Ask most engagement teams where their stakeholder data lives, and the honest answer is still a spreadsheet. That's the problem. For a UK buyer, the practical question is what each supplier publishes about where your data sits, which accreditations it holds and how it evidences a lawful basis, consent and erasure. This article sets that out for seven platforms.
A spreadsheet isn't just fragile; it's a data-protection liability. Uncontrolled files can be amended with no audit trail, which is the opposite of what UK GDPR asks of you.
What makes a stakeholder database 'GDPR-ready'?
A GDPR-ready stakeholder database lets you evidence a lawful basis for holding each contact, records opt-in and unsubscribe choices and enforces them automatically, keeps personal data in a known location, controls who can see what, and produces a date-stamped audit trail so you can answer a subject access or erasure request quickly. Security accreditations back all of that up.
Judged against those criteria, the platforms below are ranked for a UK buyer, where UK data residency, UK-specific accreditation, breadth as a stakeholder database and accessibility carry the most weight. The Information Commissioner's Office sets out the UK GDPR principles that these map to.
|
Platform |
HQ / data residency |
Security & UK accreditations |
G-Cloud |
Pricing |
Scope |
|
Tractivity |
UK (Microsoft Azure UK South) |
ISO 27001:2022, Cyber Essentials Plus, NHS DSPT, annual CREST-approved penetration testing, WCAG 2.2 Level A |
Yes |
Published: from £9,495 a year + £500 per additional user |
Full SRM |
|
Syrenis SMART (legacy product) |
HQ in Austin, TX; hosted on AWS. G-Cloud declares UK, EEA and other locations, user-controlled. |
ISO 27001 (AWS-only scope), Cyber Essentials + Cyber Essentials Plus, SOC 2 Type II, CSA STAR L2, Home Office ATO, annual CHECK pentesting |
Yes |
Published at £4,215 per user per year |
Legacy stakeholder communication tool, de-branded April 2026 |
|
Borealis |
Hosted in Canada, France or Australia, no UK region; G-Cloud declares EEA and other |
ISO/IEC 27001:2022 (Certi-Trust, cycle Mar 2026 to Mar 2029), annual third-party pentesting; no Cyber Essentials or Cyber Essentials Plus listed |
Yes (G-Cloud 14) |
No listed price; G-Cloud 14: £1,137 to £2,674 a user a year; one-time onboarding fee, amount unpublished |
Enterprise SRM |
|
Jambo |
Edmonton, Canada (AWS); UK, Ireland or EEA claimed on different pages, confirm in writing |
ISO 27001:2022 + ISO 27017:2015; no SOC 2, no Cyber Essentials Plus Plus (application underway), no NHS DSPT |
No |
From ~US$995/month (Professional) |
SIM; mapping via tags/Esri, surveys via integrations |
|
Simply Stakeholders |
Chatswood, NSW; Azure, multi-region including UK; in-country backups |
ISO 27001, SOC 2, MFA/SSO, pentesting, Vanta trust page; no AI training on customer data; no Cyber Essentials Plus |
No |
Tiered, not publicly listed |
SRM |
|
Citizen Space (Delib) |
Bristol; G-Cloud declares UK and EEA, user control Yes |
ISO 27001, Cyber Essentials, annual CHECK pentesting, BPSS-cleared staff, WCAG 2.2 AA |
Yes (G-Cloud 14) |
G-Cloud 14: £10,495 to £99,995 an instance a year |
Consultation and engagement platform |
|
Commonplace (powered by Zencity) |
London, now Zencity-owned; all data stored in the UK, hosted on AWS |
ISO 27001, Cyber Essentials, annual penetration testing, ICO registered, WCAG 2.2 AA (UK Accessibility Regulations 2018) |
Yes (G-Cloud 14) |
G-Cloud 14: £2,250 to £50,000 a licence |
Community insights, engagement and consultation platform |
Comparison based on publicly available information, reviewed August 2026, taken from each supplier's own website and its own Crown Commercial Service G-Cloud 14 listing where one exists. Vendors change their pricing, accreditations and features, so confirm current details directly before you shortlist. Published by Tractivity.
1. Tractivity
Tractivity, a UK stakeholder relationship management (SRM) platform,, is built around the question a regulator, an FOI request or a public inquiry will eventually ask: who did you engage, when, how, and what did they say? Every email, call, meeting, survey response and event is logged against the stakeholder it relates to, date-stamped and exportable, so the record holds up under scrutiny.
On GDPR specifically, communications are opt-in and tracked with unsubscribe options enforced automatically; permissions are role-based at the project, module, and record levels; and data is encrypted at rest and in transit, hosted in Microsoft Azure UK South by default, with European, US, and other regions available. That supports compliance with the UK GDPR, the Planning Act 2008, the Companies Act 2006 section 172, and the Gunning Principles. Accreditations cover ISO 27001:2022, Cyber Essentials Plus, the NHS Data Security and Protection Toolkit and G-Cloud 14, with annual CREST-approved penetration testing.
The proof lies in the regulated programmes it supports. EDF used Tractivity across major new-nuclear consultation programmes, with tens of thousands of stakeholder issues logged, tagged and reported, and National Grid runs a phased deployment across hundreds of users. Stakeholder mapping remains dynamic rather than fixed in static snapshots, and more than 150+ pre-built reports support board, regulatory and FOI reporting requirements.
Pricing is transparent, from £9,495 a year plus £500 per additional user, with no record caps and no feature restrictions based on user type. The EEngage-360 public portal is priced separately according to scale. On accessibility, to be clear about our own position: Tractivity currently meets WCAG 2.2 Level A, with Level AA on track for 2026, and the UK Public Sector Bodies Accessibility Regulations 2018 require WCAG 2.1 Level AA, so ask us, and every supplier on your shortlist, for a published conformance level and roadmap in writing.
Implementation typically takes four to six weeks and includes a dedicated UK-based Client Success Manager alongside unlimited UK support. Tractivity has been developing SRM software for more than 20 years, serves 112+ named UK clients across eight sectors, and supports communications through email, mailshots, surveys and events.
2. Syrenis SMART
Syrenis SMART is the legacy stakeholder communication tool from Syrenis Ltd. The company is registered at Sci-Tech Daresbury in Warrington, and its head office is now in Austin, Texas.
Syrenis retired the SMART branding in its 21 April 2026 brand relaunch, and it no longer appears in the site navigation. Their own Trust Center now describes it as "our stakeholder management capability, which forms a small part of the broader Syrenis platform". It remains listed and priced on G-Cloud 14, at £4,215 per user per year.
Their published security programme is one of the strongest here: ISO/IEC 27001 (EY CertifyPoint, 18 November 2022, scope excludes services outside AWS), SOC 2 Type II, Cyber Essentials and Cyber Essentials Plus, CSA STAR Level 2, a Home Office Approval to Operate with a Police National Network connection, and annual CHECK-approved penetration testing.
On residency, their G-Cloud filing declares "United Kingdom / European Economic Area (EEA) / Other locations" with user control over location, so confirm the contracted region in writing if UK-only storage is a requirement.
Two things to weigh. Syrenis does not publish the revision year of its ISO 27001 certificate, and the scope of that certificate is stated to exclude services outside AWS, so ask for the certificate and its scope statement if the revision or the boundary matters to you. And because SMART is no longer branded or marketed, ask Syrenis directly, in writing, what its published support and development commitment for SMART is, and what a migration to the current Syrenis platform would involve, since that platform is a consent and preference management product rather than a stakeholder database.
3. Borealis
Borealis is a mature, analytically deep enterprise SRM platform, developed in Magog, Quebec and owned since October 2025 by Irth Solutions of Columbus, Ohio. It publishes nine industries including Renewables, Offshore Renewable Energy, Mining, Oil and Gas, Utilities, Transport, Government and Healthcare, and four modules: Stakeholder Engagement, Issue and Complaint Management, Land Access and Acquisition, and Social Investment. Its stakeholder mapping and segmentation capabilities are impressive and among the strongest in the market.
For a UK buyer, the trade-offs are locality and cost.
Borealis publishes production hosting in Canada, France and Australia, with no UK region named, and its G-Cloud entry declares data locations as European Economic Area and other locations rather than the United Kingdom. Confirm in writing where your data would sit.
It does hold a G-Cloud 14 listing (service ID 738894393875442), priced at £1,137 to £2,674 a user a year on documents dated April and May 2024. There are no prices on its own site, and onboarding and configuration carry a one-time fee whose amount is not published.
Its UK page carries client logos including Cavendish Nuclear, Outer Dowsing, Voltalia and Thakeham, though we found no UK case study on the site as at August 2026.
On security, it publishes an ISO/IEC 27001:2022 certificate from Certi-Trust (number CT-ISMS-032026-0CU01071), covering a March 2026 to March 2029 cycle, and its G-Cloud entry answers No to both Cyber Essentials and Cyber Essentials Plus.
4. Jambo
Jambo is a Canadian stakeholder relationship management platform, headquartered in Edmonton, Alberta and part of the Silvacom Group of Companies, with its primary market in North America.
Its published office list is inconsistent. Alongside Calgary and Thunder Bay, it names a "UK and EU office" whose only published address is in Naas, Co. Kildare, Ireland. Its own copy also refers to a Dublin office and a Croatian office, neither with a published address.
On data protection, it states compliance with both EU GDPR and UK GDPR, and claims ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certification. It hosts on AWS and uses SOC 2-certified data centres rather than holding SOC 2 itself. It also publishes role-based access, multi-factor authentication, single sign-on on the Enterprise tier, annual third-party penetration testing, and breach notification within 72 hours of confirming an incident.
For UK buyers, the question is UK-specific alignment rather than security itself. Jambo was not listed on G-Cloud 14 when it was checked on the Digital Marketplace supplier index in August 2026, though their own comparison page says an application is in progress and expected by September 2026, and that a Cyber Essentials Plus application is underway. NHS DSPT is not mentioned anywhere.
Their logo wall names University of Cambridge, the Low Carbon Contracts Company and ENGIE, but no UK case study.
Two feature gaps are worth noting too. No published dedicated interest and influence mapping module; segmentation is instead handled through tags, custom fields and Esri map viewers. There's no native survey tool either; surveys run through Zapier connections to tools such as Typeform and SurveyMonkey.
Their published regional hosting story is also inconsistent: their security page names the UK, their FAQ names Ireland. Ask them to confirm the contracted region in writing.
5. Simply Stakeholders
Simply Stakeholders is a trading name of Darzin Software Pty Ltd, of Chatswood, New South Wales. It was founded in 2004 and remains founder-led. Its published features include a stakeholder register, Outlook and Gmail plugins that save email and meetings automatically, mapping on Google Maps, automatic sentiment and issue detection, commitments tracking, grievance management and an iOS and Android app.
It publishes no prices. Its three tiers, Core, Plus and Pro, all carry a "Contact" or "Book a Demo" call to action, with a per-user model capped above a certain number of users and onboarding included in the plan price. Its homepage names energy and resources clients including Drax, Statkraft, Var Energi, Goldwind and Anglo American, but no named UK public sector client on its site.
For UK public-sector procurement, several things are worth checking. On security, they publish ISO 27001 certification, with a Sensiba certification mark added to their footer in February 2026, SOC 2, MFA and SSO on every plan, third-party penetration testing and a public Vanta trust page. No Cyber Essentials Plus claim and no G-Cloud listing.
On hosting, they publish Microsoft Azure regions in the UK, Europe, Australia, Canada and the USA, with data backed up in the same country as production and live regional login subdomains including a UK one, so UK data residency is available on the same cloud Tractivity uses. On AI, their AI Policy, published in July 2026, states that "Your data is not used to train Simply Stakeholders, Microsoft, OpenAI, or any third-party AI models. This is contractually enforced through Microsoft's Data Processing Addendum." It documents a use case register, per-field AI controls, a 48-hour Microsoft retention limit and regional processing. Their privacy impact assessment, though, is stated against the Australian Privacy Act 1988 rather than UK GDPR, which is the genuine UK procurement question to put to them.
On accessibility, their own published position is "WCAG compliance in progress", with no version or conformance level stated, and we found no accessibility statement and no VPAT, ask them for a target level and date. On packaging, their pricing page places email sending, SMS, surveys, commitments tracking and grievance management on the Plus tier or above, and offline access and API access on Pro only, so check that the capabilities you need sit inside the tier you're quoted. They publish no support hours or time zones, so ask for both in writing.
6. Citizen Space (Delib)
Citizen Space is a UK-based consultation portal with strong central-government and council references. If your only requirement is publishing formal consultations, capturing responses and reporting on them, it does that job well.
Its published scope is the consultation itself. Delib's G-Cloud 14 listing names "Tools for citizens and residents panels, stakeholder and expert groups", and as at August 2026 we found no published feature for logging individual interactions against a named stakeholder record, and no commitment or obligation tracker. The nearest published mechanism is the public "We Asked, You Said, We Did" loop.
On data protection, they publish a good deal: ISO 27001 accredited by SNR on 1 February 2023, Cyber Essentials, data locations of United Kingdom and European Economic Area with user control over location, annual CHECK-approved penetration testing, staff cleared to Baseline Personnel Security Standard, and WCAG 2.2 Level AA tested with Tetralogical, accessibility consultants to GOV.UK. Note that Delib's own estate gives two ISO revision years, :2022 on their press page and :2013 in a G-Cloud field, so ask which certificate is current.
7. Commonplace
Commonplace, now powered by Zencity, is a UK community insights, engagement and consultation platform built around visual, map-based inbound feedback, popular with housing associations and planning consultations. For gathering public input on a place-based scheme, the interface is modern and purpose-built, and its UK case studies include Westminster City Council, Waltham Forest and Cairngorms National Park.
On data protection, it publishes more than most of this list. All customer data is stored in the United Kingdom on AWS, and its G-Cloud 14 listing confirms "Data storage and processing locations: United Kingdom". It holds ISO 27001, accredited by Centre for Assessment from June 2021, and Cyber Essentials, runs an annual penetration test with a 30-day remediation and re-test window, and publishes its ICO registration number, ZA074797. It's also the only supplier in this comparison whose accessibility statement explicitly names the UK Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018, claiming WCAG 2.2 Level AA and last reviewed on 23 July 2026.
Its published scope is community feedback and insight rather than a private staff-side stakeholder record. Zencity states that "our analysis of the data is always done on an aggregate basis and is not designed to identify or pinpoint any individual", though its "Commonplace Select" feature does engage a predefined list of stakeholders for statutory engagements, and its G-Cloud listing answers "API: No". If you also need regulator and private-sector engagement held against named records, ask them what they cover.
How to choose
Start with data residency and accreditation, then map platform capabilities to the way your team actually works. For UK organisations with regulatory or public-sector exposure, UK-hosted, G-Cloud-listed and ISO 27001:2022-accredited solutions should be at the top of the shortlist. Where consultation publishing is the primary requirement, a specialist portal such as Citizen Space may be sufficient.
If your organisation sits outside UK public-sector procurement, the shortlist widens, because a G-Cloud listing and Cyber Essentials Plus stop being gating requirements. UK GDPR still applies wherever you process the personal data of people in the UK, and several of the non-UK platforms here publish UK or EEA hosting options, so treat residency as a question to settle in the contract rather than a reason to rule a supplier in or out.
The deeper question is whether you need a consultation tool, a community-feedback tool, or a stakeholder database that holds the complete relationship and proves it later. For UK teams that have outgrown spreadsheets and need an auditable stakeholder record that can withstand scrutiny, staff turnover and organisational growth, the answer is typically a purpose-built, UK-accredited SRM platform.
See it against your own use case
If you're weighing up your options, the quickest way to see how a GDPR-ready stakeholder database works in practice is to book a demo and put it to your own requirements. Prefer to talk it through first? Get in touch, and we'll point you in the right direction, no pitch attached.
Frequently asked questions
The UK Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 require WCAG 2.1 Level AA. Tractivity currently meets WCAG 2.2 Level A, with Level AA on track for 2026, and we publish that position in our accessibility statement.
Among the suppliers on this page, Delib and Commonplace both publish WCAG 2.2 Level AA, Jambo publishes partial conformance with WCAG 2.1 Level AA, Borealis and Syrenis self-declare against WCAG 2.1 AA without a published statement, and Simply Stakeholders' own published position is that WCAG compliance is in progress.
Several suppliers publish different versions in their marketing and in their G-Cloud filings, so ask every vendor, including us, for the level it will contract to and the date of its most recent test.
