Law note · Denmark
Danish Data Protection Act (Databeskyttelsesloven)
The Danish Data Protection Act gives the General Data Protection Regulation (GDPR) domestic effect in Denmark and supplements it with Denmark-specific derogations for matters GDPR leaves to member states, including the digital age of consent, processing of CPR (civil registration) numbers, CCTV, and journalism. Datatilsynet, the Danish Data Protection Agency, enforces it, with the distinctive feature that Denmark cannot itself impose an administrative fine (see the enforcement instrument below).
The Act's specific derogation sections were not independently read against the Act's own text this pass; the sections named in secondary commentary are not restated here as confirmed provisions.
What it asks of an app
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Denmark, including data collected by crawling.
- Conduct a Data Protection Impact Assessment for high risk processing under the Databeskyttelsesloven and GDPR Article 35.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot
Primary source: Retsinformation.dk official consolidated text
secondary commentary (Linklaters, activeMind.legal) for national derogation topics not independently confirmed