Data & Privacy · Denmark
Data protection & GDPR compliance in Denmark (2026)
Denmark shaded by its data & privacy status
Data protection in Denmark: comprehensive law.
FrameworkEU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) as supplemented nationally by the Danish Data Protection Act (Consolidated Act No. 289 of 8 March 2024); sector rules include the TV Surveillance Act and Executive Order No. 1148/2011 on cookies. Supervisory authority: Datatilsynet (Danish Data Protection Agency).
As an EU member state, Denmark applies the GDPR directly, supplemented by the Danish Data Protection Act (most recently consolidated as Act No. 289 of 8 March 2024), which entered into force alongside the GDPR on 25 May 2018 and adds Danish-specific rules on CPR numbers, CCTV, journalism, digital-consent age and derogations for public tasks. The Danish Data Protection Agency (Datatilsynet) is the independent supervisory authority; ePrivacy/cookie rules are supervised separately by the Digitaliseringsstyrelsen. Uniquely in the EU, Datatilsynet cannot itself impose administrative GDPR fines: penalties are pursued through the criminal courts, though the DPA issues binding orders, reprimands and recommends fines.
GDPR & data protection in Denmark
In Denmark, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Danish Data Protection Agency (Datatilsynet).
- Framework
- the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
- Supervisory authority
- the Danish Data Protection Agency (Datatilsynet)
- Applies to
- any organisation processing the personal data of people in Denmark, wherever the organisation is based
- Maximum fine
- €20 million or 4% of global annual turnover, whichever is higher
- Breach notification
- within 72 hours of becoming aware, to the supervisory authority
- DPO
- required for large-scale monitoring or large-scale special-category processing
The GDPR is bloc-wide; Denmark supplements it with a national data-protection act and its own supervisory authority.
GDPR in Denmark: FAQ
Yes. As an EU/EEA member, Denmark applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Danish Data Protection Agency (Datatilsynet).
The Danish Data Protection Agency (Datatilsynet).
Up to €20 million or 4% of global annual turnover, whichever is higher.
A DPO is required where you carry out large-scale monitoring or process special-category data at scale.
Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.
Key points
GDPR applies directly and is supplemented by the Danish Data Protection Act (Consolidated Act No. 289 of 8 March 2024), which implements Member State derogations and national provisions on processing.
Datatilsynet (the Danish Data Protection Agency) supervises compliance with the GDPR and the Data Protection Act, handles complaints, conducts inspections, issues binding orders and reprimands, and can recommend fines to prosecutors.
Because Danish constitutional practice bars administrative authorities from imposing punitive fines, GDPR fines in Denmark must be pursued through the criminal courts on police/prosecution referral — e.g., the Western High Court fined ILVA A/S DKK 1.5m (~€200,900) in 2025 for storage-limitation breaches.
The Data Protection Act restricts processing of the CPR (national ID) number by private entities; the TV Surveillance Act requires CCTV footage to be deleted within 30 days unless handed to police; the digital-consent age for information-society services is set at 13.
Executive Order No. 1148 of 9 December 2011 (Cookiebekendtgørelsen) implements the ePrivacy Directive and requires prior informed consent for non-essential cookies; it is enforced by the Danish Agency for Digital Government (Digitaliseringsstyrelsen), with joint DPA guidance published in May 2025 targeting dark patterns.
Datatilsynet's 2026 focus is on new monitoring technologies (access logging, CCTV, GPS, AI-based tools), AI in health/care settings, employee monitoring, and cookie-consent compliance including manipulative design patterns.
Timeline - major decisions & events
Following its reassessment of the Google Chromebook/Workspace setup, Datatilsynet issued serious criticism of 51 municipalities for unlawful processing of pupils' data, showing the years-long schools dispute remains unresolved.
The Copenhagen Post ↗Datatilsynet extended its Helsingør ruling to all ~53 municipalities using the same Google Workspace for Education setup, issuing binding orders to fix third-country transfer and controller-control problems.
GDPRhub (Datatilsynet 2023-431-0001) ↗Datatilsynet reported Netcompany to police and recommended its largest-ever fine after a coding flaw in the mit.dk digital-mailbox authentication could let users access others' public-authority mail.
DataGuidance ↗The DPA found Google Analytics non-compliant with GDPR because it transfers personal data to the US without adequate safeguards post-Schrems II, making Denmark the fourth EU state to reach this conclusion.
DataGuidance ↗In a landmark decision, Datatilsynet banned Helsingør municipality's use of Google Chromebooks and Workspace for Education in primary schools and suspended US data transfers until GDPR-compliant.
TechCrunch ↗After the bank self-reported it could not document deletion across 400+ systems holding millions of customers' data, Datatilsynet filed a police report proposing a ~EUR 1.3m fine for retention/deletion failures.
EDPB ↗Datatilsynet proposed Denmark's first GDPR fine (DKK 1.2m) against taxi firm Taxa 4x35 for over-retaining customer phone numbers tied to ~9m rides, breaching the data-minimisation principle.
EDPB ↗Regulation (EU) 2016/679 (adopted 14 April 2016) took effect, directly applying in Denmark and establishing the core data-protection framework that supersedes the 1995 Directive.
EUR-Lex ↗Denmark enacted the Data Protection Act to supplement the GDPR with national derogations (e.g. on CPR numbers, employment and research) and designated Datatilsynet as supervisory authority.
Datatilsynet ↗Act No. 429 of 31 May 2000 transposed the EU Data Protection Directive 95/46/EC into Danish law, governing personal-data processing until replaced by the GDPR regime in 2018.
Council of Europe ↗The Private Registers Act and the Public Authorities' Registers Act introduced Denmark's first rules on personal-data registers, predating the EU framework and laying the groundwork for later laws.
GDPRhub ↗Denmark - other topics
Data & Privacy in other countries
Last verified 8/29/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →