Denmark
Denmark Data Privacy Laws: GDPR, Datatilsynet & AI Act Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 26 primary sources cited on this page. How we verify our legal content

Denmark implements the EU General Data Protection Regulation directly as binding law, supplemented by the Danish Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018, consolidated as Act No. 289 of 8 March 2024). A constitutional peculiarity sets Denmark apart from every other EU member state: Datatilsynet cannot impose GDPR fines directly. A contested penalty is set by the criminal courts after a police report, as GDPR Recital 151 anticipates. Section 42 of the Danish Data Protection Act adds an out-of-court route: where a case is not expected to draw more than a fine, Datatilsynet can issue a fine notice (bodeforelaeg) that ends the matter once the offender admits the offence and pays.
Information last verified on 2026-09-10. This article has not been reviewed by a licensed lawyer.
Jurisdiction scope: This article covers Denmark's national data protection law, including the GDPR as applied in Denmark, the Danish Data Protection Act (Act No. 502 of 2018), the Danish TV Surveillance Act, and Law No. 467 of 14 May 2025 implementing the EU AI Act. It does not address the Faroe Islands or Greenland, which are outside EU law. For EU-wide GDPR rules that apply across all member states, see EU data privacy laws. For Denmark's recording and surveillance rules, see Denmark recording laws.
Quick Answer: How Does Data Protection Work in Denmark?
Denmark protects personal data through two overlapping legal frameworks. The GDPR applies as directly binding EU law for all personal data processing by controllers and processors established in Denmark, or processing that targets Danish residents. The Danish Data Protection Act supplements the GDPR in areas where the regulation grants member states flexibility: child consent, CPR numbers, criminal data, journalistic exemptions, and the structure of enforcement. Datatilsynet (the Danish Data Protection Agency) supervises compliance, investigates complaints, and can impose orders, warnings, reprimands, and processing bans. However, Datatilsynet cannot directly levy the financial penalties that the GDPR authorises. Under GDPR Recital 151, a contested fine is imposed by the criminal courts: Datatilsynet files a report to police, who investigate and refer the case to the judiciary, and the recital tells the court to take Datatilsynet's recommendation into account. Section 42 of the Danish Data Protection Act adds an out-of-court route. Where a violation is not expected to draw more than a fine, Datatilsynet can issue a fine notice (bodeforelaeg), and the case ends there once the offender admits the offence and pays. Recital 151 accommodates only Denmark and Estonia, and Denmark is the only member state where a court imposes the penalty, because in Estonia the supervisory authority imposes it in a misdemeanour procedure. The arrangement has meaningful consequences for the speed and size of enforcement outcomes.
The Legal Framework: GDPR and the Danish Data Protection Act
The GDPR (Regulation (EU) 2016/679) has applied directly in Denmark since 25 May 2018. Unlike a directive, it required no transposition: it became part of Danish law automatically upon entry into force. The Danish Parliament passed the Danish Data Protection Act on 17 May 2018 to ensure the supplementary national provisions were in place on day one. Its formal title is Lov om supplerende bestemmelser til forordning om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger og om fri udveksling af sadanne oplysninger, known as databeskyttelsesloven, Act No. 502 of 23 May 2018. Section 46(2) repealed the earlier Act No. 429 of 31 May 2000, which is the statute the title Lov om behandling af personoplysninger actually belongs to. The Act has been consolidated once, as Act No. 289 of 8 March 2024, which incorporates the two amending acts of 28 December 2023.
Jurisdiction note: The Danish Data Protection Act explicitly states that it does not apply to the Faroe Islands or Greenland. Those territories have separate legal systems and are outside the EU.
Denmark's data protection tradition predates the GDPR. The country had comprehensive legislation in place since 2000 implementing the 1995 EU Data Protection Directive, which itself followed Denmark's Private Registers Act and Public Authorities' Registers Act, both passed on 8 June 1978 as Act No. 293 and Act No. 294. This long history means most Danish organisations entered the GDPR era with mature compliance frameworks already in place.
Beyond the main Data Protection Act, Denmark's data protection landscape includes:
- The Danish TV Surveillance Act (TV-overvagningsloven), governing video surveillance by private entities
- The Danish Law Enforcement Act (Act No. 410 of 27 April 2017 on law enforcement authorities' processing of personal data), implementing the Law Enforcement Directive for criminal justice processing
- The Cookie Order (Cookiebekendtgorelsen, Order No. 1148 of 9 December 2011), which carries the ePrivacy Directive's consent rules for storing or accessing information on a user's device. It is made under sections 9 and 81(2) of the Act on electronic communications networks and services, not under the Marketing Practices Act, and it is administered by the business and digitalisation authorities rather than by Datatilsynet
- The Marketing Practices Act, which governs unsolicited electronic marketing approaches
- Law No. 467 of 14 May 2025, implementing enforcement powers under the EU AI Act (in force 2 August 2025)

Datatilsynet: Structure, Powers, and the Court-Based Fine Model
Datatilsynet (the Danish Data Protection Agency) is Denmark's independent supervisory authority under Article 51 GDPR. Under section 27 of the Danish Data Protection Act it consists of a council and a secretariat headed by a director. The Minister of Justice constitutes the council, whose chair must be a High Court or Supreme Court judge, plus seven other members; the Minister for Business and the Minister for public innovation each appoint one of those seven, and the chair, the members and their deputies serve four-year terms. Datatilsynet operates with full independence from the government in its supervisory and enforcement activities, and participates in the European Data Protection Board (EDPB) alongside all other EU supervisory authorities.
Datatilsynet's annual report for 2024 records 18,816 new cases, an increase of 754 on 2023. Of those, 9,624 were data breach notifications. Its 2025 annual report records 20,536 new cases, of which 9,849 were breach notifications and 525 were supervision cases or cases the agency opened on its own initiative.
The Court-Based Fine Model: GDPR Recital 151
Denmark's constitutional structure does not permit administrative authorities to impose punitive financial penalties. This is not an oversight in Denmark's GDPR implementation; GDPR Recital 151 explicitly anticipates and accommodates it:
"The legal systems of Denmark and Estonia do not allow for administrative fines as set out in this Regulation. The rules on administrative fines may be applied in such a manner that in Denmark the fine is imposed by competent national courts as a criminal penalty and in Estonia the fine is imposed by the supervisory authority in the framework of a misdemeanour procedure, provided that such an application of the rules in those Member States has an equivalent effect to administrative fines imposed by supervisory authorities. Therefore the competent national courts should take into account the recommendation by the supervisory authority initiating the fine. In any event, the fines imposed should be effective, proportionate and dissuasive."
In practice, when Datatilsynet identifies a violation serious enough to warrant a fine, the process follows these steps:
- Datatilsynet completes its investigation and issues a written decision with a recommended fine amount.
- Datatilsynet files a police report (politianmeldelse) with the recommended fine.
- The police investigate the case independently and decide whether to bring formal charges.
- If charges are brought, the case is referred to the criminal courts.
- The court reviews the evidence, considers the Datatilsynet recommendation, and imposes whatever fine it finds proportionate.
This model adds substantial procedural safeguards for organisations but lengthens enforcement timelines significantly. Cases can take years from Datatilsynet's recommendation to a final court judgment, and the amount moves in both directions. The Eastern High Court imposed DKK 1 million on Arp-Hansen Hotels on 20 September 2023 against a recommendation of DKK 1.1 million, after the district court had found the company guilty but waived the penalty altogether. In the Taxa 4x35 case the Eastern High Court raised a DKK 100,000 district court fine to DKK 250,000 on 28 April 2025, still far below the DKK 1.2 million recommended. In the IDdesign case the Western High Court raised a DKK 100,000 district court fine to the full DKK 1.5 million Datatilsynet had asked for.
Not every case reaches a courtroom. Section 42 of the Danish Data Protection Act lets Datatilsynet issue a fine notice (bodeforelaeg) where a violation is not expected to draw more than a fine, and section 42(3) ends further prosecution once the fine is accepted. The Danish Immigration Service settled that way on 18 March 2024 for DKK 150,000, and Gyldendal A/S on 14 April 2026. Section 11 of Law No. 467 does not open that route directly: it empowers the Minister for Digitalisation, after negotiation with the Minister of Justice, to lay down rules allowing the market surveillance authorities to settle specified AI Act cases by fine notice, and no such rules have been identified. A case can also close with no fine at all: the Danske Bank recommendation ended in a waiver of prosecution because the bank had already been convicted in a separate criminal case.
Enforcement Powers Beyond Fines
While it cannot impose an administrative fine, Datatilsynet holds substantial non-financial enforcement powers that can be applied directly and immediately:
- Warnings for potential future violations
- Reprimands for established violations of the GDPR
- Compliance orders requiring organisations to bring processing into line with the GDPR
- Temporary or permanent processing bans
- Suspension of data flows to third countries
- Orders to notify affected data subjects of a breach
These non-financial tools are actively used and can carry serious operational consequences. A processing ban on a core business system can disrupt operations far more immediately than a fine that will not be resolved for years in the courts.
Legal Bases and Consent Under Danish Law
Denmark applies the standard six legal bases under GDPR Article 6: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. The Danish Data Protection Act adds no additional Article 6 bases but modifies how some apply in the national context.
For consent to be valid under GDPR Article 7 as applied in Denmark, it must be freely given, specific, informed, and unambiguous. Datatilsynet updated its consent guidance in 2021, clarifying several points:
- Public authorities face a higher threshold for relying on consent given the inherent power imbalance between authority and citizen. Datatilsynet's position is that consent is rarely a valid basis for public-sector processing.
- Scrolling or swiping through a page does not constitute an unambiguous indication of consent to data processing.
- Consent must be as easy to withdraw as to give. Pre-ticked boxes and bundled consents are invalid.
For employment relationships, section 12 of the Danish Data Protection Act supplies its own processing bases. Section 12(1) permits processing necessary to comply with the controller's or the employee's employment-law obligations or rights as laid down in other legislation or collective agreements, and section 12(2) adds a legitimate-interest basis where that interest arises from other legislation or collective agreements. Section 12(3) confirms that consent under Article 7 GDPR remains available. The power-imbalance caution comes from Article 7(4) GDPR and from Datatilsynet's guidance, not from section 12 itself.
Special Category Data
GDPR Article 9 applies in Denmark for special categories (health, racial or ethnic origin, political opinions, religious beliefs, genetic and biometric data, trade union membership, sex life or sexual orientation). Section 7 of the Danish Data Protection Act is the national provision for all special category data, not only health data. Section 7(1) disapplies the Article 9(1) prohibition where Article 9(2)(a), (c), (d), (e) or (f) is met, section 7(2) covers employment-law processing under Article 9(2)(b), and section 7(3) covers the health-sector limb under Article 9(2)(h). Section 7(4) carries a genuine Danish derogation: a controller outside the public sector that relies on substantial public interest under Article 9(2)(g) needs prior authorisation from Datatilsynet, which may attach conditions. Section 8 covers criminal data processing.
Data Subject Rights
All GDPR Chapter III rights apply in Denmark without material modification:
| Right | GDPR Article | Danish Context |
|---|---|---|
| Access | Art. 15 | Applies in full; public authorities must also comply with access rules under the Access to Public Administration Files Act |
| Rectification | Art. 16 | Applies in full |
| Erasure (right to be forgotten) | Art. 17 | Applies in full |
| Restriction of processing | Art. 18 | Applies in full |
| Data portability | Art. 20 | Applies to automated processing based on consent or contract |
| Object to processing | Art. 21 | Applies; includes right to object to direct marketing at any time |
| Not subject to automated decision-making | Art. 22 | Applies; Datatilsynet has issued guidance on automated profiling |
Data subjects may lodge complaints with Datatilsynet free of charge. Datatilsynet must investigate complaints unless they are manifestly unfounded or excessive.
Compensation for non-material damage under GDPR Article 82 has now been settled at the top of the Danish court system. The Eastern High Court, sitting as first instance, awarded DKK 2,500 on 20 August 2025 to a woman whose health information a municipality disclosed by mistake while handling an access-to-documents request. The Supreme Court raised that award to DKK 30,000 on 24 August 2026, holding that disclosing very sensitive information about a serious psychiatric condition to a private individual she was in conflict with was capable of affecting her sense of self-worth. Her husband, whose financial details were disclosed in the same error, recovered nothing, because the court found he had not shown damage.
CPR Number Protections
One of Denmark's most distinctive national provisions concerns the CPR number (personnummer), the unique civil registration number assigned to every person registered in Denmark's Civil Registration System. CPR numbers function as master identifiers across government and private systems, enabling linkage of datasets in ways that make their misuse a serious privacy risk.
Section 11 of the Danish Data Protection Act provides a specific regime for CPR numbers that sits alongside, not instead of, GDPR Article 6. A controller that has a valid Article 6 legal basis must also satisfy section 11 to process CPR numbers.
For public authorities, section 11(1) permits processing of a CPR number for the purpose of unambiguous identification or as a case reference number.
For private entities, section 11(2) is a closed list of four grounds:
- It follows from legislation
- The data subject has consented in accordance with GDPR Article 7
- Processing takes place solely for scientific or statistical purposes; or a CPR number is disclosed where the disclosure is a natural part of the normal operation of undertakings of that kind and is of decisive importance for ensuring unambiguous identification of the data subject, or the disclosure is required by a public authority
- The conditions in section 7 are met
Section 11(3) adds that a CPR number may not be published without Article 7 consent. There is no ground based on the number having been made public, and no legitimate-interest balancing test. That balancing test belongs to section 8(3) on criminal-offence data. The distinction matters, because breaching section 11 is a criminal offence under section 41(2)(1).
Private-sector organisations should not assume that a valid GDPR Article 6 basis (for example, contract performance) automatically authorises CPR number processing. A separate section 11 justification is required.

Data Protection Officers (DPOs)
Denmark follows GDPR Article 37(1) for mandatory DPO appointments without adding additional national obligations. A DPO must be designated when the organisation is:
- A public authority or body (except courts acting in their judicial capacity)
- An entity whose core activities require large-scale, regular, and systematic monitoring of individuals (for example, online behavioural tracking at scale)
- An entity whose core activities consist of large-scale processing of special category data or data relating to criminal convictions and offences
Section 24 of the Danish Data Protection Act adds one specific obligation for DPOs designated under grounds (b) and (c): those DPOs are subject to a statutory confidentiality obligation and may not disclose or exploit information acquired in connection with their DPO duties. This is a stricter confidentiality obligation than the GDPR itself imposes.
DPOs must report directly to the highest management level, must be involved in all data protection issues in a timely manner, and cannot be dismissed or penalised for performing their DPO tasks. The DPO's contact details must be published and communicated to Datatilsynet.
Breach Notification
Denmark applies the standard GDPR breach notification framework:
- Controllers must notify Datatilsynet within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms (GDPR Article 33)
- When a breach is likely to result in high risk to affected individuals, the controller must notify those individuals without undue delay (GDPR Article 34)
- Processors must notify their controller without undue delay upon becoming aware of a breach
Datatilsynet provides an online notification portal and has published detailed guidance on assessing breach risk levels. The agency emphasised in its 2024 report that many breach notifications it receives are submitted late, and that organisations should have documented breach response procedures tested in advance.
Data breach reporting volumes have increased substantially year on year. Datatilsynet received 9,624 breach notifications in 2024 and 9,849 in 2025.
CCTV Surveillance: The TV Surveillance Act
Denmark maintains a separate TV Surveillance Act (TV-overvagningsloven, consolidated as Act No. 182 of 24 February 2023) governing video surveillance. It applies to public authorities as well as private ones: sections 2 a and 2 c let a municipal council survey public streets, section 2 d covers a public authority's own entrances and facades, section 3 a imposes the signage duty on public authorities, section 4 d governs municipal recordings with its own 30-day deletion rule, and section 4 e gives Datatilsynet supervision of sections 4 c and 4 d.
Permitted private CCTV: Private businesses may conduct CCTV on their own premises (interior and immediately adjacent exterior areas) for security and crime prevention purposes without special authorisation, subject to GDPR compliance requirements.
Public space prohibition: Private entities are, as a general rule, prohibited from conducting CCTV surveillance of public spaces. Exceptions exist for certain categories of business where surveillance of adjacent public areas is justified by security considerations, but these require assessment against the general prohibition.
30-day retention limit: Recordings made in connection with crime-prevention CCTV must be deleted no later than 30 days after they were made (section 4 c(4)). Section 4 c(5) allows longer retention in three situations: where it is necessary because a criminal complaint has been filed, where the controller needs the footage to handle a specific dispute, or for the closed retail crime-prevention sharing scheme in section 4 c(2). The specific-dispute route carries its own duty, because the controller must notify the person the dispute concerns within the 30 days and hand over a copy of the recording on request.
Signage requirement: Any area under CCTV surveillance must display clear visible signage identifying the responsible entity and providing contact information. Failure to post adequate signage is a standalone compliance issue.
Age of Digital Consent
Section 6(2) of the Danish Data Protection Act sets the age of consent for information society services at 15 years. Children aged 15 and older may independently consent to the processing of their personal data in connection with digital services such as social media platforms and online applications, without parental authorisation. For children under 15, section 6(3) requires that consent be given or approved by the holder of parental responsibility.
The threshold was 13 until 1 January 2024. Act No. 1783 of 28 December 2023 replaced the words 13 years with 15 years in section 6(2) and (3), and its section 2 provides that the change does not apply to consent given before that date, which stays under the previous rule. GDPR Article 8(1) sets a default of 16 and lets a member state go no lower than 13, so 15 sits near the top of the permitted range rather than at the minimum.
Watch out: A separate social media age-limit initiative, which would restrict access to designated platforms below 15 (or 13 with parental consent) under a Digital Services Act framework, has been announced politically and is not yet law. It is not the source of the 15-year GDPR consent age. That age is already in force and has been since 1 January 2024.
Journalism and Freedom of Expression Exemptions
Section 3(8) of the Danish Data Protection Act exempts processing carried out solely for journalistic purposes, and processing carried out solely for artistic or literary activity. Such processing falls outside the Act and outside GDPR Chapters II through VII and Chapter IX, but Articles 28 and 32 of the GDPR still apply, so processor contracts and security obligations remain in force.
Academic and scientific research is not part of that exemption. It is governed by section 10, which permits processing of Article 9 and Article 10 data solely for statistical or scientific studies of substantial public importance, bars later use for any other purpose, and requires prior authorisation from Datatilsynet for certain disclosures to third parties.
The journalism exemption is wider than what many other EU member states provide and reflects Denmark's strong constitutional tradition of press freedom. Journalists and artists retain substantial latitude to process personal data without meeting the GDPR's full compliance requirements.
Processing of Criminal Data
Section 8 of the Danish Data Protection Act governs processing of personal data relating to criminal offences and convictions. A private entity has three routes. Section 8(3) allows processing with the data subject's explicit consent, and also where processing is necessary to pursue a legitimate interest that clearly outweighs the interest of the data subject. Section 8(5) adds that processing may take place where the conditions in section 7 are met. Section 8(4) then bars onward disclosure without explicit consent, unless disclosure serves public or private interests that clearly outweigh the interest in confidentiality.
Public administration is more restricted, not less. Section 8(1) prohibits it from processing criminal-offence data at all unless that is necessary for the performance of the authority's tasks, and section 8(2) bars disclosure except on four enumerated grounds.
Cross-Border Data Transfers
Denmark follows the standard GDPR Chapter V framework for international transfers. Transfers of personal data outside the EEA require one of:
- An adequacy decision by the European Commission (covering countries such as the UK, Switzerland, Canada, Japan, South Korea, and the US under the EU-US Data Privacy Framework)
- Appropriate safeguards including Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or approved codes of conduct
- Specific derogations under GDPR Article 49 (consent, contract necessity, vital interests, legal claims, public interest)
Datatilsynet declared the use of Google Analytics unlawful in September 2022 on the basis that it transferred personal data to the United States without adequate safeguards following the CJEU's Schrems II ruling. While the EU-US Data Privacy Framework (adopted July 2023) resolved the specific adequacy gap, Datatilsynet has maintained that DPF compliance is necessary but not sufficient for lawful analytics use. Organisations must also have valid cookie consent, a data processor agreement with Google, and compliance with all GDPR data-minimisation and purpose-limitation requirements.
The Chromebook complex went well beyond guidance. Datatilsynet banned Helsingor Kommune from processing personal data through Google Chromebooks and Workspace for Education on 14 July 2022, and upheld that ban by decision of 18 August 2022. It suspended the ban by decision of 8 September 2022 and issued the municipality four compliance orders at the same time, then issued the same four orders to 52 further municipalities up to 24 October 2022, covering 53 in all. On 4 November 2022, after the local government association KL had filed compliance documentation for the 53 municipalities, Datatilsynet told KL and the municipalities that the ban of 18 August 2022 stayed suspended until it had finished reviewing that material. Its decision of 30 January 2024 then ordered the 53 municipalities to bring their disclosure of pupil data to Google Ltd into line with the GDPR, asking them by 1 March 2024 to say how they would comply and setting 1 August 2024 as the deadline for compliance itself. On 2 February 2026 the agency issued serious criticism of 51 municipalities and warned them about how they had configured the products and about Google's use of sub-processors outside the EU, following the European Data Protection Board's October 2024 opinion on a controller's duties when it uses a processor.

Penalties and Enforcement Record
The GDPR's standard penalty tiers apply in Denmark:
- Up to EUR 10 million or 2% of worldwide annual turnover (whichever is higher) for violations of controller and processor obligations under Articles 8, 11, 25-39, 42, and 43
- Up to EUR 20 million or 4% of worldwide annual turnover (whichever is higher) for violations of core processing principles, data subject rights, international transfer rules, and supervisory authority orders
Because Datatilsynet cannot impose these amounts directly, the practical enforcement record differs significantly. Datatilsynet recommends fines to police; courts impose them as criminal penalties.
Court-Imposed Fines to Date
| Organisation | Datatilsynet Recommendation | Court Outcome | Violation | Decided |
|---|---|---|---|---|
| IDdesign A/S (now ILVA A/S) | DKK 1.5 million | DKK 1.5 million (Western High Court, raised from DKK 100,000 in the district court) | No deletion deadlines for about 385,000 customer records in a legacy system (Art. 5(1)(e)) | 2 September 2025 |
| Arp-Hansen Hotels | DKK 1.1 million | DKK 1 million (Eastern High Court; the district court had waived the penalty) | About 500,000 customer profiles retained past deletion deadlines (Art. 5(1)(e)) | 20 September 2023 |
| Taxa 4x35 (taxi company) | DKK 1.2 million | DKK 250,000 (Eastern High Court, raised from DKK 100,000 in the district court) | About 8.9 million identifiable taxi journeys retained past necessity (Art. 5(1)(e)) | 28 April 2025 |
The IDdesign case is the reference point for how a Danish fine is now calculated. The Western High Court referred the question to the EU Court of Justice, which held in Case C-383/23 on 13 February 2025 that the ceiling in GDPR Article 83(4) to (6) is measured against the worldwide turnover of the whole undertaking, group included, and that the same concept informs whether the fine actually imposed is proportionate.
Pending Recommended Fines (Not Yet Court-Confirmed)
| Organisation | Datatilsynet Recommendation | Violation | Recommended |
|---|---|---|---|
| Netcompany (mit.dk) | At least DKK 15 million | Failure to implement security measures, no privacy-by-design, no DPIA for national digital mail system (Arts. 25, 32) | January 2024 |
Datatilsynet's own list of cases still with the police or the courts also names Capio A/S, SIRIUS advokater, Det Kongelige Teater, Medicals Nordic, Texas Andreas Petersen, Gladsaxe Kommune and Lyngby-Taarbaek Kommune.
Two cases that used to sit on this list are closed. Taxa 4x35 ended in a DKK 250,000 fine in the Eastern High Court on 28 April 2025 and now appears in the table above. Danske Bank never reached a courtroom. Datatilsynet recommended DKK 10 million on 5 April 2022 over the absence of deletion rules across more than 400 systems, and the case was closed with a waiver of prosecution (tiltalefrafald) because the bank had already been convicted in a separate criminal case, so no GDPR fine was imposed.
The distance between a recommendation and the amount a court finally imposes is a structural feature of Denmark's enforcement landscape, and it runs in both directions: the courts cut the Taxa 4x35 recommendation by about four fifths and awarded the IDdesign recommendation in full. Organisations should not assume that a lower court fine means lower compliance risk. Datatilsynet's non-financial enforcement tools, processing bans, compliance orders, and public reprimands, are applied directly and carry immediate operational consequences.
The EU AI Act: Law No. 467 of 14 May 2025
Denmark became one of the first EU member states to enact national legislation implementing the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) when Parliament adopted Law No. 467 on 8 May 2025. The law entered into force on 2 August 2025, the date the AI Act's rules on general-purpose AI models, governance and penalties began to apply. The Article 5 prohibited practices, and the Article 4 AI-literacy duty, had already applied since 2 February 2025, so Law No. 467 supplied a national enforcement machinery for prohibitions that had been in force for six months.
Law No. 467 is a targeted supplementary act. The EU AI Act itself applies directly as EU law and does not require transposition. Law No. 467 does the procedural and institutional work the EU AI Act requires member states to perform: it designates national competent authorities, establishes inspection and enforcement powers at national level, and creates a criminal sanctions framework. The law does not apply to the Faroe Islands or Greenland.
Designated National Authorities Under Law No. 467
Section 2 of Law No. 467 names all three bodies as national competent authorities under Article 70(1) of the AI Act, then splits market surveillance by limb of Article 5 rather than by subject matter:
| Authority | Danish Name | Role |
|---|---|---|
| Agency for Digital Government | Digitaliseringsstyrelsen | Notifying authority, central single point of contact, and market surveillance authority for Article 5(1)(a) to (c), (e) and (f) |
| Danish Data Protection Agency | Datatilsynet | Market surveillance authority for Article 5(1)(d) and (g) |
| Danish Court Administration | Domstolsstyrelsen | Market surveillance authority for the courts' use of AI systems when the courts are not acting in their judicial capacity |
Datatilsynet's mandate therefore turns on which prohibition is in play, not on whether an AI system happens to process personal data. The Digitaliseringsstyrelsen acts as the primary coordinating body and Denmark's single point of contact with the European Commission and the EU AI Office. No market surveillance authority has yet been designated for high-risk AI in Denmark: Digitaliseringsstyrelsen states that it is still unresolved exactly who will supervise the various high-risk areas.
Enforcement Powers Under Law No. 467
The designated authorities may:
- Demand and collect all relevant technical information about AI systems from providers and deployers
- Conduct on-site inspections of business premises without prior judicial authorisation
- Issue injunctions requiring immediate remediation of non-compliant AI systems
- Impose temporary bans on AI systems using prohibited practices
- Recommend fines, imposed by the courts or by a section 42 fine notice (exclusively financial in nature), with a five-year limitation period
- Publish decisions about prohibited AI use
Consistent with Denmark's constitutional framework for financial penalties, a contested AI Act fine under Law No. 467 is set by the criminal courts as a criminal penalty rather than imposed administratively, subject to any fine-notice rules the Minister for Digitalisation may later issue under section 11.
Watch out: Law No. 467 was designed as an initial measure covering the Article 5 prohibited practices, which have applied since 2 February 2025. A comprehensive successor was introduced in the Folketing on 18 February 2026 as Bill L 111, which would have repealed Law No. 467 and moved the designation of competent authorities into a ministerial order. It had its first reading on 17 March 2026 and lapsed when the parliamentary session ended on 24 March 2026, so it never became law. Law No. 467 remains in force, and no replacement bill had been introduced as of 10 September 2026. Organisations subject to the AI Act should monitor guidance from Digitaliseringsstyrelsen and Datatilsynet.
Recent Developments (2024-2026)
Cookie compliance enforcement (2024-2026): Datatilsynet has made cookie consent a priority enforcement area. On 14 February 2024 it ordered Berlingske to bring the cookie wall on berlingske.dk within the GDPR, because users could reach embedded content only by consenting to statistical and marketing processing and so were not offered a real choice. It found on 4 September 2024 that the order had not been met, and confirmed on 24 January 2025 that Berlingske now complied. Datatilsynet and Digitaliseringsstyrelsen published joint guidance on cookies and similar technologies in May 2025. Denmark has no consent exemption for analytics cookies; section 4 of the Cookiebekendtgorelsen recognises only two narrow exemptions, for storage whose sole purpose is to carry a communication and for storage strictly necessary to provide a service the user has explicitly requested.
Google Analytics position updated (2023-2026): Following the EU-US Data Privacy Framework in July 2023, Datatilsynet confirmed that the specific data transfer issue underlying its 2022 unlawfulness finding is resolved for DPF-compliant configurations. The agency nevertheless maintained that DPF adequacy alone does not make Google Analytics lawful. Valid prior-consent mechanisms, compliant data processor agreements, and data-minimisation compliance remain mandatory.
Netcompany recommendation (January 2024): Datatilsynet recommended Denmark's largest GDPR fine to date, at least DKK 15 million, against Netcompany for security failures in the mit.dk national digital mailbox system. The agency found Netcompany had not implemented privacy-by-design, had not conducted a required data protection impact assessment (DPIA), and had deployed inappropriate coding in the user authentication component despite pre-launch testing. Datatilsynet still lists the case among those under way as of September 2026.
Supreme Court compensation ruling (August 2026): The Supreme Court held on 24 August 2026 that a municipality that mistakenly disclosed a woman's health information while handling an access-to-documents request must pay her DKK 30,000, twelve times the DKK 2,500 the Eastern High Court had awarded on 20 August 2025. Her husband, whose financial information went out in the same error, recovered nothing, because he had not shown damage. The judgment is the clearest Danish authority yet on when a data subject suffers non-material damage under Article 82 and on what that damage is worth.
AI Act enforcement begins (August 2025): With Law No. 467 in force from 2 August 2025, organisations operating prohibited AI systems in Denmark face criminal prosecution. Datatilsynet is the designated market surveillance authority for the prohibitions in Article 5(1)(d) and (g). The agency published initial guidance on how AI Act obligations interact with GDPR requirements, given that many AI systems process personal data and therefore fall under both frameworks simultaneously.
EU Digital Omnibus on AI (2026): Regulation (EU) 2026/1744 amended the AI Act and entered into force on 27 July 2026. It left the dates that matter most in Denmark right now untouched: the Article 5 prohibitions still date from 2 February 2025, and the Article 50 transparency duties still apply from 2 August 2026, with a grace period to 2 December 2026 for marking synthetic content generated by systems already on the market. It did delay the high-risk regime, to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and it added new prohibitions on AI-generated intimate imagery and on AI-generated child sexual abuse material from 2 December 2026. Separately, Denmark held the EU Council presidency in the second half of 2025 and circulated proposals to revise the ePrivacy framework, including possible exemptions for certain analytics and technical cookies; those remain in the legislative process.
Business Compliance Checklist
Organisations operating in Denmark should address the following specific features of the Danish data protection landscape:
CPR number handling: Confirm that any processing of Danish civil registration numbers has a valid legal basis under both GDPR Article 6 and section 11 of the Danish Data Protection Act. A contract-performance basis for the main processing activity does not automatically authorise CPR number use.
CCTV compliance: Review retention schedules to confirm recordings are deleted within 30 days. Audit signage at all surveilled premises. Confirm that surveillance does not extend to public spaces in breach of the TV Surveillance Act.
Cookie consent: Conduct a cookie audit. Denmark applies no analytics consent exemption. All non-strictly-necessary cookies require prior opt-in consent. Review consent management platform configuration to eliminate nudging patterns that Datatilsynet has found to invalidate consent.
Child services: If services are offered to individuals, age-gate users under 15. The statutory threshold under section 6(2) of the Data Protection Act has been 15 since 1 January 2024, and consent for a child under 15 must be given or approved by the holder of parental responsibility. Consent collected before 1 January 2024 stays under the previous 13-year rule.
AI systems: Classify all AI systems used in Denmark against the EU AI Act risk tiers, and confirm that no operations fall within the Article 5 prohibited categories, which have applied since 2 February 2025 and are the only part of the AI Act Denmark has so far assigned to national supervisors. Denmark has not yet designated market surveillance authorities for high-risk AI, so build the Chapter III documentation against the regulation itself rather than against a named Danish regulator, working to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
Breach response: Document and test breach notification procedures. The 72-hour clock runs from when any member of the organisation becomes aware of the breach, not when senior management is formally notified. Datatilsynet has noted a high rate of late notifications.
Enforcement model awareness: When assessing the risk of a GDPR violation, account for the two-phase enforcement model. Datatilsynet can impose processing bans and compliance orders immediately. Financial penalties take longer, because they are criminal fines set by a court or accepted in a fine notice under section 42, and they leave a criminal record for the organisation.
Relationship to Recording and Surveillance Laws
Denmark's data protection rules interact directly with its broader surveillance and recording laws. Any recording of individuals, whether audio or video, constitutes personal data processing under the GDPR and requires a valid Article 6 legal basis, transparency obligations under Articles 13 and 14, and compliance with purpose-limitation and data-minimisation principles.
The CCTV provisions of the TV Surveillance Act layer on top of GDPR for video surveillance specifically. For audio recording, Danish criminal law provides the primary consent framework, with GDPR compliance required in addition. For a full analysis of Denmark's recording consent rules, see Denmark recording laws.
Disclaimer: This article provides general legal information about Denmark's data privacy laws as of 10 September 2026. It does not constitute legal advice. Data protection laws change frequently, and the interaction of GDPR, national implementing legislation, and emerging AI regulation continues to evolve. Consult a lawyer qualified in Danish law for advice on your specific situation. Statutes cited reflect their in-force versions as verified on 10 September 2026.
Frequently Asked Questions
Can Datatilsynet impose GDPR fines directly in Denmark?
Not as an administrative fine. GDPR Recital 151 provides that in Denmark the fine is imposed by the competent national courts as a criminal penalty. When Datatilsynet identifies a violation warranting a fine, it files a police report with a recommended amount. Police investigate; if charges are brought, the case goes to court, and the court sets the final penalty while taking Datatilsynet's recommendation into account. This commonly takes years, and courts have raised the recommended amount as well as reduced it. Section 42 of the Danish Data Protection Act adds an out-of-court route: where a case is not expected to draw more than a fine, Datatilsynet can issue a fine notice that ends the matter once the offender admits the offence and pays.
What is the largest GDPR fine actually imposed by a Danish court?
The largest court-imposed GDPR fine in Denmark is DKK 1.5 million, imposed by the Western High Court on 2 September 2025 on IDdesign A/S (now ILVA A/S) for keeping about 385,000 customer records in a legacy system with no deletion deadline. The court raised a DKK 100,000 district court fine to that figure after the EU Court of Justice ruled in Case C-383/23 on 13 February 2025 that the ceiling in GDPR Article 83(4) to (6) is measured against the worldwide turnover of the whole undertaking. Second is DKK 1 million against Arp-Hansen Hotels (Eastern High Court, 20 September 2023). Datatilsynet's largest recommendation still awaiting a court is at least DKK 15 million against Netcompany over the mit.dk digital mailbox system.
What special rules apply to CPR numbers in Denmark?
CPR numbers receive elevated protection under section 11 of the Danish Data Protection Act, on top of the standard GDPR Article 6 requirements. Section 11(2) gives private entities a closed list of four grounds: where it follows from legislation; with the data subject's consent under GDPR Article 7; solely for scientific or statistical purposes, or where disclosing the number is a natural part of the normal operation of undertakings of that kind and is of decisive importance for unambiguous identification, or a public authority requires the disclosure; or where the conditions in section 7 are met. There is no legitimate-interest balancing route, and section 11(3) forbids publishing a CPR number without Article 7 consent. A valid GDPR legal basis alone is not sufficient, and breaching section 11 is a criminal offence.
How long can CCTV footage be retained in Denmark?
Under section 4 c(4) of the Danish TV Surveillance Act (TV-overvagningsloven), recordings made in connection with crime-prevention CCTV must be deleted no later than 30 days after they were made. Section 4 c(5) allows longer retention in three cases: where a criminal complaint has been filed, where the controller needs the footage to handle a specific dispute, or under the closed retail crime-prevention sharing scheme in section 4 c(2). If footage is kept for a specific dispute, the controller must notify the person concerned within the 30 days and give them a copy on request. Municipal recordings have their own 30-day rule in section 4 d(3).
What is the age of digital consent in Denmark?
Section 6(2) of the Danish Data Protection Act sets the age of consent for information society services at 15 years. It was 13 until Act No. 1783 of 28 December 2023 raised it with effect from 1 January 2024, and consent given before that date remains governed by the old 13-year rule. Children of 15 and older can consent to digital services without parental involvement; for a child under 15, section 6(3) requires the holder of parental responsibility to give or approve the consent. GDPR Article 8(1) allows member states to set the age anywhere between 13 and 16, so Denmark sits near the top of that range, not at the minimum.
Is Google Analytics lawful in Denmark?
Datatilsynet declared Google Analytics non-compliant in September 2022 due to unlawful transfers to the United States. The EU-US Data Privacy Framework (adopted July 2023) resolved the specific transfer adequacy issue. However, Datatilsynet has stated that DPF compliance alone is insufficient. Organisations using Google Analytics must also obtain valid prior opt-in cookie consent, have a compliant data processor agreement with Google, and comply with all GDPR data-minimisation requirements. Denmark has no consent exemption for analytics cookies.
What does Denmark's Law No. 467 of 2025 do for AI regulation?
Law No. 467 of 14 May 2025, in force from 2 August 2025, sets up Denmark's national governance framework for the EU AI Act (Regulation (EU) 2024/1689). It names Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen as national competent authorities under Article 70(1), makes Digitaliseringsstyrelsen the notifying authority and single point of contact, and divides market surveillance of the Article 5 prohibitions between them: Digitaliseringsstyrelsen takes Article 5(1)(a) to (c), (e) and (f), Datatilsynet takes Article 5(1)(d) and (g), and Domstolsstyrelsen covers the courts' non-judicial use of AI. It does not transpose the AI Act itself, which applies directly. A successor bill, L 111, would have repealed it but lapsed when the parliamentary session ended on 24 March 2026, so Law No. 467 is still in force and Denmark has not yet designated a supervisor for high-risk AI.
Does Denmark require organisations to appoint a Data Protection Officer?
Denmark follows GDPR Article 37(1) without additional national DPO appointment obligations. A DPO must be designated by public authorities or bodies, organisations whose core activities require large-scale systematic monitoring of individuals, and organisations whose core activities involve large-scale processing of special category data or criminal-conviction data. Section 24 of the Danish Data Protection Act adds a statutory confidentiality obligation for DPOs designated under the monitoring or special-category grounds, which is stricter than the GDPR itself requires.
What is the 72-hour breach notification requirement in Denmark?
Controllers must notify Datatilsynet within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms, under GDPR Article 33 as applied in Denmark. The clock starts when any part of the organisation becomes aware, not when senior management is formally notified. If the breach is likely to result in high risk to individuals, the affected data subjects must also be notified without undue delay under GDPR Article 34.
Can private businesses conduct CCTV surveillance of public streets in Denmark?
As a general rule, no. The Danish TV Surveillance Act prohibits private entities from conducting CCTV surveillance of public spaces. Narrow statutory exceptions exist for certain categories of business monitoring adjacent public areas for legitimate security purposes, but private surveillance of general public streets requires specific legal justification. Public authorities are covered by the same Act rather than by the GDPR alone: sections 2 a and 2 c let a municipal council survey public streets after consulting the police, section 2 d covers a public authority's own entrances and facades, and section 4 e gives Datatilsynet supervision of the recordings.
Updates
Corrected the age of digital consent to 15, which has been the law since 1 January 2024; replaced the outdated enforcement record with the DKK 1.5 million IDdesign judgment of 2 September 2025 and the CJEU ruling behind it, the decided Taxa 4x35 and Danske Bank outcomes, and the Supreme Court compensation ruling of 24 August 2026; restated the CPR, criminal-data, journalism, employment and CCTV provisions to match the statutes; noted that fines can also be settled out of court by fine notice; and added Danish and EU primary sources throughout. Corrected the Chromebook enforcement history (ban on Helsingor Kommune 14 July 2022, upheld 18 August 2022, suspended 8 September 2022 alongside compliance orders that reached 53 municipalities by 24 October 2022, order of 30 January 2024 to those 53 with an August 2024 deadline, criticism of 51 municipalities on 2 February 2026), dated both Danish Registers Acts to 8 June 1978, removed the claim that 2024 was Datatilsynet's busiest year now that 2025 recorded 20,536 new cases, clarified that section 11 of Law No. 467 only empowers the minister to create a fine-notice route for AI Act cases, and dropped an unverified cookie enforcement action from the changelog.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Major refresh: added EU AI Act Law No. 467/2025 analysis, GDPR Recital 151 block-quote, Arp-Hansen court fine (DKK 1 million, 2023), Netcompany DKK 15 million recommendation, Danske Bank DKK 10 million recommendation, High Court GDPR compensation ruling (August 2025), cookie enforcement action against Berlingske, DPF update on Google Analytics, breach notification statistics (2024-2025), social media age-limit proposal, and new sections on DPO requirements, breach notification, data subject rights table, processing of criminal data, and legal bases/consent.
Reviewed and approved by an editor
Initial publication covering GDPR framework, Datatilsynet structure, court-based fine model, CPR number rules, CCTV regime, and digital consent age.
Sources and References
- Danish Data Protection Act, Act No. 502 of 23 May 2018 (Ministry of Justice English translation of the original 2018 text; superseded on the age of consent by Act No. 1783 of 28 December 2023)(datatilsynet.dk).gov
- Datatilsynet - Danish Legislation(datatilsynet.dk).gov
- GDPR Recital 151 - Administrative Fines in Denmark and Estonia(gdpr-info.eu)
- EU AI Act Regulation (EU) 2024/1689(eur-lex.europa.eu).gov
- Regulations.ai - Denmark AI Act Law No. 467/2025(regulations.ai)
- ai-regulation.com - Denmark AI Act National Law(ai-regulation.com)
- Global Relay - Netcompany DKK 15 Million Recommendation(grip.globalrelay.com)
- TechGDPR - Danish High Court GDPR Compensation Ruling 2025(techgdpr.com)
- Clickport - Google Analytics Denmark 2026(clickport.io)
- White and Case - GDPR Denmark(whitecase.com)
- DLA Piper - Denmark Data Protection(dlapiperdataprotection.com)
- IAPP - Danish DPA Derogations Analysis(iapp.org)
- activeMind - Danish Sanctions Model(activemind.legal)
- GDPRhub - Arp-Hansen Decision(gdprhub.eu)
- GDPRhub - Danske Bank Decision(gdprhub.eu)
- Plesner - Denmark Digital Children Protection Initiatives(plesner.com)
- Danish Data Protection Act (databeskyttelsesloven), consolidated Act No. 289 of 8 March 2024 - retsinformation.dk(retsinformation.dk).gov
- Act No. 1783 of 28 December 2023 raising the age of consent for information society services from 13 to 15, in force 1 January 2024(retsinformation.dk).gov
- Law No. 467 of 14 May 2025 supplementing the EU AI Act (LOV nr 467 af 14/05/2025)(retsinformation.dk).gov
- Bill L 111 (2025/1 LSF 111), proposed AI Act supplementary law introduced 18 February 2026 and lapsed with the session on 24 March 2026(retsinformation.dk).gov
- Danish TV Surveillance Act (tv-overvagningsloven), consolidated Act No. 182 of 24 February 2023(retsinformation.dk).gov
- Cookie Order (cookiebekendtgorelsen), Order No. 1148 of 9 December 2011, made under the Act on electronic communications networks and services(retsinformation.dk).gov
- Act No. 410 of 27 April 2017 on law enforcement authorities processing of personal data (retshaandhaevelsesloven)(retsinformation.dk).gov
- Vestre Landsret, 2 September 2025 (IDdesign A/S / ILVA): GDPR fine raised to DKK 1.5 million, ECLI:DK:VLR:2025:SS0000000468(domsdatabasen.dk).gov
- Ostre Landsret, 28 April 2025 (Taxa 4x35): fine raised to DKK 250,000, ECLI:DK:OLR:2025:SS0000000378(domsdatabasen.dk).gov
- Ostre Landsret, 20 September 2023 (Arp-Hansen Hotel Group): DKK 1 million fine, ECLI:DK:OLR:2023:SS0000001211(domsdatabasen.dk).gov
- Danish Supreme Court, 24 August 2026: DKK 30,000 compensation under GDPR Article 82 for a municipal disclosure of health data (BS-44501/2025-HJR)(domsdatabasen.dk).gov
- CJEU Case C-383/23 ILVA A/S, judgment of 13 February 2025 on the meaning of undertaking in GDPR Article 83(4) to (6)(eur-lex.europa.eu).gov
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending the EU AI Act, in force 27 July 2026(eur-lex.europa.eu).gov
- Datatilsynet - overview of GDPR fine cases, decided and still pending (bodesager)(datatilsynet.dk).gov
- Datatilsynet - Danske Bank recommended for a DKK 10 million fine, 5 April 2022, case closed with a waiver of prosecution(datatilsynet.dk).gov
- Datatilsynet - Udlaendingestyrelsen settled by fine notice of DKK 150,000 on 18 March 2024(datatilsynet.dk).gov
- Datatilsynet - serious criticism and warning to 51 municipalities in the Chromebook case, 2 February 2026(datatilsynet.dk).gov
- Datatilsynet annual report 2025 (arsberetning): 20,536 new cases, 9,849 breach notifications(datatilsynet.dk).gov
- Digitaliseringsstyrelsen - supervision of the EU AI Act in Denmark, including that high-risk supervisors are not yet designated(digst.dk).gov
- Datatilsynet - order of 30 January 2024 to 53 municipalities in the Chromebook case, with a compliance deadline of 1 August 2024(datatilsynet.dk).gov
- Datatilsynet - decision of 18 August 2022 upholding the July 2022 processing ban on Helsingor Kommune's use of Google Workspace(datatilsynet.dk).gov
- Lov om offentlige myndigheders registre, Act No. 294 of 8 June 1978(retsinformation.dk).gov
- Lov om private registre m.v., Act No. 293 of 8 June 1978(retsinformation.dk).gov