Law / Denmark

Denmark

privacy

Denmark's private-sector regime is the General Data Protection Regulation (GDPR) plus the Danish Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018, consolidated as Act No. 289 of 8 March 2024), which supplies Denmark's national derogations and Datatilsynet as supervisory authority.

Denmark's most distinctive feature is its enforcement mechanism: GDPR Recital 151 records that Denmark's legal system does not allow Datatilsynet itself to impose an administrative fine, so a fine is instead set by the Danish courts as a criminal penalty after Datatilsynet refers the case to police. As at 2026-08-24; later amendment to the Databeskyttelsesloven is not independently confirmed this pass.

16 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Denmark

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Danish derogation from this timeline was confirmed this pass.

What it asks of an app

Comprehensive regime

Danish Data Protection Act (Databeskyttelsesloven)

cite Lov nr. 502 af 23. maj 2018 om supplerende bestemmelser til forordningen om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger og om fri udveksling af sadanne oplysninger (databeskyttelsesloven), consolidated as Act No. 289 of 8 March 2024 stage In effect since 2018-05-25 source Retsinformation.dk official consolidated text

The Danish Data Protection Act gives the General Data Protection Regulation (GDPR) domestic effect in Denmark and supplements it with Denmark-specific derogations for matters GDPR leaves to member states, including the digital age of consent, processing of CPR (civil registration) numbers, CCTV, and journalism. Datatilsynet, the Danish Data Protection Agency, enforces it, with the distinctive feature that Denmark cannot itself impose an administrative fine (see the enforcement instrument below).

The Act's specific derogation sections were not independently read against the Act's own text this pass; the sections named in secondary commentary are not restated here as confirmed provisions.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Denmark

cite Regulation (EU) 2016/679, Arts. 44-50 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Denmark outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Danish derogation broadening or narrowing General Data Protection Regulation (GDPR) Chapter V was confirmed this pass.

What it asks of an app

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Denmark

cite Regulation (EU) 2016/679, Arts. 12-23; Databeskyttelsesloven stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Denmark: access, rectification, erasure, restriction, portability, and objection, generally exercisable against the controller within one month. Article 22 gives a qualified right against a decision based solely on automated processing that produces legal or similarly significant effects, applied in Denmark through the Databeskyttelsesloven. No Danish derogation narrowing these rights was confirmed against the Act's own text this pass.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and Datatilsynet Enforcement in Denmark

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Datatilsynet holds the General Data Protection Regulation (GDPR) Article 58 corrective toolkit directly, warnings, reprimands, compliance orders and processing bans, but GDPR Recital 151 records that Denmark's legal system does not allow the supervisory authority itself to impose an administrative fine. In practice, Datatilsynet reports a violation it considers fine-worthy to the Danish police with a recommended amount, and the fine is set and imposed by the Danish courts as a criminal penalty rather than by Datatilsynet directly.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Denmark

cite Regulation (EU) 2016/679, Art. 9 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for the purpose of uniquely identifying a natural person as a special category of personal data, prohibited absent an Article 9(2) ground such as explicit consent.

No Danish statutory enumeration or illustrative list of biometric identifier types was confirmed this pass, and none is asserted; Datatilsynet has engaged case by case with facial recognition deployments through its authorization and guidance practice, but no voiceprint specific guidance or enforcement decision was located.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.