🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
DK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing16 sources retrieved model claude-sonnet-5 · 2026-08-03

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Denmark

DK schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 28 claims · 24 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 7 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Denmark's data-protection enforcement architecture, structurally distinct from the EU norm, is producing rising practical exposure for controllers even though the underlying mechanism has not changed. Datatilsynet cannot issue administrative GDPR fines directly; under the Recital 151 carve-out it refers cases to the police with a recommended fine amount, and a court decides the outcome, a structural arrangement shared with only one other member state. Against that backdrop, the Western High Court fined the Region of Southern Denmark DKK 500,000 in a case reported in April 2026 for failing to implement appropriate security measures under GDPR, a reminder that Denmark's court-mediated fining route remains fully capable of producing material penalties despite Datatilsynet's own lack of direct fining power.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, GDPR-aligned omnibus framework in force with an active, funded regulator.

Primary frameworkDatabeskyttelsesloven (Danish Data Protection Act, Act No. 502 of 23 May 2018) implementing/supplementing Regulation (EU) 2016/679 (GDPR)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenComprehensive, GDPR-aligned omnibus framework in force with an active, funded regulator.

Sub-modules (5)

Regulator And AuthorityGreen

Datatilsynet is Denmark's single DPA, structured as a council plus secretariat, re-enacted from the pre-GDPR Personal Data Act era.

Claims (1):

  • Datatilsynet's council-and-secretariat structure, pre-dating the GDPR, was re-enacted under the 2018 Danish Data Protection Act.

Act And InstrumentsGreen

Databeskyttelsesloven (2018) is the operative national instrument alongside directly-applicable GDPR.

Claims (1):

  • The Danish Data Protection Act re-enacts to a large extent the pre-existing Personal Data Act and adds specific regulation not covered by the GDPR.

Material ScopeGreen

The Act extends beyond GDPR to manual disclosures between administrative authorities and to legal-person data processed by credit agencies.

Claims (1):

  • The Act extends to areas not covered by GDPR, including manual disclosure of personal information between administrative authorities and processing of information on legal persons by credit information agencies.

Territorial ScopeGreen

Applies to controllers/processors established in Denmark regardless of where processing occurs, and to non-established controllers targeting or monitoring persons in Denmark.

Claims (1):

  • The Act applies to all processing by controllers or processors established in Denmark regardless of where the processing takes place, and to processing by non-established controllers/processors offering goods or services to, or monitoring, persons in Denmark.

Regulator Registration And FilingAmber

Prior Datatilsynet approval is required before establishing warning registers, credit-rating agencies, and judicial information systems.

Claims (1):

  • Prior approval from Datatilsynet is required before establishing warning registers, credit rating agencies and judicial information systems.

Key findings (1)

  • — source on file
Category narrative60 words

Denmark implements the GDPR through the Danish Data Protection Act (Databeskyttelsesloven, 2018), enforced by Datatilsynet (the Danish Data Protection Agency), which retains its pre-existing council-plus-secretariat structure. The Act both supplements GDPR derogation options and extends coverage to areas outside GDPR's material scope (manual administrative disclosures, credit-agency processing of legal-person data). Territorial scope tracks GDPR Art 3 but is restated domestically.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — Datatilsynet's council-and-secretariat structure, pre-dating the GDPR, was re-enacted under the 2018 Danish Data Protection Act.observed
  2. ProbableIAPP — The Danish Data Protection Act re-enacts to a large extent the pre-existing Personal Data Act and adds specific regulation not covered by the GDPR.observed
  3. ProbableIAPP — The Act extends to areas not covered by GDPR, including manual disclosure of personal information between administrative authorities and processing of information on legal persons by credit information agencies.observed
  4. ProbableIAPP — The Act applies to all processing by controllers or processors established in Denmark regardless of where the processing takes place, and to processing by non-established controllers/processors offering goods or services to, or monitoring, persons in Denmark.observed
  5. ProbableIAPP — Prior approval from Datatilsynet is required before establishing warning registers, credit rating agencies and judicial information systems.observed

#

Multiple national derogations from the GDPR baseline require jurisdiction-specific compliance attention (age threshold, CPR numbers, HR legitimate interest).

Primary frameworkGDPR Arts 6, 7, 9 as supplemented by Databeskyttelsesloven §§6-13
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberMultiple national derogations from the GDPR baseline require jurisdiction-specific compliance attention (age threshold, CPR numbers, HR legitimate interest).

Sub-modules (4)

Lawful BasesAmber

Danish Act permits processing of normal and sensitive personnel data on a legitimate-interest basis grounded in legislation or collective agreements, extended to public authorities.

Claims (1):

  • The Danish Act allows processing of normal and sensitive data in personnel administration on the basis of legitimate interests arising from legislation or collective agreements, extended to public authorities which cannot normally rely on legitimate interest.

Special CategoriesAmber

Bespoke, GDPR Art 9-adjacent regime for CPR numbers and criminal-offence data — less restrictive than Art 9 but more restrictive than Art 6.

Claims (1):

  • The Act contains specific provisions on processing of Social Security (CPR) numbers and data concerning criminal offences that are less restrictive than GDPR Article 9 but more restrictive than Article 6.

Pseudonymisation And AnonymisationAmber

No Denmark-specific statutory safe-harbour beyond GDPR Art 4(5)/25 was identified in this research pass; Datatilsynet has issued informal guidance on pseudonymised data but no distinct legal threshold.

Absence provenance: unavailable. Searched: Datatilsynet pseudonymisation anonymisation guidance Denmark.

Key findings (1)

  • — source on file
Category narrative46 words

GDPR Arts 6/9 apply directly, but the Danish Act creates notable derogations: a lowered digital age-of-consent (13), a bespoke regime for CPR (social security) numbers and criminal-offence data, and an expanded legitimate-interest basis for HR data drawn from legislation or collective agreements (including for public authorities).

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableIAPP — The Danish Act allows processing of normal and sensitive data in personnel administration on the basis of legitimate interests arising from legislation or collective agreements, extended to public authorities which cannot normally rely on legitimate interest.observed
  2. ProbableIAPP — The age limit for a child's consent to use information society services (social media, apps, etc.) has been lowered to 13 years under the Danish Act.observed
  3. ProbableIAPP — The Act contains specific provisions on processing of Social Security (CPR) numbers and data concerning criminal offences that are less restrictive than GDPR Article 9 but more restrictive than Article 6.observed

#

Rights framework is GDPR-standard; enforcement record demonstrates operative supervision.

Primary frameworkGDPR Arts 12-22, directly applicable
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenRights framework is GDPR-standard; enforcement record demonstrates operative supervision.

Sub-modules (5)

Access RightGreen

Datatilsynet has taken enforcement action (JobTeam) against erasure of personal data during the pendency of an access request, holding this defeats the basic GDPR access-right guarantee.

Claims (1):

  • Datatilsynet found that a recruitment company (JobTeam) violated GDPR's lawfulness/fairness/transparency requirements by erasing personal data subject to an access request during the period after the request was submitted and before the reply was given.

Rectification And ErasureGreen

Datatilsynet enforcement (Taxa 4x35) confirms the storage-limitation/erasure duty is actively supervised where retention exceeds necessity.

Claims (1):

  • Datatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.

Restriction And ObjectionGreen

GDPR Arts 18 and 21 apply directly; no Danish derogation identified in this pass.

Absence provenance: unavailable. Searched: Denmark GDPR right to restriction objection derogation Databeskyttelsesloven.

Data PortabilityGreen

GDPR Art 20 applies directly; no Danish derogation identified.

Absence provenance: unavailable. Searched: Denmark data portability derogation GDPR Article 20.

Deadlines And Response WindowsGreen

Standard GDPR one-month response window applies; the JobTeam case turned on conduct occurring within that window.

Claims (1):

  • Datatilsynet applies the GDPR's statutory response window to access requests, finding it unlawful for a controller to erase data linked to an access request during the pendency of that window.

Key findings (1)

  • — source on file
Category narrative39 words

Denmark applies GDPR's data-subject-rights framework (Arts 12-22) directly, with no material derogation identified for access, rectification/erasure, restriction, objection, portability, or response deadlines beyond GDPR's one-month standard. Enforcement history (JobTeam, Taxa 4x35) confirms Datatilsynet actively polices access and erasure/retention compliance.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableEDPB — Datatilsynet found that a recruitment company (JobTeam) violated GDPR's lawfulness/fairness/transparency requirements by erasing personal data subject to an access request during the period after the request was submitted and before the reply was given.observed
  2. ProbableEDPB — Datatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.observed
  3. ProbableEDPB — Datatilsynet applies the GDPR's statutory response window to access requests, finding it unlawful for a controller to erase data linked to an access request during the pendency of that window.observed

#

Framework is GDPR-standard but enforcement record shows recurring security/accountability failures driving active supervisory casework.

Primary frameworkGDPR Arts 5(2), 24, 25, 28, 30, 32-34, 35 as applied by Datatilsynet
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberFramework is GDPR-standard but enforcement record shows recurring security/accountability failures driving active supervisory casework.

Sub-modules (7)

Accountability And DpiaAmber

Datatilsynet reported hospital operator Capio to police for failing to supervise its data processors for years despite them handling special-category data, a breach of the accountability principle.

Claims (1):

  • Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.

Dpo RequirementsGreen

GDPR Art 37-39 thresholds apply directly; no Denmark-specific derogation identified in this pass.

Absence provenance: unavailable. Searched: Denmark DPO appointment threshold derogation Databeskyttelsesloven.

Ropa RequirementsAmber

GDPR Art 30 ROPA duties apply directly; Datatilsynet's Capio action implicates the adequacy of processor oversight records.

Claims (1):

  • Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.

Joint Controller ArrangementsAmber

No Denmark-specific joint-controller finding identified in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet joint controller Article 26 decision Denmark.

Security MeasuresRed

Datatilsynet recommended a DKK 15 million fine against Netcompany over inappropriate code in the 'mit.dk' digital mail service allowing unauthorized cross-user access, and a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement multifactor authentication for remote IT access.

Claims (2):

  • Datatilsynet recommended a DKK 15 million fine against Netcompany for GDPR violations in developing 'mit.dk', a digital mail service, after inappropriate code allowed unauthorized cross-user access to personal and sensitive data.
  • Datatilsynet recommended a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement basic security measures, including multifactor authentication for remote IT access, following a data breach caused by a hack.

Breach NotificationAmber

Denmark receives approximately 80 data-breach notifications per week, the highest per-capita rate of reported breaches in the EU.

Claims (1):

  • Denmark receives about 80 data breach notifications per week, making it number one in the EU for reported breaches relative to population size.

Retention And DisposalAmber

Datatilsynet's Taxa 4x35 enforcement confirms active supervision of retention/disposal obligations under the storage-limitation principle.

Claims (1):

  • Datatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.

Key findings (1)

  • — source on file
Category narrative37 words

Denmark enforces GDPR's accountability, security, and breach-notification duties vigorously: Datatilsynet has pursued controllers for inadequate processor supervision (Capio), inadequate technical security (Netcompany's mit.dk, SIRIUS Advokater), and Denmark records the EU's highest per-capita rate of breach notifications (~80/week).

Periodic update · new data 2026-09-28

Controller/Processor Duties

Denmark's security-of-processing enforcement is escalating in practical terms this cycle. The Western High Court fined the Region of Southern Denmark DKK 500,000 in a case reported April 2026 for failing to implement appropriate security measures under GDPR. This is probable rather than confirmed on the underlying facts as reported, but the case is instructive as a controller-obligation matter regardless of the fining mechanism's peculiarity in Denmark: it demonstrates that the court-mediated route, activated when Datatilsynet refers a matter with a recommended penalty, remains capable of producing a material fine against a public-sector controller for a security-measures failure. Public authorities and municipalities in Denmark, who handle substantial volumes of sensitive personal data, should read this case as confirming that public-sector status is not itself a mitigating factor in the court's fine-setting exercise.

The case sits within Denmark's broader enforcement architecture, where the regulator's own limited fining power (addressed separately under enforcement and redress) shifts the practical locus of controller accountability toward the courts rather than toward direct administrative regulatory action. For controllers and processors operating in Denmark, this means that a security-of-processing failure carries a genuinely open-ended penalty exposure determined by judicial assessment rather than by a published administrative fining tariff, which may in practice produce less predictability for entities trying to assess their own risk exposure ahead of any incident.

Outlook

The item to watch is whether further security-of-processing cases follow a similar court-referral pattern, and whether the DKK 500,000 figure in the Region of Southern Denmark case becomes a practical reference point for subsequent security-measures fines against Danish public authorities.

Sources and claims (4)
  1. ProbableDataGuidance — Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.observed
  2. ProbableDataGuidance — Datatilsynet recommended a DKK 15 million fine against Netcompany for GDPR violations in developing 'mit.dk', a digital mail service, after inappropriate code allowed unauthorized cross-user access to personal and sensitive data.observed
  3. ProbableDataGuidance — Datatilsynet recommended a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement basic security measures, including multifactor authentication for remote IT access, following a data breach caused by a hack.observed
  4. ProbableIAPP — Denmark receives about 80 data breach notifications per week, making it number one in the EU for reported breaches relative to population size.observed

#

Transfer mechanisms are fully harmonised EU-level tools; no Denmark-specific gap identified.

Primary frameworkGDPR Arts 44-49 (Chapter V), directly applicable
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenTransfer mechanisms are fully harmonised EU-level tools; no Denmark-specific gap identified.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly and uniformly; Datatilsynet is the competent BCR-approving authority for Danish corporate groups.

Claims (1):

  • Datatilsynet, as the competent supervisory authority, approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion under the Art 64 consistency mechanism.

Adequacy ReceivedGreen

Adequacy decisions are made by the European Commission at EU level and apply uniformly to Denmark as an EU Member State; Denmark does not issue bilateral adequacy findings of its own.

Absence provenance: unavailable. Searched: Denmark bilateral adequacy decision received.

Adequacy GrantedGreen

Adequacy determinations affecting Denmark are issued by the European Commission, not by Datatilsynet individually.

Absence provenance: unavailable. Searched: Denmark bilateral adequacy decision granted.

Sccs And BcrsGreen

Datatilsynet approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion.

Claims (1):

  • Datatilsynet, as the competent supervisory authority, approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion under the Art 64 consistency mechanism.

Transfer Impact AssessmentGreen

Post-Schrems II TIA obligations apply directly under GDPR/EDPB Recommendations 01/2020; no Denmark-specific variant identified.

Absence provenance: unavailable. Searched: Datatilsynet transfer impact assessment guidance Denmark.

Data LocalisationGreen

No general data-localisation mandate identified for Denmark beyond sector-specific domestic-infrastructure arrangements (e.g., the state-run 'mit.dk' digital mail platform).

Absence provenance: unavailable. Searched: Denmark data localisation mandate personal data.

Key findings (1)

  • — source on file
Category narrative59 words

As an EU Member State, Denmark's transfer regime is governed by GDPR Chapter V uniformly across the Union: adequacy decisions are adopted at EU (Commission) level rather than bilaterally by Denmark, and SCCs/BCRs are the principal mechanisms used. Datatilsynet acts as the competent authority approving Binding Corporate Rules for Danish-headquartered groups (e.g. Carlsberg), taking utmost account of EDPB opinions.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableDatatilsynet / EDPB — Datatilsynet, as the competent supervisory authority, approved Binding Corporate Rules for the Carlsberg group, taking utmost account of the corresponding EDPB opinion under the Art 64 consistency mechanism.observed

#

Several sector overlays confirmed (marketing, HR, credit, health); financial, education and insurance overlays remain evidence gaps.

Primary frameworkDatabeskyttelsesloven sector provisions; Danish Marketing Practices Act (Markedsføringsloven)
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberSeveral sector overlays confirmed (marketing, HR, credit, health); financial, education and insurance overlays remain evidence gaps.

Sub-modules (7)

Financial Sector OverlayRed

No Denmark-specific financial-sector DP overlay (e.g., Finanstilsynet interface) was substantiated in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet Finanstilsynet data protection financial sector Denmark.

Health Sector OverlayAmber

Datatilsynet's Capio (private hospital) enforcement demonstrates active health-sector supervision of processor oversight for special-category data.

Claims (1):

  • Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.

Telecoms And EprivacyGreen

Direct electronic marketing is governed by the Danish Marketing Practices Act, which implements the ePrivacy Directive's rules alongside the Data Protection Act's opt-out-register mechanism.

Claims (1):

  • The Danish Act allows disclosure of general personal data between enterprises for marketing purposes without consent provided an opt-out register is checked first, but the actual marketing activity must comply with the Danish Marketing Practices Act implementing ePrivacy Directive rules on direct electronic marketing.

Employment DataAmber

The Danish Act permits processing of normal and sensitive personnel data on a legitimate-interest basis grounded in legislation or collective agreements.

Claims (1):

  • The Danish Act allows processing of normal and sensitive data in personnel administration on the basis of legitimate interests arising from legislation or collective agreements, extended to public authorities which cannot normally rely on legitimate interest.

Credit And ScoringAmber

Prior Datatilsynet approval is required before establishing credit rating agencies.

Claims (1):

  • Prior approval from Datatilsynet is required before establishing warning registers, credit rating agencies and judicial information systems.

EducationRed

No Denmark-specific education-sector DP overlay was substantiated in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet education sector data protection guidance Denmark.

InsuranceRed

No Denmark-specific insurance-sector DP overlay was substantiated in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet insurance sector data protection Denmark.

Key findings (1)

  • — source on file
Category narrative50 words

Sector overlays in Denmark include the Marketing Practices Act (implementing ePrivacy rules on direct marketing), enhanced HR-data legitimate-interest bases, mandatory Datatilsynet pre-approval for credit-rating agencies, and active supervision of the health sector (Capio hospital-group vendor-management enforcement). Financial-sector, education, and insurance overlays were not substantiated with Denmark-specific findings in this pass.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableIAPP — The Danish Act allows disclosure of general personal data between enterprises for marketing purposes without consent provided an opt-out register is checked first, but the actual marketing activity must comply with the Danish Marketing Practices Act implementing ePrivacy Directive rules on direct electronic marketing.observed

#

Core cookie-consent and direct-marketing rules are confirmed; several sub-modules are genuinely inapplicable (US-specific) or unevidenced at Denmark level.

Primary frameworkGDPR Art 6/7 as applied via Datatilsynet cookie guidance; Danish Marketing Practices Act
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberCore cookie-consent and direct-marketing rules are confirmed; several sub-modules are genuinely inapplicable (US-specific) or unevidenced at Denmark level.

Sub-modules (6)

Cookies And TrackersGreen

Datatilsynet's 2020 guidelines on processing website-visitor data confirm that valid GDPR consent (opt-in, purpose-specific) is the standard legal basis for cookie/tracker use.

Claims (1):

  • Datatilsynet's guidelines on processing website visitor personal information state that where consent is relied upon as the legal basis, visitors must opt in and be clearly informed of processing purposes for the consent to be GDPR-valid.

Dark PatternsAmber

No Denmark-specific dark-pattern prohibition distinct from EU DSA/GDPR fair-processing norms was identified in this pass.

Absence provenance: unavailable. Searched: Datatilsynet dark patterns consent design Denmark.

Opt Out SignalsAmber

No Denmark-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: unavailable. Searched: Datatilsynet Global Privacy Control opt-out signal Denmark.

Clean Rooms And DcrAmber

No Denmark-specific clean-room/data-collaboration-room regime was identified.

Absence provenance: unavailable. Searched: Datatilsynet data clean room guidance Denmark.

Cross Context AdvertisingAmber

The CPRA 'sale'/'share' construct is a US state-law concept with no direct Danish/EU-GDPR analogue; GDPR instead regulates all processing via lawful-basis and purpose-limitation rules.

Absence provenance: unavailable. Searched: Denmark cross-context advertising sale of data equivalent.

Direct MarketingGreen

Disclosure of general personal data between enterprises for marketing without consent is permitted subject to an opt-out register check, with the Marketing Practices Act governing the actual marketing communications.

Claims (1):

  • The Danish Act allows disclosure of general personal data between enterprises for marketing purposes without consent provided an opt-out register is checked first, but the actual marketing activity must comply with the Danish Marketing Practices Act implementing ePrivacy Directive rules on direct electronic marketing.

Key findings (1)

  • — source on file
Category narrative56 words

Denmark's cookie/tracker regime relies on GDPR-standard opt-in consent as articulated in Datatilsynet's website-visitor-data guidelines, and direct marketing is governed by an opt-out-register mechanism under the Data Protection Act plus the Marketing Practices Act. Dark-pattern prohibitions, opt-out signals (GPC-equivalent), clean-room rules, and CPRA-style cross-context-advertising concepts have no Denmark-specific instrument, as these are either EU-DSA-level or US-specific constructs.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

Datatilsynet has confirmed cookie-tracking enforcement as a named 2026 supervisory priority, announced 7 January 2026. The regulator's stated practical posture recognises no analytics exemption, meaning that even cookies deployed solely for analytics purposes require valid consent under the joint GDPR and Cookiebekendtgørelsen framework, and requires a Danish-language consent solution for compliance, a specific and testable requirement that goes beyond generic multi-language consent-banner practice common elsewhere in the EU.

That stated priority is understood to have already produced a concrete enforcement referent: Datatilsynet is reported to have reprimanded JP/Politikens Hus and Berlingske, two of Denmark's most prominent media publishers, over colour-coded consent nudging and conditional cookie walls. Colour-coded nudging, using visual weighting such as colour contrast to steer users toward an accept option, and conditional cookie walls, where continued site access is made contingent on cookie acceptance, are both established dark-pattern categories, and their appearance in an enforcement action against major Danish news publishers signals that Datatilsynet is treating consent-interface design, not merely the presence or absence of a consent banner, as within its active enforcement scope.

For digital publishers and advertisers operating in the Danish market, the practical takeaway is that consent-interface design choices previously treated as a commercial optimisation question are now squarely within Datatilsynet's named 2026 priority area, and the JP/Politikens Hus and Berlingske matter demonstrates the regulator is willing to act against major domestic publishers rather than reserving enforcement for smaller or less prominent actors.

Outlook

The item to watch is whether Datatilsynet extends the cookie-tracking priority into further reprimand or fine-referral actions against other Danish publishers or advertising-technology providers beyond the JP/Politikens Hus and Berlingske matter, and whether any subsequent action clarifies the specific design threshold that triggers a dark-pattern finding under the no-analytics-exemption, Danish-language-consent standard.

Sources and claims (1)
  1. ProbableDataGuidance — Datatilsynet's guidelines on processing website visitor personal information state that where consent is relied upon as the legal basis, visitors must opt in and be clearly informed of processing purposes for the consent to be GDPR-valid.observed

#

Active soft-law/guidance activity on AI and ADM; biometric/genetic sub-modules and state-surveillance carve-outs remain evidence gaps at Denmark-specific level.

Primary frameworkGDPR Art 22 (ADM) directly applicable; EU AI Act (Regulation (EU) 2024/1689) as it enters into force, with national competent authority designation ongoing
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive soft-law/guidance activity on AI and ADM; biometric/genetic sub-modules and state-surveillance carve-outs remain evidence gaps at Denmark-specific level.

Sub-modules (6)

Profiling RestrictionsAmber

GDPR Art 22 profiling/ADM restrictions apply directly; the EU DSA additionally bans targeted advertising to minors based on profiling.

Claims (1):

  • The EU Digital Services Act bans targeted advertising to minors based on profiling on online platforms, a restriction applicable within Denmark alongside GDPR Art 22.

Automated Decision Making TransparencyAmber

Datatilsynet's AI task force produces guidance and templates for development and use of AI solutions, aimed at ensuring citizens' fundamental rights (including transparency) in automated processing.

Claims (1):

  • Datatilsynet formed an internal cross-departmental AI task force to produce guidance and templates for AI development/use and to map public-sector AI use for fundamental-rights compliance.

Ai Risk AssessmentsAmber

Datatilsynet published a legal-basis assessment for Copenhagen Municipality's AI rehabilitation-prediction tool, and co-operates an AI regulatory sandbox with Digitaliseringsstyrelsen.

Claims (2):

  • Datatilsynet published an assessment of Copenhagen Municipality's legal basis (GDPR Arts 6(1)(e), 6(2)-(3), 9(2)(g)) for developing and operating an AI solution predicting citizens' rehabilitation needs, finding the underlying Service Act insufficiently clear for the processing's scope.
  • Datatilsynet and the Danish Digital Agency (Digitaliseringsstyrelsen) jointly operate an AI regulatory sandbox alongside published guidelines on responsible use of generative AI by companies and authorities.

Biometric RegimeAmber

No Denmark-specific biometric-data regime distinct from GDPR Art 9(1) special-category treatment was identified in this pass.

Absence provenance: unavailable. Searched: Datatilsynet biometric data facial recognition regime Denmark.

Genetic DataAmber

No Denmark-specific genetic-data regime distinct from GDPR Art 9(1) was identified in this pass.

Absence provenance: unavailable. Searched: Datatilsynet genetic data processing regime Denmark.

State Surveillance CarveoutsAmber

No Denmark-specific national-security carve-out beyond GDPR Art 2(2)(d)/Art 23 and the Law Enforcement Directive transposition was substantiated in this pass.

Absence provenance: unavailable. Searched: Denmark national security data protection carve-out GDPR Article 23.

Key findings (1)

  • — source on file
Category narrative58 words

Datatilsynet has been proactive on AI governance ahead of binding EU AI Act obligations: it formed an internal cross-departmental AI task force, issued a healthcare-sector AI legal-basis assessment for Copenhagen Municipality's rehabilitation-prediction system, and co-runs an AI regulatory sandbox with the Danish Digital Agency (Digitaliseringsstyrelsen). No Denmark-specific biometric or genetic-data regime distinct from GDPR Art 9 was identified.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Denmark's AI-governance framework is emerging as a distinct compliance track alongside GDPR, anchored in Law No. 467/2025, in force since August 2025. The Act provides the national legal basis for administrative enforcement measures giving effect to the EU AI Act, including injunctions, temporary bans, product recalls, and bødeforelæg, administrative fine settlements. Its scope, however, is understood to be limited to enforceability and sanctions for the AI Act's prohibited-practices provisions specifically, rather than the Act's full substantive scope. A comprehensive successor law addressing the complete EU AI Act framework was reported to be under development as of May 2026, meaning the current Danish AI-enforcement architecture is a partial, interim structure rather than a finished transposition.

A structurally notable feature is that, as with GDPR fines, AI Act penalties in Denmark are understood to run through the criminal, court-imposed route rather than a direct administrative fining mechanism, mirroring the same court-mediated pattern that characterises Denmark's general data-protection enforcement architecture under the Recital 151 carve-out. This means the two frameworks, GDPR and the AI Act, share a common national enforcement design philosophy in Denmark even though they derive from entirely separate EU instruments.

For entities deploying AI systems that fall within the AI Act's prohibited-practices category and that operate in or target the Danish market, the current interim law already carries real enforcement teeth, injunctions, temporary bans, and product recalls are all available under it, even though the broader AI Act compliance landscape awaits the successor legislation.

Outlook

The principal item to track is the progress of Denmark's comprehensive AI Act successor law, last reported as under development as of May 2026, and whether it maintains the same court-mediated enforcement philosophy or introduces a direct administrative fining power distinct from the GDPR model.

Sources and claims (4)
  1. ProbableIAPP — The EU Digital Services Act bans targeted advertising to minors based on profiling on online platforms, a restriction applicable within Denmark alongside GDPR Art 22.observed
  2. ProbableDataGuidance — Datatilsynet formed an internal cross-departmental AI task force to produce guidance and templates for AI development/use and to map public-sector AI use for fundamental-rights compliance.observed
  3. ProbableDataGuidance — Datatilsynet published an assessment of Copenhagen Municipality's legal basis (GDPR Arts 6(1)(e), 6(2)-(3), 9(2)(g)) for developing and operating an AI solution predicting citizens' rehabilitation needs, finding the underlying Service Act insufficiently clear for the processing's scope.observed
  4. ProbableDataGuidance — Datatilsynet and the Danish Digital Agency (Digitaliseringsstyrelsen) jointly operate an AI regulatory sandbox alongside published guidelines on responsible use of generative AI by companies and authorities.observed

#

Core consent-age derogation confirmed; social-media minimum-age policy is still in development, and dependent-adult/education sub-modules are evidence gaps.

Primary frameworkDatabeskyttelsesloven §6(3) (age of digital consent); prospective Danish 'digital majority' social-media proposals
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberCore consent-age derogation confirmed; social-media minimum-age policy is still in development, and dependent-adult/education sub-modules are evidence gaps.

Sub-modules (5)

Age VerificationAmber

Denmark is among the member states piloting the European Commission's privacy-preserving age-verification blueprint under DSA Art 28 guidelines.

Claims (1):

  • The European Commission developed a privacy-preserving age-verification blueprint that is being piloted in Denmark alongside France, Greece, Italy and Spain.

Minor Profiling BansAmber

The EU DSA's ban on profiling-based targeted advertising to minors applies within Denmark; no additional Denmark-specific profiling ban was identified.

Claims (1):

  • The EU Digital Services Act bans targeted advertising to minors based on profiling on online platforms, a restriction applicable within Denmark alongside GDPR Art 22.

Education SettingsRed

No Denmark-specific education-settings DP rule was substantiated in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet school pupil data protection guidance Denmark.

Dependent AdultsRed

No Denmark-specific dependent-adult/vulnerable-adult DP protection distinct from GDPR general principles was substantiated in this research pass.

Absence provenance: unavailable. Searched: Datatilsynet vulnerable adults elderly data protection Denmark.

Key findings (1)

  • — source on file
Category narrative48 words

Denmark's headline child-specific rule is the lowered digital age-of-consent (13). Denmark is additionally among the EU governments piloting the Commission's privacy-preserving age-verification blueprint and is reportedly among nine EU governments considering (or advancing) a minimum age for social-media use. No Denmark-specific dependent-adult or education-settings DP rule was substantiated.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableIAPP — The European Commission developed a privacy-preserving age-verification blueprint that is being piloted in Denmark alongside France, Greece, Italy and Spain.observed
  2. UncertainIAPP — Denmark is reported among nine European governments considering or advancing proposals to require a minimum age for social-media use.observed

#

Active enforcement casework confirmed, but the court-mediated fining process (rather than direct administrative fines) is a structural constraint on Datatilsynet's own powers, and collective-redress specifics remain unevidenced.

Primary frameworkGDPR Art 83(9)/Recital 151 as implemented via Danish criminal-referral procedure; GDPR Arts 77-84
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive enforcement casework confirmed, but the court-mediated fining process (rather than direct administrative fines) is a structural constraint on Datatilsynet's own powers, and collective-redress specifics remain unevidenced.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Denmark's legal system does not allow administrative fines under GDPR; Datatilsynet initiates a recommendation and refers cases to the police/Public Prosecutor, with Danish courts imposing the fine as a criminal penalty under GDPR Art 83(9).

Claims (2):

  • Denmark's legal system does not allow for the imposition of administrative fines as set out in GDPR Article 83, per Recital 151; instead, the fine is initiated by Datatilsynet and imposed by competent national courts under Article 83(9).
  • Denmark and Estonia are the only two EU Member States whose national laws do not allow supervisory authorities to impose administrative fines directly; Danish courts impose the fines as criminal sanctions instead.

Enforcement Activity IndexAmber

Recent Datatilsynet-recommended court fines include Netcompany (DKK 15M, 2024), Capio (DKK 1.5M, 2024), SIRIUS Advokater (DKK 500K, 2022), Taxa 4x35 (DKK 1.2M, 2019) and JobTeam (DKK 50K, 2020); the ILVA/IDdesign case (C-383/23) resulted in a court-imposed fine of DKK 100,000 against the DPA's recommended DKK 1.5M.

Claims (6):

  • Datatilsynet recommended a DKK 15 million fine against Netcompany for GDPR violations in developing 'mit.dk', a digital mail service, after inappropriate code allowed unauthorized cross-user access to personal and sensitive data.
  • Datatilsynet recommended a DKK 500,000 fine against law firm SIRIUS Advokater for failing to implement basic security measures, including multifactor authentication for remote IT access, following a data breach caused by a hack.
  • Datatilsynet reported private hospital operator Capio A/S to the police, recommending a DKK 1.5 million fine, after finding the company had not supervised its data processors for several years despite them handling special categories of personal data, breaching the accountability principle.
  • Datatilsynet proposed a DKK 1.2 million fine against taxi company Taxa 4x35 for retaining customer phone-number data years beyond the stated retention period, holding that data must be deleted once no longer needed.
  • Datatilsynet found that a recruitment company (JobTeam) violated GDPR's lawfulness/fairness/transparency requirements by erasing personal data subject to an access request during the period after the request was submitted and before the reply was given.
  • In the ILVA/IDdesign case (CJEU C-383/23), the Aarhus District Court found ILVA guilty of GDPR retention violations but imposed a criminal fine of DKK 100,000, below the DKK 1.5 million recommended by Datatilsynet based on group turnover, prompting a referral to the CJEU on the calculation of fines against 'undertakings'.

Regulator Funding And CapacityAmber

Datatilsynet's funding and staff were increased by about 50 percent in 2018, bringing headcount to between 50 and 60 employees.

Claims (1):

  • Datatilsynet's funding and staffing were increased by about 50 percent in 2018, bringing its headcount to between 50 and 60 employees.

Collective Redress And Class ActionsRed

No Denmark-specific data-protection collective-redress/class-action mechanism was substantiated in this research pass.

Absence provenance: unavailable. Searched: Denmark data protection class action collective redress GDPR Article 80.

Private Right Of ActionGreen

GDPR Arts 79 (judicial remedy against controller/processor) and 82 (compensation) apply directly in Denmark; no national derogation identified.

Absence provenance: unavailable. Searched: Denmark private right of action GDPR Article 79 82 derogation.

Recent Developments 180DAmber

Within the last ~180 days, Denmark's consideration of a social-media minimum age (part of a broader nine-country EU push) and its piloting of the EU Commission's privacy-preserving age-verification blueprint represent the most salient recent developments.

Claims (2):

  • The European Commission developed a privacy-preserving age-verification blueprint that is being piloted in Denmark alongside France, Greece, Italy and Spain.
  • Denmark is reported among nine European governments considering or advancing proposals to require a minimum age for social-media use.

Key findings (1)

  • — source on file
Category narrative81 words

Denmark presents a jurisdiction-defining enforcement peculiarity confirmed by the CJEU: Danish law does not permit Datatilsynet to impose administrative fines directly (GDPR Recital 151/Art 83(9)); instead, Datatilsynet refers cases to the police/Public Prosecutor, and fines are imposed as criminal penalties by Danish courts (illustrated by the ILVA/IDdesign case, C-383/23, where the court reduced the DPA-recommended DKK 1.5M to DKK 100,000). Enforcement activity is nonetheless frequent (Netcompany, Capio, SIRIUS Advokater, Taxa 4x35, JobTeam), and the regulator's funding/headcount was increased ~50% in 2018.

Periodic update · new data 2026-09-28

Enforcement & Redress

Denmark's enforcement architecture remains structurally distinctive within the EU: Datatilsynet cannot issue administrative GDPR fines directly. Under the Recital 151 carve-out, a mechanism shared with only one other member state, Datatilsynet refers cases to the police with a recommended fine amount, and a court, not the regulator, imposes any resulting penalty as a criminal sanction. This structural fact is unchanged this cycle, but the practical enforcement environment around it is intensifying: the Western High Court's DKK 500,000 fine against the Region of Southern Denmark for a GDPR security-measures failure, reported April 2026, demonstrates the court-referral route remains an active and consequential enforcement channel rather than a rarely used formality.

On the private-redress side, the Western High Court awarded EUR 335 in non-material Article 82 compensation in August 2025 for the wrongful sharing of health data by a municipality, a modest sum that the claimant has appealed to the Supreme Court on the question of quantum. This case is a live private-right-of-action matter, and the outcome of the Supreme Court appeal will be informative as to how Danish courts calibrate non-material-damage awards under Article 82 relative to other EU member states, where such awards have varied considerably.

Taken together, Denmark's enforcement posture combines an unusual institutional mechanism, court-mediated rather than regulator-imposed fining, with an active and, on the evidence of the Region of Southern Denmark and cookie-enforcement cases, intensifying practical enforcement tempo. The structural mechanism itself creates no reduction in practical exposure for controllers; if anything, the unpredictability of judicial fine-setting, absent a published administrative tariff, may increase uncertainty for entities assessing their own risk.

Outlook

The items to watch are the outcome of the Supreme Court appeal on the EUR 335 Article 82 quantum question, and whether further court-referred cases follow the Region of Southern Denmark pattern in setting reference points for security-of-processing fines against Danish public authorities.

Sources and claims (4)
  1. ProbableCJEU / EUR-Lex — Denmark's legal system does not allow for the imposition of administrative fines as set out in GDPR Article 83, per Recital 151; instead, the fine is initiated by Datatilsynet and imposed by competent national courts under Article 83(9).observed
  2. ProbableIAPP — Denmark and Estonia are the only two EU Member States whose national laws do not allow supervisory authorities to impose administrative fines directly; Danish courts impose the fines as criminal sanctions instead.observed
  3. ProbableCJEU / EUR-Lex — In the ILVA/IDdesign case (CJEU C-383/23), the Aarhus District Court found ILVA guilty of GDPR retention violations but imposed a criminal fine of DKK 100,000, below the DKK 1.5 million recommended by Datatilsynet based on group turnover, prompting a referral to the CJEU on the calculation of fines against 'undertakings'.observed
  4. ProbableIAPP — Datatilsynet's funding and staffing were increased by about 50 percent in 2018, bringing its headcount to between 50 and 60 employees.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct31.25
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Denmark
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s) (28 category placement(s)), 24 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator/framework, lawful-basis derogations, and enforcement_and_redress modules are well-evidenced at T1/T2 (CJEU judgment, IAPP legal analysis, EDPB-published Datatilsynet decisions, official BCR decision). Enforcement-activity casework relies substantially on T3 secondary reporting (DataGuidance) of Datatilsynet press releases, which was not independently cross-verified against Danish-language primary Datatilsynet decision PDFs in this pass. AI/algorithmic-governance and children's-data modules rely on T2/T3 secondary sources describing Datatilsynet soft-law activity (task force, sandbox, healthcare assessment) rather than binding instruments. Sectoral_watch (financial, education, insurance) and several adtech/biometric/genetic sub-modules carry explicit absent_field_provenance after targeted but unsuccessful searches.

Unresolved questions (4):

  • Exact judgment date and final fine outcome of CJEU Case C-383/23 (ILVA) beyond the referring Aarhus District Court's 2021 ruling was not confirmed in this pass.
  • Whether Denmark has adopted or is drafting a standalone 'digital majority' / social-media minimum-age statute (as opposed to considering one) remains unconfirmed as of the research date.
  • No Denmark-specific Finanstilsynet/financial-sector data-protection interface, education-sector rule, or insurance-sector rule was located; these may exist in Danish-language primary sources not covered by this English-language search pass.
  • No Denmark-specific dark-pattern, opt-out-signal, clean-room, or biometric/genetic-data instrument distinct from GDPR baseline was located.

Escalate to primary-source review: yes