evidoria

← Back to browse

Good practice Imported

Denmark's Chromebook Case (2021-2026): From Helsingør's Google Workspace Ban to a National Reprimand of 51 Municipalities

Denmark · Helsingør · See the Denmark profile

Evidence: Observational / pre–post Top 89% 27/100 · Ask Evidence Copilot about this practice

Denmark banned Helsingør's use of Google Chromebooks/Workspace in schools in 2022 over undocumented data transfers. A five-year probe ended in January 2026 with serious criticism of 51 municipalities, including Copenhagen and Aarhus, for the same unresolved risks.

~53 municipalities
Municipalities covered by the investigation by 2024 (2024)
51 municipalities
Municipalities issued serious criticism at investigation close (29 January 2026)
3 August 2022 date
Deadline to delete transferred data (Helsingør ban) (2022)

Details

Promoter
Datatilsynet (Danish Data Protection Agency)
Period
2021-2026 (Helsingør ban Jul-Aug 2022; national reprimand of 51 municipalities Jan 2026)
Keywords
cloud EdTech, Chromebooks, Google Workspace, third-country data transfers, GDPR enforcement, sub-processor oversight

Context

In September 2021, Denmark's data protection authority, Datatilsynet, first criticised Helsingør Municipality after a data-security breach linked to its use of Google Chromebooks and Google Workspace for Education in primary schools.

Activities

On 14 July 2022, Datatilsynet imposed an outright processing ban on Helsingør (later ratified 18 August 2022), ordering the municipality to stop using the services and delete already-transferred data by 3 August 2022. The authority found that Helsingør had not documented or assessed the risk that pupils' personal data could be transferred to Google's sub-processors outside the EU/EEA for support purposes, and had not adequately tested the hardware and software before deployment. Datatilsynet explicitly warned that its findings would likely apply to other Danish municipalities using the same Google products.

Results

By 2024 the investigation grew to cover roughly 53 municipalities, and on 29 January 2026 Datatilsynet closed the investigation by issuing serious criticism ('alvorlig kritik') to 51 municipalities — including Copenhagen and Aarhus — for failing to document a lawful basis for processing, failing to verify that Google's sub-processors outside the EU/EEA offered data protection essentially equivalent to European standards, and for depending on technical and contractual configurations set unilaterally by the vendor rather than the municipality.

Conclusions

This is a cautionary governance case: it shows that even five years after the initial finding, most Danish municipalities had still not brought their cloud EdTech contracts into documented GDPR compliance, illustrating how difficult it is for individual schools and municipalities to exercise real oversight over global cloud-service sub-processing chains. Independent legal commentary (SSRN, the European Data Protection Law Review) and international press (TechCrunch, CyberNews) have used the case as the reference example for third-country transfer risk in publicly procured EdTech.

Implementation

Indicative cost
High (€500k–€5M) — Not disclosed in financial terms; the case represents a significant compliance/legal remediation burden across 51 municipalities nationally, following an initial processing ban on Helsingør in 2022.
Time to results
Long (> 3 years) — September 2021: initial criticism of Helsingør. 14 July 2022: processing ban issued (ratified 18 August 2022), data-deletion deadline 3 August 2022. By 2024: investigation covers ~53 municipalities. 29 January 2026: investigation closed with serious criticism issued to 51 municipalities.
Staffing & skills
Enforcement led by Datatilsynet (Danish Data Protection Agency), Individual municipalities responsible for their own Google Workspace/Chromebook procurement and data-processing agreements

Conditions for success

  • Documented lawful basis for processing personal data before deployment
  • Verification that third-country sub-processors offer data protection essentially equivalent to EU/EEA standards
  • Municipality-level (not just vendor-level) testing and risk assessment of hardware/software before deployment

Common failure modes

  • Municipalities relied on technical/contractual configurations set unilaterally by the vendor (Google) rather than their own documented risk assessment
  • Five years after the first finding, most municipalities still had not achieved documented GDPR compliance
  • No individual municipality-level remediation deadlines disclosed beyond the original Helsingør ban

Where it fits

Governance type
national data-protection regulator (Datatilsynet) overseeing municipal-level EdTech procurement
Scale
national — 51 municipalities (including Copenhagen and Aarhus)
Income level
high-income (Denmark, EU member state)

Commonly funded by

National / regional programmes

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Replication kit

Reusable artefacts from this practice — as published by their sources.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Similar practices you may find useful