DAT A/S

dat.dk · 46 vendors

Resilience scores

Technology vendors

Insights

Last updated 2026-07-03 · revision 15

46 direct vendors, 404 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DAT A/S exhibits low migration readiness, scoring 25, primarily due to several significant unknowns and the nature of its current technology stack. The internal tech stack, heavily reliant on WordPress and Elementor, suggests a traditional web architecture that is likely not cloud-native, containerized, or microservices-based. Migrating such a system to a modern cloud environment would typically involve substantial re-architecture and effort. A major impediment is the "Unknown" vendor lock-in risk. With 69 services identified, there's a high likelihood of numerous vendor dependencies, and without clarity on lock-in, the cost and complexity of disentangling these relationships for migration are uncertain. The absence of data residency requirements is another critical gap; if strict requirements exist, they could severely limit cloud migration options and increase compliance overhead. Similarly, the lack of financial data (revenue concentration, growth history) makes it impossible to assess the company's capacity to fund a potentially costly and complex migration initiative. Furthermore, the regulatory environment, including GDPR and the required NIS2 assessment, adds layers of compliance complexity that must be carefully managed during any migration. While vendor geographic diversity is a resilience strength, it can complicate migration planning and coordination across multiple international providers. Overall, the combination of a potentially legacy tech stack, significant vendor-related unknowns, and critical missing data points to substantial challenges for a smooth and efficient migration.

Compliance

9 in-scope frameworks identified; showing 3.

Danish Bookkeeping Act — Assessment Required

As a Danish A/S (Aktieselskab — public limited company), DAT A/S is subject to Danish financial reporting and bookkeeping requirements. The Danish Bookkeeping Act (Bogføringsloven, consolidated act no. 700 of 2023) requires digital bookkeeping and data retention for 5 years. The Annual Accounts Act (Årsregnskabsloven) requires annual financial statements. Risk is Low as these are standard compliance requirements for all Danish companies, and DAT A/S as an established company since 1989 is expected to have these in place. No evidence of non-compliance has been found.

Evidence: https://datacvr.virk.dk/enhed/virksomhed/12654693, https://dat.dk/corporate/

ISO 27001 (source) — Assessment Required

No ISO 27001 certification has been found for DAT A/S. Given that DAT A/S is an airline processing sensitive passenger data (PII, payment card data, travel history), operating safety-critical aviation IT systems, and likely subject to NIS2 as an Essential Entity, the absence of ISO 27001 certification represents a significant risk. ISO 27001 is widely regarded as the baseline information security standard for aviation and transport operators. Risk is High because: (1) NIS2 Art. 21 requires Essential Entities to implement cybersecurity risk management measures that align closely with ISO 27001 controls; (2) aviation cybersecurity is increasingly regulated (EASA Regulation 2023/203 on cybersecurity for aviation); (3) DAT processes payment card data (PCI DSS relevance) and sensitive passenger data; (4) ACMI/wet lease operations expose DAT's systems to partner airline networks globally; (5) the absence of a publicly verifiable ISMS certification increases the likelihood of undetected security gaps.

Evidence: https://dat.dk/privacy_policy_dk-2/, https://dat.dk/corporate/, https://www.easa.europa.eu/en/domains/cyber-security

EU Air Passenger Rights Regulation — Partially Compliant

EC 261/2004 establishes rights for air passengers in cases of denied boarding, cancellation, and long delays. DAT A/S operates scheduled passenger services within the EU and is therefore directly subject to this regulation. DAT publishes information about delayed and cancelled flights ('Forsinkede og aflyste fly') on its website, indicating awareness of obligations. Risk is Medium because: (1) airlines are frequently subject to complaints and enforcement actions under EC 261/2004; (2) the Danish Civil Aviation Authority (Trafikstyrelsen) enforces this regulation in Denmark; (3) no specific compliance audit or enforcement history has been found, but the airline industry generally has high complaint rates under this regulation.

Evidence: https://dat.dk/rejseinfo/forsinkede-og-aflyste-fly/, https://dat.dk/, https://www.trafikstyrelsen.dk/en

Financials

Three-year financials

Financial Resilience Score: 5/10

DAT A/S is a small, privately owned Danish regional airline whose economics are anchored by the Bornholm PSO (Public Service Obligation) contract, providing a stable government-backed revenue floor for its core domestic route. The company's diversified business model — combining scheduled passenger service, ACMI wet-lease, and ad-hoc charter operations — helps smooth cyclical demand and improve aircraft utilization. Its mixed fleet of ATR turboprops and A320-family jets allows it to serve thin regional routes economically while bidding on jet-capacity ACMI contracts. As an owner-managed private company with a long operating history since 1989, DAT faces no dividend pressure from public shareholders and has historically taken a conservative growth approach. However, resilience is constrained by significant risks. Route concentration on the Bornholm PSO creates a material single-point exposure at tender renewal. The company's small scale limits its buffer against fuel price shocks, currency swings (USD exposure for fuel, leasing, and maintenance against DKK/EUR revenue), or downturns in ACMI demand. Regulatory pressures including the Danish green flight tax, EU ETS, and future SAF mandates will raise unit costs. Fleet age is also a concern, with capital reinvestment in newer/greener aircraft a challenge for a company of this size. Regional aviation's thin margins and high operating leverage to load factors further limit resilience. COVID-19 caused multi-million DKK losses in FY2020-2021, though recovery was reported in 2022-2023.

Key strengths: Government-backed PSO contract on Copenhagen–Bornholm route provides stable revenue floor, Diversified business model: scheduled passenger + ACMI wet-lease + ad-hoc charter, Mixed fleet (ATR turboprops + A320-family jets) enables flexible route economics and ACMI bidding, Long operating history since 1989 with strong brand as Bornholm 'livslinje', Owner-managed private company with no public dividend pressure, Recovery to and past pre-pandemic revenue levels reported in 2022-2023

Risk factors: Route concentration risk: Bornholm PSO loss at tender renewal would be material, Small scale limits buffer against fuel price shocks and currency swings, Danish green flight tax and EU ETS/SAF mandates will raise cost per seat, Aging ATR turboprop fleet requires capital reinvestment challenging for company size, Thin margins typical of regional aviation with high operating leverage to load factors, FX exposure to USD (fuel, leasing, maintenance) against DKK/EUR revenue base, COVID-19 pandemic caused significant multi-million DKK losses in FY2020-2021

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report