Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Jurisdiction | DK

GDPR and the Danish Data Protection Act, Datatilsynet's cloud position, international transfers after Schrems II, MedCom, NIS2 and EU MDR.

What the review turns on

Regulatory themes in this market

GDPR
Regulation (EU) 2016/679, with the Article 28 processor terms and the Standard Contractual Clauses Module Two written into the EU/EEA data processing agreement.
Datatilsynet
The Danish supervisory authority, and its published position on cloud processing, which is more specific than the GDPR text and is addressed directly.
Schrems II
Transfers to India require a transfer impact assessment and supplementary measures. One exists, and DM-3 or DM-4 removes the transfer question altogether.
MedCom
Denmark's messaging certification, per standard. Pensieve holds none today and the gate analysis says which standard would be needed for which scope.
NIS2
The supply-chain security obligations an essential entity passes to its suppliers. Pensieve publishes a supplier statement rather than answering the same annexe forty times.
EU MDR
Rule 11 and MDCG 2019-11 Rev.1: where software becomes a medical device. The boundary statement says which side of it Pensieve sits on, and why.

Bound values

What Pensieve’s paper resolves to in Denmark

These are not descriptions of the contract. They are the values the contract binds to when it is rendered for this market, taken from the same token registry the documents themselves read from, so a clause and this table cannot disagree.

FieldValueWhy it matters
Governing lawthe laws of DenmarkThe law the master agreement is construed under.
Courtsthe Danish courtsWhere a matter goes if arbitration is not used or is set aside.
Arbitration seatCopenhagen, DenmarkThe legal seat, which fixes the supervisory court.
Arbitration rulesthe Rules of the Danish Institute of ArbitrationThe procedural rules the reference runs under.
Data protection lawthe GDPR and the Danish Data Protection ActThe statute the processing agreement is written against.
RegulatorDatatilsynetWho the hospital, as controller or fiduciary, reports to.
Breach notification72 hoursThe controller's statutory clock. Pensieve notifies the hospital inside 4 hours of its own awareness, in every market.
CurrencyDKKThe currency the order form and every invoice are denominated in.
TaxMOMSThe indirect tax that appears on the invoice.
Standard rate25%Applied unless an exemption or reverse charge is evidenced.
Invoice formatOIOUBL via NemHandel / PeppolThe format the hospital's accounts payable system will accept.
Document languageda-DKThe language documents are issued in for this market.
Stamp dutyNot applicableWhether execution attracts duty, which, where it does, sits directly on the critical path to cash.

2 artefacts | jurisdiction DK

Written for Denmark, not translated into it

5 further artefacts are internal to Pensieve and not listed. The count is published rather than the existence concealed.

Open these in the register, with facets

8 artefacts | EU / EEA

The EU/EEA set also applies here

Denmark sits inside the EU/EEA regime, so the GDPR variants govern alongside the national layer above. Where the two differ on a Denmark question, the Denmark document governs and says so on its face.

74 artefacts | jurisdiction GL

The global set, which applies in Denmark too

Most of the register carries no jurisdiction because it carries all of them: how the platform is built, how it is defended, how data leaves at the end. Every market page sits on top of these. The eight below are the ones a hospital’s reviewers open first.

Open the whole global setWhat Pensieve holds, and what it does notWhich deployment model suits this market