EnglishDA
Denmark flag

Denmark

Denmark Data Privacy Laws: GDPR, Datatilsynet & AI Act Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 26 primary sources cited on this page. How we verify our legal content

Denmark Data Privacy Laws: GDPR, Datatilsynet & AI Act Guide (2026)

Frequently Asked Questions

Can Datatilsynet impose GDPR fines directly in Denmark?

Not as an administrative fine. GDPR Recital 151 provides that in Denmark the fine is imposed by the competent national courts as a criminal penalty. When Datatilsynet identifies a violation warranting a fine, it files a police report with a recommended amount. Police investigate; if charges are brought, the case goes to court, and the court sets the final penalty while taking Datatilsynet's recommendation into account. This commonly takes years, and courts have raised the recommended amount as well as reduced it. Section 42 of the Danish Data Protection Act adds an out-of-court route: where a case is not expected to draw more than a fine, Datatilsynet can issue a fine notice that ends the matter once the offender admits the offence and pays.

What is the largest GDPR fine actually imposed by a Danish court?

The largest court-imposed GDPR fine in Denmark is DKK 1.5 million, imposed by the Western High Court on 2 September 2025 on IDdesign A/S (now ILVA A/S) for keeping about 385,000 customer records in a legacy system with no deletion deadline. The court raised a DKK 100,000 district court fine to that figure after the EU Court of Justice ruled in Case C-383/23 on 13 February 2025 that the ceiling in GDPR Article 83(4) to (6) is measured against the worldwide turnover of the whole undertaking. Second is DKK 1 million against Arp-Hansen Hotels (Eastern High Court, 20 September 2023). Datatilsynet's largest recommendation still awaiting a court is at least DKK 15 million against Netcompany over the mit.dk digital mailbox system.

What special rules apply to CPR numbers in Denmark?

CPR numbers receive elevated protection under section 11 of the Danish Data Protection Act, on top of the standard GDPR Article 6 requirements. Section 11(2) gives private entities a closed list of four grounds: where it follows from legislation; with the data subject's consent under GDPR Article 7; solely for scientific or statistical purposes, or where disclosing the number is a natural part of the normal operation of undertakings of that kind and is of decisive importance for unambiguous identification, or a public authority requires the disclosure; or where the conditions in section 7 are met. There is no legitimate-interest balancing route, and section 11(3) forbids publishing a CPR number without Article 7 consent. A valid GDPR legal basis alone is not sufficient, and breaching section 11 is a criminal offence.

How long can CCTV footage be retained in Denmark?

Under section 4 c(4) of the Danish TV Surveillance Act (TV-overvagningsloven), recordings made in connection with crime-prevention CCTV must be deleted no later than 30 days after they were made. Section 4 c(5) allows longer retention in three cases: where a criminal complaint has been filed, where the controller needs the footage to handle a specific dispute, or under the closed retail crime-prevention sharing scheme in section 4 c(2). If footage is kept for a specific dispute, the controller must notify the person concerned within the 30 days and give them a copy on request. Municipal recordings have their own 30-day rule in section 4 d(3).

What is the age of digital consent in Denmark?

Section 6(2) of the Danish Data Protection Act sets the age of consent for information society services at 15 years. It was 13 until Act No. 1783 of 28 December 2023 raised it with effect from 1 January 2024, and consent given before that date remains governed by the old 13-year rule. Children of 15 and older can consent to digital services without parental involvement; for a child under 15, section 6(3) requires the holder of parental responsibility to give or approve the consent. GDPR Article 8(1) allows member states to set the age anywhere between 13 and 16, so Denmark sits near the top of that range, not at the minimum.

Is Google Analytics lawful in Denmark?

Datatilsynet declared Google Analytics non-compliant in September 2022 due to unlawful transfers to the United States. The EU-US Data Privacy Framework (adopted July 2023) resolved the specific transfer adequacy issue. However, Datatilsynet has stated that DPF compliance alone is insufficient. Organisations using Google Analytics must also obtain valid prior opt-in cookie consent, have a compliant data processor agreement with Google, and comply with all GDPR data-minimisation requirements. Denmark has no consent exemption for analytics cookies.

What does Denmark's Law No. 467 of 2025 do for AI regulation?

Law No. 467 of 14 May 2025, in force from 2 August 2025, sets up Denmark's national governance framework for the EU AI Act (Regulation (EU) 2024/1689). It names Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen as national competent authorities under Article 70(1), makes Digitaliseringsstyrelsen the notifying authority and single point of contact, and divides market surveillance of the Article 5 prohibitions between them: Digitaliseringsstyrelsen takes Article 5(1)(a) to (c), (e) and (f), Datatilsynet takes Article 5(1)(d) and (g), and Domstolsstyrelsen covers the courts' non-judicial use of AI. It does not transpose the AI Act itself, which applies directly. A successor bill, L 111, would have repealed it but lapsed when the parliamentary session ended on 24 March 2026, so Law No. 467 is still in force and Denmark has not yet designated a supervisor for high-risk AI.

Does Denmark require organisations to appoint a Data Protection Officer?

Denmark follows GDPR Article 37(1) without additional national DPO appointment obligations. A DPO must be designated by public authorities or bodies, organisations whose core activities require large-scale systematic monitoring of individuals, and organisations whose core activities involve large-scale processing of special category data or criminal-conviction data. Section 24 of the Danish Data Protection Act adds a statutory confidentiality obligation for DPOs designated under the monitoring or special-category grounds, which is stricter than the GDPR itself requires.

What is the 72-hour breach notification requirement in Denmark?

Controllers must notify Datatilsynet within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms, under GDPR Article 33 as applied in Denmark. The clock starts when any part of the organisation becomes aware, not when senior management is formally notified. If the breach is likely to result in high risk to individuals, the affected data subjects must also be notified without undue delay under GDPR Article 34.

Can private businesses conduct CCTV surveillance of public streets in Denmark?

As a general rule, no. The Danish TV Surveillance Act prohibits private entities from conducting CCTV surveillance of public spaces. Narrow statutory exceptions exist for certain categories of business monitoring adjacent public areas for legitimate security purposes, but private surveillance of general public streets requires specific legal justification. Public authorities are covered by the same Act rather than by the GDPR alone: sections 2 a and 2 c let a municipal council survey public streets after consulting the police, section 2 d covers a public authority's own entrances and facades, and section 4 e gives Datatilsynet supervision of the recordings.

Updates

Corrected the age of digital consent to 15, which has been the law since 1 January 2024; replaced the outdated enforcement record with the DKK 1.5 million IDdesign judgment of 2 September 2025 and the CJEU ruling behind it, the decided Taxa 4x35 and Danske Bank outcomes, and the Supreme Court compensation ruling of 24 August 2026; restated the CPR, criminal-data, journalism, employment and CCTV provisions to match the statutes; noted that fines can also be settled out of court by fine notice; and added Danish and EU primary sources throughout. Corrected the Chromebook enforcement history (ban on Helsingor Kommune 14 July 2022, upheld 18 August 2022, suspended 8 September 2022 alongside compliance orders that reached 53 municipalities by 24 October 2022, order of 30 January 2024 to those 53 with an August 2024 deadline, criticism of 51 municipalities on 2 February 2026), dated both Danish Registers Acts to 8 June 1978, removed the claim that 2024 was Datatilsynet's busiest year now that 2025 recorded 20,536 new cases, clarified that section 11 of Law No. 467 only empowers the minister to create a fine-notice route for AI Act cases, and dropped an unverified cookie enforcement action from the changelog.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major refresh: added EU AI Act Law No. 467/2025 analysis, GDPR Recital 151 block-quote, Arp-Hansen court fine (DKK 1 million, 2023), Netcompany DKK 15 million recommendation, Danske Bank DKK 10 million recommendation, High Court GDPR compensation ruling (August 2025), cookie enforcement action against Berlingske, DPF update on Google Analytics, breach notification statistics (2024-2025), social media age-limit proposal, and new sections on DPO requirements, breach notification, data subject rights table, processing of criminal data, and legal bases/consent.

Reviewed and approved by an editor

Initial publication covering GDPR framework, Datatilsynet structure, court-based fine model, CPR number rules, CCTV regime, and digital consent age.

Sources and References

  1. Danish Data Protection Act, Act No. 502 of 23 May 2018 (Ministry of Justice English translation of the original 2018 text; superseded on the age of consent by Act No. 1783 of 28 December 2023)(datatilsynet.dk).gov
  2. Datatilsynet - Danish Legislation(datatilsynet.dk).gov
  3. GDPR Recital 151 - Administrative Fines in Denmark and Estonia(gdpr-info.eu)
  4. EU AI Act Regulation (EU) 2024/1689(eur-lex.europa.eu).gov
  5. Regulations.ai - Denmark AI Act Law No. 467/2025(regulations.ai)
  6. ai-regulation.com - Denmark AI Act National Law(ai-regulation.com)
  7. Global Relay - Netcompany DKK 15 Million Recommendation(grip.globalrelay.com)
  8. TechGDPR - Danish High Court GDPR Compensation Ruling 2025(techgdpr.com)
  9. Clickport - Google Analytics Denmark 2026(clickport.io)
  10. White and Case - GDPR Denmark(whitecase.com)
  11. DLA Piper - Denmark Data Protection(dlapiperdataprotection.com)
  12. IAPP - Danish DPA Derogations Analysis(iapp.org)
  13. activeMind - Danish Sanctions Model(activemind.legal)
  14. GDPRhub - Arp-Hansen Decision(gdprhub.eu)
  15. GDPRhub - Danske Bank Decision(gdprhub.eu)
  16. Plesner - Denmark Digital Children Protection Initiatives(plesner.com)
  17. Danish Data Protection Act (databeskyttelsesloven), consolidated Act No. 289 of 8 March 2024 - retsinformation.dk(retsinformation.dk).gov
  18. Act No. 1783 of 28 December 2023 raising the age of consent for information society services from 13 to 15, in force 1 January 2024(retsinformation.dk).gov
  19. Law No. 467 of 14 May 2025 supplementing the EU AI Act (LOV nr 467 af 14/05/2025)(retsinformation.dk).gov
  20. Bill L 111 (2025/1 LSF 111), proposed AI Act supplementary law introduced 18 February 2026 and lapsed with the session on 24 March 2026(retsinformation.dk).gov
  21. Danish TV Surveillance Act (tv-overvagningsloven), consolidated Act No. 182 of 24 February 2023(retsinformation.dk).gov
  22. Cookie Order (cookiebekendtgorelsen), Order No. 1148 of 9 December 2011, made under the Act on electronic communications networks and services(retsinformation.dk).gov
  23. Act No. 410 of 27 April 2017 on law enforcement authorities processing of personal data (retshaandhaevelsesloven)(retsinformation.dk).gov
  24. Vestre Landsret, 2 September 2025 (IDdesign A/S / ILVA): GDPR fine raised to DKK 1.5 million, ECLI:DK:VLR:2025:SS0000000468(domsdatabasen.dk).gov
  25. Ostre Landsret, 28 April 2025 (Taxa 4x35): fine raised to DKK 250,000, ECLI:DK:OLR:2025:SS0000000378(domsdatabasen.dk).gov
  26. Ostre Landsret, 20 September 2023 (Arp-Hansen Hotel Group): DKK 1 million fine, ECLI:DK:OLR:2023:SS0000001211(domsdatabasen.dk).gov
  27. Danish Supreme Court, 24 August 2026: DKK 30,000 compensation under GDPR Article 82 for a municipal disclosure of health data (BS-44501/2025-HJR)(domsdatabasen.dk).gov
  28. CJEU Case C-383/23 ILVA A/S, judgment of 13 February 2025 on the meaning of undertaking in GDPR Article 83(4) to (6)(eur-lex.europa.eu).gov
  29. Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending the EU AI Act, in force 27 July 2026(eur-lex.europa.eu).gov
  30. Datatilsynet - overview of GDPR fine cases, decided and still pending (bodesager)(datatilsynet.dk).gov
  31. Datatilsynet - Danske Bank recommended for a DKK 10 million fine, 5 April 2022, case closed with a waiver of prosecution(datatilsynet.dk).gov
  32. Datatilsynet - Udlaendingestyrelsen settled by fine notice of DKK 150,000 on 18 March 2024(datatilsynet.dk).gov
  33. Datatilsynet - serious criticism and warning to 51 municipalities in the Chromebook case, 2 February 2026(datatilsynet.dk).gov
  34. Datatilsynet annual report 2025 (arsberetning): 20,536 new cases, 9,849 breach notifications(datatilsynet.dk).gov
  35. Digitaliseringsstyrelsen - supervision of the EU AI Act in Denmark, including that high-risk supervisors are not yet designated(digst.dk).gov
  36. Datatilsynet - order of 30 January 2024 to 53 municipalities in the Chromebook case, with a compliance deadline of 1 August 2024(datatilsynet.dk).gov
  37. Datatilsynet - decision of 18 August 2022 upholding the July 2022 processing ban on Helsingor Kommune's use of Google Workspace(datatilsynet.dk).gov
  38. Lov om offentlige myndigheders registre, Act No. 294 of 8 June 1978(retsinformation.dk).gov
  39. Lov om private registre m.v., Act No. 293 of 8 June 1978(retsinformation.dk).gov
Share: