Compliance Node Overview
Denmark's Data Protection Act (Databeskyttelsesloven, Consolidated Act No. 502 of 23 May 2018, as amended by Act No. 1052 of 28 August 2018) is Denmark's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Denmark. The GDPR is directly applicable Danish law by virtue of Denmark's EU membership. The Databeskyttelsesloven provides the national derogations, additions, and specifications that the GDPR permits EU member states to adopt. Enforcement: Datatilsynet (the Danish Data Protection Agency) is Denmark's independent data protection supervisory authority. Datatilsynet is Denmark's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Danish national provisions: (1) Age of digital consent: Denmark has lowered the GDPR default age of 16 years - the age of consent for information society services in Denmark is 13 years; data subjects under 13 require parental or guardian consent for information society services; (2) CPR number (Det Centrale Personregister - Central Personal Register number): the Danish CPR number is a unique 10-digit civil registration number assigned to every person registered in Denmark; processing of CPR numbers is subject to special restrictions under the Databeskyttelsesloven - CPR numbers may only be processed where permitted by law, where the data subject has consented, or where the processing is for clearly legitimate purposes that outweigh the interests of the data subject; registration with a sector-specific authority may be required; CPR numbers are equivalent to a national identification number and require heightened protection; (3) Criminal data: restrictions on processing personal data relating to criminal convictions and offences by private entities; (4) Employment context: Danish data protection law interacts with Danish employment legislation including the Salaried Employees Act (Funktionærloven) and collective agreements; (5) Freedom of expression: Danish constitutional protections for freedom of expression and press freedom under the Danish Constitution (Grundloven) and the Danish Media Liability Act (Medieansvarslov) create exemptions for journalistic, artistic, and literary processing; (6) Public sector: significant provisions on processing by public authorities, including the Public Administration Act (Forvaltningsloven) and the Access to Public Administration Files Act (Offentlighedsloven); (7) Research and statistics: specific provisions permitting extended processing for scientific research, statistics, and archiving in the public interest. Fines: GDPR administrative fines apply in Denmark - up to EUR 20 million or 4% of global annual turnover for the most serious violations. Datatilsynet has imposed significant GDPR fines and issued enforcement guidance across multiple sectors. Datatilsynet publishes annual statistics on breach notifications, enforcement actions, and guidance.
Pillar: Cybersecurity · Authority: Datatilsynet (Danish Data Protection Agency) · Version: 1.0.0 · Last updated:
Primary source: https://www.datatilsynet.dk/
SHA-256 integrity: 33791a40d862cd3b1b3e7e9c764434000eaab948bc2f116d0a3f27fe7933b4f3
Primary Citations — 6 traced to source
- Databeskyttelsesloven (Consolidated Act No. 502 of 23 May 2018, Denmark, as amended by Act No. 1052 of 28 August 2018) - Denmark's national GDPR implementation law; supplements EU GDPR with national derogations: age of digital consent 13 years (lowered from GDPR default of 16); CPR number (civil registration number) subject to special processing restrictions; criminal data restrictions for private entities; journalism exemption via Medieansvarslov; research and statistics derogations
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Denmark as EU member state; fines up to EUR 20 million or 4% of global annual turnover; EDPB binding decisions apply; 72-hour breach notification to Datatilsynet under Art. 33; DPIA for high-risk processing under Art. 35; Datatilsynet is Denmark's lead supervisory authority for cross-border processing by controllers established in Denmark
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access