Data security has become an increasingly important issue for businesses and organisations in Denmark. As more processes move to cloud-based services and external digital providers, companies are becoming increasingly dependent on how those providers protect the data they are entrusted with.
This has become particularly clear in a recent case in Denmark involving unauthorized access to Danish CPR records. Millions of Danish citizens’ personal data have been compromised, raising questions about the Danish CPR system, how we use personal data, and the way we identify ourselves. The Danish Data Protection Authority (Datatilsynet) is currently working to establish exactly what happened.
But the incident should also prompt businesses to ask themselves an important question:
Who actually has access to the data we entrust to our digital providers?
Data security is not only about how a company protects its own systems. As processes increasingly move to cloud-based services, the security of external providers becomes part of the company’s own security.
Security does not stop at your own systems
Most companies today have policies, access controls and procedures in place to protect their data. But your data no longer resides solely within your own infrastructure. It is also stored and processed by SaaS providers, integration partners and other digital services.
This means that you depend on how an external provider protects the data you have entrusted to them. This also applies to digital signing and identity solutions.
When you send contracts for signing, the documents may contain information about customers, employees, tenants or business partners. This could include Danish CPR numbers, addresses, financial information or other confidential data.
When documents are handled through external services, your provider therefore becomes part of your own security.
Security should be part of your provider selection
When you choose digital solutions, functionality, price and user experience are naturally important. But security should matter just as much.
You need to know how your data is processed and stored. Who has access to it. Which subcontractors have access to your data. What happens if something goes wrong. How long your data is retained. And perhaps most importantly:
How can the provider demonstrate its security?
It is not enough for a provider to say that it has a high level of data security. Your provider should be able to document it. You should be able to see documentation of the processes and controls in place to protect your company’s data.
Data security is part of Addo
At Addo, we believe that the current case highlights how important it is for providers to focus on the proper handling and protection of data.
When your company uses Addo Sign to handle documents, signatures and identity, we take on a responsibility. For us, data security is not something that sits alongside our products. It is a fundamental part of them.
We have established security and compliance standards, as well as processes and controls that are regularly reviewed and documented through independent audits and assurance reports, including ISAE 3000 and ISAE 3402.
For us, it is not just about saying that we take data security seriously.
It is about being able to document how we do it.
You can learn more about data security in our Trust Center.
5 questions to ask your digital provider
When you entrust personal data or confidential documents to an external digital service, it is reasonable to expect clear answers about how your data is processed and protected. Here are five questions you should be able to get clear answers to.
You should know where your data is physically located, which geographical regions it is processed in, and which rules and security requirements apply to its storage.
It should be clear who at the provider can access your data, under what circumstances, and how access is restricted and controlled.
A digital solution often relies on several services and subcontractors. You should therefore know who is part of your provider’s setup and how the same security and data processing requirements are enforced across them.
A provider should have clear processes for detecting, handling and reporting security incidents. This is about both limiting the damage and being able to respond quickly if your data is compromised.
It is not enough for a provider to tell you that its security is strong. Ask for documentation of the processes, controls and standards in place to protect your data – such as independent audits and assurance reports.
You should know where your data is physically located, which geographical regions it is processed in, and which rules and security requirements apply to its storage.
It should be clear who at the provider can access your data, under what circumstances, and how access is restricted and controlled.
A digital solution often relies on several services and subcontractors. You should therefore know who is part of your provider’s setup and how the same security and data processing requirements are enforced across them.
A provider should have clear processes for detecting, handling and reporting security incidents. This is about both limiting the damage and being able to respond quickly if your data is compromised.
It is not enough for a provider to tell you that its security is strong. Ask for documentation of the processes, controls and standards in place to protect your data – such as independent audits and assurance reports.
Frederik Peter Volkers
I primarily share perspectives on software development, emerging technologies, and digital product development – and on how technology can be used to simplify workflows, achieve business goals, and create real value for organisations.
Today, I am Head of Development at Addo Sign, where I work on the development of our platform and on turning new technologies into secure, scalable, and user-friendly solutions.