Skip to the content
Global Data RulesData governance rules, country by country

Denmark

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Active

Denmark follows the European Union rulebook: personal data may leave the country once you have the right legal paperwork in place. There is no general rule that data must stay in Denmark. But there are three real walls. Named Danish state computer systems must run inside Denmark. Every business must keep a backup of its accounting records on a server inside Europe. And Denmark punishes data protection breaches as crimes, not with administrative fines.

Data governance in Denmark

The eight things that decide how you handle data about people in Denmark. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The Danish data protection law reaches a company with no office in Denmark, as long as it offers goods or services to people located in Denmark, or watches what they do here. There is no size or revenue threshold to hide below. A company based entirely outside Europe must appoint a representative inside Europe under the European Union rules, but Denmark does not add a second, Denmark-only representative on top for ordinary businesses.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

In general, yes. Denmark is an ordinary European Union member, so data can go abroad once the standard European paperwork is in place, and there is no Danish rule that personal data must stay in Denmark. But four areas override that. Named Danish state computer systems must run inside Denmark. Accounting backups must sit on a server inside Europe. Detailed population statistics given to researchers can never leave the government's own machines. And schools and town halls have been told their cloud classroom setups did not meet the rules.

High confidenceDepends on your industryAllowlistKeep the data in the country

Sending data out of the country

Denmark adds nothing of its own. You use the European Union machinery: send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. There is no Danish permit, no Danish filing and no Danish waiting period. The one Danish twist is at the other end: sending data abroad without a proper legal basis is a criminal offence here, not just something you get fined for.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claimsCriminal liability

The regulator, and whether it actually acts

The Danish Data Protection Agency, and it is fully staffed and busy. It opened 20,536 new cases in 2025 and received 9,849 breach reports. But it cannot fine you. Denmark is almost alone in Europe in treating data protection breaches as crimes, so the agency has to hand the case to the police, who then prosecute in court. In all of 2025 it did that just twice. So expect orders, bans and public criticism rather than large fines.

High confidenceActiveCriminal liabilityOrder to stop

How long you must keep it — and when to delete it

Denmark sets several minimum keeping periods. Accounting records: five years after the financial year ends. Patient records: ten years for doctors and dentists, five for other health professionals. Gambling records: five years. Telephone and internet traffic records: one year. In the other direction, the European rules say delete personal data once you no longer need it. Where the two collide, the specific Danish keeping duty wins for as long as it runs, and you delete after it expires.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count at least three clocks and they run at different speeds. For a personal data breach you have 72 hours to tell the Danish Data Protection Agency, and you must tell affected people without delay if the risk to them is high. If you are a company covered by the Danish cyber security law, you have only 24 hours to send an early warning, then 72 hours for a fuller report, then one month for the final report. Financial firms report separately under the European resilience rules.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things catch people out. A child in Denmark is anyone under 15 for online consent, not 13 and not 16. Breaking the data rules is a crime here, with prison on the books. The Danish personal identity number has its own rulebook and must never be published. Your accounting backup must be on a European server, and getting that wrong is a criminal offence. And the Justice Minister can order any government system to run only in Denmark, overnight, with no consultation.

High confidenceGet a parent's consent for childrenCriminal liabilityKeep the data in the countryChildren's data

What's changing next

Three things are already law and biting now: the cyber security regime, the new health digitisation body, and the last stage of the digital bookkeeping rules. One big thing is promised but not yet law: an age limit of 15 for social media, agreed by politicians in November 2025 but with no bill found as of August 2026. And two switches can flip without warning: the list of government systems that must stay in Denmark, and the telephone logging order, which has to be renewed every year.

Medium confidenceIn forceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Bekendtgørelse om hel eller delvis opbevaring her i landet af personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning

Directly binding regulation · Executive order no. 220 of 11 February 2022, amended by order no. 817 of 3 June 2022 and order no. 302 of 15 March 2023

In forceNo — it stays put

A short executive order with a long reach: personal data in a list of named Danish government computer systems must be held inside Denmark, with no copy abroad. The Minister of Justice can add systems to the list at any time by issuing a new order, without consultation, and has already done so once.

In force since 14 February 2022But only enforceable from 1 April 2023

Enforced by Ministry of Justice

Transfer model: Not allowed

High confidence
Telecoms

Bekendtgørelse om generel og udifferentieret registrering af trafikdata fra og med den 30. marts 2026 til og med den 29. marts 2027 og opbevaring til og med den 29. marts 2028

Directly binding regulation · Executive order no. 397 of 20 March 2026, made under sections 786 e and 786 j of the Administration of Justice Act

In forceYes, with paperwork

Denmark reimposes blanket recording of who called whom, from where and when, on every telecoms provider, for a year at a time. It is justified each year by a fresh national security threat assessment, and the current order only covers 30 March 2026 to 29 March 2027, so it has to be renewed annually. No rule was found requiring the logs to be stored in Denmark.

In force since 30 March 2026

Enforced by Ministry of Justice

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven)

Act of parliament · Act no. 434 of 6 May 2025

In forceYes, with paperwork

Denmark's cyber security law started on 1 July 2025 and covers essential and important organisations across most of the economy. It adds a 24-hour early warning duty on top of the 72-hour privacy breach clock. It imposes no data localisation. Enforcement is again criminal rather than administrative.

In force since 1 July 2025But only enforceable from 1 October 2025

Enforced by Danish Agency for Societal Security

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Databeskyttelsesloven

Act of parliament · Act no. 502 of 23 May 2018, consolidated as LBK no. 289 of 8 March 2024

In forceYes, with paperwork

Denmark's national companion to the European rules. Its two Denmark-specific features are that the age of online consent is 15, and that breaking the rules is a criminal offence carrying up to six months in prison, so cases go to the police and the courts rather than ending in an administrative fine. It also has a dedicated rulebook for the Danish personal identity number.

In force since 25 May 2018

Enforced by Danish Data Protection Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Bekendtgørelse om krav til virksomheders digitale bogføringssystemer der ikke er registreret efter bogføringsloven

Directly binding regulation · Executive order no. 205 of 29 February 2024, made under the Bookkeeping Act no. 700 of 24 May 2022

In forceA copy must stay

Every Danish business using a bookkeeping system that is not on the official Danish register must take a full backup at least weekly and keep it with an unrelated third party on a server inside the European Union or European Economic Area. The equivalent duty applies to registered standard systems. Breaking it is a criminal offence.

In force since 1 January 2025But only enforceable from 1 January 2026

Enforced by Danish Business Authority

Transfer model: Allowlist · Accepted routes: Nothing required

High confidence

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Databeskyttelsesforordningen (General Data Protection Regulation)

Directly binding regulation · Regulation (EU) 2016/679, Chapter V

In forceYes, with paperwork

The European Union baseline. Personal data may leave Europe once you have an approved destination, the European standard contract, or approved group-wide rules. Storage location is a risk factor, never a ban. In Denmark the fine tiers exist on paper but the money is collected through the criminal courts, not by the regulator.

In force since 25 May 2018

Enforced by Danish Data Protection Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Who you would hear from

  • Datatilsynet

    General data protection law, all sectors

    Fully staffed and busy. Opened 20,536 new cases in 2025, received 9,849 personal data breach notifications, ran 3,653 supervision and enforcement cases, and opened 525 cases on its own initiative. It cannot impose fines itself: it must report the matter to the police with a recommended amount, and it did so twice in 2025. Its practical instruments are orders, prohibitions and public criticism, most visibly the February 2026 decision against 51 municipalities.

  • Justitsministeriet

    Data protection legislation, the storage-in-Denmark power for public systems, telecoms data retention orders

    Issued the current traffic data retention order in March 2026 and maintains the list of government systems that must stay in Denmark.

  • Erhvervsstyrelsen

    Bookkeeping, digital bookkeeping systems, company records

    Runs the register of approved digital bookkeeping systems and a risk-based control programme.

  • Styrelsen for Samfundssikkerhed

    Cyber security regime coordination and registration; competent authority for several sectors

    Ran the registration process that opened 1 July 2025 and closed 1 October 2025. Sector authorities supervise; the Danish Defence Intelligence Service acts as the national computer security incident response team.

  • Center for Cybersikkerhed, Forsvarets Efterretningstjeneste

    National computer security incident response team; recipient of 24-hour cyber early warnings

    Publishes threat assessments and incident handling guidance; must respond to an early warning within 24 hours.

  • Finanstilsynet

    Banking, payments, insurance, securities; technology and outsourcing supervision

    Operates notification of planned technology outsourcing contracts and the register of technology suppliers under the European digital operational resilience rules.

  • Spillemyndigheden

    Gambling licences, technical requirements, the SAFE data warehouse

  • Digitaliseringsstyrelsen

    Public sector digitalisation, cloud guidance, digital sovereignty programme

    Publishes guidance and case material rather than binding rules. Has 80 million Danish kroner for a digital sovereignty action plan covering 2026 to 2029.

  • Styrelsen for Patientsikkerhed

    Health record keeping and retention

  • Danmarks Statistik

    National register microdata for research; controls the research machines

    Person-level register data is only accessible on its own machines and may not be copied off them.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether any bill implementing the November 2025 political agreement on a social media age limit of 15 has been introduced in the Danish parliament

    The agreement itself is confirmed on the Ministry of Digital Affairs' own site, and further government statements were reported in 2026, but no bill text was located on the parliament's or the legal information portal's own sites as of 18 August 2026. Treated as policy, not law.

  • Whether the Danish Data Protection Agency has ever actually used its power to issue a settlement fine notice under section 42 of the Danish Data Protection Act

    The power exists in the consolidated 2024 text, but the 2025 annual report does not mention any use of it and the agency's fines page still describes fines as going through the courts. No confirmed example found.

  • Whether any Danish rule requires health records or genomic data to be stored inside Denmark

    Retention periods are confirmed from the Danish Patient Safety Authority, but no storage-location rule was located in the health legislation reviewed. The National Genome Centre's database arrangements were not verified in the statute text. No rule found, checked 18 August 2026, confidence medium.

  • Whether the Danish telecoms security and preparedness law imposes location or personnel requirements beyond the cyber security law

    That law is expressly carved out of the scope of the 2025 cyber security law but was not examined in its own right in this pass.

  • The current version and exact wording of the Danish Gambling Authority's technical requirements document

    The regulator's own document links returned 404 errors during this run. The rule content is therefore taken from the June 2025 online betting executive order, which is primary law, and from a European Commission notification recording version 2.5 of 1 January 2025.

  • Whether any Danish national rule survives alongside the European digital operational resilience rules for financial sector outsourcing

    The Danish Financial Supervisory Authority's own pages describe the European regime and its notification duties, but the fate of the 2020 Danish outsourcing executive order was not confirmed from a government source.

  • Whether the storage-in-Denmark annex has been amended again since March 2023

    The March 2023 amending order is confirmed from the official gazette. A search for later amendments returned nothing, but absence of a later order cannot be proven from a search alone.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Denmark versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.