Bruun & Hjejle
Denmark · owned by Independent (Denmark) · www.bruunhjejle.dk · 10 vendors
Resilience scores
- Digital Sovereignty: 50
- Digital Resilience: 4
- Financial Resilience: 7
Technology vendors
- Acquia, Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Centerasecurity — Technology — Denmark
- and 7 more
Services catalogue
1 service in catalogue across 1 category; runs on 10 sub-vendors.
- Financial sponsorship
Insights
Last updated 2026-09-13 · revision 2
10 direct vendors, 164 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 4
- United States: 3
- Belgium: 1
Subvendors by controlling owner country (sample)
- Belgium: 1
- Czech Republic: 2
- France: 3
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Bruun & Hjejle's migration readiness is assessed as medium-low, primarily due to significant unknowns regarding its technical foundation and vendor dependencies. The absence of information regarding the internal tech stack and key technologies suggests a lack of modern, cloud-native architectures (e.g., containerization, microservices). This implies a likely legacy or monolithic environment, which would require substantial re-platforming or re-architecting efforts, posing a significant challenge and cost for any migration initiative. Data on the regulatory environment and specific data residency requirements is not provided, introducing potential complexities and risks that would need thorough assessment during migration planning. Similarly, information on financial stability, crucial for funding a potentially costly migration, is unavailable. Regarding vendor relationships, the data is contradictory: 'Total Vendors: 0' would imply minimal vendor lock-in, which is highly favorable for migration readiness. However, the presence of 'Total Services: 11' and details about 'Vendor HQ Countries' and 'Vendor Owner Countries' suggests external dependencies. The 'Vendor Lock-in Risk: Unknown' is a critical concern, as high lock-in could significantly impede migration flexibility and increase costs. While the geographic diversity of these service providers (3 unique HQ countries, 5 unique owner countries) is present, it could also add complexity to migration planning and coordination if these services are deeply integrated across different providers and jurisdictions.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is an American Institute of CPAs (AICPA) framework primarily relevant for technology and cloud service providers. Bruun & Hjejle is a law firm, not a cloud/SaaS provider, so SOC 2 is not directly mandated. However, large international clients (particularly US-based or multinational corporations) increasingly require their legal advisors and professional service firms to demonstrate SOC 2 compliance or equivalent information security assurance as part of vendor due diligence. Risk level is Medium because while not legally mandated, the absence of SOC 2 or equivalent certification could affect the firm's ability to win mandates from security-conscious international clients. The firm's focus on complex transactions suggests significant international client exposure.
Evidence: https://www.aicpa-cima.com/resources/landing/soc-2, https://www.bruunhjejle.dk
ISO 27001 (source) — Assessment Required
ISO 27001 is not legally mandated for law firms in Denmark, but it is highly relevant given the sensitivity of client data handled by law firms (M&A transactions, litigation strategy, financial data). The Danish legal market increasingly expects law firms to demonstrate robust information security. Large corporate clients and financial institutions routinely require ISO 27001 certification or equivalent from their legal advisors. Risk level is Medium because while not legally required, the reputational and commercial risk of a data breach at a law firm handling sensitive transaction data is significant. Non-certification may limit the firm's ability to serve security-conscious clients.
Evidence: https://www.iso.org/isoiec-27001-information-security.html, https://www.bruunhjejle.dk
GDPR (source) — Assessment Required
Bruun & Hjejle is a Danish law firm headquartered in Copenhagen, Denmark — an EU member state — making GDPR unconditionally applicable. Law firms process extensive volumes of highly sensitive personal data including client identities, financial records, litigation details, employment data, and potentially special-category data (e.g., health, criminal proceedings). The Danish Data Protection Authority (Datatilsynet) is an active enforcer with a track record of auditing professional services firms. Non-compliance risks include fines up to €20M or 4% of global annual turnover, reputational damage, and loss of client trust — all particularly severe for a law firm whose business depends on confidentiality and trust. The risk level is High due to the volume and sensitivity of personal data processed, the firm's role as both a data controller and data processor for clients, and the active Danish regulatory enforcement environment.
Evidence: https://www.bruunhjejle.dk, https://www.datatilsynet.dk/english, https://gdpr-info.eu/, https://www.datatilsynet.dk/afgoerelser-domme-og-udtalelser
Financials
Three-year financials
- 2025: revenue DKK 711M, EBIT DKK 11.1M, equity DKK 3.75M
- 2024: revenue DKK 602M, EBIT DKK 12.4M, equity DKK 3.50M
- 2023: revenue DKK 530M, EBIT DKK 11.0M, equity DKK 3.50M
Financial Resilience Score: 7/10
Bruun & Hjejle is one of Denmark's oldest and most established law firms (founded 1878), consistently ranked among the top-tier Danish commercial law firms ('de fem store'). The firm benefits from a strong brand, diversified practice areas (M&A, real estate, disputes, capital markets, tax), and a steady flow of premium mandates from international corporates and funds using it as Danish counsel. As an advokatpartnerselskab, profits are distributed to partners, limiting ongoing capital needs and leverage risk. Historically reported revenue is in the range of DKK 500–700 million annually, placing it among the top 5–7 largest Danish law firms by revenue. However, exact figures for the last three fiscal years could not be verified in this session as CVR filings were not accessible. Key risks include cyclicality tied to Danish and Nordic M&A and real estate deal flow, key-person dependency on senior partners, rising Danish legal salaries pressuring margins, and limited international scale as a single-office Copenhagen-based firm competing against magic-circle and pan-Nordic firms.
Key strengths: One of Denmark's oldest law firms (founded 1878) with strong brand recognition, Top-tier ranking among Danish commercial law firms ('de fem store'), Diversified practice areas reducing single-sector exposure, Steady flow of premium mandates (M&A, real estate, IP litigation), Partnership model (advokatpartnerselskab) limits capital needs and leverage, Recognized in Chambers, Legal 500, and IFLR1000
Risk factors: Cyclicality of transactions exposed to Danish and Nordic M&A/real estate deal flow, Key-person dependency on senior partners, Rising Danish legal salaries pressuring margins, Limited international scale as single-office Copenhagen firm, Competition from magic-circle and pan-Nordic firms
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 275
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.