TomTom N.V.
Netherlands · owned by Independent (Netherlands) · www.tomtom.com · 43 vendors
TomTom N.V. is a Dutch technology company specializing in maps, navigation software, and location-based services. It provides mapping data, real-time traffic information, and navigation solutions to automotive manufacturers, enterprises, and developers worldwide. TomTom operates as an independent location technology specialist, offering products such as the TomTom Maps Platform and navigation APIs.
Resilience scores
- Digital Sovereignty: 12
- Digital Resilience: 5
Disruption prediction
TomTom N.V. has an estimated 40% probability of disruption in the next 6 months.
30 of TomTom N.V.'s 43 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Elektrobit (EB) — Technology — Germany
- and 40 more
Services catalogue
5 services in catalogue across 2 categories; runs on 43 sub-vendors.
- SKY / SCALAR
- Navigation
- Mapping
Insights
Last updated 2026-03-02 · revision 6
43 direct vendors, 414 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- United States: 37
- Germany: 4
Subvendors by controlling owner country (sample)
- India: 2
- Unknown: 1
- Spain: 2
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
TomTom faces significant challenges in migration readiness due to its complex regulatory environment and stringent data residency requirements. GDPR and NIS2 impose strict rules on data processing and transfers, particularly for EU personal data, which will heavily influence cloud migration strategies and increase complexity and cost. The 'Assessment Required' status for SOC2 and ISO 27001 also means any new infrastructure must meet these standards. A major impediment to assessing readiness is the complete lack of information on TomTom's internal tech stack (e.g., cloud-native, containerization, microservices), making it impossible to gauge technical feasibility. While vendor geographic diversity is present, the 'Total Vendors: 0' entry is contradictory, and specific vendor lock-in risks are 'Unknown,' preventing an assessment of flexibility to change vendors. There is also no data on financial stability to assess the ability to fund a migration. These critical unknowns and the high regulatory burden place TomTom's migration readiness in the lower-to-medium range, indicating substantial hurdles and uncertainties.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
As a Dutch company headquartered in the EU, TomTom processes personal data of EU residents through their navigation services, mapping data collection, customer accounts, and employee data. GDPR non-compliance can result in fines up to 4% of annual turnover or €20 million. Given TomTom's significant revenue and data processing activities, the financial and reputational risks are substantial. The company's location-based services inherently involve processing personal data including location tracking, which is considered sensitive under GDPR.
ISO 27001 (source) — Assessment Required
As a technology company handling significant amounts of location and customer data, ISO 27001 certification would be expected for information security management. While not legally mandatory, it's often required by enterprise customers and helps demonstrate security maturity. The risk level is medium as lack of certification could impact business opportunities but doesn't carry direct regulatory penalties.
NIS2 (source) — Assessment Required
TomTom operates in the transport sector providing critical digital infrastructure and services for navigation and traffic management systems. As an Essential Entity under NIS2 (transport sector), they face mandatory cybersecurity requirements. The company exceeds size thresholds (large enterprise with significant revenue) and provides services critical to transport infrastructure. Non-compliance can result in fines up to 2% of annual turnover and operational restrictions. Given their role in critical transport infrastructure and digital services, cybersecurity incidents could have significant societal impact.
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.