Danish Agency for Data Supply and Efficiency (SDFE)

Denmark · sdfe.dk · 9 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 9 sub-vendors.

Insights

Last updated 2026-06-18 · revision 2

9 direct vendors, 133 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SDFE exhibits a high degree of migration readiness, largely driven by its modern API-driven architecture, including extensive use of GraphQL and REST APIs for data distribution. This modular approach provides a solid foundation for transitioning services to cloud environments. The agency's engagement with advanced technologies such as Digital Twin initiatives and Bitemporality also suggests sophisticated internal capabilities that can adapt to new platforms. A significant factor contributing to high readiness is the explicit statement of "Total Vendors: 0" in the provided data. If accurate, this eliminates vendor lock-in risks, granting SDFE complete autonomy and flexibility in planning and executing any migration strategy without external contractual or technical dependencies. However, the assessment is constrained by several unknowns: there is no explicit information on current cloud-native adoption (e.g., containerization, microservices), data residency requirements are not specified (a critical consideration for cloud deployments), and details regarding the regulatory environment and financial capacity to fund a large-scale migration are absent. The internal effort required to migrate 22 internally managed services could also be substantial.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR is universally applicable to this agency as a Danish public authority headquartered in Copenhagen, Denmark (EU member state). As a government agency, SDFE/Klimadatastyrelsen processes personal data of employees, contractors, registered users of its data platforms (Datafordeler, Dataforsyningen), and individuals whose data may appear in geospatial or cadastral records. Danish public authorities are subject to both GDPR and the Danish Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018). Non-compliance risk is High because: (1) the agency operates large-scale public data distribution platforms accessible to businesses and citizens; (2) it handles data for the Danish Armed Forces and Emergency Management, which may include sensitive operational data; (3) the Danish Data Protection Authority (Datatilsynet) actively enforces GDPR against public bodies; (4) fines for public authorities under Danish law can reach DKK 10 million (~€1.34M); (5) the agency's privacy policy page exists (confirmed via official website), indicating active GDPR compliance efforts, but no independent audit evidence was found to confirm full compliance status.

Evidence: https://www.eng.klimadatastyrelsen.dk/about-us/privacy-policy, https://www.eng.klimadatastyrelsen.dk/about-us, https://www.klimadatastyrelsen.dk/om-klimadatastyrelsen/politikker-retningslinjer-og-whistleblowerordning, https://www.klimadatastyrelsen.dk/cookies, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA, primarily relevant for cloud service providers and technology companies that store, process, or transmit customer data. While not legally mandated for Danish government agencies, SDFE/Klimadatastyrelsen operates large-scale public data platforms (Datafordeler, Dataforsyningen) that serve as national digital infrastructure for businesses and public authorities. Commercial and government clients accessing these platforms may request SOC 2 assurance. Risk is Medium because: (1) the agency is a public body, not a commercial cloud provider, so SOC 2 is not a regulatory requirement; (2) however, the scale and criticality of its data distribution platforms create reputational and operational risk if security controls are not independently verified; (3) Danish public sector entities typically rely on ISO 27001 or ISAE 3000/3402 rather than SOC 2 for assurance; (4) no SOC 2 report evidence was found.

Evidence: https://datafordeler.dk/, https://dataforsyningen.dk/, https://www.eng.klimadatastyrelsen.dk/about-us

NIS2 (source) — Assessment Required

NIS2 applicability is assessed as High risk and highly likely for the following reasons: (1) The agency operates critical digital infrastructure — specifically the Datafordeler (national Data Distribution Platform) and Dataforsyningen (national data and map supply), which are foundational digital infrastructure services for Danish public administration and businesses; (2) It manages the Register of Underground Cable Owners, which maps underground cables and pipes — directly relevant to critical infrastructure protection; (3) It provides data and map products to the Danish Armed Forces and Emergency Management Agency, placing it squarely within national security-adjacent digital infrastructure; (4) It operates measuring stations in Greenland for ice sheet monitoring — part of climate/environmental monitoring infrastructure; (5) Under NIS2, 'Public Administration' entities at central government level are classified as Essential Entities; (6) 'Digital Infrastructure' providers are Essential Entities under NIS2 Annex I; (7) Denmark transposed NIS2 via the 'Lov om sikkerhed i net- og informationssystemer' (NIS2 Act), effective October 2024. Non-compliance consequences include significant fines and mandatory incident reporting obligations. The agency's size as a national government body clearly exceeds the 50-employee threshold.

Evidence: https://www.eng.klimadatastyrelsen.dk/about-us, https://www.klimadatastyrelsen.dk/, https://www.cfcs.dk/en/, https://www.retsinformation.dk/eli/lta/2023/1697, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://datafordeler.dk/, https://dataforsyningen.dk/

Financials

Three-year financials

Financial Resilience Score: 9/10

SDFE (now Klimadatastyrelsen) is a Danish central government agency, not a commercial entity. As such, it does not face going-concern risk in the conventional sense. Its funding is set annually through the Danish Finanslov (national budget) under §29 (Ministry of Climate, Energy and Utilities), providing extremely stable, state-backed funding. There is essentially no default risk and no equity in a commercial sense. The agency's strategic mandate covering geodata, the Datafordeler platform, climate adaptation data, and defence/emergency services support gives it strong political anchoring across multiple Danish digitalisation and climate strategies. Cross-ministerial customer relationships (Danish Armed Forces, Emergency Management, municipalities) broaden political support for sustained funding. However, the agency faces reorganisation risk — it has already been merged/renamed once into Klimadatastyrelsen in 2023, and further machinery-of-government changes remain possible. Reliance on appropriation means no commercial cushion exists if Finanslov cuts occur, and the 'free basic data' policy limits the ability to grow user-payment revenue to offset such cuts. Large IT programs (Datafordeler, Dataforsyningen) also carry typical public-sector execution risk. Historical order of magnitude suggests an annual operating budget around DKK 250-350M with headcount of ~280-330 FTE, though exact figures could not be verified.

Key strengths: State-backed funding via Danish Finanslov §29, No going-concern risk as central government agency, Strategic political mandate in digitalisation and climate adaptation, Cross-ministerial customer base (Defence, Emergency Management, municipalities), Legal continuity preserved through rebrand (CVR 37 28 41 14 retained)

Risk factors: Reorganisation risk (already renamed once into Klimadatastyrelsen in 2023), Full reliance on annual Finanslov appropriation with no commercial cushion, Limited ability to grow user-payment revenue due to free basic data policy, IT-project execution risk on large platforms (Datafordeler, Dataforsyningen)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report