Danmark · Danish Data Protection Act
TL;DR
Websites targeting users in Denmark must comply with GDPR as implemented locally through the Danish Data Protection Act. The supervisory authority is the Datatilsynet. Notable enforcement: IDdesign fined for excessive data retention (€200,000). Use our free scanner below to check your website instantly.
Free audit — 25+ automated checks in 60 seconds
Scan My Website Free →Authority
Datatilsynet
Website
www.datatilsynet.dk ↗Local Law
Danish Data Protection Act
Language
Danish
Largest Fine
€200,000
Population
5.9 million
Datatilsynet cookie guidance aligns with strict EU standards
Consent required before setting non-essential cookies
Data retention periods must be defined and documented
DPO required for public bodies and large processors
Strong focus on data minimization principle
Cloud service providers must meet specific security standards
Denmark was one of the first countries to raise concerns about Google Workspace and Microsoft 365 in schools due to GDPR concerns. Datatilsynet has given detailed guidance on cloud services and international data transfers.
Cookie consent banner that requires opt-in before non-essential cookies
Privacy policy available in Danish
Clear identification of data controller and contact details
Data Processing Agreement (DPA) with all third-party processors
Lawful basis documented for each processing activity
Data Subject Access Request (DSAR) process in place
Data breach notification procedure compliant with 72-hour rule
Data Protection Impact Assessment for high-risk processing
International data transfer mechanisms documented (SCCs, adequacy decisions)
Records of processing activities (ROPA) maintained
In Denmark, websites must comply with GDPR as implemented by the Danish Data Protection Act. Key requirements include obtaining explicit consent before setting non-essential cookies, providing a clear privacy policy, appointing a DPO when required, and notifying data breaches within 72 hours to the Datatilsynet.
The Datatilsynet is the supervisory authority responsible for enforcing data protection laws in Denmark. They can investigate complaints, conduct audits, and issue fines up to €20 million or 4% of annual global turnover.
Use PrivacyChecker's free scanner to perform an instant audit of your website. Our tool checks 25+ compliance points including cookie consent, privacy policy presence, security headers, tracker detection, and more — all relevant to Denmark's GDPR requirements.
Find out in 60 seconds with our free GDPR scanner
Run Free Audit →