JN Data A/S
Denmark · owned by Independent (Denmark) · jndata.dk · 13 vendors
JN Data is a Danish IT operations and infrastructure company that provides critical IT services to the Danish financial sector, including mobile banking and payment processing. Founded in 2002 as a joint venture between Jyske Bank and Nykredit, it now serves six financial-sector customers with 24/7 IT operations and datacenter services. The company is jointly owned by the two bank IT cooperatives BEC and Bankdata, as well as Jyske Bank and Nykredit.
Resilience scores
- Digital Sovereignty: 38
- Digital Resilience: 7
- Financial Resilience: 8
Technology vendors
- Adobe Inc. — Technology — United States
- Flexera — United States
- Jyske Bank A/S — Financial Services — Denmark
- and 10 more
Services catalogue
31 services in catalogue across 8 categories; runs on 13 sub-vendors.
- WinCable
- Data Canopy Colocation
- secure data access
Insights
Last updated 2026-09-13 · revision 8
13 direct vendors, 202 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 2
- Denmark: 4
- Luxembourg: 1
Subvendors by controlling owner country (sample)
- Norway: 4
- Canada: 3
- India: 4
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
JN Data A/S exhibits a medium level of migration readiness (Score: 45). The primary challenge to migration readiness is the heavy reliance on legacy mainframe computing (IBM Z-series) for mission-critical banking and financial applications. Migrating these complex, often monolithic, workloads to modern cloud-native environments would be a substantial, costly, and time-consuming undertaking. Strict data residency requirements, stemming from GDPR and Danish financial regulations, mandate that data remains within approved EU/Danish jurisdictions, which significantly limits the choice of cloud providers and requires meticulous architectural planning for any cloud migration. Furthermore, the 'Assessment Required' status for key compliance frameworks like NIS2, SOC2, and ISO 27001 means that these regulatory hurdles would need to be fully addressed and integrated into any migration strategy, adding complexity and potential delays. Despite the data stating 'Total Vendors: 0', other vendor-related information (e.g., 'Vendor HQ Countries', 'Vendor Geographic Diversity', 'Total Services: 17', and the 'Shared IT Procurement Cooperative') indicates the presence of external vendor relationships. The 'Vendor Lock-in Risk: Unknown' is a concern, and the mainframe itself implies a degree of vendor lock-in. On the positive side, JN Data has existing 'Cloud & Hybrid Infrastructure' and 'Software-Defined Infrastructure' capabilities, indicating some foundational experience with modern environments. Their stable financial position (DKK 2,533M revenue in 2024) also provides the necessary resources to fund a complex migration effort.
Compliance
8 in-scope frameworks identified; showing 3.
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act supplements GDPR with national-specific provisions and is directly applicable to JN Data A/S as a Danish company. JN Data explicitly references the Databeskyttelsesloven §6(1) in its privacy policy as a legal basis for processing, confirming awareness and applicability. The Act includes specific Danish provisions on employee data, CPR number (Danish personal identification number) processing, and sector-specific rules. Given JN Data processes data for financial institutions, CPR number processing is highly likely, which requires specific legal authorization under Danish law. The risk is High due to the sensitivity of financial data and the active enforcement posture of Datatilsynet.
Evidence: https://www.jndata.dk/om-os/privatlivspolitik/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502
EBA Outsourcing Guidelines — Assessment Required
The EBA Guidelines on Outsourcing Arrangements directly govern the relationship between JN Data's financial institution clients and JN Data as their IT service provider. Under these guidelines, financial institutions (Jyske Bank, Nykredit, etc.) must conduct thorough due diligence on JN Data, maintain exit strategies, ensure audit rights, and monitor JN Data's performance and security continuously. JN Data, as the outsourced IT provider, must contractually support all these requirements. Non-compliance by the financial institutions due to inadequate oversight of JN Data could result in regulatory action by Finanstilsynet. This creates strong indirect compliance pressure on JN Data. The risk is High because JN Data is classified as a critical outsourcing arrangement for its clients (IT operations for banking infrastructure).
Evidence: https://www.eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-outsourcing-arrangements, https://www.finanstilsynet.dk/, https://www.jndata.dk/om-os/historie/, https://www.jndata.dk/forretning/kunder/
ISAE 3000 (source) — Assessment Required
ISAE 3402 (Assurance Reports on Controls at a Service Organization) is the European standard equivalent to SOC 2 and is the most commonly used assurance framework for IT service providers to financial institutions in Denmark and the EU. JN Data's financial institution clients are required by Finanstilsynet, EBA outsourcing guidelines (EBA/GL/2019/02), and DORA to obtain independent assurance over their outsourced IT service providers' controls. An ISAE 3402 Type II report from JN Data would be a standard contractual requirement from clients like Jyske Bank and Nykredit. The risk is Medium because while not legally mandated for JN Data directly, the absence of such reporting would create significant compliance gaps for its regulated clients, potentially jeopardizing client relationships.
Evidence: https://www.jndata.dk/forretning/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3402-assurance-reports-controls-service, https://www.finanstilsynet.dk/, https://www.eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-outsourcing-arrangements
Financials
Three-year financials
- 2025: revenue DKK 2.55B, EBIT DKK 10.9M, equity DKK 389M
- 2024: revenue DKK 2.53B, EBIT DKK 14.8M, equity DKK 381M
- 2023: revenue DKK 2.26B, EBIT DKK 12.3M, equity DKK 366M
Financial Resilience Score: 8/10
JN Data A/S demonstrates strong financial resilience underpinned by its unique cost-plus business model and ownership structure. As a jointly-owned IT operations company serving Jyske Bank, Nykredit, Bankdata, BEC, SDC, and EG A/S, revenue is highly predictable and has grown every year since 2020, reaching DKK 2.53B in 2024 (+12.3% YoY). The equity base has grown consistently from DKK 329.7M in 2019 to DKK 380.9M in 2024, with solvency ratio improving to 44.1% (from 31.4% in 2020), reflecting a strong balance sheet. Cash generation is robust — operating cash flow was DKK 237.8M in 2024 and DKK 253.4M in 2023 — comfortably funding capex of ~DKK 175-180M annually. Profitability is deliberately thin (net margin ~0.4%) due to the cost-plus pricing model, but this is by design rather than a sign of financial weakness. All five prior Finanstilsyn (Danish FSA) orders have been closed, and the company received Deloitte's Best Managed Companies award in 2024. Key risks include extreme customer concentration (six customers = 100% of revenue), structurally thin margins with little cushion for cost overruns, and cyber/operational resilience risk as a critical financial infrastructure provider. Contractual obligations of at least DKK 860M and lease obligations of DKK 67M represent a sizable fixed-cost base. Overall, the ownership-customer alignment substantially mitigates the concentration risk, supporting a strong resilience score.
Key strengths: Locked-in owner-customer base ensures highly predictable revenue, Consecutive years of revenue growth (6-year CAGR ~4.4%), Strong and improving solvency ratio (44.1% in 2024), Robust operating cash flow (DKK 237.8M in 2024), Consistent positive net income (DKK 8.6-10.3M annually), All Finanstilsyn regulatory orders closed by 2023, Cost-plus pricing structurally protects against demand risk
Risk factors: Extreme customer concentration — 6 customers generate 100% of revenue, Structurally thin net margin (~0.4%) with limited cushion for cost overruns, Cybersecurity and operational resilience risk as critical financial infrastructure, Large fixed contractual obligations (at least DKK 860M), Lease obligations of DKK 67M, FX exposure (USD, PLN) managed via hedging, Geopolitical exposure via Warsaw, Poland branch
Revenue by geography
- Denmark: 99.93%
- Foreign: 0.07%
Revenue by product/service
- IT operations, technology, infrastructure and procurement community services: 100%
Workforce by country
- Denmark: 700
- Poland: 225
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.