Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024)
In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests.
Status Not cited by any decision here yet
Original title: Datatilsynet (Denmark) - 2024-432-0039
Holding
The DPA acknowledges that since executing a reprimand against the controller for the period of 2019-2024, the controller has reduced the average processing time from 100 days to 59 days in 2025. Regardless, the DPA once again held that the controller did not deal with a significant enough amount of access requests pursuant to Article 15 GDPR and within the deadline of Article 12(3) GDPR. The DPA held that the controller cannot extend deadline to process access requests pursuant to Article 12(3) GDPR on the grounds that they are also dealing with other requests, regardless of the complexity, number or time of receipt. The DPA further held that controllers must implement sufficient resources to be able to process data subject’s requests to exercise their rights within the time limits established by the GDPR. The DPA requests the controller to submit a statement in January of 2027 declaring its processing times from 2026 allowing them to ensure that the controller is working towards reducing processing times.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
30 September 2025 the DPA reprimanded the controller for the processing time of access requests requested between 2019-2024, and ordered the controller to submit a statement informing how long the processing of access requests will take in 2025. 4 February 2026 the DPA received the requested report for the period of 2025. This revealed a decrease in processing time from 100 days to 59, and that the controller processes the requests in the order in which they are received. Similar to the period between 2019-2024, the controller emphasised that the processing times were a result of a lot of factors, such as case complexity, extensive documentation and log data related requests. The DPA emphasised that in accordance with Article 12(3) GDPR the controller is to respond to data subject’s requests without undue delay and latest within a month. Additionally, that the extension of the deadline pursuant to Article 12(3) GDPR and Recital 59 GDPR is dependent on the complexity and number of requests, and applies to individual requests which must be processed separately from other data subject’s requests.
Full text 5 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Skip the main navigation The Tax Administration Faces Serious Criticism Once Again Date: August 11, 2026 Decision Public Authorities Severe Criticism Complaint Right of Access The Data Protection Authority has issued severe criticism of the Tax Administration’s handling of requests for access in 2025. The Authority has previously voiced serious criticism of the Tax Administration’s handling of such requests for the period 2019–2024. Case number: 2024-432-0039. Summary The Danish Data Protection Agency initiated (based on a complaint) an ex officio case in November 2024, which primarily concerned the Tax Administration’s general processing time for requests for access. After the case had been reviewed by the Data Council, the Danish Data Protection Agency first voiced serious criticism in a decision issued on September 30, 2025, regarding the Tax Administration’s handling of requests for access during the period 2019–2024. To monitor trends in processing times, the Danish Data Protection Agency simultaneously requested that the Tax Administration submit a report in early 2026 detailing the agency’s handling of requests for access during the period 2025. The report showed, among other things, that the average case processing time in 2025 was approximately 59 days. The Tax Administration’s Explanation The Tax Administration has stated that the case processing time (once again) has been affected by several different factors, including, among other things, extensive cases involving a large number of documents, complex cases requiring cross-departmental clarifications and approvals, as well as requests concerning log data. In addition, the Tax Administration has stated that the processing time has generally been affected by the fact that its staff have been busy processing previously received requests for access. Unlike during the 2019–2024 period, the Tax Administration has not stated that it processes requests for access according to the principle that they must be processed in the order in which they are received, regardless of the specific request’s complexity, etc. The Danish Data Protection Agency’s Assessment After the case was reviewed by the Data Council, the Danish Data Protection Agency again finds grounds to express serious criticism of the fact that, during the 2025 period, the Tax Administration failed to process a significant number of requests for access in accordance with the deadlines set forth in the General Data Protection Regulation. In this regard, the Danish Data Protection Agency—as was also the case in the Agency’s decision of September 30, 2025— —emphasized that the data controller’s prioritization of—or lack of—resources, personnel, measures, and the like is, as a clear starting point, not a circumstance that, under data protection law, can justify processing times for requests for access of such length, as was again the case with a public authority such as the Tax Administration during the period 2025. In this regard, the Danish Data Protection Agency has emphasized that a data controller is always obligated to allocate sufficient resources to process specific requests for access from data subjects within the time limits set forth in the General Data Protection Regulation, regardless of whether the data controller is already processing other requests for access. However, the Danish Data Protection Agency acknowledges—and has taken into account in determining the sanction—that the Tax Administration has been working on and focusing on the processing of requests for access, and that the agency has reduced the average processing time from approximately 100 days in the period 2019–2024 to approximately 59 days in 2025. Report in 2027 In the decision, the Danish Data Protection Agency requests that the Tax Administration submit a report to the Agency in January 2027 regarding the Administration’s case processing times in 2026, so that the Authority can continue to ensure that processing times are further reduced. Decision The Danish Data Protection Agency hereby returns to the case in which the Authority, on November 14, November 2024, based on a complaint, decided to initiate an investigation into the Tax Administration’s handling of requests for access under Article 15 of the General Data Protection Regulation. After the case had been reviewed by the Data Council, the Danish Data Protection Agency issued its first decision[1] on September 30, 2025, regarding the Tax Administration’s processing of requests for access during the period 2019–2024, in which the Authority expressed serious criticism of the Tax Administration’s failure to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation (GDPR), in accordance with the time limits set forth in Article 12(3) of the GDPR. In the decision, the Danish Data Protection Agency also requested that the Tax Administration submit a report on its handling of requests for access for the period January 1 through December 31, 2025, so that the Authority could verify whether the processing time had been reduced. This decision thus concerns the Tax Administration’s handling of requests for access in 2025.
Decision After reviewing the case—and following its consideration by the Data Council—the Data Protection Authority finds that there is once again grounds for expressing serious criticism of the fact that the Tax Administration has failed to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation[2], in accordance with the time limits set forth in Article 12(3) of the General Data Protection Regulation. Below is a detailed review of the case and the reasoning behind the Danish Data Protection Agency’s decision.
Statement of Facts On February 4, 2026, the Danish Data Protection Agency received the report on the Tax Administration’s handling of requests for access in 2025, which the Agency had requested in its decision of September 30, 2025. Subsequently, on February 6, 2026, the Danish Data Protection Agency posed a series of follow-up questions to the Tax Administration, which the Administration answered in two rounds on February 25 and March 10, 2026. The case file indicates that the Tax Administration received 152 requests for access in 2025, of which 62 requests had been pending for more than 30 days, 44 requests had been pending for more than 60 days, 23 requests had been pending for more than 90 days, and the average processing time was 59.05 days. The request for access that had been pending the longest had been pending for 189 days. Furthermore, the case file indicates that the Tax Administration—with regard to the processing of requests for access in 2025, as opposed to the processing of such requests during the period 2019–2024 —no longer states that it processes requests based on a fixed principle that they must be processed in the order in which they are received.
Comments from the Tax Administration In general, the Tax Administration notes that in 2025, the agency focused on processing requests for access, and that additional resources were allocated to this area. In addition, the Tax Administration has generally noted that the case processing time—as was also the case during the 2019–2024 period — has been influenced by a combination of unclear requests, extremely complex cases, and external complications. Specifically, the Tax Administration has cited the following factors that affected case processing times in 2025: Extensive cases involving a large number of documents Processing requests for access to personal data dating back between five and 20 years, which often requires a physical review of more than 10,000 files, including assessing any exceptions and limitations to the right of access. Complex cases requiring cross-functional clarifications and approvals Requests for access that involve the need for coordination with and/or approvals from other authorities and/or other agencies within the Tax Administration. This also includes the time required for the accurate, unambiguous identification of the person requesting access, as well as any clarification and narrowing of the request, which typically takes place through dialogue with the person requesting access, and which may also affect the case processing time. Requests Concerning Log Data The Tax Administration states that it has been time-consuming to implement an appropriate process for handling requests for access that include log data, which has affected the case processing time, just as the processing of the requests for access itself is time-consuming. General delays Impact on the overall processing time resulting from Tax Administration employees processing current and/or previous requests. Requests that Turn Out Not to Be Access Requests The time spent reviewing requests that subsequently turn out not to be access requests under data protection law. Access Requests Resulting from Personal Data Breaches Cross-functional (internal and legal) clarification in collaboration with external parties regarding the question of whether the name of an unintended recipient of personal data must be disclosed to the person requesting access. In addition to the above, the Tax Administration has also stated that the case processing time has been affected by periods of exceptional caseload pressure, including as a result of a general increase in the number of requests for access.
Rationale for the Data Protection Authority’s Decision The Danish Data Protection Agency first notes that the Tax Administration—as was also the case for the period 2019–2024—processes requests for access in accordance with established guidelines and procedures approved by management. It follows from Article 15(1) of the General Data Protection Regulation that the data subject has the right to obtain confirmation from the data controller as to whether personal data concerning the data subject are being processed, and, if so, to access the personal data and other information specified in subparagraphs (a) through (h) of that provision. In addition, the data subject has the right to receive a copy of the personal data processed by the data controller, see Article 15(3). Depending on the circumstances, the data subject also has the right to access log data if such data contains personal information about a data subject, e.g., log data regarding searches of the data subject’s information and the dates and purposes of those searches. The data subject may also have the right to be informed of who performed the searches when this information is necessary for the data subject to effectively exercise their rights. Pursuant to Article 12(3) of the General Data Protection Regulation, requests for access—and other requests by data subjects under Chapter III of the Regulation —must, as a general rule, be processed without undue delay and no later than one month from the date of receipt of the request. This period may be extended by two months if necessary, taking into account the complexity and number of requests. In this regard, it is the Danish Data Protection Agency’s view that the circumstances justifying an extension of the processing time apply only to the individual request, a view supported by Recital 59 of the Regulation, which states that the data controller should be required to respond to requests from a data subject without undue delay and no later than within one month. Requests for rights from a data subject should thus be processed separately and independently of other requests received. In the opinion of the Danish Data Protection Agency, the data controller cannot therefore extend the processing of specific requests for access on the grounds that the data controller is processing other requests from other data subjects, regardless of the complexity, number, or time of receipt. Furthermore, the data controller must organize the processing of personal data, both technically and organizationally, in a manner that enables the fulfillment of requests for access —including requests for access that may be considered extensive and/or complex—without undue delay and no later than within one month, unless it is necessary to extend the response deadline, as noted above. After reviewing the case—and following its consideration by the Data Council—the Danish Data Protection Agency finds that there are again grounds for expressing serious criticism of the fact that the Tax Administration – in several instances, took more than 30 and 90 days, respectively, to process requests for access from data subjects, even though the nature of the specific requests did not necessarily justify an extended processing time – has failed to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation, in accordance with the deadlines set forth in Article 12(3) of the General Data Protection Regulation, during the period from January 1 to December 31, 2025. In this regard, the Data Protection Authority has emphasized—as was also the case in the Authority’s decision of September 30, 2025—that the data controller’s prioritization of—or lack of—resources, staff, measures, and the like are, as a clear starting point, not circumstances that, under data protection law, can justify processing times for requests for access of such length, as was again the case with a public authority such as the Tax Administration during the period from January 1 to December 31, 2025, regardless of the circumstances that the Administration has stated influenced the processing times, see section 2.1 above. Furthermore, the Danish Data Protection Agency emphasizes that, in the Agency’s assessment, the Tax Administration cannot, in particular, justify extended processing times for specific requests for access, see Article 12(3) of the General Data Protection Regulation, on the grounds of “general delay.” In this regard, the Danish Data Protection Agency has emphasized that a data controller is always obligated to allocate sufficient resources to process specific requests for access from data subjects within the time limits set forth in the General Data Protection Regulation, regardless of whether the data controller is already processing other requests for access. However, the Danish Data Protection Agency acknowledges—and has taken into account in determining the sanction—that the Tax Administration has been working on and has focused on processing requests for access, and that the agency has reduced the average processing time from approximately 100 days in the period 2019–2024 to approximately 59 days in 2025. Furthermore, the Danish Data Protection Agency acknowledges that the Tax Administration may, in several cases, receive extensive and complex requests for access, but regardless—as noted above—it is the Authority’s view that this does not justify processing times as long as those observed in 2025 (and during the period 2019–2024). The Data Protection Authority therefore requests that the Tax Administration submit a report to the Authority no later than January 11, 2027, detailing the Administration’s handling of requests for access to data during the period from January 1, January 2026 to December 31, 2026, so that the Authority can ensure that processing times are further reduced. The report must be similar to the one the Danish Data Protection Agency received from the Tax Administration on March 10, 2026, regarding the processing of requests for access in 2025. Appendix: Legal Basis Excerpt from Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Article 12. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication pursuant to Articles 15–22 and 34 regarding processing to the data subject in a concise, transparent, easily understandable, and easily accessible form, and in clear and plain language, in particular where information is specifically addressed to a child. The information shall be provided in writing or by other means, including, where appropriate, electronically. When requested by the data subject, the information may be provided orally, provided that the data subject’s identity is verified by other means. (2) The data controller shall facilitate the exercise of the data subject’s rights under Articles 15–22. In the cases referred to in Article 11(2), the data controller may not refuse to comply with the data subject’s request to exercise his or her rights under Articles 15–22, unless the data controller demonstrates that it is unable to identify the data subject. Paragraph 3. The data controller shall inform the data subject without undue delay, and in any event no later than one month after receipt of the request, of the measures taken in response to a request under Articles 15–22. This period may be extended by two months if necessary, taking into account the complexity and number of requests. The data controller shall notify the data subject of any such extension no later than one month after receiving the request, together with the reasons for the delay. If the data subject submits a request electronically, the information shall be provided electronically to the extent possible, unless the data subject requests otherwise. Paragraph 4. If the data controller does not take action in response to the data subject’s request, the data controller shall, without undue delay and no later than one month after receiving the request, inform the data subject of the reason for this and of the possibility of lodging a complaint with a supervisory authority and bringing the matter before a court. Paragraph 5. Information provided pursuant to Articles 13 and 14, and any communication or measure taken pursuant to Articles 15–22 and 34, shall be free of charge. If requests from a data subject are manifestly unfounded or excessive, in particular because they are repetitive, the data controller may either: a) charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the requested action, or b) refuse to comply with the request. The burden of proof that the request is manifestly unfounded or excessive lies with the data controller. Paragraph 6. Without prejudice to Article 11, if there is reasonable doubt as to the identity of the natural person making a request under Articles 15–21, the data controller may request additional information necessary to verify the data subject’s identity. Article 15. The data subject has the right to obtain from the data controller confirmation as to whether personal data concerning him or her are being processed and, where that is the case, access to the personal data and the following information: a) the purposes of the processing b) the categories of personal data concerned c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations d) if possible, the envisaged period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period e) the right to request from the data controller the rectification or erasure of personal data, or the restriction of processing of personal data concerning the data subject, or to object to such processing f) the right to lodge a complaint with a supervisory authority g) any available information regarding the source of the personal data, if it is not collected from the data subject h) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4), and, at a minimum, meaningful information about the logic involved, as well as the significance and the expected consequences of such processing for the data subject. (2) If the personal data is transferred to a third country or an international organization, the data subject has the right to be informed of the necessary safeguards pursuant to Article 46 in connection with the transfer. (3) The data controller shall provide a copy of the personal data being processed. For additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. If the data subject submits the request electronically, and unless the data subject requests otherwise, the information shall be provided in a commonly used electronic format. (4) The right to receive a copy as referred to in paragraph (3) must not infringe upon the rights and freedoms of others. [1] The decision has been published on the Danish Data Protection Agency’s website here. [2] Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). The Danish Data Protection Agency Carl Jacobsens Vej 35 2500 Valby Tel. 33 19 32 00 dt@datatilsynet.dk About Us About the Danish Data Protection AgencyPressWebsitePrivacy PolicyAccessibility Statement Quick Links Guide to the GDPRFile a Complaint with the Danish Data Protection AgencyCall UsNewsletterThe National Whistleblower Scheme Follow Us The Danish Data Protection Agency on LinkedIn SearchSearch Clear Load More The Danish Tax Administration Faces Serious Criticism Again Date: August 11, 2026 Decision Public Authorities Severe Criticism Complaint Right of Access The Danish Data Protection Agency has issued severe criticism of the Tax Administration’s handling of requests for access in 2025. The Authority has previously issued serious criticism of the Tax Administration’s handling of such requests for the period 2019–2024. Case Number: 2024-432-0039. Summary The Danish Data Protection Agency initiated (based on a complaint) an ex officio investigation in November 2024, which primarily concerned the Tax Administration’s general processing time for requests for access to data. After the case had been reviewed by the Data Council, the Danish Data Protection Agency first voiced serious criticism in a decision it issued on September 30, 2025, regarding the Tax Administration’s handling of requests for access during the period 2019–2024. To monitor trends in processing times, the Data Protection Authority also requested that the Tax Administration submit, in early 2026, a report on the administration’s handling of requests for access during the period 2025. The report showed, among other things, that the average processing time in 2025 was approximately 59 days. The Tax Administration’s Explanation The Tax Administration has stated that the processing time (once again) was influenced by several different factors, including, among other things, extensive cases involving a large number of documents, complex cases requiring cross-departmental clarifications and approvals, and requests concerning log data. In addition, the Tax Administration has stated that processing times have generally been affected by the fact that its staff have been busy processing previously received requests for access. Unlike in the 2019–2024 period, the Tax Administration has not stated that it processes requests for access according to the principle that they must be processed in the order in which they are received, regardless of the specific request’s complexity, etc. The Danish Data Protection Agency’s Assessment After the case was reviewed by the Data Council, the Danish Data Protection Agency once again finds grounds to express serious criticism of the fact that, during the 2025 period, the Tax Administration failed to process a significant number of requests for access in accordance with the deadlines set forth in the General Data Protection Regulation. In this regard, the Danish Data Protection Agency has—as was also the case in the Agency’s decision of September 30, 2025 —emphasized that the data controller’s prioritization of—or lack of—resources, personnel, measures, and the like is, as a clear starting point, not a circumstance that, under data protection law, can justify processing times for requests for access of such length, as was again the case with a public authority such as the Tax Administration during the period 2025. In this regard, the Danish Data Protection Agency has emphasized that a data controller is always obligated to allocate sufficient resources to process specific requests for access from data subjects within the time limits set forth in the General Data Protection Regulation, regardless of whether the data controller is already processing other requests for access. However, the Danish Data Protection Agency acknowledges—and has taken into account in determining the sanction—that the Tax Administration has been working on and has focused on processing requests for access, and that the agency has reduced the average processing time from approximately 100 days during the period 2019–2024 to approximately 59 days in 2025. Report in 2027 In the decision, the Danish Data Protection Agency requests that the Tax Administration submit a report to the Agency in January 2027 regarding the Administration’s case processing times in 2026, so that the Authority can continue to ensure that processing times are further reduced. Decision The Danish Data Protection Agency hereby returns to the case in which, on November 14, November 2024, based on a complaint, decided to initiate an investigation into the Tax Administration’s handling of requests for access pursuant to Article 15 of the General Data Protection Regulation. After the case had been reviewed by the Data Council, the Danish Data Protection Agency issued its first decision[1] on September 30, 2025, regarding the Tax Administration’s processing of requests for access during the period 2019–2024, in which the Authority expressed serious criticism of the Tax Administration’s failure to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation (GDPR), in accordance with the time limits set forth in Article 12(3) of the GDPR. In the decision, the Danish Data Protection Agency also requested that the Tax Administration submit a report on its handling of requests for access for the period from January 1 to December 31, 2025, so that the Authority could verify whether the processing time had been reduced. This decision thus concerns the Tax Administration’s handling of requests for access in 2025. 1 Decision After reviewing the case—and following its consideration by the Data Council—the Data Protection Authority finds that there are again grounds for expressing serious criticism of the fact that the Tax Administration has failed to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation[2], in accordance with the deadlines set forth in Article 12(3) of the General Data Protection Regulation. Below is a detailed review of the case and a justification for the Danish Data Protection Agency’s decision. 2 Case Summary On February 4, 2026, the Danish Data Protection Agency received the report on the Tax Administration’s handling of requests for access in 2025, which the Agency had requested in its decision of September 30, 2025. Subsequently, on February 6, 2026, the Danish Data Protection Agency posed a series of follow-up questions to the Tax Administration, which the Administration answered in two rounds on February 25 and March 10, 2026. The case file indicates that the Tax Administration received 152 requests for access in 2025, of which 62 requests had been pending for more than 30 days, 44 requests had been pending for more than 60 days, 23 requests had been pending for more than 90 days, and the average processing time was 59.05 days. The request for access that had been pending the longest had been pending for 189 days. Furthermore, the case file indicates that the Tax Administration—with regard to the processing of requests for access in 2025, as opposed to the processing of such requests during the period 2019–2024 —no longer states that it processes requests based on a fixed principle that they must be processed in the order in which they are received. 2.1 Comments from the Tax Administration In general, the Tax Administration notes that in 2025, the agency focused on processing requests for access, and that additional resources were allocated to this area. In addition, the Tax Administration has generally noted that the case processing time—as was also the case during the period 2019–2024 —has been affected by a combination of unclear requests, highly complex cases, and external complications. Specifically, the Tax Administration has cited the following factors that influenced processing times in 2025: Extensive cases involving a large number of documents Processing requests for access that involve personal data dating back between five and 20 years, where it is often necessary to physically review more than 10,000 files, including assessing any exceptions and limitations to the right of access. Complex cases requiring cross-functional clarifications and approvals Requests for access that involve the need for coordination with and/or approvals from other authorities and/or other agencies within the Tax Administration. This also includes the time required for the accurate, unambiguous identification of the person requesting access, as well as any clarification and narrowing of the scope of the request, which typically takes place through dialogue with the person requesting access—a process that can also affect the case processing time. Requests Concerning Log Data The Tax Administration states that it has been time-consuming to implement an appropriate process for handling requests for access that include log data, which has affected the case processing time, just as the processing of the access requests themselves is time-consuming. General Delay Impact on the overall processing time resulting from Tax Administration employees processing current and/or previous requests. Requests that turn out not to be access requests The time spent reviewing requests that subsequently turn out not to be access requests under data protection law. Access requests resulting from personal data security breaches Cross-functional (internal and legal) clarification in collaboration with external parties regarding the question of whether the name of an unintended recipient of personal data must be disclosed to the person requesting access. In addition to the above, the Tax Administration has also stated that the case processing time has been affected by periods of extraordinary caseload pressure, including as a result of a general increase in the number of requests for access. 3 Rationale for the Danish Data Protection Agency’s Decision The Danish Data Protection Agency first notes that the Tax Administration—as was also the case for the period 2019–2024—processes requests for access in accordance with established guidelines and procedures approved by management. It follows from Article 15(1) of the General Data Protection Regulation that the data subject has the right to obtain confirmation from the data controller as to whether personal data concerning the data subject are being processed, and, if so, to access the personal data and other information specified in subparagraphs (a) through (h) of that provision. In addition, the data subject has the right to receive a copy of the personal data processed by the data controller, see Article 15(3). Depending on the circumstances, the data subject also has the right to access log data if such data contains personal information about a data subject, such as log data regarding searches of the data subject’s information and the dates and purposes of those searches. The data subject may also have the right to be informed of who conducted the searches when this information is necessary for the data subject to effectively exercise their rights. Pursuant to Article 12(3) of the General Data Protection Regulation, requests for access—and other requests regarding rights made by data subjects under Chapter III of the Regulation —must, as a general rule, be handled without undue delay and no later than one month from the date of receipt of the request. This period may be extended by two months if necessary, taking into account the complexity and number of requests. In this regard, it is the Danish Data Protection Agency’s view that the circumstances justifying an extension of the processing time apply only to the individual request, a view supported by Recital 59 of the Regulation, which states that the data controller should be required to respond to requests from a data subject without undue delay and no later than within one month. Requests for the exercise of rights by a data subject should thus be processed separately and independently of other requests received. In the opinion of the Danish Data Protection Agency, the data controller cannot therefore extend the processing of specific requests for access on the grounds that the data controller is processing other requests from other data subjects, regardless of the complexity of those other requests, number, or time of receipt. Furthermore, the data controller must organize the processing of personal data, both technically and organizationally, in a manner that enables the fulfillment of requests for access —including requests for access that may be considered extensive and/or complex—without undue delay and no later than within one month, unless it is necessary to extend the response deadline, as noted above. After reviewing the case—and following its consideration by the Data Council—the Danish Data Protection Agency finds that there is again grounds for expressing serious criticism of the fact that the Tax Administration – in several instances, took more than 30 and 90 days, respectively, to process requests for access from data subjects, even though the nature of the specific requests did not necessarily justify an extended processing time – has failed to process a significant number of requests for access, pursuant to Article 15 of the General Data Protection Regulation, in accordance with the deadlines set forth in Article 12(3) of the General Data Protection Regulation, during the period from January 1 to December 31, 2025. In this regard, the Data Protection Authority has emphasized—as was also the case in the Authority’s decision of September 30, 2025—that the data controller’s prioritization of—or lack of—resources, staff, measures, and the like are, as a clear starting point, not circumstances that, under data protection law, can justify processing times for requests for access of such length, as was again the case with a public authority such as the Tax Administration during the period from January 1 to December 31, 2025, regardless of the circumstances that the Tax Administration has stated influenced the processing times, see section 2.1 above. Furthermore, the Danish Data Protection Agency emphasizes that, in its assessment, the Tax Administration cannot, in particular, justify extended processing times for specific requests for access, see Article 12(3) of the General Data Protection Regulation, on the grounds of “general delay.” In this regard, the Danish Data Protection Agency has emphasized that a data controller is always obligated to allocate sufficient resources to process specific requests for rights from data subjects within the time limits set forth in the General Data Protection Regulation, regardless of whether the data controller is already processing other requests for access. However, the Danish Data Protection Agency acknowledges—and has taken into account in determining the sanction—that the Tax Administration has been working on and focusing on the processing of requests for access, and that the agency has reduced the average processing time from approximately 100 days in the 2019–2024 period to approximately 59 days in 2025. Furthermore, the Danish Data Protection Agency acknowledges that the Tax Administration may, in several cases, receive extensive and complex requests for access, but regardless—as noted above—it is the Authority’s view that this does not justify processing times of the length seen in 2025 (and during the 2019–2024 period). The Data Protection Authority therefore requests that the Tax Administration submit a report to the Authority no later than January 11, 2027, detailing the Administration’s handling of requests for access to data during the period from January 1, January 2026 to December 31, 2026, so that the Authority can ensure that processing times are further reduced. The report must be similar to the one the Danish Data Protection Agency received from the Tax Administration on March 10, 2026, regarding the processing of requests for access in 2025. Appendix: Legal Basis Excerpt from Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Article 12. The data controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication pursuant to Articles 15–22 and 34 regarding processing to the data subject in a concise, transparent, easily understandable, and easily accessible form and in clear and plain language, in particular where information is specifically addressed to a child. The information shall be provided in writing or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the data subject’s identity is verified by other means. (2) The data controller shall facilitate the exercise of the data subject’s rights under Articles 15–22. In the cases referred to in Article 11(2), the data controller may not refuse to comply with the data subject’s request to exercise his or her rights under Articles 15–22, unless the data controller demonstrates that it is unable to identify the data subject. Paragraph 3. The data controller shall inform the data subject without undue delay, and in any event no later than one month after receiving the request, of the measures taken in response to a request pursuant to Articles 15–22. This period may be extended by two months if necessary, taking into account the complexity and number of requests. The data controller shall notify the data subject of any such extension no later than one month after receipt of the request, together with the reasons for the delay. If the data subject submits a request electronically, the information shall be provided electronically to the extent possible, unless the data subject requests otherwise. Paragraph 4. If the data controller does not take action in response to the data subject’s request, the data controller shall, without undue delay and no later than one month after receipt of the request, inform the data subject of the reason for this and of the possibility of lodging a complaint with a supervisory authority and bringing the matter before a court. Paragraph 5. Information provided pursuant to Articles 13 and 14, and any notification or measure taken pursuant to Articles 15–22 and 34, shall be free of charge. If requests from a data subject are manifestly unfounded or excessive, in particular because they are repetitive, the data controller may either: a) charge a reasonable fee, taking into account the administrative costs of providing the information or notices or taking the requested action, or b) refuse to comply with the request. The burden of proof that the request is manifestly unfounded or excessive rests with the data controller. Paragraph 6. Without prejudice to Article 11, if there is reasonable doubt as to the identity of the natural person making a request as referred to in Articles 15–21, the data controller may request additional information necessary to verify the data subject’s identity. Article 15. The data subject has the right to obtain from the data controller confirmation as to whether personal data concerning him or her are being processed and, where that is the case, access to the personal data and the following information: a) the purposes of the processing b) the categories of personal data concerned c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations d) if possible, the envisaged period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period e) the right to request that the data controller rectify or erase personal data, or restrict the processing of personal data concerning the data subject, or to object to such processing f) the right to lodge a complaint with a supervisory authority g) any available information regarding the source of the personal data, if it is not collected from the data subject h) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4), and, at a minimum, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. (2) If the personal data is transferred to a third country or an international organization, the data subject has the right to be informed of the necessary safeguards pursuant to Article 46 in connection with the transfer. (3) The data controller shall provide a copy of the personal data being processed. For any additional copies requested by the data subject, the data controller may charge a reasonable fee based on the administrative costs. If the data subject submits the request electronically, and unless the data subject requests otherwise, the information shall be provided in a commonly used electronic format. (4) The right to receive a copy as referred to in paragraph (3) must not infringe upon the rights and freedoms of others. [1] The decision is published on the Danish Data Protection Agency’s website here. [2] Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).