# Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub)

- Type: Enforcement
- Source: Datatilsynet (Denmark)
- Date: 2026-09-01
- Original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_09-07-2026_(Lyngby_Boldklub)
- Canonical: https://overview.legal/posts/353640
- Topics: Special Categories of Data, Personal Data, Types of Special Categories of Personal Data, Supervisory Authorities, Biometric Data, Biometric Data, Controllers

## Summary

Facts — Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition during football matches to process biometric data. Processing such data would be done on the basis of Article 9(1) GDPR and Article 9(2)(g) GDPR, that is, necessary for reasons of public interest. Holding — The DPA granted the controller authorisation to process biometric data with the use of automatic facial recognition for the purpose of uniquely identifying natural persons. The DPA granted the authorisation under a number of conditions, requires notification of any changes, and reserves the right to review them. The conditions include, inter alia: Authorisation only applies when the controller is in the Danish Super League. Suspensions from matches must be imposed on an objective and proportionate manner following a violation of the controller’s stadium regulations and/or the Super League's code of conduct. Personal data which does not concern an individual on the controller’s suspension list, persons of interest list or police’s suspension list may not be stored. Personal data which concern one of those persons must be deleted after every match. The DPA emphasised that the GDPR and the Data Protection Act apply to the extent that the issue at hand is not regulated by the above conditions. The DPA stressed that a data protection impact assessment must be performed in accordance with Article 35 GDPR. If it results in a high risk the controller must seek prior consultation under Article 36 GDPR. The DPA also maintained its position in handling complaints. The DPA further clarified that the use of images from the surveillance to be covered by the national CCTV Surveillance Act. The DPA declared the controller’s communication and enforcement of the suspension list as, necessary for the purpose of processing a specific dispute following the Danish CCTV Surveillance Act. The DPA thus permits the controller to store the stadium’s security camera footage for longer than 30 days. The DPA emphasises that retention of this footage for longer than 30 days imposes a subsequent obligation on the controller to inform the data subject visible in the footage and allow them to request a copy of such.

## Full text

Skip the main navigation Lyngby Boldklub Granted Permission to Use Automated Facial Recognition Date: July 9, 2026 Authorization: Private Companies Following an application from Lyngby Boldklub and AC Horsens, the Danish Data Protection Agency has granted authorization for the clubs to process biometric data and thereby use automatic facial recognition during soccer matches. The above processing involves the processing of biometric data covered by the prohibition in Article 9(1) of the General Data Protection Regulation. Pursuant to Article 9(2)(g) of the Regulation, the prohibition on the processing of sensitive information does not apply if the processing is necessary for reasons of substantial public interest. Pursuant to Section 7(4) of the Data Protection Act, the Danish Data Protection Agency must grant authorization for such processing when it is not carried out by a public authority. The Danish Data Protection Agency hereby grants LYNGBY BOLDKLUB A/S Authorization to process biometric data pursuant to Section 7(4) of the Data Protection Act through the use of automated facial recognition at the LYNGBY BOLDKLUB A/S stadium Authorization to process biometric data for the purpose of uniquely identifying a natural person, through the use of automated facial recognition, is granted under the following conditions: This authorization applies only when LYNGBY BOLDKLUB A/S is the sole data controller for the processing of personal data with respect to the CCTV surveillance and the facial recognition system. This authorization applies only when LYNGBY BOLDKLUB A/S is a member of the Superliga. In this context, the authorization applies to the conduct of soccer matches, including friendly matches, involving teams from the Superliga, the 1st and 2nd divisions, as well as soccer matches organized by UEFA. The imposition of a ban must be based on objective and proportionate grounds in relation to the violation committed of LYNGBY BOLDKLUB A/S’s stadium regulations and/or the Superliga’s rules of conduct. Personal data processed as part of the facial recognition system that does not result in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s ban list and/or watchlist or 2) the police’s general ban list, may not be stored. Personal data processed as part of the facial recognition system that results in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s quarantine list and/or watchlist or 2) the police’s general quarantine list must be deleted immediately after each match. LYNGBY BOLDKLUB A/S must comply with the duty to provide information when collecting personal data. LYNGBY BOLDKLUB A/S must also, through signage or other clear means, provide information that access control is being conducted, including the processing of biometric data using an automated facial recognition system. Personal data processed as part of the facial recognition system must be transmitted to and stored in encrypted form on the server using up-to-date and widely recognized encryption algorithms. Surveillance cameras must be installed on a separate VLAN and must not be exposed to the internet. LYNGBY BOLDKLUB A/S must implement access control using the facial recognition system, including ensuring that employees are authorized to operate the facial recognition software and logging manual lookups during the login process. Use of multi-factor authentication in the login process. 10. Any changes to the conditions covered by this authorization must be reported to the Danish Data Protection Agency. The above terms apply until further notice. The Danish Data Protection Agency reserves the right to review these terms should the need arise. The above terms are supplementary and clarifying in relation to the provisions of the General Data Protection Regulation (GDPR) and the Danish Data Protection Act. It should be emphasized that the General Data Protection Regulation and the Data Protection Act thus apply to the extent that matters are involved that are not regulated by the terms and conditions above. The processing must therefore also be carried out in accordance with the rules regarding, among other things, the preparation of a data protection impact assessment, see Article 35 of the General Data Protection Regulation, including in particular Article 35(7) regarding the requirements for the content of a data protection impact assessment. The data protection impact assessment must be completed before processing begins. If the risk associated with the processing cannot be reduced to a level lower than “high,” LYNGBY BOLDKLUB A/S must comply with the requirement for prior consultation set forth in Article 36 of the General Data Protection Regulation. The Danish Data Protection Agency further reserves the right to take a position in the event of a potential complaint. In addition, for the sake of good order, the Danish Data Protection Agency must draw LYNGBY BOLDKLUB A/S’ that the use of images from surveillance cameras may be subject to Section 4c(4) and (5) of the Video Surveillance Act. This would be the case if the surveillance cameras at the stadium are installed for crime prevention purposes and if LYNGBY BOLDKLUB A/S —rather than a template—uses, including in the facial recognition system, an actual image derived from the surveillance cameras at the stadium. It follows from Section 4c(4) of the CCTV Surveillance Act that recordings as mentioned in paragraph (1), i.e., video and audio recordings containing personal data that are made in connection with television surveillance for the purpose of crime prevention, must be deleted no later than 30 days after the recordings are made; see, however, subsection (5). The term “video and audio recordings” refers to both still images and moving images. In the opinion of the Danish Data Protection Agency, this means that images from the surveillance cameras at the stadium that are intended to be recorded in the automatic facial recognition system must, as a general rule, be deleted no later than 30 days after the recordings are made. This also applies to images that have been “transferred” to the facial recognition system. However, pursuant to Section 4c(5) of the Video Surveillance Act, recordings may be retained for a longer period than specified in paragraph (4) if necessary for the data controller’s handling of a specific dispute. If retention is necessary for the purpose of resolving a specific dispute, the data controller must, within the time limit specified in paragraph (4), notify the person involved in the dispute and, upon request, provide that person with a copy of the recording. In the opinion of the Danish Data Protection Agency, it is reasonable to consider LYNGBY BOLDKLUB A/S’s notification and enforcement of a suspension as the handling of a specific dispute. Images—derived from the surveillance cameras at the stadium—may thus be stored for longer than 30 days. It is therefore the Danish Data Protection Agency’s assessment that Section 4c(4) of the Video Surveillance Act will not prevent LYNGBY BOLDKLUB A/S from using images from surveillance cameras at the stadium as the basis for registering, in the automatic facial recognition system, individuals who violate the stadium regulations and/or the rules of conduct. The notification requirement in Section 4c(5), second sentence, of the CCTV Surveillance Act does not appear to contain any exceptions. Individuals appearing in an image captured by the stadium’s surveillance cameras that is retained for longer than 30 days must therefore be notified of this and may request a copy of the image. The Danish Data Protection Agency Carl Jacobsens Vej 35 2500 Valby Tel. 33 19 32 00 dt@datatilsynet.dk About Us About the Danish Data Protection AgencyPressWebsitePrivacy PolicyAccessibility Statement Quick Links Guide to the GDPRFile a Complaint with the Danish Data Protection AgencyCall UsNewsletterThe National Whistleblower Scheme Follow Us The Danish Data Protection Agency on LinkedIn SearchSearch Clear Load More Lyngby Boldklub Granted Permission to Use Automated Facial Recognition Date: July 9, 2026 Authorization for Private Companies Following an application from Lyngby Boldklub and AC Horsens, the Danish Data Protection Agency has granted authorization for the clubs to process biometric data and thus use automated facial recognition during soccer matches. The above processing involves the processing of biometric data covered by the prohibition in Article 9(1) of the General Data Protection Regulation. Pursuant to Article 9(2)(g) of the Regulation, the prohibition on the processing of sensitive personal data does not apply if the processing is necessary for reasons of substantial public interest. Pursuant to Section 7(4) of the Data Protection Act, the Danish Data Protection Agency must grant authorization for such processing when it is not carried out by a public authority. The Danish Data Protection Agency hereby grants LYNGBY BOLDKLUB A/S Authorization to process biometric data pursuant to Section 7(4) of the Data Protection Act through the use of automated facial recognition at the LYNGBY BOLDKLUB A/S stadium Authorization to process biometric data for the purpose of uniquely identifying a natural person through the use of automated facial recognition is granted under the following conditions: This authorization applies only when LYNGBY BOLDKLUB A/S is the sole data controller for the processing of personal data with respect to the CCTV surveillance and the facial recognition system. This authorization applies only when LYNGBY BOLDKLUB A/S is a member of the Superliga. In this context, the authorization applies to the conduct of soccer matches, including exhibition matches, involving teams from the Superliga, the 1st and 2nd divisions, as well as to soccer matches organized by UEFA. The imposition of a ban must be based on objective and proportionate grounds in relation to the violation committed of LYNGBY BOLDKLUB A/S’s stadium regulations and/or the Superliga’s code of conduct. Personal data processed as part of the facial recognition system that does not result in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s ban list and/or watch list or 2) the police’s general ban list, may not be stored. Personal data processed as part of the facial recognition system that results in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s quarantine list and/or watchlist or 2) the police’s general quarantine list must be deleted immediately after each match. LYNGBY BOLDKLUB A/S must comply with the duty to provide information when collecting personal data. LYNGBY BOLDKLUB A/S must also provide information—via signage or in another clear manner—that access control is being conducted, including the processing of biometric data using an automated facial recognition system. Personal data processed as part of the facial recognition system must be transmitted to and stored on the server in encrypted form using up-to-date and widely recognized encryption algorithms. The surveillance cameras must be installed on a separate VLAN and must not be exposed to the internet. LYNGBY BOLDKLUB A/S must implement access control using the facial recognition system, including ensuring that employees are authorized to operate the facial recognition software and logging manual lookups during the login process. Use of multi-factor authentication in the login process. 10. Any changes to the conditions covered by this authorization must be reported to the Danish Data Protection Agency. The above terms apply until further notice. The Danish Data Protection Agency reserves the right to review these terms should the need arise. The above terms are supplementary and clarifying in relation to the provisions of the General Data Protection Regulation and the Danish Data Protection Act. It should be emphasized that the General Data Protection Regulation and the Data Protection Act thus apply to the extent that matters are involved that are not regulated by the terms above. The processing must therefore also be carried out in accordance with the rules regarding, among other things, the preparation of a data protection impact assessment, see Article 35 of the General Data Protection Regulation (GDPR), including in particular Article 35(7) regarding the requirements for the content of a data protection impact assessment. The data protection impact assessment must be completed before processing begins. If the risk associated with the processing cannot be reduced to a level lower than “high,” LYNGBY BOLDKLUB A/S must comply with the requirement for prior consultation set forth in Article 36 of the General Data Protection Regulation. The Danish Data Protection Agency further reserves the right to take a position in the event of a potential complaint. In addition, for the sake of good order, the Danish Data Protection Agency must draw LYNGBY BOLDKLUB A/S’s that the use of images from surveillance cameras may be subject to Section 4c(4) and (5) of the Video Surveillance Act. This would be the case if the surveillance cameras at the stadium are installed for crime prevention purposes and if LYNGBY BOLDKLUB A/S —rather than a template—uses, including in the facial recognition system, an actual image derived from the surveillance cameras at the stadium. It follows from Section 4c(4) of the CCTV Surveillance Act that recordings as mentioned in paragraph (1), i.e., video and audio recordings containing personal data that are made in connection with CCTV surveillance for the purpose of crime prevention, must be deleted no later than 30 days after the recordings are made; see, however, subsection (5). The term “video and audio recordings” refers to both still images and moving images. In the opinion of the Danish Data Protection Agency, this means that images from the surveillance cameras at the stadium that are intended to be registered in the automatic facial recognition system must, as a general rule, be deleted no later than 30 days after the recordings are made. This also applies to images that have been “transferred” to the facial recognition system. However, Section 4c(5) of the Video Surveillance Act provides that recordings may be retained for a longer period than specified in paragraph (4) if necessary for the data controller’s handling of a specific dispute. If retention is necessary for the purposes of a specific dispute, the data controller must, within the time limit specified in paragraph (4), notify the person involved in the dispute and, upon request, provide a copy of the recording to that person. In the opinion of the Danish Data Protection Agency, it is reasonable to consider LYNGBY BOLDKLUB A/S’s notification and enforcement of a suspension as the handling of a specific dispute. Images—derived from the surveillance cameras at the stadium—may thus be retained for longer than 30 days. It is therefore the Danish Data Protection Agency’s assessment that Section 4c(4) of the Video Surveillance Act will not prevent LYNGBY BOLDKLUB A/S from using images from surveillance cameras at the stadium as the basis for using the automatic facial recognition system to identify individuals who violate the stadium regulations and/or the rules of conduct. The notification requirement in Section 4c(5), second sentence, of the CCTV Surveillance Act is not deemed to contain any exceptions. Individuals appearing in an image captured by the stadium’s surveillance cameras that is retained for longer than 30 days must therefore be notified of this and may request a copy of the image.

---
Generated by overview.legal · https://overview.legal/posts/353640 · 2026-09-03
