GDPR fines in Denmark: what does your business risk?
An overview of GDPR enforcement in Denmark: known Datatilsynet cases, the Article 83 fine levels, the most frequent breaches and what your business can do.
Karoline, Dokumentkonsulent
Since the GDPR entered into force in May 2018, the Danish Data Protection Agency (Datatilsynet) has handled thousands of complaints, carried out inspections and, increasingly, recommended fines and referred cases to the police. Many businesses still think GDPR enforcement mainly hits large companies. That is a dangerous misunderstanding.
This article reviews enforcement in Denmark, which breaches typically lead to sanctions, and what your business can concretely do to reduce the risk.
How is the GDPR enforced in Denmark?
In Denmark, Datatilsynet (datatilsynet.dk) is the competent supervisory authority for the GDPR. It has the power to:
- Issue orders to bring a processing activity into compliance with the GDPR
- Temporarily or permanently limit or ban a processing activity
- File a police report for serious breaches that can lead to a fine
An important peculiarity of the Danish model is that Datatilsynet cannot itself issue administrative fines. Instead it recommends a fine and files a police report, after which it is the courts that impose any criminal fine. This differs from many other EU countries, where the supervisory authority can issue administrative fines directly.
The size of fines: what does the law say?
Article 83 of the GDPR operates with two levels of fine:
Level 1: up to EUR 10 million or 2% of global annual turnover
Applies, among other things, to breaches of:
- The requirements for a data processing agreement (Article 28)
- The requirements for technical and organisational security measures (Article 32)
- The notification of a data breach (Article 33)
- The requirements for a data protection officer, DPO (Articles 37 to 39, where required)
Level 2: up to EUR 20 million or 4% of global annual turnover
Applies, among other things, to breaches of:
- Processing without a legal basis (Article 6)
- The basic principles (Article 5)
- Unlawful transfer to third countries (Articles 44 to 49)
- The rights of data subjects (Articles 12 to 22)
The higher of the two limits applies. It is an upper limit, not a fixed amount; the actual fine depends on a specific assessment.
Well-known Danish cases
Denmark has a relatively cautious fine tradition compared with countries such as Italy, France and Spain, but the cases are real and increasing.
Taxa 4x35 (2019): Datatilsynet recommended a fine of DKK 1.2 million because the company did not delete customers' personal data (phone numbers) in time but in reality kept them longer than necessary. One of the first and still best-known Danish GDPR cases.
IDdesign (2019): Datatilsynet recommended a fine of DKK 1.5 million because the furniture chain kept customer data beyond the necessary purpose.
Arp-Hansen Hotel Group (2021): a case about failure to delete historical guest data, in breach of the storage-limitation principle, led to a police report.
Cookie cases: Datatilsynet has run a coordinated effort against missing or invalid cookie consent and has reported several businesses to the police.
Health data and CPR numbers: over the years the authority has handled numerous cases of unlawful use of CPR numbers and health data, especially in HR systems and the health sector.
Datatilsynet's decision register and annual reports on datatilsynet.dk are the authoritative source for the actual cases and amounts.
The most frequent causes of GDPR sanctions in Denmark
1. Failure to delete personal data
Businesses keep customer, employee or subscriber data far beyond the necessary purpose. The storage-limitation principle (Article 5(1)(e)) requires data to be deleted when the purpose is fulfilled.
Typical mistake: a CRM system with inactive customers from ten years ago, without any assessment of whether the data can be deleted.
2. A missing or deficient data processing agreement
Many businesses use cloud services, payroll bureaus and marketing platforms without a legally correct data processing agreement. Article 28 requires a written agreement with every data processor.
Typical mistake: accepting a supplier's standard terms without ensuring they meet the requirements for a data processing agreement.
3. A missing or incorrect privacy policy
A website without a privacy policy, or with a policy that does not reflect the actual processing, is a breach of the duty to inform (Articles 13 and 14).
Typical mistake: a generic privacy policy that does not mention the actual cookies, third parties and storage periods.
4. Invalid cookie consent
Analytics and marketing cookies set before the user has given consent are a systematic breach of the cookie rules and the GDPR.
5. A data breach without notification
Businesses that discover a data breach but fail to notify Datatilsynet within 72 hours breach the notification duty (Article 33).
6. Unlawful transfer to third countries
Using US services without correct transfer mechanisms (for example EU standard contractual clauses or a valid adequacy decision) can constitute a breach.
Factors that affect the size of a fine
In setting the sanction, factors include:
- The nature of the breach: intentional or negligent?
- Duration: has the breach gone on for one year or ten?
- The number of people affected: 100 or 100,000?
- Harm: has actual harm been caused to the data subjects?
- The business's cooperation with Datatilsynet
- Previous breaches
- Proactive, remedial measures
Businesses that react quickly, cooperate openly and put things right generally receive a milder sanction.
Reputational risk
For many businesses the reputational risk can be at least as great as the direct fine risk. Datatilsynet publishes decisions, and trade media in IT, HR and law cover the cases. Customers' trust in a business's handling of data is a competitive parameter, and a public case about irresponsible data handling can damage that trust.
How does your business avoid GDPR sanctions?
1. Map your data processing
Create or update your record of processing activities (Article 30). Document the purpose, legal basis, categories of data, storage periods and data processors.
2. Enter into data processing agreements with all relevant suppliers
Review all services and suppliers that have access to personal data, and ensure a valid data processing agreement with each.
3. Update the privacy policy
Make sure the privacy policy is precise and complete, with correct information about third parties, cookies and storage periods.
4. Implement deletion routines
Set specific storage periods for all data types and introduce fixed deletion processes. Storage limitation is one of the most frequently breached principles.
5. Establish a data-breach procedure
Ensure a clear internal procedure for what happens on a discovered data breach, including who must be notified and that Datatilsynet is notified within 72 hours for a relevant breach.
6. Check your cookies
Map all cookies on the website and verify that the cookie banner obtains valid consent before the non-essential cookies are set.
Datatilsynet's guidance
Datatilsynet is not only an enforcement authority; it continually publishes guidance and examples that help businesses comply. Especially useful are the guides on the record of processing activities, data processing agreements, cookies and consent, and data breaches, and the annual report gives an overview of the latest decisions.
What do you do about an approach from Datatilsynet?
If your business receives a complaint or approach, it is important to:
- Reply within the deadline, which is typically a few weeks
- Document your processing practice, that is, produce the record of processing activities, data processing agreements and relevant policies
- Cooperate constructively
- Implement and document remedial measures
Consider involving a lawyer with GDPR expertise, especially if the case can have criminal consequences.
Frequently asked questions
Can a sole proprietorship get a GDPR fine?
Yes. The GDPR and the Danish Data Protection Act apply to everyone who processes personal data, whether it is a sole proprietorship with a website or a large group. The size of the sanction does, however, reflect the business's circumstances.
What are some of the best-known Danish cases?
The Taxa 4x35 case (a recommended fine of DKK 1.2 million) and the IDdesign case (a recommended fine of DKK 1.5 million). In an EU perspective, Danish fines are still at the lower end compared with cases in, for example, Ireland and Luxembourg, where fines in the hundreds of millions have been issued against large tech companies.
Is Datatilsynet actively looking for breaches?
Datatilsynet carries out proactive inspections in particular sectors (including health, finance and HR systems) and responds to complaints from citizens. The volume of complaints is rising.
Can employees complain about their employer's GDPR breaches?
Yes. Any data subject, including an employee, can complain to Datatilsynet. HR-related breaches (unlawful monitoring, deficient handling of employee data) make up a significant share of complaints.
Does having a legal adviser or DPO protect me?
Having a lawyer or DPO can reflect good faith and be taken into account in assessing a sanction, but it does not guarantee compliance. Compliance requires concrete processes and documentation, not just an advisory agreement.
Conclusion
GDPR sanctions in Denmark are real, and the risk applies to all businesses regardless of size. The most frequent causes are failure to delete data, missing data processing agreements and invalid cookie consent. All three can be remedied with the right documents and processes.
Start with the basics: an updated privacy policy, valid data processing agreements and correct deletion routines. That is where the risk is greatest, and the solution is within reach.
The content of this article is for guidance only and does not constitute legal advice. GDPR enforcement is complex, and specific cases should be assessed by a lawyer with expertise in data protection law. Datatilsynet's annual reports and decision register on datatilsynet.dk are the authoritative source for actual cases.
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.