DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇩🇰 Denmark Data Privacy Laws

Denmark is the odd one out procedurally: Datatilsynet cannot fine directly and must refer cases to the police and courts. It compensates with detailed guidance, including some of the EU's clearest cookie consent standards, and it forced Google Workspace out of schools over transfer concerns.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
GDPR + Danish Data Protection Act
Year
2018
Authority
Datatilsynet
Marketing consent
GDPR legal basis required; ePrivacy consent for cookies and tracking.
Transfers
GDPR Chapter V.
Penalties
The DPA cannot fine directly; it refers cases to the police, and the courts set fines within GDPR maximums.

The GDPR baseline

As an EU member state, this jurisdiction applies the General Data Protection Regulation directly: every use of personal data needs one of six legal bases, individuals hold rights to access, correct, delete and port their data, breaches are reportable within 72 hours, and fines reach EUR 20M or 4% of global turnover. Layered on top, the ePrivacy Directive's national implementation requires prior consent for cookies and similar tracking, with electronic marketing on an opt-in basis softened only by the existing-customer exception.

For advertisers that means the EU standard playbook applies here in full: consent before tracking and behavioral targeting, a compliant consent platform, documented transfer mechanics for any non-EU stack, and one eye on the Digital Omnibus negotiations, which could amend the cookie rules once a final text is adopted. The national details below are what this member state adds or emphasizes.

The national layer

The national implementing act is the Danish Data Protection Act, and day-to-day supervision belongs to Datatilsynet. Denmark is the odd one out procedurally: Datatilsynet cannot fine directly and must refer cases to the police and courts. It compensates with detailed guidance, including some of the EU's clearest cookie consent standards, and it forced Google Workspace out of schools over transfer concerns.

Key instruments

GDPR + Danish Data Protection Act

2018 · In force

Denmark is the odd one out procedurally: Datatilsynet cannot fine directly and must refer cases to the police and courts. It compensates with detailed guidance, including some of the EU's clearest cookie consent standards, and it forced Google Workspace out of schools over transfer concerns.

Marketing and advertising

GDPR legal basis required; ePrivacy consent for cookies and tracking. Most channel decisions here follow from that consent rule.

Cross-border transfers

GDPR Chapter V applies in full, so personal data leaves the EEA only under an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, with a transfer impact assessment expected where the destination has surveillance-law exposure. The mechanics are identical across the bloc, so a transfer stack built for one member state travels to all of them.

Enforcement and penalties

The DPA cannot fine directly; it refers cases to the police, and the courts set fines within GDPR maximums.

Primary sources

Cite this page: "Denmark Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/denmark.html. Accessed [date].