



Denmark is one of the most digitalised economies in Europe, and its financial sector reflects that reality more than almost any other market in the EU. Open banking and PSD2 did not arrive in a vacuum here; they landed in a country where NemID (now MitID), instant payments and near‑cashless retail were already part of everyday life. That makes Denmark a fascinating testbed for the legal and regulatory questions that now shape digital finance across Europe.
At the centre of this transformation stands PSD2, the EU directive that forced banks to open up payment account data and payment initiation to licensed third parties. In Denmark, this framework is implemented primarily through the Danish Payments Act and supervised by the Danish Financial Supervisory Authority (Finanstilsynet). But the real story is not just about transposing EU law. It is about how Danish regulators, banks and fintechs interpret grey zones, manage risks and prepare for the next wave: PSD3, the Payment Services Regulation (PSR) and a broader move towards open finance.
To understand the evolving legal framework, it helps to start with the basic architecture. PSD2 created two new regulated roles: Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs). In Denmark, any company that wants to operate as AISP or PISP must either obtain a licence or registration with Finanstilsynet, comply with capital and governance requirements, and connect to bank APIs that meet the technical standards of the European Banking Authority (EBA). This is the formal layer. The informal layer is the negotiation between banks and fintechs over API quality, data scope and commercial models, which often determines whether open banking is a legal right in practice or just a theoretical possibility.
From a legal perspective, Denmark follows the EU baseline but tends to implement rules in a relatively technology‑friendly way. The Danish Payments Act mirrors PSD2’s strong customer authentication (SCA) rules, liability regime and consumer protection standards, yet the supervisory practice is shaped by a long tradition of digital public infrastructure. The widespread use of MitID for SCA, the national real‑time payment system and the high penetration of mobile payments (MobilePay) all influence how compliance is interpreted and enforced. This means that a fintech launching in Denmark faces a different risk profile than in a less digitalised EU state, even though the underlying directive is the same.
For companies planning to enter the Danish open banking ecosystem, the legal journey typically unfolds in several steps. It is not just a licensing exercise; it is a strategic compliance project that touches product design, data architecture and contracts with partners.
A simplified step‑by‑step path for a new AISP or PISP in Denmark often looks like this:
1) Define the exact services: pure account aggregation, payment initiation, or a combined personal finance management tool.
2) Map regulatory status: determine whether you need a full payment institution licence, a limited licence, or only registration as an AISP with Finanstilsynet.
3) Prepare documentation: business plan, risk management framework, IT security policies, outsourcing strategy and AML/CTF procedures, even if your model has limited money‑flow risk.
4) Engage with Finanstilsynet: submit the application, respond to follow‑up questions, and be ready to adjust your governance or technical controls.
5) Integrate with Danish bank APIs: use the standardised PSD2 interfaces, test SCA flows via MitID and ensure your consent management aligns with both PSD2 and GDPR.
6) Launch with monitoring: implement continuous transaction monitoring, incident reporting procedures and periodic compliance reviews to stay aligned with evolving guidance.
Each of these steps is framed by EU‑level law, but the Danish context adds specific expectations. Finanstilsynet pays particular attention to operational resilience, outsourcing to cloud providers and cybersecurity, reflecting Denmark’s high dependence on digital channels. A provider that underestimates these local expectations may be formally compliant with PSD2 but still face delays or conditions before receiving approval.
Data protection is the second pillar of the legal framework, and in Denmark it is impossible to discuss open banking without discussing GDPR. PSD2 grants third‑party providers access to payment account data, but only with explicit user consent and only to the extent necessary for the service. GDPR overlays this with principles of data minimisation, purpose limitation and storage limitation. The Danish Data Protection Agency (Datatilsynet) has issued guidance on financial data processing that, while not specific to PSD2, strongly influences how banks and fintechs design consent flows and retention policies.
This interaction between PSD2 and GDPR creates both opportunities and legal tensions. On one hand, Denmark’s high level of digital trust - surveys often show that more than 80% of Danes are comfortable using digital public services - supports user willingness to share data with regulated providers. On the other hand, any misuse or unclear communication about data sharing can quickly erode that trust and trigger regulatory scrutiny. The legal risk is not only about fines; it is about reputational damage in a relatively small and interconnected market.
When assessing whether to build on open banking in Denmark, companies should weigh a set of strengths and weaknesses that are specific to this jurisdiction. The legal framework is stable and predictable, but the bar for security and user experience is high.
Key advantages of operating under the Danish open banking regime include: a mature digital identity infrastructure (MitID) that simplifies SCA and onboarding; a banking sector that is already heavily API‑driven, reducing integration friction; and a regulator that is generally open to dialogue and innovation, including participation in EU‑level sandboxes and working groups. These factors can significantly shorten time‑to‑market for well‑prepared players.
The downsides are more subtle. Compliance expectations around IT security, incident reporting and outsourcing can be demanding, especially for smaller fintechs. Danish consumers are digitally savvy and have low tolerance for friction or security incidents, which raises the de facto standard beyond the legal minimum. In addition, the market is relatively concentrated: a few large banks hold a dominant share, so any API instability or restrictive interpretation of PSD2 obligations by these institutions can have outsized impact on third‑party providers.
Comparing Denmark with other EU markets helps clarify these trade‑offs. In some larger countries, the sheer number of banks and fintechs creates more competitive pressure and a broader variety of API standards, but also more fragmentation and inconsistent supervisory practice. Denmark, by contrast, offers a more homogeneous environment with strong coordination between banks, public authorities and regulators. For a company that values predictability and deep integration with national infrastructure, Denmark can be more attractive than a larger but less coordinated market. For a player seeking massive scale from day one, it may be more of a pilot market than a final destination.
Looking beyond PSD2, the legal horizon is already shifting. The European Commission’s proposals for PSD3 and the Payment Services Regulation aim to harmonise rules further, strengthen consumer protection and address gaps identified in PSD2, such as inconsistent API quality and varying enforcement across member states. Denmark will have to adapt its Payments Act and supervisory practices once these instruments are finalised, but the direction of travel is already clear: more standardisation, more focus on fraud prevention, and a gradual move from open banking to open finance, where data from savings, investments, insurance and pensions may also be shared under regulated conditions.
For Danish institutions, this evolution raises strategic questions. Banks must decide whether to treat open finance as a compliance cost or as a platform opportunity, building ecosystems around their APIs and partnering with fintechs to deliver new services. Fintechs, in turn, need to anticipate how licensing categories, capital requirements and conduct rules may change under PSD3 and related EU initiatives such as the Data Act and the Digital Operational Resilience Act (DORA). Legal teams cannot simply react; they must build flexible compliance architectures that can absorb new requirements without constant re‑engineering.
One practical way to prepare for this future in Denmark is to design products around modular compliance. Instead of hard‑coding PSD2‑specific rules, companies can structure their systems around broader principles: strong authentication, explicit and granular consent, audit‑ready logging of data access, and clear segregation of duties in payment initiation. This approach aligns with both current Danish expectations and the likely direction of EU law. It also makes it easier to demonstrate to Finanstilsynet that the organisation understands not only the letter but also the spirit of the rules.
Another emerging area is the intersection of open banking with anti‑money laundering (AML) and counter‑terrorist financing (CTF) obligations. While PSD2 itself is not an AML directive, payment institutions and many fintechs in Denmark fall under the Danish AML Act. Access to rich transaction data via open banking can enhance risk‑based monitoring, but it also increases responsibility for data governance and algorithmic transparency. Supervisors are increasingly interested in how machine‑learning models used for fraud detection or credit scoring are trained, validated and monitored, especially when they rely on data obtained through PSD2 channels.
Ultimately, navigating the evolving legal framework of digital finance in Denmark requires a blend of legal expertise, technical understanding and strategic foresight. The country’s advanced digital infrastructure and high level of trust create fertile ground for innovation, but they also raise expectations for security, transparency and reliability. Companies that treat PSD2 and its successors as a living framework - not a one‑off compliance project - are best positioned to thrive.
Denmark will continue to play an outsized role in shaping how open banking and open finance work in practice within the EU. Its combination of ambitious digital policy, pragmatic regulation and demanding consumers makes it both a challenge and an opportunity. For those willing to engage deeply with the legal and technical details, the Danish market offers a glimpse of what the future of regulated digital finance in Europe may look like.
If the topic discussed proved interesting, we encourage you to proceed to the next section, which may expand your knowledge: Denmark’s New Digital Finance Rules: What Companies Must Change