evidoria

← Back to browse

Good practice

Denmark's Chromebook Case (2021-2026): From Helsingør's Google Workspace Ban to a National Reprimand of 51 Municipalities

Denmark · Helsingør · See the Denmark profile

Denmark banned Helsingør's use of Google Chromebooks/Workspace in schools in 2022 over undocumented data transfers. A five-year probe ended in January 2026 with serious criticism of 51 municipalities, including Copenhagen and Aarhus, for the same unresolved risks.

Details

Promoter
Datatilsynet (Danish Data Protection Agency)
Period
2021-2026 (Helsingør ban Jul-Aug 2022; national reprimand of 51 municipalities Jan 2026)
Keywords
cloud EdTech, Chromebooks, Google Workspace, third-country data transfers, GDPR enforcement, sub-processor oversight

Description

In September 2021, Denmark's data protection authority, Datatilsynet, first criticised Helsingør Municipality after a data-security breach linked to its use of Google Chromebooks and Google Workspace for Education in primary schools. On 14 July 2022, Datatilsynet went further and imposed an outright processing ban, later ratified on 18 August 2022, ordering the municipality to stop using the services and delete already-transferred data by 3 August 2022. The authority found that Helsingør had not documented or assessed the risk that pupils' personal data could be transferred to Google's sub-processors outside the EU/EEA for support purposes, and had not adequately tested the hardware and software before deployment.

Datatilsynet explicitly warned that its findings would likely apply to other Danish municipalities using the same Google products, and the case grew accordingly: by 2024 it covered roughly 53 municipalities, and on 29 January 2026 Datatilsynet closed the investigation by issuing serious criticism ("alvorlig kritik") to 51 municipalities - including Copenhagen and Aarhus - for failing to document a lawful basis for processing, failing to verify that Google's sub-processors outside the EU/EEA offered data protection essentially equivalent to European standards, and for depending on technical and contractual configurations set unilaterally by the vendor rather than the municipality.

This is a cautionary governance case: it shows that even five years after the initial finding, most Danish municipalities had still not brought their cloud EdTech contracts into documented GDPR compliance, illustrating how difficult it is for individual schools and municipalities to exercise real oversight over global cloud-service sub-processing chains. Independent legal commentary (SSRN, the European Data Protection Law Review) and international press (TechCrunch, CyberNews) have used the case as the reference example for third-country transfer risk in publicly procured EdTech.

Read the full analysis: https://www.datatilsynet.dk/afgoerelser/afgoerelser/2026/jan/datatilsynet-giver-51-kommuner-alvorlig-kritik-i-chromebook-sag

Implementation

Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.

Data sources

Where this practice's information was retrieved from, and when.

Similar practices you may find useful