Obsidian Digital A/S

Denmark · owned by Oskar HoldCo ApS (Denmark) · obsidianagency.com · 28 vendors

Obsidian Digital is an international digital marketing agency that helps businesses grow by orchestrating their AI and digital marketing efforts. The company provides comprehensive digital marketing services including SEO, Google Ads, social media advertising, AI implementation, website development, and marketing automation across multiple countries.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 28 sub-vendors.

Insights

Last updated 2026-09-13 · revision 9

28 direct vendors, 296 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company exhibits high migration readiness primarily due to its reliance on SaaS and cloud-native technologies rather than legacy on-premise infrastructure, facilitating easier digital transitions. The presence of 69 services suggests a 'best-of-breed' architecture with low vendor concentration (avoiding single-vendor lock-in), which typically enhances flexibility. However, readiness is tempered by significant regulatory complexity; moving operations or data involves strict GDPR compliance measures for the non-EU branches. Furthermore, while the technical stack is portable, the administrative burden of managing contracts and integrations for 69 distinct services adds complexity to any potential migration event.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Applies because Obsidian Digital A/S is headquartered in Denmark (an EU member state) and processes personal data of EU residents, clients, and employees through its digital marketing and analytics services.

GDPR applies with HIGH certainty as Obsidian Digital A/S is headquartered in Denmark (EU member state) and operates as a digital marketing agency processing personal data of clients, employees, and EU residents. Non-compliance can result in fines up to 4% of annual turnover or €20M. As a digital marketing agency with 412 employees handling customer data, tracking analytics, and marketing automation, they process significant volumes of personal data. The high risk level reflects both the certainty of applicability and severe financial/reputational consequences of non-compliance.

SOC 2 (source) — Assessment Required

Relevant for digital service providers handling client data in cloud environments to demonstrate security controls, often required by enterprise-level clients.

SOC2 may be relevant as Obsidian provides digital services including tracking & analytics, marketing automation, and website development that could involve processing client data in cloud environments. While not mandatory, SOC2 compliance demonstrates security controls and may be required by enterprise clients. Risk level is medium as it's not legally mandated but could impact business relationships and competitive positioning. The 412-employee size and multi-country operations suggest they likely handle significant client data requiring robust security controls.

ISO 27001 (source) — Assessment Required

Considered best practice for information security management for an agency of this size handling extensive client data across multiple countries.

ISO 27001 is highly relevant for a digital marketing agency of this size (412 employees) handling extensive client data, tracking analytics, and marketing automation. While not legally mandatory, it's considered best practice for information security management and may be required by enterprise clients or for competitive differentiation. Risk level is medium as lack of certification could impact business opportunities and client trust, though it's not a legal requirement with direct penalties.

Financials

Three-year financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report