Datatilsynet

Denmark · owned by Independent (Denmark) · datatilsynet.dk · 7 vendors

Datatilsynet is the central independent Danish supervisory authority responsible for ensuring compliance with data protection rules, including the GDPR. It advises and guides both public authorities and private companies, handles complaints from citizens, and conducts inspections. It is headquartered at Carl Jacobsens Vej 35, 2500 Valby, Denmark.

Resilience scores

Technology vendors

Insights

Last updated 2026-05-20 · revision 2

7 direct vendors, 142 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 1/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Assessing the migration readiness of Datatilsynet (a government regulatory body) in the context of migrating *its own* internal systems requires detailed knowledge of its internal technology stack, architecture, and operational practices, which are not publicly available. The prompt's scoring criteria (legacy tech stack, monolithic architecture, cloud-native, microservices) are designed for commercial entities developing and selling software, not typically for a regulatory agency's internal IT infrastructure. Without this specific internal information, providing a meaningful score would be speculative and unverified. (Confidence: High, Source: Lack of public information regarding Datatilsynet's internal IT infrastructure.)

Financials

Three-year financials

Financial Resilience Score: 9/10

Datatilsynet is the Danish Data Protection Authority, an independent public-sector regulator under the Ministry of Justice, not a commercial company. Its funding comes directly via appropriations on the Danish state budget (Finansloven), meaning its credit and solvency risk is effectively that of the Kingdom of Denmark (AAA/Aaa rated). There is no commercial revenue risk, no shareholders, and no equity in the commercial sense. The 2025 appropriation is DKK 60.1 million supporting approximately 74 employees. The authority benefits from a strong political mandate—GDPR enforcement is an EU treaty obligation, and the role is statutorily protected as independent. Budget trajectory has been consistently upward since GDPR took effect in May 2018, growing from a small pre-GDPR office of ~30 staff to ~74 in 2025, with the budget rising from low-double-digit DKK millions to DKK 60.1M. Fines collected under GDPR flow to the Danish state treasury rather than to Datatilsynet itself, decoupling the budget from enforcement volume. Key pressures include workload growth outpacing resources (9,849 breach notifications and 20,536 new cases in 2025 against ~74 FTEs, with 92-day average complaint case-handling time), exposure to political/budget cycles as a Finanslov line-item, and scope creep from added responsibilities like the National Whistleblower Unit and joint reporting with Tilsynet med Efterretningstjenesterne from FY2024 onward.

Key strengths: Sovereign funding backed by Kingdom of Denmark (AAA/Aaa), Strong statutory mandate as independent EU GDPR enforcement authority, Multi-year upward funding trend since GDPR (2018), DKK 60.1M appropriation in 2025, Budget decoupled from fine collection (fines go to treasury)

Risk factors: Workload growth outpacing resources (~74 FTEs handling 20,536 new cases and 9,849 breach notifications in 2025), Political/budget cycle exposure as Finanslov line-item, Scope creep from added responsibilities (Whistleblower Unit, joint reporting with Intelligence Services Oversight Board), Reputational risk from high-profile decisions and EU one-stop-shop cases, 92-day average complaint case-handling time reflects capacity strain

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report