GlobalConnect A/S
Denmark · owned by EQT Infrastructure (Sweden) · www.globalconnect.dk · 46 vendors
GlobalConnect A/S is one of the leading providers of digital infrastructure and data communications in the Nordic countries, operating over 235,000 kilometres of fibre network across Denmark, Norway, Sweden, Germany, and Finland. The company delivers fibre-based broadband services to more than 800,000 private consumers and end-to-end network solutions to over 30,000 B2B customers, including managed networking, cybersecurity, cloud, and telephony services. GlobalConnect is headquartered in Copenhagen, Denmark (CVR 26759722) and handles more than 50% of all data traffic in the Nordics.
Resilience scores
- Digital Sovereignty: 28
- Digital Resilience: 5
- Financial Resilience: 5
Disruption prediction
GlobalConnect A/S has an estimated 11% probability of disruption in the next 6 months.
18 of GlobalConnect A/S's 46 vendors monitored for disruptions.
Technology vendors
- Dealfront — Technology — Germany
- Netlify, Inc. — Technology — United States
- Zscaler, Inc. — Cybersecurity — United States
- and 44 more
Services catalogue
23 services in catalogue across 6 categories; runs on 46 sub-vendors.
- GlobalConnect CDN
- GlobalConnect DNS
- Dedicated Servers
Insights
Last updated 2026-09-13 · revision 32
46 direct vendors, 412 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 4
- India: 2
- Australia: 2
Subvendors by controlling owner country (sample)
- Italy: 2
- Belgium: 5
- Canada: 15
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
GlobalConnect A/S exhibits medium migration readiness, leaning towards the lower end, primarily due to a complex regulatory environment and potential operational vendor lock-in. The company's internal tech stack is mixed; while it leverages modern IAM solutions like Keycloak/OpenID Connect and SaaS platforms like Microsoft Teams, its public-facing websites rely on WordPress and Divi, which may represent legacy components requiring careful consideration during migration. Conversely, GlobalConnect's product offerings, such as SD-WAN, SASE, Cloud Access, and CCaaS, demonstrate a strategic understanding and capability in cloud-oriented services, which could be leveraged for internal migration efforts. Migration readiness is significantly challenged by the high-risk regulatory landscape. NIS2 and the EU Electronic Communications Code (EECC) are critical for a telecommunications provider and will impose stringent requirements on any migration, particularly concerning security, incident reporting, and supply chain integrity. The 'Partially Compliant' status for GDPR and the Danish Data Protection Act, coupled with explicit EU/EEA data residency requirements, further restrict the choice of cloud providers/regions and necessitate meticulous data governance planning. The absence of publicly available SOC 2, ISO 27001, or ISAE 3402 reports means additional effort may be required to provide assurance to customers and regulators during and after migration. Despite the provided data stating "Total Vendors: 0", the December 2023 Kista fire incident clearly indicates reliance on critical subcontractors for infrastructure, which could lead to operational vendor lock-in and complicate migration if these relationships are deeply embedded or inflexible. While the geographic diversity of listed vendor HQs/owners is good, the operational concentration risk with critical infrastructure partners remains. On the positive side, GlobalConnect's stable financial growth provides the capacity to fund necessary migration investments, and its well-defined EU/EEA data residency policy, while a constraint, simplifies the scope of acceptable cloud environments.
Compliance
10 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
GlobalConnect A/S is headquartered in Denmark (EU member state) and processes personal data of customers, employees, suppliers, and end-users across Denmark, Sweden, Norway, Germany, and Finland. GDPR is unconditionally applicable. Risk is rated High because: (1) as a major telecommunications and digital infrastructure provider, GlobalConnect processes large volumes of personal data including traffic data, location data, and communications metadata — categories that attract heightened regulatory scrutiny under GDPR Article 5 and the ePrivacy Directive; (2) the Danish DPA (Datatilsynet) is an active enforcement authority with a track record of fining telecoms and digital service providers; (3) cross-border operations across 5+ EU/EEA countries create multi-jurisdictional exposure; (4) the company's privacy policy for business contacts was last updated in September 2021, raising questions about whether it reflects current GDPR guidance and enforcement trends; (5) fines under GDPR can reach €20 million or 4% of global annual turnover, whichever is higher. Status is 'Partially Compliant' because while a privacy policy and data subject rights framework are publicly documented, no independent GDPR audit, DPO appointment disclosure, or Records of Processing Activities (RoPA) are publicly available, and the privacy policy has not been updated since 2021.
Evidence: https://globalconnect.dk/globalconnect-privatlivspolitik-for-forretningsforbindelser/, https://globalconnect.dk/cookies/, https://www.datatilsynet.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Danish Whistleblower Protection Act — Compliant
GlobalConnect A/S has published a Whistleblower Policy ('Whistleblower-politik i GlobalConnect') on its website, demonstrating compliance with the Danish Whistleblower Protection Act (implementing EU Whistleblowing Directive 2019/1937). Risk is Low because the company has demonstrably implemented the required whistleblower channel and policy. The Danish Whistleblower Protection Act applies to companies with 50+ employees, which GlobalConnect clearly exceeds.
Evidence: https://globalconnect.dk/whistleblower-politik-i-globalconnect/, https://www.retsinformation.dk/eli/lta/2021/1436
SOC 2 (source) — Assessment Required
GlobalConnect A/S provides cloud services (Cloud Access, Colocation), managed security services (SOC-as-a-service, Managed SASE, DDoS protection), and managed network services to over 30,000 Nordic businesses. These service categories are precisely those for which enterprise customers routinely require SOC 2 Type II reports as part of vendor due diligence and supply chain security assessments. Risk is Medium because: (1) the absence of a publicly available SOC 2 report may create a competitive disadvantage and customer trust gap, particularly for large enterprise and public sector clients; (2) as GlobalConnect serves as a critical infrastructure provider, its customers (especially in regulated industries like finance and healthcare) may contractually require SOC 2 attestation; (3) however, SOC 2 is a US-origin voluntary framework and European companies often substitute it with ISO 27001 certification — if GlobalConnect holds ISO 27001, the SOC 2 gap is partially mitigated. Risk is not High because SOC 2 is not legally mandated in the EU/EEA.
Evidence: https://globalconnect.dk/produkter/cloud/colocation/, https://globalconnect.dk/produkter/sikkerhed/soc/, https://globalconnect.dk/produkter/cloud/cloudaccess/
Financials
Three-year financials
- 2025: revenue DKK 1.27B, EBIT DKK 17.3M, equity DKK 640M
- 2024: revenue DKK 1.19B, EBIT DKK 47.1M, equity DKK 828M
- 2002: revenue DKK 1.27B, EBIT DKK -134M, equity DKK 822M
Financial Resilience Score: 5/10
GlobalConnect Group demonstrates a mixed financial resilience profile. On the positive side, it owns the largest pan-Nordic fibre backbone (~250,000 km), has a highly recurring contracted revenue base (SEK 7.5bn MRC in 2025), and has consistently grown Adjusted EBITDA to SEK 4.8bn in 2025 with an expanding margin of 59.9% (up from 53.2% in 2023). Organic revenue growth of ~6% and improving operating profit (turning positive in 2024 and tripling in 2025) suggest the business is reaching an inflection point where earnings approach investment levels. However, the group is heavily leveraged with interest-bearing debt of SEK 44bn against equity of only SEK 8.6bn (gross debt/EBITDA ~9x). Equity has eroded by ~38% over three years due to persistent large net losses (SEK -2.15bn in 2025, SEK -2.83bn in 2024, SEK -2.64bn in 2023) driven by heavy depreciation (~SEK 4.3bn/yr) and interest expense (~SEK 2.7-3.2bn/yr). Cash position remains thin (SEK 363m) relative to debt service needs. Mitigating factors include long-dated debt maturities (2028), 64% of debt hedged to fixed rates, full covenant compliance, and strong sponsorship from EQT and Mubadala. The Denmark CGU is flagged as vulnerable to negative DCF changes with SEK 4.1bn of goodwill at risk. Overall, the company has strong operational fundamentals but a strained balance sheet requiring continued sponsor support and successful EBITDA-to-CapEx convergence.
Key strengths: Largest pan-Nordic fibre backbone (~250,000 km) with ~50% of Nordic data traffic, Highly recurring contracted revenue base (SEK 7.5bn MRC in 2025), Strong Adjusted EBITDA growth to SEK 4.8bn (59.9% margin) in 2025, Organic revenue growth of ~6% in both 2024 and 2025, Long-dated debt maturities (2028) with full covenant compliance, 64% of debt hedged to fixed rates, Strong sponsors: EQT Infrastructure III & IV (~84%) and Mubadala, Operating profit turned positive in 2024 and tripled in 2025
Risk factors: Very high leverage: gross debt/Adj. EBITDA ~9x (SEK 44bn debt vs SEK 8.6bn equity), Persistent large net losses (SEK -2.15bn in 2025) eroding equity base, Equity declined 38% over three years (SEK 13.8bn to SEK 8.6bn), Denmark CGU flagged as vulnerable with SEK 4.1bn of goodwill at risk, Physical infrastructure risks: Baltic subsea cable sabotage, cyber threats (NIS2/CER), FX exposure across SEK/EUR/NOK/DKK on debt and revenue, Transition risk from ongoing B2C divestments (Norway to Telenor, Finland to Telia), Thin cash position (SEK 363m) relative to debt service needs, Regulatory risk from NIS2, CSRD and evolving EU frameworks
Revenue by geography
- Sweden (incl. Finland & Norwegian IP-Only): 47.8%
- Denmark (incl. Germany): 26.6%
- Norway: 25.6%
Revenue by product/service
- B2B & GlobalConnect Carrier (GCC): 60.5%
- B2C: 39.5%
Workforce by country
- Sweden (incl. Finland): 730
- Denmark (incl. Germany): 557
- Norway: 446
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.