California Privacy Protection Agency (CPPA) with enhanced enforcement powers; (4) Data broker registration requirements under AB 1202 and SB 362 (Delete Act) impose ongoing obligations; (5) Fines up to $7,500 per intentional violation. Merkle demonstrates partial compliance through published DSRR metrics, opt-out mechanisms, and a dedicated Product Privacy Notice, but the scale of data operations creates ongoing risk.
Evidence: https://www.merkle.com/en/privacy-policy.html, https://www.merkle.com/en/privacy-policy/data-product-privacy-notice.html, https://www.merkle.com/en/privacy-policy/data-product-privacy-notice/control-your-personal-information.html, https://www.merkle.com/content/dam/merkle/en/site-content/privacy/2024%20Annual%20CCPA%20DSRR%20Metrics%20-%20Merkle.pdf
China PIPL — Assessment Required
Merkle has confirmed offices in Beijing, Guangzhou, Shanghai, and Nanjing, China. China's PIPL (effective November 2021) is one of the world's strictest data protection laws with significant extraterritorial reach and severe penalties. The risk is HIGH because: (1) Merkle's data-driven marketing business in China involves large-scale processing of Chinese consumer personal information; (2) PIPL imposes strict requirements on cross-border data transfers including security assessments by the CAC (Cyberspace Administration of China) for large-scale transfers; (3) Data localization requirements may apply to Merkle's China operations; (4) Penalties up to ¥50M or 5% of annual revenue; (5) Merkle's identity resolution and data products may qualify as 'important data' or trigger 'important data processor' obligations under China's data security framework.
Evidence: https://www.merkle.com/en/locations.html, https://www.merkle.com/zh/home.html
Financials
Three-year financials
- 2024: revenue ¥1,410.5B, EBIT ¥46.6B, equity ¥579B
- 2023: revenue ¥1,439.1B, EBIT -¥30.1B, equity ¥595B
- 2022: revenue ¥1,240.0B, EBIT ¥100.7B, equity ¥665B
Financial Resilience Score: 7/10
Merkle benefits from the substantial backing of Dentsu Group, a top-6 global agency network with approximately ¥1.1 trillion in net revenue and 67,000 employees across 120 countries. This parent-company support provides balance-sheet stability, funding access, and cross-selling opportunities that a standalone agency of similar size would not have. Merkle's blue-chip client base, proprietary technology assets (Merkury identity platform, LoyaltyPlus), and deep partnerships with Adobe, Salesforce, Google, AWS, and other technology leaders provide meaningful competitive differentiation in the CX consulting and systems-integration market. However, financial resilience is tempered by several concerns. In FY2023, Dentsu recorded a ~¥170 billion goodwill impairment charge, a substantial portion of which related to CXM/Merkle, signaling that acquisition-era growth assumptions were not met. The Americas segment (Merkle-heavy) has been Dentsu's weakest performer in 2023-2024, with underlying operating profit declining 14.7% in FY23 and another 11.5% in FY24. Structural competitive pressure from Accenture Song, Deloitte Digital, IBM iX, and hyperscaler professional services arms directly threatens Merkle's core CX budget. The lack of standalone financial transparency also limits external assessment of Merkle-specific solvency and working capital.
Key strengths: Backing of Dentsu Group (¥1.1T net revenue, 67,000 employees globally), Blue-chip, long-tenured client base across diversified verticals, Proprietary technology (Merkury identity platform, LoyaltyPlus), Deep partnerships with Adobe, Salesforce, Google, AWS, Snowflake, Diversified service portfolio across consulting, engineering, analytics, media, Multi-decade track record since 1971
Risk factors: No standalone financial transparency as wholly-owned subsidiary, ~¥170B goodwill impairment in FY2023 tied to CXM/Merkle, Americas/CXM segment is Dentsu's weakest performer 2023-2024, Competitive encroachment from Accenture Song, Deloitte Digital, IBM iX, Third-party cookie/signal-loss transition risk to identity business, Ongoing restructuring and headcount reductions across international operations, Client project deferrals and marketing-services pricing pressure
Revenue by geography
- Americas: 42%
- Japan: 29%
- EMEA: 20%
- APAC ex-Japan: 9%
Workforce by country
- United States: 8000
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.