# Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Danish Data Protection Authority (Datatilsynet)
- Date: 2020-07-28
- Original: https://www.enforcementtracker.com/ETid-361
- Canonical: https://overview.legal/posts/46476
- Topics: Retention Period, Personal Data, IP Address, Processing, Healthcare, Supervisory Authorities, Supervision

## Summary

During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were not kept longer than necessary for the purposes of collection. It was found that one of the reservation systems contained a large amount of personal data that should already have been deleted in accordance with the deletion deadlines set by Arp-Hansen itself.

## Full text

During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were not kept longer than necessary for the purposes of collection. It was found that one of the reservation systems contained a large amount of personal data that should already have been deleted in accordance with the deletion deadlines set by Arp-Hansen itself.

GDPR Articles: Art. 5 (1) e) GDPR
Industry: Accomodation and Hospitality

---
Generated by overview.legal · https://overview.legal/posts/46476 · 2026-08-22
