Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Danish derogation from this timeline was confirmed this pass.
What it asks of an app →
Comprehensive regime
cite Lov nr. 502 af 23. maj 2018 om supplerende bestemmelser til forordningen om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger og om fri udveksling af sadanne oplysninger (databeskyttelsesloven), consolidated as Act No. 289 of 8 March 2024
stage In effect
since 2018-05-25
source Retsinformation.dk official consolidated text
The Danish Data Protection Act gives the General Data Protection Regulation (GDPR) domestic effect in Denmark and supplements it with Denmark-specific derogations for matters GDPR leaves to member states, including the digital age of consent, processing of CPR (civil registration) numbers, CCTV, and journalism. Datatilsynet, the Danish Data Protection Agency, enforces it, with the distinctive feature that Denmark cannot itself impose an administrative fine (see the enforcement instrument below).
The Act's specific derogation sections were not independently read against the Act's own text this pass; the sections named in secondary commentary are not restated here as confirmed provisions.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-50
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Denmark outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Danish derogation broadening or narrowing General Data Protection Regulation (GDPR) Chapter V was confirmed this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-23; Databeskyttelsesloven
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Denmark: access, rectification, erasure, restriction, portability, and objection, generally exercisable against the controller within one month. Article 22 gives a qualified right against a decision based solely on automated processing that produces legal or similarly significant effects, applied in Denmark through the Databeskyttelsesloven. No Danish derogation narrowing these rights was confirmed against the Act's own text this pass.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Datatilsynet holds the General Data Protection Regulation (GDPR) Article 58 corrective toolkit directly, warnings, reprimands, compliance orders and processing bans, but GDPR Recital 151 records that Denmark's legal system does not allow the supervisory authority itself to impose an administrative fine. In practice, Datatilsynet reports a violation it considers fine-worthy to the Danish police with a recommended amount, and the fine is set and imposed by the Danish courts as a criminal penalty rather than by Datatilsynet directly.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for the purpose of uniquely identifying a natural person as a special category of personal data, prohibited absent an Article 9(2) ground such as explicit consent.
No Danish statutory enumeration or illustrative list of biometric identifier types was confirmed this pass, and none is asserted; Datatilsynet has engaged case by case with facial recognition deployments through its authorization and guidance practice, but no voiceprint specific guidance or enforcement decision was located.
What it asks of an app →