Denmark banned Helsingør's use of Google Chromebooks/Workspace in schools in 2022 over undocumented data transfers. A five-year probe ended in January 2026 with serious criticism of 51 municipalities, including Copenhagen and Aarhus, for the same unresolved risks.
~53 municipalities
Municipalities covered by the investigation by 2024 (2024)
51 municipalities
Municipalities issued serious criticism at investigation close (29 January 2026)
3 August 2022 date
Deadline to delete transferred data (Helsingør ban) (2022)
Details
Promoter
Datatilsynet (Danish Data Protection Agency)
Period
2021-2026 (Helsingør ban Jul-Aug 2022; national reprimand of 51 municipalities Jan 2026)
Keywords
cloud EdTech, Chromebooks, Google Workspace, third-country data transfers, GDPR enforcement, sub-processor oversight
Context
In September 2021, Denmark's data protection authority, Datatilsynet, first criticised Helsingør Municipality after a data-security breach linked to its use of Google Chromebooks and Google Workspace for Education in primary schools.
Activities
On 14 July 2022, Datatilsynet imposed an outright processing ban on Helsingør (later ratified 18 August 2022), ordering the municipality to stop using the services and delete already-transferred data by 3 August 2022. The authority found that Helsingør had not documented or assessed the risk that pupils' personal data could be transferred to Google's sub-processors outside the EU/EEA for support purposes, and had not adequately tested the hardware and software before deployment. Datatilsynet explicitly warned that its findings would likely apply to other Danish municipalities using the same Google products.
Results
By 2024 the investigation grew to cover roughly 53 municipalities, and on 29 January 2026 Datatilsynet closed the investigation by issuing serious criticism ('alvorlig kritik') to 51 municipalities — including Copenhagen and Aarhus — for failing to document a lawful basis for processing, failing to verify that Google's sub-processors outside the EU/EEA offered data protection essentially equivalent to European standards, and for depending on technical and contractual configurations set unilaterally by the vendor rather than the municipality.
Conclusions
This is a cautionary governance case: it shows that even five years after the initial finding, most Danish municipalities had still not brought their cloud EdTech contracts into documented GDPR compliance, illustrating how difficult it is for individual schools and municipalities to exercise real oversight over global cloud-service sub-processing chains. Independent legal commentary (SSRN, the European Data Protection Law Review) and international press (TechCrunch, CyberNews) have used the case as the reference example for third-country transfer risk in publicly procured EdTech.
Implementation
Indicative cost
High (€500k–€5M) — Not disclosed in financial terms; the case represents a significant compliance/legal remediation burden across 51 municipalities nationally, following an initial processing ban on Helsingør in 2022.
Time to results
Long (> 3 years) — September 2021: initial criticism of Helsingør. 14 July 2022: processing ban issued (ratified 18 August 2022), data-deletion deadline 3 August 2022. By 2024: investigation covers ~53 municipalities. 29 January 2026: investigation closed with serious criticism issued to 51 municipalities.
Staffing & skills
Enforcement led by Datatilsynet (Danish Data Protection Agency), Individual municipalities responsible for their own Google Workspace/Chromebook procurement and data-processing agreements
Conditions for success
Documented lawful basis for processing personal data before deployment
Verification that third-country sub-processors offer data protection essentially equivalent to EU/EEA standards
Municipality-level (not just vendor-level) testing and risk assessment of hardware/software before deployment
Common failure modes
Municipalities relied on technical/contractual configurations set unilaterally by the vendor (Google) rather than their own documented risk assessment
Five years after the first finding, most municipalities still had not achieved documented GDPR compliance
No individual municipality-level remediation deadlines disclosed beyond the original Helsingør ban
Where it fits
Governance type
national data-protection regulator (Datatilsynet) overseeing municipal-level EdTech procurement
Scale
national — 51 municipalities (including Copenhagen and Aarhus)
Income level
high-income (Denmark, EU member state)
Commonly funded by
National / regional programmes
Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.
Replication kit
Reusable artefacts from this practice — as published by their sources.