DBC (Dansk BiblioteksCenter)
Denmark · owned by KL (Denmark) · www.dbc.dk · 16 vendors
Resilience scores
- Digital Sovereignty: 38
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- and 13 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- Fælles Bibliotekssystem
Insights
Last updated 2026-09-13 · revision 2
16 direct vendors, 212 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Australia: 1
- Austria: 2
Subvendors by controlling owner country (sample)
- Finland: 2
- China: 1
- Cyprus: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DBC exhibits a high technical readiness for migration, primarily driven by its modern tech stack. The extensive use of Kubernetes, containerization, open-source software, GraphQL/REST APIs, and an Agile development methodology makes their systems highly portable and adaptable to cloud-native environments. Their existing 'GDPR-compliant data architecture' and 'Privacy by Design' principles would also streamline compliance during a migration. However, several factors temper their overall migration readiness. DBC's explicit strategic focus on 'Digital Sovereignty Infrastructure' and 'On-Premises Private Data Centers' suggests a strong organizational preference for their current internal cloud model, which could present a significant strategic hurdle for a full migration to public cloud. While not explicitly stated, it is highly probable that national infrastructure like theirs has strict data residency requirements within Denmark, potentially limiting public cloud options. Information on financial stability (ability to fund a large migration) and specific vendor lock-in risks is unknown. While vendor geographic diversity is good, the exact number of vendors and contract complexities are not detailed, making vendor lock-in an unknown but potential challenge.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
Given DBC DIGITAL's role in critical infrastructure and emphasis on IT security, ISO 27001 certification would be highly valuable. Risk is medium as lack of formal ISMS certification could impact customer confidence and competitive positioning, especially for critical infrastructure providers.
Evidence: https://dbcdigital.dk/vores-dna/it-datasikkerhed/
NIS2 (source) — Assessment Required
DBC DIGITAL operates critical digital infrastructure for Denmark's library system and explicitly describes their services as 'kritisk data- og it-infrastruktur'. They provide ICT services and digital infrastructure that could qualify as Important Entities under NIS2. The high risk stems from potential significant penalties for non-compliance and the critical nature of their infrastructure services. However, definitive classification requires formal assessment of their exact services against NIS2 criteria.
Evidence: https://dbcdigital.dk/vores-dna/kritisk-data-og-it-infrastruktur/, https://dbcdigital.dk/om-os/
GDPR (source) — Compliant
DBC DIGITAL is headquartered in Denmark (EU) and processes extensive personal data including library user data, employee data, and customer data. They have a comprehensive privacy policy demonstrating GDPR compliance awareness, including DPO appointment and detailed data processing descriptions. Risk is medium due to the extensive personal data processing across multiple services, but they show strong compliance framework.
Evidence: https://dbcdigital.dk/privatlivspolitik/
Financials
Three-year financials
- 2025: revenue DKK 187M, EBIT DKK 2.66M, equity DKK 48.3M
- 2024: revenue DKK 181M, EBIT DKK 2.91M, equity DKK 46.1M
- 2023: revenue DKK 175M, EBIT DKK 5.16M, equity DKK 43.3M
Financial Resilience Score: 7/10
DBC DIGITAL A/S exhibits strong balance sheet resilience underpinned by its quasi-public role as operator of Denmark's shared library infrastructure (FBI). Revenue has grown steadily every year (CAGR ~3.2% from 2023 to 2025), and the equity base has strengthened from DKK 43.3M to DKK 48.3M, with a very high solvency ratio of 64.4% in 2025. Ownership by KL (Kommunernes Landsforening) and the statutory anchoring of its services provide exceptional revenue predictability and minimal customer churn risk. However, profitability is thin and deteriorating. EBIT margin has compressed from 2.9% in 2023 to just 1.4% in 2025, as personnel costs (+14.4% over two years) have grown more than twice as fast as revenue (+6.6%). Net profit has roughly halved over the period (DKK 4.5M to DKK 2.2M), and rising CapEx on AI initiatives and Danish data centres (DKK 4.2M to DKK 6.9M) will pressure future operating profit through depreciation. The company is also highly concentrated — single country, single language, single public-sector vertical — which limits diversification but is offset by its mission-critical role.
Key strengths: Stable, recurring public-sector revenue with steady ~3% annual growth, Very strong solvency ratio of 64.4% (2025), Equity growth of 11.6% over two years, Owned by KL (Danish municipalities' association), providing quasi-public mandate, Improving gross margin (64.7% to 67.7%), Operator of statutorily anchored national library infrastructure
Risk factors: Thin and deteriorating EBIT margin (2.9% to 1.4%), Personnel costs growing faster than revenue (+14.4% vs +6.6%), Net profit halved over two years, Customer concentration on Danish public sector / KL, Rising CapEx pressuring future profitability, Single-country, single-vertical exposure with no geographic diversification
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 159
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.