Blog
Business16 June 2026 9 min🇩🇰 Denmark

Digital bookkeeping and IT security for SMEs

Guide to digital bookkeeping and IT security for SMEs: legal requirements, GDPR, cloud solutions, NIS2 and the legal documents that ensure your business's compliance.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Digital bookkeeping is no longer optional

From 2024, the new Bookkeeping Act requires businesses subject to a duty to file annual accounts (reporting class B and up) to use an approved digital bookkeeping system. For many SMEs the switch to digital bookkeeping has already happened, but it raises new questions about IT security, GDPR and the legal agreements that support digital data handling.

This guide gives you an overview of:

  • What the requirements for digital bookkeeping involve
  • Which IT-security risks SMEs should address
  • Which legal documents are necessary when you keep your books in the cloud

What does the Bookkeeping Act require of digital systems?

The new Bookkeeping Act (in force from 2024) requires approved bookkeeping systems to meet a number of technical standards. The Danish Business Authority registers and approves systems that meet the requirements.

Requirements for the digital bookkeeping system

An approved system must:

  • Record transactions chronologically and in accordance with good bookkeeping practice
  • Support double-entry bookkeeping (debit/credit)
  • Ensure ongoing and secure storage (backup), so data is not lost
  • Protect against manipulation, so that it is not possible to delete or change bookkeeping entries without the change being visible
  • Support export in SAF-T format (Standard Audit File for Tax), a standardised format that allows authorities and auditors to review the data
  • Retain accounting material for at least 5 years

Popular systems that meet the requirements: e-conomic, Billy, Dinero, Uniconta, Microsoft Dynamics 365, SAP Business One.

What if you do not use an approved system?

If you are covered by the requirement but your system lacks approval, you risk:

  • A fine for breach of the Bookkeeping Act
  • The Tax Agency being able to set aside your accounts and make a discretionary assessment
  • The auditor being unable to issue a clean report

Cloud bookkeeping and GDPR, an underestimated overlap

The vast majority of modern bookkeeping systems are cloud-based. This means that your data, including personal data about customers, suppliers and employees, is stored with a third party.

That is lawful and sensible, but it requires the right legal agreement.

Data processing agreement, mandatory for cloud bookkeeping

When your bookkeeping provider processes personal data on your behalf (invoices with customer names, payslips with CPR numbers), they are your data processor in the GDPR sense.

That requires a signed data processing agreement.

Under GDPR article 28, a data processing agreement must contain:

  • A description of the purpose and nature of the processing
  • Instructions to the processor
  • A requirement of confidentiality
  • Security measures
  • Rules for sub-processors (for example, does your cloud provider rely on AWS or Azure?)
  • What happens to the data on termination of the contract

Many bookkeeping systems include a data processing agreement in their standard terms, but you should make sure you have actually accepted it and that it meets GDPR's requirements.

Read our guide to data processing agreements and our GDPR guide for SMEs.


IT-security risks for SMEs

The most important risk: human error

Most IT-security incidents in SMEs are not caused by sophisticated hacker attacks, they are caused by human error:

  • Clicking on phishing emails
  • Weak passwords
  • A lack of access control (former employees with access to the systems)
  • A lack of backup routines

Ransomware, a growing threat

Ransomware attacks, where criminals encrypt your data and demand a ransom, increasingly hit SMEs. The attacks exploit weak passwords, un-updated software and a lack of backup.

The consequences for an SME:

  • Loss of access to bookkeeping and customer data
  • A GDPR breach that as a rule must be reported to Datatilsynet within 72 hours
  • Operational loss for days or weeks

Social attacks and CEO fraud

Criminals pose as the director or the auditor and ask the bookkeeper to transfer money. The attacks are targeted and convincing.

Solution: Clear internal procedures for approving payments and two-factor authentication on all systems.


IT service contract, when is it necessary?

Do you use an external IT supplier to administer your systems, whether it is an accounting system, your server, your backup solution or your email? Then you should have an IT service contract.

An IT service contract should contain:

  • Scope: Which systems and tasks are included?
  • SLA (Service Level Agreement): What is the response time on an outage? What is the guaranteed uptime?
  • Security requirements: Requirements for encryption, access management and backup
  • Allocation of liability: Who is responsible if data is lost?
  • GDPR: Is the supplier a data processor? Is a data processing agreement required (and it typically is)?
  • Termination terms: What happens to the data on termination of the contract? Can you export it?

Read our guide to IT service contracts.


Privacy policy, not only for webshops

Does your business have a website that collects data (contact forms, newsletter, cookies)? Then you are obliged to have a privacy policy that informs visitors of how the data is used.

A privacy policy (or personal-data policy) should:

  • Describe what data is collected
  • Explain the purpose of the processing
  • State who the data controller is
  • Inform about rights (access, erasure, complaint to Datatilsynet)
  • List any third parties the data is shared with

Cookie consent is a separate requirement, a cookie banner cannot replace a privacy policy.

Read more in our guide to the personal-data policy.


Practical IT-security checklist for SMEs

Use this checklist to assess your business's IT security:

Bookkeeping and data:

  • Do you use an approved digital bookkeeping system (per the Bookkeeping Act)?
  • Is a data processing agreement signed with your bookkeeping provider?
  • Is accounting material kept for at least 5 years?
  • Is the backup tested (not just set up, but actually tried out)?

Access control:

  • Do all employees use strong, unique passwords?
  • Is there two-factor authentication (2FA) on critical systems?
  • Has former employees' access been removed from all systems?
  • Are there limited access rights (people only see what they need)?

Contracts and agreements:

  • An IT service contract with an external IT supplier?
  • Data processing agreements with all suppliers that process personal data?
  • A privacy policy on the website?
  • A cookie policy and consent?

Preparedness:

  • Is there a plan for what you do in the event of a data breach?
  • Do all relevant employees know that a data breach as a rule must be reported to Datatilsynet within 72 hours?

GDPR and bookkeeping, four specific requirements

To comply with GDPR in your bookkeeping you must:

  1. Have a basis for processing, for example performance of a contract (invoice to a customer), a legal obligation (payslip) or legitimate interest
  2. Have data processing agreements with all third-party systems that process personal data
  3. Implement appropriate security measures, encryption, access restriction, backup
  4. Delete data that is no longer necessary, but remember that accounting documents must be kept for at least 5 years

Backup strategies: the 3-2-1 rule explained

A backup you have not tested is not a backup, it is a hope. For SMEs there is a simple rule of thumb: the 3-2-1 rule.

  • 3 copies of your data
  • 2 different storage media (for example your server + an external hard drive)
  • 1 offsite copy, that is, a copy physically separated from your business (for example cloud storage or a secure location at another address)

For cloud-based bookkeeping systems such as e-conomic or Billy, backup is typically handled by the provider as part of the agreement. But check:

  • Is backup included in your subscription, or is it an add-on?
  • What is the provider's RTO (Recovery Time Objective, the time to restore data) and RPO (Recovery Point Objective, how old the data is on restoration)?
  • Can you export your own data in a standard format (SAF-T) for your own purposes?

Remember to test the backup at least once a year by actually restoring data in a test environment.


The NIS2 Directive and SMEs: what you need to know

The NIS2 Directive (Network and Information Security 2) is an EU directive that tightens the requirements for cybersecurity and risk management for a wide range of sectors and businesses. In Denmark, NIS2 was implemented by the NIS-2 Act, which was passed in April 2025 and entered into force on 1 July 2025. Denmark was thus late relative to the EU's implementation deadline of 17 October 2024.

Who is directly affected? NIS2 applies to entities in a number of important societal sectors (for example energy, transport, health, digital infrastructure) that also reach a certain size (typically more than 50 employees or a turnover and balance sheet exceeding EUR 10 million). Most very small businesses are not directly subject to NIS2.

But as a subcontractor: If you supply IT services, data processing or other services to businesses that are subject to NIS2, you may find that your customers set requirements for your IT security as part of their own obligations. This can include requirements for:

  • Written IT-security policies
  • Documented backup and disaster-recovery procedures
  • Access management and two-factor authentication
  • Incident reporting

Contact an IT-security adviser if you are unsure whether NIS2 affects you or your customers.


Mobile payment and cash registers, special requirements

Does your business use a cash register, mobile payment (MobilePay, Dankort, Nets) or point-of-sale systems? Special requirements apply:

Cash-register requirements: The Tax Agency sets requirements for electronic cash-register systems for certain industries (for example retail, restaurants, cafés). The requirements are that the cash-register system must not be able to delete or change completed transactions. Systems that do not meet the requirements can lead to fines and a discretionary assessment.

Mobile payment and GDPR: Payment via MobilePay, Stripe, QuickPay or the like requires you, as the data controller, to ensure that transaction data is processed correctly. Check the terms with your payment gateway, including whether a data processing agreement is required.

Bookkeeping of digital payments: Make sure your bookkeeping integration with the payment platform is set up correctly. A lack of reconciliation between the till and the books is a frequent audit finding.


The three most important legal documents

Three documents are the foundation of IT security and digital bookkeeping for SMEs:

  1. A data processing agreement, with all cloud providers that process personal data
  2. An IT service contract, with your IT supplier
  3. A privacy policy, on your website

This article is informational and does not constitute legal advice or IT-security advice. Contact a specialist for guidance on your specific situation.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.