Enforcement · Danish Data Protection Authority (Datatilsynet) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidance Guidelines 9/2022 on personal data breach notification under GDPR Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Literature General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679
Full text
During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were not kept longer than necessary for the purposes of collection. It was found that one of the reservation systems contained a large amount of personal data that should already have been deleted in accordance with the deletion deadlines set by Arp-Hansen itself.
Industry: Accomodation and Hospitality
Original document at the source www.datatilsynet.dk