🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
DK · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

Denmark

DK schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 28 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, GDPR-aligned omnibus framework in force with an active, funded regulator.

Primary frameworkDatabeskyttelsesloven (Danish Data Protection Act, Act No. 502 of 23 May 2018) implementing/supplementing Regulation (EU) 2016/679 (GDPR)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenComprehensive, GDPR-aligned omnibus framework in force with an active, funded regulator.

Sub-modules (5)

Regulator And AuthorityGreen

Datatilsynet is Denmark's single DPA, structured as a council plus secretariat, re-enacted from the pre-GDPR Personal Data Act era.

Claims: CLM-DK-1a2b3c4d

Act And InstrumentsGreen

Databeskyttelsesloven (2018) is the operative national instrument alongside directly-applicable GDPR.

Claims: CLM-DK-2b3c4d5e

Material ScopeGreen

The Act extends beyond GDPR to manual disclosures between administrative authorities and to legal-person data processed by credit agencies.

Claims: CLM-DK-3c4d5e6f

Territorial ScopeGreen

Applies to controllers/processors established in Denmark regardless of where processing occurs, and to non-established controllers targeting or monitoring persons in Denmark.

Claims: CLM-DK-4d5e6f7a

Regulator Registration And FilingAmber

Prior Datatilsynet approval is required before establishing warning registers, credit-rating agencies, and judicial information systems.

Claims: CLM-DK-5e6f7a8b

Category narrative60 words

Denmark implements the GDPR through the Danish Data Protection Act (Databeskyttelsesloven, 2018), enforced by Datatilsynet (the Danish Data Protection Agency), which retains its pre-existing council-plus-secretariat structure. The Act both supplements GDPR derogation options and extends coverage to areas outside GDPR's material scope (manual administrative disclosures, credit-agency processing of legal-person data). Territorial scope tracks GDPR Art 3 but is restated domestically.

Sources and claims (5)
  1. ConfirmedIAPPDatatilsynet's council-and-secretariat structure, pre-dating the GDPR, was re-enacted under the 2018 Danish Data Protection Act.
  2. ConfirmedIAPPThe Danish Data Protection Act re-enacts to a large extent the pre-existing Personal Data Act and adds specific regulation not covered by the GDPR.
  3. ConfirmedIAPPThe Act extends to areas not covered by GDPR, including manual disclosure of personal information between administrative authorities and processing of information on legal persons by credit information agencies.
  4. ConfirmedIAPPThe Act applies to all processing by controllers or processors established in Denmark regardless of where the processing takes place, and to processing by non-established controllers/processors offering goods or services to, or monitoring, persons in Denmark.
  5. ConfirmedIAPPPrior approval from Datatilsynet is required before establishing warning registers, credit rating agencies and judicial information systems.

#

Multiple national derogations from the GDPR baseline require jurisdiction-specific compliance attention (age threshold, CPR numbers, HR legitimate interest).

Primary frameworkGDPR Arts 6, 7, 9 as supplemented by Databeskyttelsesloven §§6-13
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberMultiple national derogations from the GDPR baseline require jurisdiction-specific compliance attention (age threshold, CPR numbers, HR legitimate interest).

Sub-modules (4)

Lawful BasesAmber

Danish Act permits processing of normal and sensitive personnel data on a legitimate-interest basis grounded in legislation or collective agreements, extended to public authorities.

Claims: CLM-DK-6f7a8b9c

Special CategoriesAmber

Bespoke, GDPR Art 9-adjacent regime for CPR numbers and criminal-offence data — less restrictive than Art 9 but more restrictive than Art 6.

Claims: CLM-DK-8b9c0d1e

Pseudonymisation And AnonymisationAmber

No Denmark-specific statutory safe-harbour beyond GDPR Art 4(5)/25 was identified in this research pass; Datatilsynet has issued informal guidance on pseudonymised data but no distinct legal threshold.

Absence provenance: not recorded. Searched: Datatilsynet pseudonymisation anonymisation guidance Denmark.

Category narrative46 words

GDPR Arts 6/9 apply directly, but the Danish Act creates notable derogations: a lowered digital age-of-consent (13), a bespoke regime for CPR (social security) numbers and criminal-offence data, and an expanded legitimate-interest basis for HR data drawn from legislation or collective agreements (including for public authorities).

Sources and claims (3)
  1. ConfirmedIAPPThe Danish Act allows processing of normal and sensitive data in personnel administration on the basis of legitimate interests arising from legislation or collective agreements, extended to public authorities which cannot normally rely on legitimate interest.
  2. ConfirmedIAPPThe age limit for a child's consent to use information society services (social media, apps, etc.) has been lowered to 13 years under the Danish Act.
  3. ConfirmedIAPPThe Act contains specific provisions on processing of Social Security (CPR) numbers and data concerning criminal offences that are less restrictive than GDPR Article 9 but more restrictive than Article 6.

#

Rights framework is GDPR-standard; enforcement record demonstrates operative supervision.

Primary frameworkGDPR Arts 12-22, directly applicable
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenRights framework is GDPR-standard; enforcement record demonstrates operative supervision.

Sub-modules (5)

Access RightGreen

Datatilsynet has taken enforcement action (JobTeam) against erasure of personal data during the pendency of an access request, holding this defeats the basic GDPR access-right guarantee.

Claims: CLM-DK-9c0d1e2f

Rectification And ErasureGreen

Datatilsynet enforcement (Taxa 4x35) confirms the storage-limitation/erasure duty is actively supervised where retention exceeds necessity.

Claims: CLM-DK-0d1e2f3a

Restriction And ObjectionGreen

GDPR Arts 18 and 21 apply directly; no Danish derogation identified in this pass.

Absence provenance: not recorded. Searched: Denmark GDPR right to restriction objection derogation Databeskyttelsesloven.

Data PortabilityGreen

GDPR Art 20 applies directly; no Danish derogation identified.

Absence provenance: not recorded. Searched: Denmark data portability derogation GDPR Article 20.

Deadlines And Response WindowsGreen

Standard GDPR one-month response window applies; the JobTeam case turned on conduct occurring within that window.

Claims: CLM-DK-1e2f3a4b

Category narrative39 words

Denmark applies GDPR's data-subject-rights framework (Arts 12-22) directly, with no material derogation identified for access, rectification/erasure, restriction, objection, portability, or response deadlines beyond GDPR's one-month standard. Enforcement history (JobTeam, Taxa 4x35) confirms Datatilsynet actively polices access and erasure/retention compliance.

Sources and claims (3)
  1. ConfirmedEDPBDatatilsynet found that a recruitment company (JobTeam) violated GDPR's lawfulness/fairness/transparency requirements by erasing personal data subject to an access request during the period after the request was submitted and before the reply was given.
  2. ConfirmedEDPBDatatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.
  3. ProbableEDPBDatatilsynet applies the GDPR's statutory response window to access requests, finding it unlawful for a controller to erase data linked to an access request during the pendency of that window.

#

Framework is GDPR-standard but enforcement record shows recurring security/accountability failures driving active supervisory casework.

Primary frameworkGDPR Arts 5(2), 24, 25, 28, 30, 32-34, 35 as applied by Datatilsynet
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberFramework is GDPR-standard but enforcement record shows recurring security/accountability failures driving active supervisory casework.

Sub-modules (7)

Accountability And DpiaAmber

Datatilsynet reported hospital operator Capio to police for failing to supervise its data processors for years despite them handling special-category data, a breach of the accountability principle.

Claims: CLM-DK-2f3a4b5c

Dpo RequirementsGreen

GDPR Art 37-39 thresholds apply directly; no Denmark-specific derogation identified in this pass.

Absence provenance: not recorded. Searched: Denmark DPO appointment threshold derogation Databeskyttelsesloven.

Ropa RequirementsAmber

GDPR Art 30 ROPA duties apply directly; Datatilsynet's Capio action implicates the adequacy of processor oversight records.

Claims: CLM-DK-2f3a4b5c

Joint Controller ArrangementsAmber

No Denmark-specific joint-controller finding identified in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet joint controller Article 26 decision Denmark.

Security MeasuresRed

Datatilsynet recommended a DKK 15 million fine against Netcompany over inappropriate code in the 'mit.dk' digital mail service allowing unauthorized cross-user access, and a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement multifactor authentication for remote IT access.

Claims: CLM-DK-3a4b5c6d, CLM-DK-4b5c6d7e

Breach NotificationAmber

Denmark receives approximately 80 data-breach notifications per week, the highest per-capita rate of reported breaches in the EU.

Claims: CLM-DK-5c6d7e8f

Retention And DisposalAmber

Datatilsynet's Taxa 4x35 enforcement confirms active supervision of retention/disposal obligations under the storage-limitation principle.

Claims: CLM-DK-0d1e2f3a

Category narrative37 words

Denmark enforces GDPR's accountability, security, and breach-notification duties vigorously: Datatilsynet has pursued controllers for inadequate processor supervision (Capio), inadequate technical security (Netcompany's mit.dk, SIRIUS Advokater), and Denmark records the EU's highest per-capita rate of breach notifications (~80/week).

Sources and claims (4)
  1. ConfirmedDataGuidanceDatatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.
  2. ConfirmedDataGuidanceDatatilsynet recommended a DKK 15 million fine against Netcompany for GDPR violations in developing 'mit.dk', a digital mail service, after inappropriate code allowed unauthorized cross-user access to personal and sensitive data.
  3. ConfirmedDataGuidanceDatatilsynet recommended a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement basic security measures, including multifactor authentication for remote IT access, following a data breach caused by a hack.
  4. ProbableIAPPDenmark receives about 80 data breach notifications per week, making it number one in the EU for reported breaches relative to population size.

#

Transfer mechanisms are fully harmonised EU-level tools; no Denmark-specific gap identified.

Primary frameworkGDPR Arts 44-49 (Chapter V), directly applicable
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenTransfer mechanisms are fully harmonised EU-level tools; no Denmark-specific gap identified.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly and uniformly; Datatilsynet is the competent BCR-approving authority for Danish corporate groups.

Claims: CLM-DK-6d7e8f9a

Adequacy ReceivedGreen

Adequacy decisions are made by the European Commission at EU level and apply uniformly to Denmark as an EU Member State; Denmark does not issue bilateral adequacy findings of its own.

Absence provenance: not recorded. Searched: Denmark bilateral adequacy decision received.

Adequacy GrantedGreen

Adequacy determinations affecting Denmark are issued by the European Commission, not by Datatilsynet individually.

Absence provenance: not recorded. Searched: Denmark bilateral adequacy decision granted.

Sccs And BcrsGreen

Datatilsynet approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion.

Claims: CLM-DK-6d7e8f9a

Transfer Impact AssessmentGreen

Post-Schrems II TIA obligations apply directly under GDPR/EDPB Recommendations 01/2020; no Denmark-specific variant identified.

Absence provenance: not recorded. Searched: Datatilsynet transfer impact assessment guidance Denmark.

Data LocalisationGreen

No general data-localisation mandate identified for Denmark beyond sector-specific domestic-infrastructure arrangements (e.g., the state-run 'mit.dk' digital mail platform).

Absence provenance: not recorded. Searched: Denmark data localisation mandate personal data.

Category narrative59 words

As an EU Member State, Denmark's transfer regime is governed by GDPR Chapter V uniformly across the Union: adequacy decisions are adopted at EU (Commission) level rather than bilaterally by Denmark, and SCCs/BCRs are the principal mechanisms used. Datatilsynet acts as the competent authority approving Binding Corporate Rules for Danish-headquartered groups (e.g. Carlsberg), taking utmost account of EDPB opinions.

Sources and claims (1)
  1. ConfirmedDatatilsynet / EDPBDatatilsynet, as the competent supervisory authority, approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion under the Art 64 consistency mechanism.

#

Several sector overlays confirmed (marketing, HR, credit, health); financial, education and insurance overlays remain evidence gaps.

Primary frameworkDatabeskyttelsesloven sector provisions; Danish Marketing Practices Act (Markedsføringsloven)
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberSeveral sector overlays confirmed (marketing, HR, credit, health); financial, education and insurance overlays remain evidence gaps.

Sub-modules (7)

Financial Sector OverlayRed

No Denmark-specific financial-sector DP overlay (e.g., Finanstilsynet interface) was substantiated in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet Finanstilsynet data protection financial sector Denmark.

Health Sector OverlayAmber

Datatilsynet's Capio (private hospital) enforcement demonstrates active health-sector supervision of processor oversight for special-category data.

Claims: CLM-DK-2f3a4b5c

Telecoms And EprivacyGreen

Direct electronic marketing is governed by the Danish Marketing Practices Act, which implements the ePrivacy Directive's rules alongside the Data Protection Act's opt-out-register mechanism.

Claims: CLM-DK-7e8f9a0b

Employment DataAmber

The Danish Act permits processing of normal and sensitive personnel data on a legitimate-interest basis grounded in legislation or collective agreements.

Claims: CLM-DK-6f7a8b9c

Credit And ScoringAmber

Prior Datatilsynet approval is required before establishing credit rating agencies.

Claims: CLM-DK-5e6f7a8b

EducationRed

No Denmark-specific education-sector DP overlay was substantiated in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet education sector data protection guidance Denmark.

InsuranceRed

No Denmark-specific insurance-sector DP overlay was substantiated in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet insurance sector data protection Denmark.

Category narrative50 words

Sector overlays in Denmark include the Marketing Practices Act (implementing ePrivacy rules on direct marketing), enhanced HR-data legitimate-interest bases, mandatory Datatilsynet pre-approval for credit-rating agencies, and active supervision of the health sector (Capio hospital-group vendor-management enforcement). Financial-sector, education, and insurance overlays were not substantiated with Denmark-specific findings in this pass.

Sources and claims (1)
  1. ConfirmedIAPPThe Danish Act allows disclosure of general personal data between enterprises for marketing purposes without consent provided an opt-out register is checked first, but the actual marketing activity must comply with the Danish Marketing Practices Act implementing ePrivacy Directive rules on direct electronic marketing.

#

Core cookie-consent and direct-marketing rules are confirmed; several sub-modules are genuinely inapplicable (US-specific) or unevidenced at Denmark level.

Primary frameworkGDPR Art 6/7 as applied via Datatilsynet cookie guidance; Danish Marketing Practices Act
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberCore cookie-consent and direct-marketing rules are confirmed; several sub-modules are genuinely inapplicable (US-specific) or unevidenced at Denmark level.

Sub-modules (6)

Cookies And TrackersGreen

Datatilsynet's 2020 guidelines on processing website-visitor data confirm that valid GDPR consent (opt-in, purpose-specific) is the standard legal basis for cookie/tracker use.

Claims: CLM-DK-8f9a0b1c

Dark PatternsAmber

No Denmark-specific dark-pattern prohibition distinct from EU DSA/GDPR fair-processing norms was identified in this pass.

Absence provenance: not recorded. Searched: Datatilsynet dark patterns consent design Denmark.

Opt Out SignalsAmber

No Denmark-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: not recorded. Searched: Datatilsynet Global Privacy Control opt-out signal Denmark.

Clean Rooms And DcrAmber

No Denmark-specific clean-room/data-collaboration-room regime was identified.

Absence provenance: not recorded. Searched: Datatilsynet data clean room guidance Denmark.

Cross Context AdvertisingAmber

The CPRA 'sale'/'share' construct is a US state-law concept with no direct Danish/EU-GDPR analogue; GDPR instead regulates all processing via lawful-basis and purpose-limitation rules.

Absence provenance: not recorded. Searched: Denmark cross-context advertising sale of data equivalent.

Direct MarketingGreen

Disclosure of general personal data between enterprises for marketing without consent is permitted subject to an opt-out register check, with the Marketing Practices Act governing the actual marketing communications.

Claims: CLM-DK-7e8f9a0b

Category narrative56 words

Denmark's cookie/tracker regime relies on GDPR-standard opt-in consent as articulated in Datatilsynet's website-visitor-data guidelines, and direct marketing is governed by an opt-out-register mechanism under the Data Protection Act plus the Marketing Practices Act. Dark-pattern prohibitions, opt-out signals (GPC-equivalent), clean-room rules, and CPRA-style cross-context-advertising concepts have no Denmark-specific instrument, as these are either EU-DSA-level or US-specific constructs.

Sources and claims (1)
  1. ConfirmedDataGuidanceDatatilsynet's guidelines on processing website visitor personal information state that where consent is relied upon as the legal basis, visitors must opt in and be clearly informed of processing purposes for the consent to be GDPR-valid.

#

Active soft-law/guidance activity on AI and ADM; biometric/genetic sub-modules and state-surveillance carve-outs remain evidence gaps at Denmark-specific level.

Primary frameworkGDPR Art 22 (ADM) directly applicable; EU AI Act (Regulation (EU) 2024/1689) as it enters into force, with national competent authority designation ongoing
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive soft-law/guidance activity on AI and ADM; biometric/genetic sub-modules and state-surveillance carve-outs remain evidence gaps at Denmark-specific level.

Sub-modules (6)

Profiling RestrictionsAmber

GDPR Art 22 profiling/ADM restrictions apply directly; the EU DSA additionally bans targeted advertising to minors based on profiling.

Claims: CLM-DK-9a0b1c2d

Automated Decision Making TransparencyAmber

Datatilsynet's AI task force produces guidance and templates for development and use of AI solutions, aimed at ensuring citizens' fundamental rights (including transparency) in automated processing.

Claims: CLM-DK-0b1c2d3e

Ai Risk AssessmentsAmber

Datatilsynet published a legal-basis assessment for Copenhagen Municipality's AI rehabilitation-prediction tool, and co-operates an AI regulatory sandbox with Digitaliseringsstyrelsen.

Claims: CLM-DK-1c2d3e4f, CLM-DK-2d3e4f5a

Biometric RegimeAmber

No Denmark-specific biometric-data regime distinct from GDPR Art 9(1) special-category treatment was identified in this pass.

Absence provenance: not recorded. Searched: Datatilsynet biometric data facial recognition regime Denmark.

Genetic DataAmber

No Denmark-specific genetic-data regime distinct from GDPR Art 9(1) was identified in this pass.

Absence provenance: not recorded. Searched: Datatilsynet genetic data processing regime Denmark.

State Surveillance CarveoutsAmber

No Denmark-specific national-security carve-out beyond GDPR Art 2(2)(d)/Art 23 and the Law Enforcement Directive transposition was substantiated in this pass.

Absence provenance: not recorded. Searched: Denmark national security data protection carve-out GDPR Article 23.

Category narrative58 words

Datatilsynet has been proactive on AI governance ahead of binding EU AI Act obligations: it formed an internal cross-departmental AI task force, issued a healthcare-sector AI legal-basis assessment for Copenhagen Municipality's rehabilitation-prediction system, and co-runs an AI regulatory sandbox with the Danish Digital Agency (Digitaliseringsstyrelsen). No Denmark-specific biometric or genetic-data regime distinct from GDPR Art 9 was identified.

Sources and claims (4)
  1. ProbableIAPPThe EU Digital Services Act bans targeted advertising to minors based on profiling on online platforms, a restriction applicable within Denmark alongside GDPR Art 22.
  2. ConfirmedDataGuidanceDatatilsynet formed an internal cross-departmental AI task force to produce guidance and templates for AI development/use and to map public-sector AI use for fundamental-rights compliance.
  3. ConfirmedDataGuidanceDatatilsynet published an assessment of Copenhagen Municipality's legal basis (GDPR Arts 6(1)(e), 6(2)-(3), 9(2)(g)) for developing and operating an AI solution predicting citizens' rehabilitation needs, finding the underlying Service Act insufficiently clear for the processing's scope.
  4. ConfirmedDataGuidanceDatatilsynet and the Danish Digital Agency (Digitaliseringsstyrelsen) jointly operate an AI regulatory sandbox alongside published guidelines on responsible use of generative AI by companies and authorities.

#

Core consent-age derogation confirmed; social-media minimum-age policy is still in development, and dependent-adult/education sub-modules are evidence gaps.

Primary frameworkDatabeskyttelsesloven §6(3) (age of digital consent); prospective Danish 'digital majority' social-media proposals
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberCore consent-age derogation confirmed; social-media minimum-age policy is still in development, and dependent-adult/education sub-modules are evidence gaps.

Sub-modules (5)

Age VerificationAmber

Denmark is among the member states piloting the European Commission's privacy-preserving age-verification blueprint under DSA Art 28 guidelines.

Claims: CLM-DK-3e4f5a6b

Minor Profiling BansAmber

The EU DSA's ban on profiling-based targeted advertising to minors applies within Denmark; no additional Denmark-specific profiling ban was identified.

Claims: CLM-DK-9a0b1c2d

Education SettingsRed

No Denmark-specific education-settings DP rule was substantiated in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet school pupil data protection guidance Denmark.

Dependent AdultsRed

No Denmark-specific dependent-adult/vulnerable-adult DP protection distinct from GDPR general principles was substantiated in this research pass.

Absence provenance: not recorded. Searched: Datatilsynet vulnerable adults elderly data protection Denmark.

Category narrative48 words

Denmark's headline child-specific rule is the lowered digital age-of-consent (13). Denmark is additionally among the EU governments piloting the Commission's privacy-preserving age-verification blueprint and is reportedly among nine EU governments considering (or advancing) a minimum age for social-media use. No Denmark-specific dependent-adult or education-settings DP rule was substantiated.

Sources and claims (2)
  1. ProbableIAPPThe European Commission developed a privacy-preserving age-verification blueprint that is being piloted in Denmark alongside France, Greece, Italy and Spain.
  2. UncertainIAPPDenmark is reported among nine European governments considering or advancing proposals to require a minimum age for social-media use.

#

Active enforcement casework confirmed, but the court-mediated fining process (rather than direct administrative fines) is a structural constraint on Datatilsynet's own powers, and collective-redress specifics remain unevidenced.

Primary frameworkGDPR Art 83(9)/Recital 151 as implemented via Danish criminal-referral procedure; GDPR Arts 77-84
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive enforcement casework confirmed, but the court-mediated fining process (rather than direct administrative fines) is a structural constraint on Datatilsynet's own powers, and collective-redress specifics remain unevidenced.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Denmark's legal system does not allow administrative fines under GDPR; Datatilsynet initiates a recommendation and refers cases to the police/Public Prosecutor, with Danish courts imposing the fine as a criminal penalty under GDPR Art 83(9).

Claims: CLM-DK-5a6b7c8d, CLM-DK-6b7c8d9e

Enforcement Activity IndexAmber

Recent Datatilsynet-recommended court fines include Netcompany (DKK 15M, 2024), Capio (DKK 1.5M, 2024), SIRIUS Advokater (DKK 500K, 2022), Taxa 4x35 (DKK 1.2M, 2019) and JobTeam (DKK 50K, 2020); the ILVA/IDdesign case (C-383/23) resulted in a court-imposed fine of DKK 100,000 against the DPA's recommended DKK 1.5M.

Claims: CLM-DK-3a4b5c6d, CLM-DK-4b5c6d7e, CLM-DK-2f3a4b5c, CLM-DK-0d1e2f3a, CLM-DK-9c0d1e2f, CLM-DK-7c8d9e0f

Regulator Funding And CapacityAmber

Datatilsynet's funding and staff were increased by about 50 percent in 2018, bringing headcount to between 50 and 60 employees.

Claims: CLM-DK-8d9e0f1a

Collective Redress And Class ActionsRed

No Denmark-specific data-protection collective-redress/class-action mechanism was substantiated in this research pass.

Absence provenance: not recorded. Searched: Denmark data protection class action collective redress GDPR Article 80.

Private Right Of ActionGreen

GDPR Arts 79 (judicial remedy against controller/processor) and 82 (compensation) apply directly in Denmark; no national derogation identified.

Absence provenance: not recorded. Searched: Denmark private right of action GDPR Article 79 82 derogation.

Recent Developments 180DAmber

Within the last ~180 days, Denmark's consideration of a social-media minimum age (part of a broader nine-country EU push) and its piloting of the EU Commission's privacy-preserving age-verification blueprint represent the most salient recent developments.

Claims: CLM-DK-3e4f5a6b, CLM-DK-4f5a6b7c

Category narrative81 words

Denmark presents a jurisdiction-defining enforcement peculiarity confirmed by the CJEU: Danish law does not permit Datatilsynet to impose administrative fines directly (GDPR Recital 151/Art 83(9)); instead, Datatilsynet refers cases to the police/Public Prosecutor, and fines are imposed as criminal penalties by Danish courts (illustrated by the ILVA/IDdesign case, C-383/23, where the court reduced the DPA-recommended DKK 1.5M to DKK 100,000). Enforcement activity is nonetheless frequent (Netcompany, Capio, SIRIUS Advokater, Taxa 4x35, JobTeam), and the regulator's funding/headcount was increased ~50% in 2018.

Sources and claims (4)
  1. ConfirmedCJEU / EUR-LexDenmark's legal system does not allow for the imposition of administrative fines as set out in GDPR Article 83, per Recital 151; instead, the fine is initiated by Datatilsynet and imposed by competent national courts under Article 83(9).
  2. ConfirmedIAPPDenmark and Estonia are the only two EU Member States whose national laws do not allow supervisory authorities to impose administrative fines directly; Danish courts impose the fines as criminal sanctions instead.
  3. ConfirmedCJEU / EUR-LexIn the ILVA/IDdesign case (CJEU C-383/23), the Aarhus District Court found ILVA guilty of GDPR retention violations but imposed a criminal fine of DKK 100,000, below the DKK 1.5 million recommended by Datatilsynet based on group turnover, prompting a referral to the CJEU on the calculation of fines against 'undertakings'.
  4. ConfirmedIAPPDatatilsynet's funding and staffing were increased by about 50 percent in 2018, bringing its headcount to between 50 and 60 employees.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Denmark
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s), 16 source(s) in the cumulative register.