Dataproces

Denmark · owned by Independent (Denmark) · dataproces.dk · 14 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 14 sub-vendors.

Insights

Last updated 2026-09-13 · revision 1

14 direct vendors, 196 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Dataproces demonstrates medium migration readiness. The company's internal tech stack, featuring Next.js, Vercel, and Cloudflare, along with its SaaS product offerings, suggests a modern, potentially cloud-native or cloud-friendly architecture. This foundation is a strong enabler for future migrations, indicating a higher likelihood of compatibility with modern cloud platforms and practices. However, several critical pieces of information are missing, which significantly impede a full assessment of migration readiness. There is no data available on regulatory environment or data residency requirements, both of which are paramount for planning and executing a compliant migration, especially for a company serving municipalities. Financial stability data (revenue concentration, growth history) is also absent, making it impossible to assess the company's capacity to fund a potentially complex migration. Additionally, while the company utilizes 18 services with vendors from 8 diverse countries, the specific vendor lock-in risk remains unknown, which is a key factor in determining migration complexity and cost. The number of services (18) could also imply a complex integration landscape that would need careful planning during migration.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Dataproces is headquartered in Denmark (EU) and processes highly sensitive personal data — including CPR numbers (Danish national ID), health data, criminal records, and social welfare data — on behalf of Danish municipalities. As a data processor under GDPR Article 28, they operate under strict municipal data processing instructions. The company demonstrates substantial compliance maturity: a formally appointed DPO (Poul Schmith/Kammeradvokaten), detailed privacy notices covering all processing activities, documented legal bases for each processing activity, data subject rights procedures, and a whistleblower channel. However, the status is 'Partially Compliant' rather than 'Compliant' because no independent third-party GDPR audit or certification has been publicly evidenced, and full compliance cannot be confirmed without such verification. Risk is Medium (not High) because the company clearly invests heavily in GDPR compliance infrastructure, reducing the likelihood of systemic non-compliance, but the sensitivity of the data processed (CPR numbers, health data, criminal records for municipalities) means any breach would carry significant regulatory and reputational consequences. Danish Datatilsynet (DPA) enforcement is active and has issued fines to public sector data processors.

Evidence: https://dataproces.dk/datasikkerhed, https://dataproces.dk/, https://www.datatilsynet.dk/, https://dataproces.dk/organisationen

Danish Whistleblower Protection Act — Compliant

The Danish Whistleblower Protection Act (Lov nr. 1436 af 29/06/2021, implementing EU Whistleblower Directive 2019/1937) requires companies with 50+ employees to establish an internal whistleblower channel. Dataproces has implemented a comprehensive whistleblower policy and secure reporting channel (via HaileyHR). The policy covers all required elements: anonymous reporting, confidentiality, non-retaliation, 7-day acknowledgment, 3-month response timeline, and GDPR-compliant data handling. Risk is Low as the company has clearly implemented a compliant whistleblower system. Note: if Dataproces has fewer than 50 employees, the mandatory channel requirement may not apply, but they have implemented it voluntarily, which is best practice.

Evidence: https://dataproces.dk/datasikkerhed, https://haileyhr.app/whistleblowing/583a6e63-2b63-465d-8bf1-5b79ba0afa08

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, implemented in Denmark via Lov om sikkerhed i net- og informationssystemer) applies to Essential and Important Entities in listed sectors. Dataproces operates as a digital provider/ICT service management company serving Danish municipalities (public administration). Two potential NIS2 angles exist: (1) As an ICT service management provider (Managed Service Provider) to public administration entities, Dataproces could fall under NIS2 Annex I or II depending on size and classification; (2) Their municipal clients are likely NIS2-regulated entities (public administration), which may impose contractual NIS2-aligned security requirements on Dataproces as a supplier. However, Dataproces is a small-to-medium Danish company (estimated under 50 employees based on the organizational chart showing ~10 named leadership/team members), which may place them below the NIS2 size threshold (50+ employees OR €10M+ turnover for Important Entities). Risk is rated Low because: (a) size threshold may not be met, (b) they are not in a primary NIS2 sector themselves, (c) their existing GDPR and ISAE-adjacent security practices already address many NIS2 technical requirements. Assessment is required to confirm employee count, turnover, and formal sector classification.

Evidence: https://dataproces.dk/datasikkerhed, https://www.cfcs.dk/, https://dataproces.dk/

Financials

Three-year financials

Financial Resilience Score: 8/10

Dataproces Group A/S demonstrates strong financial resilience for a small-cap SaaS company. The company achieved a successful turnaround from significant losses in 2022/23 (EBIT -DKK 8.6m) to solid profitability by 2024/25 (EBIT DKK 8.5m, EBITDA margin 40.4%). The balance sheet is robust with a solvency ratio of approximately 61%, cash reserves of DKK 25.4m, and modest long-term debt of only DKK 4.8m. Equity nearly doubled in 2025/26 to DKK 52.9m following a capital raise associated with the Boelplan acquisition. Recurring revenue provides strong visibility, with ARR reaching DKK 28.6m (56% of total revenue) and historically low customer churn. The customer base of 90 out of 98 Danish municipalities represents a payment-strong public sector clientele with minimal credit risk. ARPA grew 20% year-over-year to DKK 318,000, indicating successful upsell dynamics. Risks include the small Danish home market (only 98 municipalities), execution risk on the ambitious 2030 revenue target of DKK 200m (requiring successful international M&A), and short-term margin compression as the company invests in German expansion and product development. The First North listing carries liquidity risk, and the stock has been volatile amid broader SaaS-sector concerns about AI disruption.

Key strengths: Solvency ratio of ~61% at end-FY2025/26, Cash position of DKK 25.4M providing acquisition flexibility, ARR of DKK 28.6M representing 56% of revenue with low churn, 90 of 98 Danish municipalities as customers (payment-strong public sector), Equity nearly doubled to DKK 52.9M in 2025/26, Modest long-term debt of only DKK 4.8M, EBITDA margin of 34.2% in 2025/26 (peak 40.4% in 2024/25), ARPA growth of 20% YoY to DKK 318,000

Risk factors: Small Danish home market (only 98 municipalities), Execution risk on 2030 target of DKK 200M revenue, Margin compression from growth investments (EBITDA margin declining), Concentrated public-sector customer base with long sales cycles, Limited liquidity on Nasdaq First North; stock down ~19% in 2026, AI disruption risk to broader SaaS sector, International expansion execution risk (Germany, potentially Sweden/Norway)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report