Skip to content
Content type · 38 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Denmark (38) Clear filter
1–38 of 38 sort newestlargest fineoldest
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation Sep 1, 2026
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
Datatilsynet (DK) · 2023-31-0321 A customer of a bank ('the data subject'), suspected that their former spouse, who was employed by the same bank ('the controller'), was accessing their accounts and decided to… 2023-31-0321 ·Denmark ·Art. 12, 15 Right of Access Personal Data Controllers Aug 18, 2026
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€200,900 ILVA A/S: Overtreding van algemene principes voor gegevensverwerking. Een boete van 200.900 euro - De Deense Autoriteit voor Gegevensbescherming (Datatilsynet). DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Retention Period Storage Limitation Controllers Sep 2, 2025
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Data Breaches Security Nov 27, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Data Breaches Processors Controllers Nov 12, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Encryption Education Aug 14, 2024
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·Datatilsynet (DK) Processors Controllers Supervisory Authorities
€6,700 Hørsholm municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Hørsholm municipality. The municipality had reported a data breach to the DPA pursuant to Art. 33 GDPR. An employee's work… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Sep 12, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Aug 11, 2022
€67,200 SIRIUS (law firm): Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 67,200 on the law firm SIRIUS. The law firm had suffered a cyber attack in which hackers gained access to the firm's servers and encrypted… DENMARK ·Datatilsynet (DK) ·Art. 32 Encryption Security Integrity and Confidentiality Principle Jul 14, 2022
€134,000 Gyldendal A/S: Non-compliance with general data processing principles The Danish DPA has fined publisher Gyldendal A/S EUR 134,000. During its investigation, the DPA found that the company had kept the data of approximately 685,000 unsubscribed… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Processing Telecommunications Jun 22, 2022
€13,400 Civilstyrelsen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 13,400 on the Danish agency Civilstyrelsen. A Civilstyrelsen USB stick containing more than 800 pages of sensitive and confidential… DENMARK ·Datatilsynet (DK) ·Art. 32, 33 Encryption Data Breaches Security May 12, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet (DK) ·Art. 5 Accountability Personal Data Processing Apr 5, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet (DK) ·Art. 36 DPIA Supervisory Authorities Healthcare Mar 25, 2022
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Dec 16, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 29, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 17, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Personal Data Supervisory Authorities Sep 8, 2021
€20,100 Danish Immigration Agency: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Privacy by Design & Default Public Authority Aug 17, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Controllers Personal Data Jul 16, 2021
€80,700 Medicals Nordic I/S: Non-compliance with general data processing principles The Danish DPA (Datatilsynet) has fined Medicals Nordic I/S EUR 80,700. In January 2021, the DPA became aware that Medicals Nordic was using WhatsApp to transmit confidential… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Healthcare Health Data Human Resources Jul 9, 2021
€53,800 Nordbornholms Byggeforretning Aps: Insufficient legal basis for data processing The Danish DPA ( Datatilsynet) has imposed a fine of EUR 53,800 on Nordbornholms Byggeforretning Aps. In 2018, the DPA was contacted by a data subject who complained that his… DENMARK ·Datatilsynet (DK) ·Art. 5, 6 Legitimate Interest Personal Data Controllers Jul 7, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Fines Personal Data Feb 12, 2021
€20,100 PrivatBo A.M.B.A.: Insufficient technical and organisational measures to ensure information security The company had distributed USB sticks to tenants in the context of a sale of real estate, which contained not only non-personal information on the real estate objects in question… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Personal Data Supervisory Authorities Aug 4, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet (DK) ·Art. 5 Retention Period Personal Data Processing Jul 28, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet (DK) ·Art. 5, 6, 33 +1 Data Breaches Personal Data Types of Special Categories of Personal Data Jun 30, 2020
€6,700 JobTeam A/S DKK: Insufficient fulfilment of data subjects rights The company has deleted personal data affected by a request for access without legal reason. DENMARK ·Datatilsynet (DK) ·Art. 15 Personal Data Supervisory Authorities Employees May 15, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Personal Data Public Authority Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Encryption Security Personal Data Mar 10, 2020
€160,000 Taxa 4x35: Non-compliance with general data processing principles The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the… DENMARK ·Datatilsynet (DK) ·Art. 5 Processing Administrative Fines on Union Institutions, Bodies, Offices and Agencies Fines Jan 1, 2019