{
 "jurisdiction_id": "DK",
 "jurisdiction": "Denmark",
 "url": "https://dataprotection.gi/jurisdictions/denmark/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 28,
  "sub_modules": 57,
  "source_register": 16
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, GDPR-aligned omnibus framework in force with an active, funded regulator.",
   "claims": [
    {
     "statement": "Datatilsynet's council-and-secretariat structure, pre-dating the GDPR, was re-enacted under the 2018 Danish Data Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Danish Data Protection Act re-enacts to a large extent the pre-existing Personal Data Act and adds specific regulation not covered by the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act extends to areas not covered by GDPR, including manual disclosure of personal information between administrative authorities and processing of information on legal persons by credit information agencies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act applies to all processing by controllers or processors established in Denmark regardless of where the processing takes place, and to processing by non-established controllers/processors offering goods or services to, or monitoring, persons in Denmark.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Prior approval from Datatilsynet is required before establishing warning registers, credit rating agencies and judicial information systems.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Multiple national derogations from the GDPR baseline require jurisdiction-specific compliance attention (age threshold, CPR numbers, HR legitimate interest).",
   "claims": [
    {
     "statement": "The Danish Act allows processing of normal and sensitive data in personnel administration on the basis of legitimate interests arising from legislation or collective agreements, extended to public authorities which cannot normally rely on legitimate interest.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The age limit for a child's consent to use information society services (social media, apps, etc.) has been lowered to 13 years under the Danish Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act contains specific provisions on processing of Social Security (CPR) numbers and data concerning criminal offences that are less restrictive than GDPR Article 9 but more restrictive than Article 6.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-standard; enforcement record demonstrates operative supervision.",
   "claims": [
    {
     "statement": "Datatilsynet found that a recruitment company (JobTeam) violated GDPR's lawfulness/fairness/transparency requirements by erasing personal data subject to an access request during the period after the request was submitted and before the reply was given.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/fine-proposed-danish-recruitment-company_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/danish-data-protection-agency-proposes-dkk-12-million-fine-danish-taxi_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet applies the GDPR's statutory response window to access requests, finding it unlawful for a controller to erase data linked to an access request during the pendency of that window.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/fine-proposed-danish-recruitment-company_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Framework is GDPR-standard but enforcement record shows recurring security/accountability failures driving active supervisory casework.",
   "claims": [
    {
     "statement": "Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-recommends-fine-dkk-15m-capio",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet recommended a DKK 15 million fine against Netcompany for GDPR violations in developing 'mit.dk', a digital mail service, after inappropriate code allowed unauthorized cross-user access to personal and sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-recommends-fine-dkk-15-million",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet recommended a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement basic security measures, including multifactor authentication for remote IT access, following a data breach caused by a hack.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-recommends-dkk-500000-fine-against",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Denmark receives about 80 data breach notifications per week, making it number one in the EU for reported breaches relative to population size.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are fully harmonised EU-level tools; no Denmark-specific gap identified.",
   "claims": [
    {
     "statement": "Datatilsynet, as the competent supervisory authority, approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion under the Art 64 consistency mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2024-04/dk_sa_final_decision_bcr-c_carlsberg_as_20231221_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Several sector overlays confirmed (marketing, HR, credit, health); financial, education and insurance overlays remain evidence gaps.",
   "claims": [
    {
     "statement": "The Danish Act allows disclosure of general personal data between enterprises for marketing purposes without consent provided an opt-out register is checked first, but the actual marketing activity must comply with the Danish Marketing Practices Act implementing ePrivacy Directive rules on direct electronic marketing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core cookie-consent and direct-marketing rules are confirmed; several sub-modules are genuinely inapplicable (US-specific) or unevidenced at Denmark level.",
   "claims": [
    {
     "statement": "Datatilsynet's guidelines on processing website visitor personal information state that where consent is relied upon as the legal basis, visitors must opt in and be clearly informed of processing purposes for the consent to be GDPR-valid.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-publishes-guidelines-processing-website-visitor-personal-information",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Active soft-law/guidance activity on AI and ADM; biometric/genetic sub-modules and state-surveillance carve-outs remain evidence gaps at Denmark-specific level.",
   "claims": [
    {
     "statement": "The EU Digital Services Act bans targeted advertising to minors based on profiling on online platforms, a restriction applicable within Denmark alongside GDPR Art 22.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-brussels-to-ban-or-not-to-ban",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet formed an internal cross-departmental AI task force to produce guidance and templates for AI development/use and to map public-sector AI use for fundamental-rights compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-announces-new-ai-task-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet published an assessment of Copenhagen Municipality's legal basis (GDPR Arts 6(1)(e), 6(2)-(3), 9(2)(g)) for developing and operating an AI solution predicting citizens' rehabilitation needs, finding the underlying Service Act insufficiently clear for the processing's scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-datatilsynet-issues-assessment-development-and",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet and the Danish Digital Agency (Digitaliseringsstyrelsen) jointly operate an AI regulatory sandbox alongside published guidelines on responsible use of generative AI by companies and authorities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/denmark-digitaliseringsstyrelsen-publishes-thematic",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core consent-age derogation confirmed; social-media minimum-age policy is still in development, and dependent-adult/education sub-modules are evidence gaps.",
   "claims": [
    {
     "statement": "The European Commission developed a privacy-preserving age-verification blueprint that is being piloted in Denmark alongside France, Greece, Italy and Spain.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/are-new-global-age-verification-requirements-creating-a-children-s-online-safety-legal-patchwork-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Denmark is reported among nine European governments considering or advancing proposals to require a minimum age for social-media use.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-brussels-to-ban-or-not-to-ban",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/denmark/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active enforcement casework confirmed, but the court-mediated fining process (rather than direct administrative fines) is a structural constraint on Datatilsynet's own powers, and collective-redress specifics remain unevidenced.",
   "claims": [
    {
     "statement": "Denmark's legal system does not allow for the imposition of administrative fines as set out in GDPR Article 83, per Recital 151; instead, the fine is initiated by Datatilsynet and imposed by competent national courts under Article 83(9).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CJEU / EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0383",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Denmark and Estonia are the only two EU Member States whose national laws do not allow supervisory authorities to impose administrative fines directly; Danish courts impose the fines as criminal sanctions instead.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-gdpr-part-10-consequences-for-grpr-violations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the ILVA/IDdesign case (CJEU C-383/23), the Aarhus District Court found ILVA guilty of GDPR retention violations but imposed a criminal fine of DKK 100,000, below the DKK 1.5 million recommended by Datatilsynet based on group turnover, prompting a referral to the CJEU on the calculation of fines against 'undertakings'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CJEU / EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0383",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet's funding and staffing were increased by about 50 percent in 2018, bringing its headcount to between 50 and 60 employees.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analysis-the-danish-data-protection-act-and-its-gdpr-derogations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}