What Is Databeskyttelsesloven (Danish Data Protection Act)?
Denmark’s current consolidated national statute is LBK nr. 289 af 8. marts 2024, Databeskyttelsesloven, marked GÆLDENDE on Retsinformation. It consolidates the original Act No. 502 of 23 May 2018 and incorporates two amendments effective 1 January 2024. The current Act, rather than the unamended 2018 text, should be cited. The Danish framework is distinctive because Datatilsynet cannot itself impose GDPR fines. It may report matters to the police and recommend a fine, after which police, prosecution, and courts handle the matter criminally. Denmark also has meaningful sector-specific protections for licensed credit-information bureaux, but no general consumer data-broker deletion route was located. Greenland and the Faroe Islands are expressly outside the Danish Act and require separate treatment.
At a glance
- Full name
- Databeskyttelsesloven (Danish Data Protection Act)
- Short code
- Databeskyttelsesloven
- Jurisdiction
- Denmark
- Enacted
- 2018
- Last major update
- Current consolidated text is LBK nr. 289 af 8. marts 2024, incorporating Act No. 1783 and Act No. 1784 of 28 December 2023, effective 1 January 2024; the amendments raised the child-consent age from 13 to 15 and changed marketing and oversight provisions
- Regulator
- Danish Data Protection Agency (Datatilsynet)
- Private right of action
- Limited
- Statutory citation
- LBK nr. 289 af 8. marts 2024, Databeskyttelsesloven
Scope, who Databeskyttelsesloven covers
Protected data
Data subject rights
Right to transparent information and access
Right to rectification
Right to erasure subject to GDPR and Danish-law exceptions
Right to restriction of processing
Right to data portability
Right to object, subject to Danish statutory restrictions
Right to complain to Datatilsynet under GDPR Article 77 and Danish Act §39
Credit-bureau access, correction, and deletion rights in stated circumstances
Protection against adverse credit information generally being retained beyond five years, subject to exceptions
Right to be notified of bad-payer registration within a reasonable period and no later than one month
Notable features
Denmark’s penalty model is distinctive: Datatilsynet refers matters for criminal handling rather than directly imposing GDPR fines. The Act also contains substantial journalism, intelligence, parliamentary, public-authority, court, research, CPR, and credit-bureau restrictions. Section 48 creates a hard scope boundary because Greenland and the Faroe Islands are outside the Danish Act and have separate legal frameworks.
Enforcement & penalties
Regulator: Danish Data Protection Agency (Datatilsynet)
Penalties: GDPR Article 83 provides fines of up to €10 million or 2% of worldwide annual turnover for the Article 83(4) category and up to €20 million or 4% of worldwide annual turnover for the Article 83(5)-(6) category. Denmark’s enforcement model is criminal rather than an administrative-fine system imposed directly by Datatilsynet: the agency may report matters to police and recommend a fine, with prosecution and courts handling the case. Danish Act §41 makes specified GDPR and Danish-law violations punishable by a fine or imprisonment up to six months. Section 42 permits Datatilsynet to issue a settlement-fine proposal, which is not the agency imposing an administrative fine itself. No general Danish numeric fine schedule or separate public-sector-limited schedule was located.
Private right of action: GDPR judicial-remedy routes are identified, including the Article 78(2) trigger where Datatilsynet does not handle a complaint or provide information within three months. A dedicated private action for general data-broker deletion was not identified. Credit-bureau rights and source-register protections remain sector-specific.
Relevance to data brokers
A general Denmark-wide consumer deletion portal or universal data-broker suppression route was not located. Public-register information may often be used under legitimate-interest balancing, and an objection generally succeeds only with particularly strong grounds. Licensed credit-information bureaux are a distinct regulated sector with access, correction, deletion, notification, and five-year adverse-information limits, but those protections must not be generalized to ordinary people-search or data-broker sites. CPR and municipal address-protection mechanisms protect source-register information rather than creating general downstream deletion rights.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Datatilsynet directly impose GDPR fines?+
No. Datatilsynet may report matters to the police and recommend a fine. Police, prosecution, and courts handle the matter as a criminal case; a settlement-fine proposal under §42 is not Datatilsynet directly imposing an administrative fine.
Does the Danish Data Protection Act cover Greenland and the Faroe Islands?+
No. Section 48 expressly excludes Greenland and the Faroe Islands. Each has a separate data-protection framework, so they should not be silently included in a Denmark-proper explainer.
Does Denmark have a general data-broker deletion route?+
Not located. Denmark has ordinary GDPR objection and other rights, plus stronger sector-specific access, correction, and deletion protections for licensed credit-information bureaux, but those protections do not create a universal deletion right for general data-broker sites.
Official sources & citations
Other international privacy regimes
Databeskyttelsesloven sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
