Sydjysk Sparekasse
Denmark · owned by Independent (Denmark) · broagersparekasse.dk · 17 vendors
Sydjysk Sparekasse is a modern, independent and democratically owned savings bank that works daily to create growth, security and profit in everyday life. The bank provides personal banking services, investment solutions, insurance, and loans to private customers and businesses in Southern and South Jutland.
Resilience scores
- Digital Sovereignty: 59
- Digital Resilience: 5
- Financial Resilience: 9
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Nykredit Bank A/S — Financial Services — Denmark
- Totalkredit A/S — Financial Services — Denmark
- and 14 more
Insights
Last updated 2026-07-30 · revision 2
17 direct vendors, 229 subvendors
Direct vendors by controlling owner country (sample)
- Luxembourg: 1
- Japan: 1
- United States: 6
Subvendors by controlling owner country (sample)
- Italy: 2
- Sweden: 8
- Luxembourg: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The company's migration readiness is hampered by several factors. The internal tech stack, while featuring digital integrations, does not explicitly indicate cloud-native, containerized, or microservices architecture (e.g., "Sitecore CMS" is mentioned), suggesting a potentially more monolithic or traditional infrastructure that could complicate migration efforts. Crucially, there is no information available regarding specific regulatory environment compliance requirements or data residency requirements, which are fundamental considerations for any migration strategy. Furthermore, the company's financial stability and ability to fund a significant migration project cannot be assessed due to missing data on revenue concentration and growth history. While the company utilizes a moderate number of distinct vendors (at least 9 explicitly mentioned, such as Worldline, Acubiz/Visma, Sparinvest, Privatsikring, eSignatur.dk, MobilePay, Sitecore, Google, Vimeo), the specific terms of these vendor relationships and potential lock-in risks are unknown, making it difficult to gauge the flexibility for migrating away from or integrating with new providers. The geographic diversity of vendors (4 countries) could also introduce complexity in contract renegotiations during a migration.
Compliance
11 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 is highly likely applicable to Sydjysk Sparekasse with high confidence. The banking and financial market infrastructure sector is explicitly listed as an 'Essential Entity' sector under Annex I of NIS2 Directive. The bank has 215 employees, well exceeding the medium enterprise threshold of 50+ employees (or €10M+ turnover). Denmark transposed NIS2 into national law via Lov om net- og informationssikkerhed (NIS2-loven), effective October 2024. Risk is High because: (1) Essential Entities face the most stringent NIS2 obligations including mandatory incident reporting to CSIRT within 24 hours, comprehensive cybersecurity risk management measures, and supply chain security requirements; (2) penalties for Essential Entities can reach €10M or 2% of global annual turnover; (3) financial institutions are high-value cyberattack targets; (4) the bank operates digital banking platforms (netbank, mobilbank) that are critical infrastructure; (5) Finanstilsynet is the designated competent authority for financial sector NIS2 compliance in Denmark. Status is 'Assessment Required' because no public NIS2 compliance assessment, registration confirmation, or audit has been found.
Evidence: https://www.sydjysksparekasse.dk/om-sparekassen/om-os, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.finanstilsynet.dk/en, https://www.cfcs.dk
Lov om Finansiel Virksomhed — Partially Compliant
The Danish Financial Business Act is the primary regulatory framework governing Sydjysk Sparekasse as a licensed savings bank (sparekasse). Risk is High because: (1) it is the core licensing and operational regulation — non-compliance could result in license revocation; (2) Finanstilsynet actively supervises compliance through on-site inspections; (3) the January 2026 Finanstilsynet inspection on mortgage lending indicates active regulatory scrutiny; (4) the bank must comply with capital adequacy requirements (CRR/CRD IV), governance requirements, and conduct of business rules; (5) as one of Denmark's 20 largest financial institutions, it receives heightened supervisory attention. Status is 'Partially Compliant' because the January 2026 inspection report exists (indicating active supervision) but the full content of any findings, orders, or reprimands is not publicly available in detail.
Evidence: https://www.sydjysksparekasse.dk/om-sparekassen/finanstilsynets-redegoerelser, https://www.sydjysksparekasse.dk/-/media/sydjysksparekasse/images/om-sparekassen/finanstilsynets-redegoerelse/redegrelse-_-sydjysk-sparekasse-_-boligfinansierings-inspektion-2025.pdf, https://www.finanstilsynet.dk/en
GDPR (source) — Partially Compliant
GDPR is universally applicable to Sydjysk Sparekasse as a Danish (EU) financial institution processing large volumes of sensitive personal and financial data for ~73,000 customers, 18,000 guarantors, and 215 employees. The risk level is High because: (1) financial institutions are prime targets for data breaches and regulatory scrutiny; (2) the bank processes special categories of data (health information referenced in privacy policy) and highly sensitive financial data; (3) Danish Datatilsynet actively enforces GDPR with fines and orders; (4) the bank explicitly transfers data to third countries outside EU/EEA, creating elevated cross-border transfer risk; (5) automated profiling and credit scoring activities are mentioned, which carry heightened GDPR obligations under Article 22; (6) non-compliance penalties can reach €20M or 4% of global annual turnover. Status is 'Partially Compliant' because while a privacy policy exists and GDPR legal bases are cited, no independent audit evidence, DPO appointment confirmation, or GDPR certification has been publicly disclosed.
Evidence: https://www.sydjysksparekasse.dk/om-sparekassen/publikationer/privacy-policy, https://www.sydjysksparekasse.dk/-/media/sydjysksparekasse/images/om-sparekassen/publikationer---pdf-filer/politikker-og-andre-oplysninger/2026/information-om-behandling-af-personoplysninger-uden-for-eu-til-hjemmesiden.pdf, https://www.datatilsynet.dk, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Financials
Three-year financials
- 2024: revenue DKK 573.2M, EBIT DKK 220.9M, equity DKK 1.54B
- 2023: revenue DKK 587.9M, EBIT DKK 199.1M, equity DKK 1.48B
- 2022: revenue DKK 444.1M, EBIT DKK 103.3M, equity DKK 1.30B
Financial Resilience Score: 9/10
Sydjysk Sparekasse displays exceptional financial resilience for a regional Danish savings bank. Its total capital ratio of 26.9% (CET1 26.4%) at end-2024 is nearly three times the regulatory solvency need of 9.5%, providing an excess capital buffer of approximately DKK 896m. Liquidity is equally robust with an LCR of 766%, far above the 100% regulatory minimum and even the bank's internal 400% floor. All four Danish Tilsynsdiamant (supervisory diamond) limits are comfortably met, and the auditor (EY) issued a clean opinion. The balance sheet is deposit-funded with a loan-to-deposit ratio of only 37.6%, minimizing wholesale funding dependence. Loan book diversification is strong: no single industry exceeds 10% of exposure, the largest single exposure is only 3.3% of core capital, and 71% of lending is to private customers. Profitability has strengthened materially post-merger, with ROE before tax rising from 8.2% (2022) to 14.6% (2024) and net profit doubling from 2020 to 2024. Management has prudently built a DKK 118.8m macro/credit management overlay. Key vulnerabilities are geographic (100% Danish/Southern Jutland exposure), a 6% agricultural exposure facing potential CO2 tax legislation, and expected NII compression as Danish rates decline (management guides 2025 PBT of DKK 130–160m vs 220.9m in 2024). Capital repayments (DKK 190m of hybrid/subordinated debt in spring 2024) reduced the capital ratio from 31.1% to 26.9% but it remains very strong.
Key strengths: Very strong capital ratio of 26.9% vs 9.5% solvency need (~DKK 896m excess), LCR of 766%, far above regulatory and internal minimums, Deposit-funded balance sheet, loan-to-deposit ratio only 37.6%, Diversified loan book — no industry >10%, largest single exposure 3.3% of core capital, All Tilsynsdiamant limits met; clean audit opinion from EY, ROE before tax improved to 14.6% in 2024; profit doubled since 2020, Rising guarantee capital (DKK 554.4m, 18,155 garanter) signals local confidence, 179-year heritage and deep local franchise in Southern Jutland
Risk factors: 100% Danish geographic concentration, dependent on regional Southern Jutland economy, Expected NII compression from falling Danish rates (2025 PBT guidance DKK 130-160m vs 220.9m in 2024), Agriculture exposure (6%) at risk from pending Danish CO2 tax legislation, Merger integration risk — IT conversion completed 2024, ongoing policy harmonisation, Cyber/IT dependency on SDC A/S data centre explicitly flagged as special risk, Repayment of DKK 190m hybrid/subordinated capital in 2024 reduced capital ratio, Management overlay increased to DKK 118.8m, signalling hidden credit risk concerns, 2023 impairment spike to DKK 64.0m reflected cautious overlay build
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Interest income: 68%
- Fee & commission income: 29%
- Dividends: 3%
Workforce by country
- Denmark: 209
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.