GDPR for Denmark
GDPR compliance for companies in Denmark — Datatilsynet enforcement, Google Analytics ruling, and Danish data protection requirements.
Data Protection Authority
Datatilsynet
Key Requirements
- →Datatilsynet ruled Google Analytics illegal for Danish companies (2022)
- →Denmark has strict breach notification practices — proactive communication expected
- →Danish Data Protection Act supplements GDPR with national rules
- →High data rights awareness among Danish consumers
Denmark's Datatilsynet is one of the most technically sophisticated data protection authorities in Europe. In 2022, Datatilsynet followed Austria's lead and ruled that the use of Google Analytics by Danish companies violated GDPR because of the associated transfer of personal data to the United States without adequate safeguards. Danish companies using Google Analytics were ordered to bring their data flows into compliance — or stop using the service.
The Google Analytics ruling reflects Datatilsynet's approach: detailed technical analysis of data flows, not just review of privacy policies. If your data processing involves US-headquartered cloud services, Datatilsynet will examine the actual data transfer mechanisms, not just whether you've signed SCCs.
The Danish Data Protection Act (Databeskyttelsesloven) supplements GDPR with national provisions on sensitive data categories, criminal records processing, and requirements for the public sector. For private sector companies, the most relevant addition is the rules around processing of sensitive data (health, biometrics) that require explicit DPA notification for some processing activities.
Data breach handling in Denmark has a strong proactive communication culture. Datatilsynet expects companies to notify affected data subjects quickly and comprehensively — companies that delay individual notifications or provide vague information face additional scrutiny even when the DPA notification was timely.
Danish consumers have a high awareness of data rights and are among the most active DSAR filers in Europe. Build a robust DSAR response process before entering the Danish market — response time compliance (one month) is monitored and late responses generate complaints.
Check your GDPR compliance now
Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.
Run free GDPR compliance check →