Denmark
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Denmark — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Denmark follows the European Union rulebook. Personal data can leave the country once you have the right legal paperwork. There is no general rule that data must stay in Denmark. But there are three real limits. Named Danish state computer systems must run inside Denmark. Every business must keep a backup of its accounting records on a server inside Europe. And Denmark treats data protection breaches as crimes, not as something you just get fined for.
Data governance in Denmark
The eight things that decide how you handle data about people in Denmark. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Danish data protection law reaches you even with no office in Denmark. It applies if you offer goods or services to people in Denmark. It also applies if you watch what they do here. There is no size or revenue threshold to stay under. If your company is based entirely outside Europe, you must appoint a representative inside Europe. That comes from European Union rules. Denmark does not add a second Denmark-only representative for ordinary businesses.
- What you have to do here:
- Appoint a representative
Danish data protection law copies the European Union rule on who is covered. It covers any company based in Denmark, wherever the computers actually sit. It also covers companies based outside the European Union when they handle data about people in Denmark. That applies when you offer them goods or services, or track how they behave in Denmark. Two industries add a hard local-presence rule. For gambling, a licence can only go to a company based in Denmark or another European Union or European Economic Area country. A company based elsewhere must appoint a representative approved by the Danish Gambling Authority. That representative must live or be based in Denmark. They must be able to represent the licence holder in court cases, including criminal ones. Under Danish network and information security law, some suppliers fall under Danish rules if their main European Union base is in Denmark. That covers cloud, data centre, content delivery, managed service, online marketplace, search engine and social network suppliers.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 4 (territorial scope)
retsinformation.dk
“Loven og regler udstedt i medfør af loven gælder for behandling af personoplysninger om registrerede, der befinder sig i Danmark, som foretages af en dataansvarlig eller databehandler, der ikke er etableret i EU”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalConsolidated Danish Gambling Act, sections 26, 27 and 30 (establishment and approved representative)
retsinformation.dk
Link checked 18 August 2026
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalDanish network and information security law (NIS 2 law), section 2 (Danish jurisdiction)
retsinformation.dk
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Denmark is an ordinary European Union member. Data can go abroad once the standard European paperwork is in place. No Danish rule says personal data must stay in Denmark. But four areas override that. Named Danish state computer systems must run inside Denmark. Accounting backups must sit on a server inside Europe. Detailed population statistics given to researchers can never leave the government's own machines. And schools and town halls have been told their cloud classroom setups did not meet the rules.
- What you have to do here:
- Keep the data in the country
The answer depends on your industry. Here is each one, checked 18 August 2026. GOVERNMENT AND PUBLIC SECTOR — closed for a named list. An order made in February 2022 and re-issued in March 2023 lists eleven groups of systems that must run in Denmark. They are the defence resource system, Digital Post, the national identity login MitID, the public login gateway NemLog-in3, the state payroll solution, the national police systems, the common public data distributor, the civil registration system, the public case and document handling system, the credit register, and the emergency call system. The power behind this is open-ended. The Minister of Justice can add any government computer system to the list by making a new order. ACCOUNTING, ALL INDUSTRIES — a copy must stay in Europe. Is your bookkeeping system on the Danish Business Authority's register? If not, you must take a full backup at least weekly. You must keep it with a party unconnected to your business. It must sit on a server in a European Union or European Economic Area country. The same rule applies to registered standard systems. Breaking it brings a criminal fine. STATISTICS AND RESEARCH — closed. Detailed person-level data from Denmark's national registers is only available on Statistics Denmark's own research machines. You cannot copy, export, email, print or photograph data from those machines. Only summary results can be released, and only after review. EDUCATION AND LOCAL GOVERNMENT — it depends, and it is being fought over now. On 2 February 2026 the Danish Data Protection Agency issued serious criticism to 51 municipalities. The subject was Google's classroom products on pupil devices. The agency warned about hiring a supplier that uses sub-suppliers outside the European Economic Area without equal protection. That would likely break the European rules. It also said products with unclear data handling arrangements cannot lawfully be used. TELECOMS — no location rule, but a heavy record-keeping duty. From 30 March 2026 to 29 March 2027 all providers must record traffic data. That covers fixed, mobile and internet telephony, text messages, their own email services and internet access. They must keep it for one year. So records are held until 29 March 2028 at the latest. We found no requirement that the logs sit in Denmark. GAMBLING — no location rule, despite what many people say. A licence holder must build a data warehouse called SAFE. It holds standard records of every game played. The Danish Gambling Authority must be able to reach it online. Nothing in the current order says that warehouse must be in Denmark. All betting data must be kept five years. Player identity data must be kept five years after the customer relationship ends. BANKING, PAYMENTS, INSURANCE AND SECURITIES — conditions apply, but no rule about staying in the country. The European Union digital operational resilience rules have applied since January 2025. The Danish regulator runs outsourcing contract notifications and a register of technology suppliers through them. We found no Danish rule requiring financial data to stay in Denmark, checked 18 August 2026. HEALTH — conditions apply, but we found no rule about staying in the country. Doctors and dentists must keep patient records for ten years. Other health professionals must keep them for five years. We found no rule requiring those records to be held in Denmark, checked 18 August 2026. MAPPING AND GEOSPATIAL, DEFENCE — we found no civil rule about staying in the country, checked 18 August 2026. Classified defence material is handled under separate security rules. We did not examine those.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022 on storing in Denmark personal data processed in specified information technology systems run for the public administration
retsinformation.dk
“It-systemer, der er nævnt i bilag 1, skal føres her i landet.”
Link checked 18 August 2026
- Official sourceLovtidende, the official Danish gazetteExecutive order no. 302 of 15 March 2023 amending the storage-in-Denmark order — replacement annex listing eleven system groups
lovtidende.dk
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024 on requirements for company digital bookkeeping systems not registered under the Bookkeeping Act, section 4
retsinformation.dk
“Virksomheden skal opbevare sikkerhedskopien efter stk. 1 hos en ikke nærtstående part ... på en server i et EU- eller EØS-land”
Link checked 18 August 2026
- Official sourceStatistics DenmarkRules for working with microdata on Statistics Denmark's research machines
dst.dk
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency issues serious criticism to 51 municipalities in the Chromebook case, 2 February 2026
datatilsynet.dk
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting — the SAFE data warehouse and five-year retention
retsinformation.dk
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Denmark adds nothing of its own. You use the European Union machinery. Send data to a country the European Commission has approved. Or sign the European standard contract. Or use approved group-wide rules. There is no Danish permit, no Danish filing and no waiting period. The Danish twist comes at the other end. Sending data abroad without a proper legal basis is a crime here, not just something you get fined for.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
- What it costs if you get it wrong:
- Criminal liability
You can only send data to approved countries, and the approved list is long. These are the countries the European Commission had approved as of 18 August 2026. Andorra, Argentina, Brazil (new on 26 January 2026, and mutual), Canada for commercial organisations, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), and Uruguay. The United States is included, but only for organisations that have self-certified under the European Union-United States Data Privacy Framework. The European Patent Organisation has been on the list since 15 July 2025. No approval has been withdrawn or suspended. If no approval covers your destination, use the 2021 standard contract clauses. They are still the current set and are unchanged. The promised new clauses for recipients already covered directly by European rules have still not been adopted. Approved group-wide rules are also available. The narrow emergency exceptions cannot be used for routine or bulk transfers. You are still expected to write a risk assessment for the transfer. The European Union-United States arrangement is in force and legally valid today. But it is under pressure. An appeal against the General Court's September 2025 dismissal in the Latombe case is pending before the Court of Justice. On 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent United States developments affect its validity. Never build on it as your only route. Separately, Danish law makes breaking the European transfer rules a crime. The penalty is a fine or up to six months in prison.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 41 subsection 1 number 6 — criminal liability for unlawful third-country transfers
retsinformation.dk
“straffes med bøde eller fængsel indtil 6 måneder den, der overtræder bestemmelserne om ... overførsel af personoplysninger til en modtager i et tredjeland eller en international organisation i henhold til databeskyttelsesforordningens artikel 44-49.”
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission list of adequacy decisions
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — legislation and executive orders it administers
datatilsynet.dk
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Danish Data Protection Agency, and it is fully staffed and busy. It opened 20,536 new cases in 2025. It received 9,849 breach reports. But it cannot fine you. Denmark is almost alone in Europe in treating data protection breaches as crimes. So the agency has to hand the case to the police. The police then prosecute in court. In all of 2025 it did that just twice. Expect orders, bans and public criticism rather than large fines.
- What it costs if you get it wrong:
- Criminal liability · Order to stop
Enforcement is active, not aggressive. The numbers come from the regulator's own 2025 annual report, published March 2026. It opened 20,536 new cases. It received 9,849 personal data breach reports, 5,167 from public authorities and 4,630 from private organisations. It ran 3,653 supervision and enforcement cases and 2,867 advice and guidance cases. It opened 525 cases on its own initiative. It filed exactly 2 police reports with a recommended fine during the year. The agency's own fines page explains why. In most European countries the privacy regulator can impose fines itself. In Denmark that currently has to go through the courts. The agency refers the case to the police with a recommended amount. Since a 2023 change the agency can also offer a settlement without a court case. That only works where the offender admits guilt and pays. The 2025 annual report does not record any use of that route. So its strongest tools are the ones that do not involve money. Those are orders, bans on using data, and public criticism. The February 2026 Chromebook decision, covering 51 municipalities at once, is the clearest recent example. Other regulators are also active. The Danish Business Authority covers bookkeeping. The Danish Financial Supervisory Authority covers technology resilience in finance. The Danish Gambling Authority covers licence holders. The Danish Agency for Societal Security covers the network and information security rules. The Danish Defence Intelligence Service acts as the national computer security incident response team.
Sources
- Official sourceDatatilsynetDanish Data Protection Agency annual report 2025
datatilsynet.dk
“Datatilsynet har i 2025 indgivet 2 politianmeldelser med indstilling om bøde for overtrædelse af databeskyttelsesreglerne.”
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — fine cases and how fines are imposed in Denmark
datatilsynet.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, sections 41 and 42 — criminal penalties and the settlement fine notice
retsinformation.dk
Link checked 18 August 2026
How long you must keep it — and when to delete it
Denmark sets several minimum keeping periods. Accounting records: five years after the financial year ends. Patient records: ten years for doctors and dentists, five for other health professionals. Gambling records: five years. Telephone and internet traffic records: one year. The European rules push the other way. Delete personal data once you no longer need it. Where the two clash, the specific Danish keeping duty wins for as long as it runs. You delete after it expires.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums, all checked 18 August 2026. Accounting material must be kept securely for five years from the end of the financial year it covers. That comes from the Bookkeeping Act. You also need a weekly full backup with an unrelated third party, on a server in the European Union or European Economic Area. Patient records must be kept at least ten years from the last entry by doctors, dentists, midwives and certain specialists. Other authorised health professionals must keep them at least five years. That comes from the Danish Patient Safety Authority. Gambling licence holders must keep identity and control information about a registered player for at least five years after the customer relationship ends. They must keep all data about betting offered in the gambling system for at least five years. Telecoms providers must keep the traffic data recorded under the March 2026 logging order for one year from when it was recorded. So data recorded on the last covered day is held until 29 March 2028. Criminal liability under the data protection law itself runs out after five years. Now the maximums. The European rule against keeping data longer than you need applies unchanged. Danish law also protects information about people who have died for ten years after death. That is a Danish addition with no European equivalent. When a minimum and a maximum clash, Denmark handles it the ordinary European way. A legal duty to keep data is an express exception to the right to erasure. So the specific keeping period wins until it runs out.
Sources
- Official sourceDanish Business Authority, via the official Danish legal information portalDanish Bookkeeping Act no. 700 of 24 May 2022, section 12 — five-year retention of accounting material
retsinformation.dk
“Virksomheder skal på betryggende vis opbevare regnskabsmateriale, jf. § 4, i 5 år fra udgangen af det regnskabsår, materialet vedrører.”
Link checked 18 August 2026
- Official sourceStyrelsen for PatientsikkerhedDanish Patient Safety Authority — how long patient records must be kept
stps.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 397 of 20 March 2026 on general and undifferentiated recording of traffic data — one-year retention
retsinformation.dk
“De oplysninger, der er registreret i medfør af stk. 1, skal opbevares i 1 år fra registreringstidspunktet.”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting, sections 4 and 30 — five-year retention
retsinformation.dk
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least three clocks, and they run at different speeds. For a personal data breach you have 72 hours to tell the Danish Data Protection Agency. You must tell affected people without delay if the risk to them is high. If the Danish cyber security law covers your company, you have only 24 hours to send an early warning. Then 72 hours for a fuller report. Then one month for the final report. Financial firms report separately under the European resilience rules.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one, personal data. You have 72 hours from the moment you know, and you tell the Danish Data Protection Agency. You must also tell affected people without undue delay where the risk to their rights is high. The Agency received 9,849 such reports in 2025. So this is a heavily used channel and the reporting form is well established. Clock two, cyber security. The Danish network and information security law has applied since 1 July 2025. Essential and important organisations must send an early warning about a significant incident. It goes to the relevant sector authority and to the national computer security incident response team. It is due without undue delay and within 24 hours of becoming aware. It must say whether the incident looks malicious or has cross-border effects. A fuller notice follows within 72 hours, with a first severity assessment and signs of compromise. An interim report follows on request. A final report is due within one month of the incident notice. The incident response team must reply within 24 hours of the early warning. You must also tell affected customers without undue delay. Failing to report brings a criminal fine, and companies can be held criminally liable. Clock three, finance. The European digital operational resilience rules have applied to financial firms since 17 January 2025. They run their own major incident reporting timetable through the Danish Financial Supervisory Authority. Clock four, telecoms. A separate Danish law on security and preparedness in telecoms sits outside the cyber security law. We did not examine it in detail here. The overlap is the usual failure point. The 24-hour cyber warning is due long before the 72-hour privacy report is ready.
Sources
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalDanish network and information security law no. 434 of 6 May 2025, sections 12, 13, 15, 32 and 33
retsinformation.dk
“En tidlig varsling ... sendes uden unødigt ophold, og senest inden for 24 timer efter at enheden har fået kendskab til den væsentlige hændelse.”
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — questions and answers on the network and information security law, including who acts as the national incident response team
samsik.dk
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency annual report 2025 — 9,849 personal data breach notifications received
datatilsynet.dk
Link checked 18 August 2026
- Official sourceFinanstilsynetDanish Financial Supervisory Authority — the European digital operational resilience regulation
finanstilsynet.dk
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, a child in Denmark is anyone under 15 for online consent. Not 13 and not 16. Second, breaking the data rules is a crime here, with prison on the books. Third, the Danish personal identity number has its own rulebook and must never be published. Fourth, your accounting backup must be on a European server, and getting that wrong is a crime. Fifth, the Justice Minister can order any government system to run only in Denmark, overnight, with no consultation.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
Trap one, the age. Denmark set the age at which a child can agree to online services at 15. That is the middle of the range the European rules allow. Most global age gates are built for 13 or 16. So both settings are wrong for Denmark. Below 15, a parent or guardian must give or approve consent. Trap two, crime not fine. Danish law punishes four kinds of breach. The core principles. People's individual rights. The duties on companies that handle data. And the rules on sending data abroad. The penalty is a fine or up to six months in prison. Blocking the regulator, or ignoring its orders, is a separate crime. A court can also ban someone from running a business that stores personal data. This changes how you handle an investigation. Because it is a criminal matter, the file is closed. You cannot use the ordinary right to see case documents. Trap three, the personal identity number. The Danish civil registration number has its own rulebook. Public authorities can use it to identify someone uniquely, or as a file number. Private organisations can only use it in limited cases. Those cases are these. Where a law requires it. Where the person has agreed. For scientific or statistical purposes. Where an authority requires it. Or where passing it on is a natural part of normal business of that kind, and is decisive for identifying someone uniquely. You must never publish it without consent. Danish systems are full of this number. Foreign-built systems routinely treat it as an ordinary customer reference. Trap four, the accounting backup. Is your bookkeeping system on the Danish register? If not, you must take a full weekly backup. It must be kept with a party unrelated to your business, on a server in a European Union or European Economic Area country. That party is presumed to meet recognised information security standards. Breaking this brings a fine. This is a real rule about keeping data in Europe. It hides inside company law rather than privacy law. It hits foreign groups running a single global accounting platform hardest. Trap five, the switch that can be flipped at any time. Danish law lets the Minister of Justice decree that personal data in named government computer systems may only be stored in Denmark. The Minister consults the relevant minister first. Beyond that, the law sets no consultation requirement, no threshold and no list of qualifying systems. The power has already been used to capture eleven groups of systems. The list was expanded once in 2023. If you run a system for a Danish public authority, treat this as a live commercial risk.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, sections 3, 6, 11, 41 and 43
retsinformation.dk
“er behandling af personoplysninger om et barn lovlig, hvis barnet er mindst 15 år. Stk. 3. Er barnet under 15 år, er behandling kun lovlig, hvis og i det omfang samtykke gives eller godkendes af indehaveren af forældremyndigheden over barnet.”
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024, sections 4 and 6 — European server backup and criminal fine
retsinformation.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022 — the storage-in-Denmark power in use
retsinformation.dk
Link checked 18 August 2026
What's changing next
Three things are already law and already in force. Those are the cyber security rules, the new health digitisation body, and the last stage of the digital bookkeeping rules. One big thing is promised but not yet law. Politicians agreed an age limit of 15 for social media in November 2025. We found no bill as of August 2026. Two more things can change without warning. One is the list of government systems that must stay in Denmark. The other is the telephone logging order, which has to be renewed every year.
Already in force. The Danish network and information security law started on 1 July 2025. Registration through the business portal opened the same day and closed on 1 October 2025. Organisations that become covered later get a two-week window. Changes must be reported within three months. Digital Sundhed Danmark is a new self-governing institution for health digitisation. It was passed on 29 December 2025 and started on 1 January 2026. The digital bookkeeping duty reached its final phase on 1 January 2026. It now covers non-financial businesses with net revenue above 300,000 Danish kroner, roughly 45,000 United States dollars, in two years running. Proposed, with no legal effect yet. On 7 November 2025 the government and a broad group of parties agreed a package on digital protection of children. It is funded with 160 million Danish kroner, roughly 24 million United States dollars, across fourteen measures. The centrepiece is an age limit of 15 for certain social media, with parental consent possible from 13. As of 18 August 2026 we found no bill on the parliament's own site. Treat it as policy, not law. Also in motion. The Agency for Digital Government has 80 million Danish kroner for a digital sovereignty action plan. That is roughly 12 million United States dollars. The plan covers 2026 to 2029. Public-sector parties were due to agree next steps in spring 2026. Today this is analysis and guidance, not binding rules. The risk is that it hardens into purchasing requirements. Switches that can flip at any time. These matter most. First, the Minister of Justice can add any public administration system to the must-stay-in-Denmark list by order, with no consultation. Second, the general telephone and internet logging duty rests on an annual national security assessment. The current order runs only from 30 March 2026 to 29 March 2027 and must be re-made each year. So it can lapse or be widened with a single ministerial signature. Third, at European level the digital operational resilience rules give supervisors growing powers over cloud suppliers. And the European Union Data Act requires all cloud switching and data export charges to fall to zero by 12 January 2027.
Sources
- Official sourceDanish Ministry of Digital AffairsPolitical agreement on digital child protection, 7 November 2025 — age limit of 15 for social media, parental consent from 13
digmin.dk
Link checked 18 August 2026
- Official sourceMinistry of the Interior and Health, via the official Danish legal information portalAct no. 1758 of 29 December 2025 on Digital Sundhed Danmark, section 36 — in force 1 January 2026
retsinformation.dk
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — registration under the network and information security law
samsik.dk
Link checked 18 August 2026
- Official sourceDigitaliseringsstyrelsenDanish Agency for Digital Government — digital sovereignty work and the 2026 to 2029 action plan
digst.dk
Link checked 18 August 2026
- Official sourceErhvervsstyrelsenDanish Business Authority guidance on the Bookkeeping Act, including the 1 January 2026 phase-in
erhvervsstyrelsen.dk
Link checked 18 August 2026
What to do: Diarise 29 March 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Bekendtgørelse om hel eller delvis opbevaring her i landet af personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning · Executive order no. 220 of 11 February 2022, amended by order no. 817 of 3 June 2022 and order no. 302 of 15 March 2023 · Directly binding regulation
A short government order with a long reach. Personal data in a list of named Danish government computer systems must be held inside Denmark, with no copy abroad. The Minister of Justice can add systems to the list at any time by issuing a new order. There is no consultation, and it has already been done once.
Enforced by Ministry of Justice
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryEleven groups of systems must run inside Denmark. They are the defence resource system, Digital Post, the national identity login MitID, the login gateway NemLog-in3, the state payroll solution, the national police systems, the common public data distributor, the civil registration system, the public case and document handling system, the credit register, and the emergency call system.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022
retsinformation.dk
“It-systemer, der er nævnt i bilag 1, skal føres her i landet.”
Link checked 18 August 2026
- Official sourceLovtidende, the official Danish gazetteExecutive order no. 302 of 15 March 2023 — annex replaced, list extended to eleven system groups, in force 1 April 2023
lovtidende.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 3 subsection 9 — the enabling power
retsinformation.dk
“Justitsministeren kan efter forhandling med vedkommende minister fastsætte regler om, at personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning, helt eller delvis alene må opbevares her i landet.”
Link checked 18 August 2026
Telecoms rules
Official name: Bekendtgørelse om generel og udifferentieret registrering af trafikdata fra og med den 30. marts 2026 til og med den 29. marts 2027 og opbevaring til og med den 29. marts 2028 · Executive order no. 397 of 20 March 2026, made under sections 786 e and 786 j of the Administration of Justice Act · Directly binding regulation
Denmark makes every telecoms provider record who called whom, from where and when. It covers everyone, for a year at a time. A fresh national security threat assessment justifies it each year. The current order only covers 30 March 2026 to 29 March 2027, so it must be renewed annually. We found no rule requiring the logs to be stored in Denmark.
Enforced by Ministry of Justice
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep logs — 1 yearProviders record calling and called numbers, with subscriber names and addresses. They also record device identifiers, cell locations at the start and end of a call, and message receipts. They record sender and recipient addresses for their own email service, and internet telephony traffic. This covers everyone. Records are kept one year from when they are made.
- Keep data for a minimum period — 1 year
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableFailure to record and retain
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 397 of 20 March 2026, sections 1 to 7 and annex 1
retsinformation.dk
“Regler om registreringspligt i medfør af retsplejelovens § 786 e kan fastsættes for en periode på højst ét år ad gangen ... og oplysninger registreret i medfør af de fastsatte regler skal opbevares i ét år”
Link checked 18 August 2026
Cyber security rules
Official name: Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven) · Act no. 434 of 6 May 2025 · Act of parliament
Denmark's cyber security law started on 1 July 2025. It covers essential and important organisations across most of the economy. It adds a 24-hour early warning duty on top of the 72-hour privacy breach clock. It does not require data to stay in the country. Enforcement is again criminal rather than a fine from a regulator.
Enforced by Danish Agency for Societal Security
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Register or notify — from 1 July 2025Registration through the business portal opened 1 July 2025 and closed 1 October 2025. Organisations that become covered later have two weeks. Changes must be reported within three months.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours, incident notification within 72 hours, interim report on request, final report within one month.
- Secure the data
- Tell affected peopleService recipients must be told without undue delay where the incident is likely to affect the service.
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableFailure to notify, to register, to implement measures, or to comply with an order
- Order to stopOrders and prohibitions from the sector authority
Sources
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalAct no. 434 of 6 May 2025 on measures to secure a high level of cyber security
retsinformation.dk
“§ 33. Loven træder i kraft den 1. juli 2025.”
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — registration duty and deadlines
samsik.dk
Link checked 18 August 2026
Online gaming data rules
Official name: Bekendtgørelse om online væddemål · Executive order no. 684 of 11 June 2025, replacing order no. 1276 of 29 November 2019 · Directly binding regulation
Denmark does not require a gambling operator's data to be stored in Denmark, despite what many people claim. What it requires is a data warehouse called SAFE. It holds a standard record of every game. The regulator must be able to reach it online. It must be sealed against tampering, and records kept five years. The duty to have a local presence falls on the company, not the servers.
Enforced by Danish Gambling Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 5 yearsKeep player identity and control information for five years after the customer relationship ends. Keep all data about betting offered in the gambling system for five years.
- Independent auditGambling systems and random number generators must be tested and certified by an approved test house before use.
- Appoint a representativeA licence holder based outside the European Union or European Economic Area must appoint a representative approved by the regulator. That representative must live or be based in Denmark.
- Register or notify
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableBreach of the retention, system or player protection provisions
- Loss of your licenceLoss of the conditions on which the licence was granted
Sources
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting, sections 4, 28 to 33 and annex
retsinformation.dk
“SAFE er tilladelsesindehavers eget datalager (en filserver), hvor tilladelsesindehaver skal opbevare spildata ... Spillemyndigheden skal kunne få online adgang til datalagret hos tilladelsesindehaver.”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalConsolidated Danish Gambling Act, LBK no. 1182 of 22 September 2025, sections 26, 27, 30 and 41
retsinformation.dk
Link checked 18 August 2026
- Official sourceSpillemyndighedenDanish Gambling Authority — online casino licence requirements
spillemyndigheden.dk
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Data rules
Official name: Databeskyttelsesloven · Act no. 502 of 23 May 2018, consolidated as LBK no. 289 of 8 March 2024 · Act of parliament
Denmark's national companion to the European rules. Two things are specific to Denmark. The age of online consent is 15. And breaking the rules is a crime carrying up to six months in prison. So cases go to the police and the courts rather than ending in a fine from the regulator. Danish law also has its own rulebook for the Danish personal identity number.
Enforced by Danish Data Protection Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 15Denmark set the age of digital consent at 15, not 13 or 16.
- Get consent
- Secure the data
- Delete data after a periodDanish law also protects information about people who have died, for ten years after death.
- Appoint a data protection officerEuropean Union rules apply. Denmark adds no separate national duty to appoint anyone for ordinary businesses.
What it costs if you get it wrong
- Criminal liability: Fine or imprisonment up to 6 monthsBreach of core principles, individual rights, controller and processor duties, or the third-country transfer rules
- Criminal liability: Fine or imprisonment up to 6 monthsObstructing the regulator or ignoring its orders
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, LBK no. 289 of 8 March 2024
retsinformation.dk
“§ 11. Offentlige myndigheder kan behandle oplysninger om personnummer med henblik på en entydig identifikation eller som journalnummer.”
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — how fines work in Denmark
datatilsynet.dk
Link checked 18 August 2026
Personal data needs a copy kept in the country
Official name: Bekendtgørelse om krav til virksomheders digitale bogføringssystemer der ikke er registreret efter bogføringsloven · Executive order no. 205 of 29 February 2024, made under the Bookkeeping Act no. 700 of 24 May 2022 · Directly binding regulation
Does your business use a bookkeeping system that is not on the official Danish register? Then you must take a full backup at least weekly. You must keep it with an unrelated third party, on a server inside the European Union or European Economic Area. The same duty applies to registered standard systems. Breaking it is a crime.
Enforced by Danish Business Authority
How this country controls where data goes: Only approved countries · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryThe weekly full backup must sit with a party unconnected to your business. It must be on a server in a European Union or European Economic Area country. The floor is Europe, not Denmark.
- Keep data for a minimum period — 5 yearsFive years from the end of the financial year the material relates to.
- Secure the dataThe backup holder must be presumed to meet recognised information security standards.
What it costs if you get it wrong
- Criminal liability: FineFailure to hold the backup with an unrelated party on a European server
Sources
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024, sections 4, 6 and 7
retsinformation.dk
“Virksomheden skal opbevare sikkerhedskopien efter stk. 1 hos en ikke nærtstående part, jf. § 2, stk. 4, som må formodes at opfylde anerkendte standarder for it-sikkerhed, på en server i et EU- eller EØS-land”
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 97 of 26 January 2023 on requirements for digital standard bookkeeping systems — matching European server rule for registered systems
retsinformation.dk
Link checked 18 August 2026
- Official sourceErhvervsstyrelsenDanish Business Authority guidance on the Bookkeeping Act, including that paper records no longer have to be kept in Denmark or the Nordic countries
erhvervsstyrelsen.dk
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Databeskyttelsesforordningen (General Data Protection Regulation) · Regulation (EU) 2016/679, Chapter V · Directly binding regulation
The European Union baseline. Personal data can leave Europe once you have an approved destination, the European standard contract, or approved group-wide rules. Where you store data is a risk factor, never a ban. Denmark has the European fine levels on paper. But the money is collected through the criminal courts, not by the regulator.
Enforced by Danish Data Protection Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeYou are still expected to write a risk assessment for the transfer, whichever route you pick.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20 million — about $22 millionSame tier, whichever is higher
- Order to stopOrder to stop processing or suspend third-country flows
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions — list verified 18 August 2026
commission.europa.eu
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — the rules it applies
datatilsynet.dk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether any bill implementing the November 2025 political agreement on a social media age limit of 15 has been introduced in the Danish parliament
The Ministry of Digital Affairs confirms the political agreement on its own site. We could not find a bill on the parliament's site or the legal information portal as of 18 August 2026. Treat this as policy, not law, and check parliament's site before you plan around it.
Whether the Danish Data Protection Agency has ever actually used its power to issue a settlement fine notice under section 42 of the Danish Data Protection Act
The power to offer a settlement fine exists in the consolidated 2024 Danish text. We found no confirmed example of the agency using it. The 2025 annual report does not mention it, and the agency's fines page still says fines go through the courts.
Whether any Danish rule requires health records or genomic data to be stored inside Denmark
We confirmed the keeping periods with the Danish Patient Safety Authority. We found no rule saying health records must stay in Denmark in the health laws we reviewed. We did not check the National Genome Centre's database arrangements in the law itself. If you handle Danish health or genomic data, check before you rely on this.
Whether the Danish telecoms security and preparedness law imposes location or personnel requirements beyond the cyber security law
The Danish telecoms security and preparedness law is expressly left out of the 2025 cyber security law. We did not review it on its own. If you are a telecoms provider, check it for rules about where data and staff must sit.
The current version and exact wording of the Danish Gambling Authority's technical requirements document
We could not open the regulator's own copy of the technical requirements document. So the rule content here comes from two places. The June 2025 online betting order, which is primary law. And a European Commission notification recording version 2.5 of 1 January 2025. Check the regulator's current document before you build to it.
Whether any Danish national rule survives alongside the European digital operational resilience rules for financial sector outsourcing
The Danish Financial Supervisory Authority's own pages describe the European rules and their notification duties. We could not confirm from a government source what happened to the 2020 Danish outsourcing order. Check with the authority if you outsource financial technology.
Whether the storage-in-Denmark annex has been amended again since March 2023
We confirmed the March 2023 amending order from the official gazette. We searched for later amendments and found none. A search alone cannot prove that no later order exists. Check the gazette if you run a system for a Danish public authority.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.