DK — Country Profile

Denmark

29TOTAL
29OFFICIAL SOURCES
2TOPIC AREAS
Law / Act2
Executive Order1
Policy / Guidance6
National Strategy1
Standard / Framework5
Working Paper1
Other13
02 MAR 2026 · Law / Act

Bill amending the Copyright Act (Introduction of performance protection and protection against digitally generated imitations, etc.) (2025/0654/DK)

On 3 February 2026, the European Commission issued an opinion under Article 5(2) of Directive (EU) 2015/1535 regarding Denmark’s notified draft Act amending the Copyright Act (Introduction of performance protection and protection against digitally generated imitations, etc.) (Notification 2025/0654/DK). The draft Act introduces two new forms of copyright protection. The first is a general right under Section 73a against the making available to the public of realistic digitally generated imita...

Primary legal sourceIntellectual PropertyOfficial source · technical-regulation-information-system.ec.europa.eu ↗
23 JAN 2025 · Standard / Framework

Danish Data Protection Agency's guidelines on secure transmissions

On 23 January 2025, the Danish Data Protection Authority (DPA) published guidance on secure transmission with validated sender, receiver, and content in line with Article 32 of the General Data Protection Regulation (GDPR). The guidance outlines how this approach ensures both the protection and verification of data during transmission. Alongside encryption, the measures aim to prevent data from being sent to unintended recipients and to maintain the integrity of messages during transfer. The ...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
17 JAN 2025 · Other

Data Protection Authority investigation into Berlingske's use of cookie walls over alleged non-compliance with data protection regulations

On 17 January 2025, the Danish Data Protection Authority (Datatilsynet) issued a ruling on Berlingske’s compliance with its order regarding the use of a cookie wall on berlingske.dk. In February 2024, the Authority had found Berlingske’s method of obtaining consent for personal data processing through a cookie wall to be non-compliant with General Data Protection Regulation (GDPR) consent requirements. It was highlighted that users were not offered a genuine choice to access content without g...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
26 NOV 2024 · Policy / Guidance

Data Protection Authority guidance on enhanced security breach response

On 26 November 2024, the Danish Data Protection Authority announced an update in its guidance efforts for organisations affected by breaches of personal data security. This initiative, building on a year of targeted guidance, aims to provide quicker and more relevant assistance to prevent repeat incidents. The authority has refined its approach based on the analysis of 54,681 reviews, ensuring that organizations reporting breaches through the Danish Business Authority's online form receive ef...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
28 OCT 2024 · Other

Data Protection Agency investigation into Booligal ApS data processing practices

On 28 October 2024, the Danish Data Protection Agency (DPA) concluded its investigation into Boliglag ApS, determining that the company had engaged in the illicit processing of homeowner data on its website. The investigation, which commenced in March 2024, was initiated in response to complaints regarding the website's functionality that permitted users to search for property information using a homeowner's name or address. This resulted in the exposure of personal details, including names, ...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
07 OCT 2024 · Other

Danish Data Protection Agency's investigation into Google Workspace Usage in Schools

On 10 July 2024, the Danish Data Protection Agency issued an assessment to municipalities regarding the use of Google Workspace in primary and lower secondary schools, confirming that municipalities are compliant with the Agency's January 2024 order and have ceased the unauthorised passing of personal data. KL, representing 52 municipalities, stated that from 1 August 2024, personal data would no longer be shared for Google's purposes, addressing the Agency's concerns. The Agency noted that c...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
26 SEP 2024 · Other

Datatilsynet investigation into Dansk Retursystem's app "Pant" for alleged unauthorised processing of sensitive user financial information

On 26 September 2024, the Danish Data Protection Authority (Datatilsynet) issued a decision in an investigation into Dansk Retursystem's mortgage app, 'Pant' for unauthorised processing of sensitive user financial information. The investigation focused on the concerns raised regarding the app's features, such as its ability to track user's locations, access extensive information on devices, and interact with user's banks. The decision mandates that Dansk Retursystem review its data processin...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
10 SEP 2024 · Other

Guide on Controlled and Monitored Disclosure of Data

On 10 September 2024, the Danish Data Protection Agency (Datatilsynet) adopted a new Guide aimed at preventing unintended disclosure of personal data during the public release of materials. In particular, the Guide provides preventive actions to help organisations avoid mistakenly sharing personal data, as well as corrective steps to identify already disclosed personal data and take corrective measures. Specifically, it emphasises the importance of removing unnecessary personal data before pu...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
27 JUN 2024 · Other

Datatilsynet Investigation into IDA Forsikring regarding use of AI to analyse recorded conversations

On 27 June 2024, the Danish Data Protection Authority (Datatilsynet) issued a ruling in its investigation into insurance company IDA Forsikring regarding their use of artificial intelligence to analyse recordings of customer service telephone conversations. Datatilsynet found that the recording an analysis of such phone calls was permissible in principle, but that the current process for obtaining consent did not meet prerequisites set by data protection rules.

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
23 MAY 2024 · Other

Datatilsynet Investigation into Netcompany's Alleged Failure to Implement Security Measures

On 23 May 2024, the Norwegian Data Protection Authority (Datatilsynet) concluded its investigation into Netcompany's alleged failure to implement security measures. Datatilsynet had posed several inquiries to Netcompany at the end of February to determine if the situation fell under the scope of General Data Protection Regulation (GDPR) and other pertinent data protection regulations. After reviewing Netcompany's responses, Datatilsynet determined that there is currently no grounds for furthe...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
22 MAY 2024 · Working Paper

Data Protection Authority 's Generic Impact Assessment Template

Official source record dated 2024-05-22 for Denmark concerning Data Protection Authority 's Generic Impact Assessment Template. See the linked datatilsynet.dk source for the authoritative text, procedural context, and implementation details.

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
01 MAY 2024 · Policy / Guidance

Japan-Denmark Memorandum of Cooperation on Safe AI

On 1 May 2024, the Ministry of Internal Affairs and Communications of Japan and the Ministry of Digital Government and Gender Equality of the Kingdom of Denmark signed a Memorandum of Cooperation (MOC). The agreement aims to increase cooperation in the digital field, particularly in the development of machine learning and artificial intelligence (AI), in accordance with the domestic laws and regulations of both countries. The MOC outlines areas of collaboration, including the promotion of saf...

Official materialNational StrategyOfficial source · soumu.go.jp ↗
29 APR 2024 · Other

Data Protection Authority investigation into Telmore A/S and Meta Ireland's Data Sharing Practices

On 29 April 2024, the Danish Data Protection Authority (DPA) concluded its investigation into Telmore A/S for disclosing a citizen's email address to Meta Ireland for the purpose of targeted marketing. The investigation found that Telmore A/S and Meta Ireland were joint data controllers in this context, contrary to Telmore's assertion that Meta Ireland acted merely as a data processor. The DPA ruled that the data-sharing practice could not be justified under the balancing of interests rule an...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
07 APR 2024 · Standard / Framework

Data Protection Authority guidelines on handling personal data security breaches

On 4 July 2024, the Danish data protection authority (Datatilsynet) adopted its updated and expanded guidelines on handling personal data security breaches, incorporating several examples based on current practices and providing detailed instructions for organisations. The guidelines define breaches as incidents leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data. Examples include stolen media, hacker access, and ransomware atta...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
06 APR 2024 · Standard / Framework

Data Protection Authority guidelines on security testing of software

On 4 June 2024, the Danish Data Protection Authority (DPA) adopted guidelines on security testing of software to identify vulnerabilities in newly developed software. The guidelines aim to provide practical guidance in implementing the General Data Protection Regulation (GDPR)'s requirement for an appropriate level of security. The guidelines provide information related to testing, including vulnerability and penetration testing, to establish technical minimum requirements that are compliant ...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
25 MAR 2024 · Other

Datatilsynet investigation into GulogGratis' use of cookie walls

On 25 March 2024, the Danish Data Protection Authority (Datatilsynet) rejected GulogGratis' request to reopen its case on the use of cookie walls, which required users to either pay or consent to cookie tracking.The DPA had found the usage to be lawful but required GulogGratis to demonstrate that its personal data processing for statistical purposes was lawful and in line with GDPR requirements on voluntary consent. The DPA's ruling found that GulogGratis had not demonstrated that the process...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
05 MAR 2024 · Other

Regulatory Sandbox for AI by Danish Data Protection Authority

On 5 March 2024, the Danish Data Protection Authority, in collaboration with the Danish Agency for Digitalisation, announced the establishment of a regulatory sandbox for Artificial Intelligence (AI). The sandbox aims to provide companies and authorities with free access to relevant expertise and guidance on the applicable legal framework, with an initial focus on the General Data Protection Regulation (GDPR). The sandbox process is expected to support innovation and the use of responsible AI...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
04 MAR 2024 · Executive Order

Amendment to the Danish Data Protection Authority's Standard Data Processing Agreement

On 4 March 2024, the Danish Data Protection Authority made two changes to its standard data processing agreement. The amendments pertain to the provision that includes the data controller as a beneficiary third party in the event of the data processor's bankruptcy. The new amended version clarifies that this provision is optional for the data controller and data processor to include in the data processor agreement. Additionally, the wording of the provision has been aligned with the correspon...

Primary legal sourceNational StrategyOfficial source · datatilsynet.dk ↗
07 FEB 2024 · Other

Danish Data Protection Agency position on language technology development

On 7 February 2024, the Danish Data Protection Agency published two opinions about the lawful sharing and publication of datasets used for the development of Artificial Intelligence (AI) and language models. Regarding the publication of a dataset used for the development of an AI model, the Agency stated that the data must be lawfully collected and processed. In particular, the principles of minimisation, accuracy, and legality must be complied with. Further, in the case of the data being pro...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
05 FEB 2024 · Other

Investigation into Rejsekort App by Danish Data Protection Authority

On 2 May 2024, the Danish Data Protection Authority announced it is considering whether to initiate a detailed investigation into the Rejsekort app, which provides tickets to Denmark's public transport system, following preliminary inquiries. The authority has requested information from Rejsekort & Rejseplan about the app's functionality and the nature of personal data processed, including location data of users. This step comes before deciding whether to initiate a formal supervisory case.

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
28 NOV 2023 · Standard / Framework

Datatilsynet Guidelines on Security Measures

On 28 November 2023, the Danish Data Protection Authority (Datatilsynet) adopted guidelines in the form of a Catalogue of Security Measures, introducing tools intended to support companies and authorities in implementing appropriate security measures in various contexts. The catalogue includes a range of technical and organisational measures, with a focus on future guidelines for rights management. Furthermore, the catalogue is intended to provide a specific and applicable tool for meeting th...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
13 JUL 2023 · Policy / Guidance

Danish Data Protection Authority Guidance for the removal of information from search engines

On 13 July 2023, the Danish Data Protection Authority (Datatilsynet) published guidance for data subjects to request search engines such as Google and Bing to remove search results associated with their name. The guidance explains the exercise of the right to have information deleted under the data protection framework and how to contact the search engine to submit a request to delete information. Further, the guidance specifies that data subjects have the right to submit a complaint to Datat...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
20 APR 2023 · Law / Act

Data Protection Authority investigation into Boligportal compliance with GDPR

On 20 April 2023, the Danish Data Protection Authority issued its ruling in the case against the house rental platform Boligportal. After having received complaints about Boligportal's data processing with the help of Facebook Business tools, which collect information about any person visiting the website, the Authority started an investigation. The Authority stated that it was unable to decide whether personal data was transferred to the US in the context of Boligportal's use of Facebook Bus...

Primary legal sourceNational StrategyOfficial source · datatilsynet.dk ↗
20 JAN 2023 · Standard / Framework

Guidelines on consent in the storage of personal data

On 20 January 2023, the Danish Data Protection Authority issued guidelines on the storage of personal data. The guidelines were aimed at clarifying regulations for documentation requirements for data collectors in seeking data subjects’ consent for the storage of personal data under Article 7 of the Danish Data Protection Regulation. The guidelines state that the condition for consent, according to Article 8, applies only as long as data processing is ongoing for the purpose that the data sub...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
27 OCT 2022 · Other

Danish Data Protection Authority investigation on online data processing practices by JP/Politikens Hus media group

On 27 October 2022, the Danish Protection Authority (DPA) issued a decision expressing serious criticisms on how the media group JP/Politikens Hus (JP) processed the personal data of visitors through their website “www.eb.dk”. The investigation was initiated in 2021 when the DPA carried out written inspections of several websites. The DPA found that the “www.eb.dk” website offered three different consent solutions “Accept All”, “Only Necessary”, and “Customize Settings” and was processing per...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
21 SEP 2022 · Policy / Guidance

Datatilsynet guidance on Google Analytics data transfer

On September 21 2022, the Danish Data Protection Authority (Datatilsynet) published its guidance on the use of Google Analytics in relation to cross-border data transfers. Following the 2020 Schrems II ruling by the CJEU that data transfers to the United States under the EU-US Privacy Shield were not in compliance with the EU's General Data Protection Regulation (GDPR), Datatilsynet concludes that the Google Analytics tool cannot be used lawfully without further measures. One technical soluti...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
09 MAR 2022 · Policy / Guidance

Guidance and expert group on data protection regarding cloud services

The Danish Data Protection Agency has published a guide on the use of cloud services and announced the establishment of a dedicated expert group. The guide aims to help data controllers in the use and management of cloud services. Specifically, it provides instructions to assess the choices of data processors and deal with data transfers to third countries. The expert group will be set up to investigate legislative measures that enforce the legal use of cloud services. The expert group is req...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
15 DEC 2021 · National Strategy

Denmark National Strategy for cyber and information security includes funds for new database on breaches of personal data security

On 15 December 2021, the Danish Government published the Danish National Strategy for cyber and information security for 2022-2024. It includes additional funding for the Data Protection Agency (DPA) to create a new public database encompassing information concerning personal data security breaches that the DPA had been notified about. The Danish DPA noted that in 2020 it has reviewed around 9’000 cases of personal data breaches which were reported by companies and organizations pursuant to t...

Official materialNational StrategyOfficial source · datatilsynet.dk ↗
15 JUL 2021 · Policy / Guidance

Guidance on third country transfers of personal data

The Datatilsynet updates its guidance on the transfer of personal data to third countries. The guidance includes additional measures, which are aligned to those adopted by the European Data Protection Board following the delivery of the Schrems II decision, particularly as concerns the requirement of adopting standard contractual clauses.

Official materialNational StrategyOfficial source · datatilsynet.dk ↗