Denmark
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
Denmark follows the European Union rulebook: personal data may leave the country once you have the right legal paperwork in place. There is no general rule that data must stay in Denmark. But there are three real walls. Named Danish state computer systems must run inside Denmark. Every business must keep a backup of its accounting records on a server inside Europe. And Denmark punishes data protection breaches as crimes, not with administrative fines.
Data governance in Denmark
The eight things that decide how you handle data about people in Denmark. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The Danish data protection law reaches a company with no office in Denmark, as long as it offers goods or services to people located in Denmark, or watches what they do here. There is no size or revenue threshold to hide below. A company based entirely outside Europe must appoint a representative inside Europe under the European Union rules, but Denmark does not add a second, Denmark-only representative on top for ordinary businesses.
Section 4 of the Danish Data Protection Act mirrors Article 3 of the General Data Protection Regulation. Subsection 1 covers processing carried out by a controller or processor established in Denmark, wherever the processing physically happens. Subsection 3 extends the Act to controllers and processors not established in the European Union where they process data about people who are in Denmark, in connection with offering goods or services to them, or monitoring their behaviour in Denmark. Two sectors do add a hard local-presence rule. Under the Gambling Act, a licence can only be granted to a company established in Denmark or another European Union or European Economic Area state; a company established elsewhere must appoint a representative approved by the Danish Gambling Authority who is resident or established in Denmark and empowered to represent the licence holder in litigation and criminal proceedings. Under the Danish network and information security law, a cloud, data centre, content delivery, managed service, online marketplace, search engine or social network provider falls under Danish jurisdiction if its main establishment in the European Union is in Denmark.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 4 (territorial scope)
retsinformation.dk
“Loven og regler udstedt i medfør af loven gælder for behandling af personoplysninger om registrerede, der befinder sig i Danmark, som foretages af en dataansvarlig eller databehandler, der ikke er etableret i EU”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalConsolidated Danish Gambling Act, sections 26, 27 and 30 (establishment and approved representative)
retsinformation.dk
Link checked 18 August 2026
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalDanish network and information security law (NIS 2 law), section 2 (Danish jurisdiction)
retsinformation.dk
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Denmark is an ordinary European Union member, so data can go abroad once the standard European paperwork is in place, and there is no Danish rule that personal data must stay in Denmark. But four areas override that. Named Danish state computer systems must run inside Denmark. Accounting backups must sit on a server inside Europe. Detailed population statistics given to researchers can never leave the government's own machines. And schools and town halls have been told their cloud classroom setups did not meet the rules.
Rated sectoral. Sector by sector, verified 18 August 2026. GOVERNMENT AND PUBLIC SECTOR — closed for a named list. An executive order made in February 2022 and re-issued in March 2023 lists eleven system groups that must be operated in Denmark: the defence resource system, Digital Post, the national identity login MitID, the public login gateway NemLog-in3, the state payroll solution, the national police systems portfolio, the common public data distributor, the civil registration system, the public case and document handling system, the credit register, and the emergency call system. The power behind it is open-ended: the Minister of Justice may add any information technology system run for the public administration by executive order. ACCOUNTING, ALL INDUSTRIES — a copy must stay in Europe. A business using a digital bookkeeping system that is not on the Danish Business Authority's register must take a full backup at least weekly and keep it with a party unconnected to the business, on a server in a European Union or European Economic Area country. The equivalent rule applies to registered standard systems. Breaking it is punished by a criminal fine. STATISTICS AND RESEARCH — closed. Detailed person-level data from Denmark's national registers is only made available on Statistics Denmark's own research machines. Copying, exporting, emailing, printing or photographing data from those machines is forbidden outright; only aggregated results may be released, and only after review. EDUCATION AND LOCAL GOVERNMENT — conditional, and currently contested. On 2 February 2026 the Danish Data Protection Agency issued serious criticism to 51 municipalities over the use of Google's classroom products on pupil devices, warning that engaging a processor that uses sub-processors outside the European Economic Area without equivalent protection would likely breach the European rules, and that products with unclear processing arrangements cannot lawfully be used. TELECOMS — no location rule, but a heavy retention duty. From 30 March 2026 to 29 March 2027 all providers must record traffic data about fixed, mobile and internet telephony, text messages, their own email services and internet access, and keep it for one year, so retained until 29 March 2028 at the latest. No requirement was found that the logs be stored in Denmark. GAMBLING — no location rule, contrary to common belief. A licence holder must build a data warehouse called SAFE holding standard records of every game played, and the Danish Gambling Authority must be able to reach it online. Nothing in the current order requires that warehouse to be in Denmark. All betting data must be kept five years and player identity data five years after the customer relationship ends. BANKING, PAYMENTS, INSURANCE AND SECURITIES — conditional, no localisation. The European Union digital operational resilience rules apply since January 2025 and the Danish regulator runs notification of outsourcing contracts and a register of technology suppliers through them. No Danish rule requiring financial data to stay in Denmark was found, checked 18 August 2026. HEALTH — conditional, no localisation found. Patient records must be kept for ten years by doctors and dentists and five years by other health professionals, but no rule requiring them to be held in Denmark was located, checked 18 August 2026. MAPPING AND GEOSPATIAL, DEFENCE — no civil localisation rule found, checked 18 August 2026. Classified defence material is handled under separate security rules that were not examined.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022 on storing in Denmark personal data processed in specified information technology systems run for the public administration
retsinformation.dk
“It-systemer, der er nævnt i bilag 1, skal føres her i landet.”
Link checked 18 August 2026
- Official sourceLovtidende, the official Danish gazetteExecutive order no. 302 of 15 March 2023 amending the storage-in-Denmark order — replacement annex listing eleven system groups
lovtidende.dk
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024 on requirements for company digital bookkeeping systems not registered under the Bookkeeping Act, section 4
retsinformation.dk
“Virksomheden skal opbevare sikkerhedskopien efter stk. 1 hos en ikke nærtstående part ... på en server i et EU- eller EØS-land”
Link checked 18 August 2026
- Official sourceStatistics DenmarkRules for working with microdata on Statistics Denmark's research machines
dst.dk
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency issues serious criticism to 51 municipalities in the Chromebook case, 2 February 2026
datatilsynet.dk
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting — the SAFE data warehouse and five-year retention
retsinformation.dk
Link checked 18 August 2026
Sending data out of the country
Denmark adds nothing of its own. You use the European Union machinery: send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. There is no Danish permit, no Danish filing and no Danish waiting period. The one Danish twist is at the other end: sending data abroad without a proper legal basis is a criminal offence here, not just something you get fined for.
The model is an allowlist with a populated list. Countries approved by the European Commission as of 18 August 2026: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial organisations, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, and the United States but only for organisations that have self-certified under the European Union-United States Data Privacy Framework, plus the European Patent Organisation since 15 July 2025. No approval has been withdrawn or suspended. Where no approval covers the destination, the 2021 standard contractual clauses remain the operative set and are unamended; the promised new clauses for importers already directly caught by the European rules are still not adopted. Binding corporate rules remain available. The narrow exceptions in Article 49 are not usable for routine or bulk transfers, and a transfer risk assessment is still expected. The European Union-United States framework is in force and legally valid today, but is under pressure: an appeal against the General Court's September 2025 dismissal in the Latombe case is pending before the Court of Justice, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent United States developments affect the decision's validity. Never build on it as your only mechanism. Separately, the Danish Act makes breach of the European transfer rules in Articles 44 to 49 a criminal offence punishable by fine or up to six months in prison.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 41 subsection 1 number 6 — criminal liability for unlawful third-country transfers
retsinformation.dk
“straffes med bøde eller fængsel indtil 6 måneder den, der overtræder bestemmelserne om ... overførsel af personoplysninger til en modtager i et tredjeland eller en international organisation i henhold til databeskyttelsesforordningens artikel 44-49.”
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission list of adequacy decisions
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — legislation and executive orders it administers
datatilsynet.dk
Link checked 18 August 2026
The regulator, and whether it actually acts
The Danish Data Protection Agency, and it is fully staffed and busy. It opened 20,536 new cases in 2025 and received 9,849 breach reports. But it cannot fine you. Denmark is almost alone in Europe in treating data protection breaches as crimes, so the agency has to hand the case to the police, who then prosecute in court. In all of 2025 it did that just twice. So expect orders, bans and public criticism rather than large fines.
Enforcement rated active, not aggressive. Evidence from the regulator's own 2025 annual report, published March 2026: 20,536 new cases opened, 9,849 personal data breach notifications received (5,167 from public authorities, 4,630 from private organisations), 3,653 supervision and enforcement cases, 2,867 advice and guidance cases, 525 cases opened on the agency's own initiative, and exactly 2 police reports with a recommended fine filed during the year. The agency's own fines page states plainly that in most European countries the supervisory authority can impose administrative fines itself, whereas in Denmark that must currently go through the courts, with the agency referring the case to the police with a recommended amount. Since a 2023 amendment the agency may also issue a fine notice offering to settle without a court case, but only where the offender admits guilt and pays; the 2025 annual report does not record any use of that route. The practical consequence is that the strongest tools are the non-financial ones: orders, bans on processing, and public criticism. The February 2026 Chromebook decision, covering 51 municipalities at once, is the clearest recent example. Other regulators are separately active: the Danish Business Authority for bookkeeping, the Danish Financial Supervisory Authority for the financial sector's technology resilience rules, the Danish Gambling Authority for licence holders, the Danish Agency for Societal Security for the network and information security regime, and the Danish Defence Intelligence Service acting as the national computer security incident response team.
Sources
- Official sourceDatatilsynetDanish Data Protection Agency annual report 2025
datatilsynet.dk
“Datatilsynet har i 2025 indgivet 2 politianmeldelser med indstilling om bøde for overtrædelse af databeskyttelsesreglerne.”
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — fine cases and how fines are imposed in Denmark
datatilsynet.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, sections 41 and 42 — criminal penalties and the settlement fine notice
retsinformation.dk
Link checked 18 August 2026
How long you must keep it — and when to delete it
Denmark sets several minimum keeping periods. Accounting records: five years after the financial year ends. Patient records: ten years for doctors and dentists, five for other health professionals. Gambling records: five years. Telephone and internet traffic records: one year. In the other direction, the European rules say delete personal data once you no longer need it. Where the two collide, the specific Danish keeping duty wins for as long as it runs, and you delete after it expires.
Floors, all verified 18 August 2026. Accounting material must be kept securely for five years from the end of the financial year it relates to, under the Bookkeeping Act, with a weekly full backup that must sit with an unrelated third party on a server in the European Union or European Economic Area. Patient records: at least ten years from the last entry for doctors, dentists, midwives and certain specialists, at least five years for other authorised health professionals, per the Danish Patient Safety Authority. Gambling licence holders must keep identity and control information about a registered player for at least five years after the customer relationship ends, and all data about the offering of betting in the gambling system for at least five years. Telecommunications providers must keep the traffic data recorded under the March 2026 logging order for one year from the moment of recording, so data recorded on the last covered day is held until 29 March 2028. Criminal liability under the data protection Act itself is time-barred after five years. Ceilings: the European storage limitation principle applies unchanged, and the Danish Act extends the rules to information about deceased people for ten years after death, which is a Danish addition with no European equivalent. Denmark resolves a floor-versus-ceiling conflict the ordinary European way: a legal obligation to retain is an express exception to the right to erasure, so the specific statutory period governs until it runs out.
Sources
- Official sourceDanish Business Authority, via the official Danish legal information portalDanish Bookkeeping Act no. 700 of 24 May 2022, section 12 — five-year retention of accounting material
retsinformation.dk
“Virksomheder skal på betryggende vis opbevare regnskabsmateriale, jf. § 4, i 5 år fra udgangen af det regnskabsår, materialet vedrører.”
Link checked 18 August 2026
- Official sourceStyrelsen for PatientsikkerhedDanish Patient Safety Authority — how long patient records must be kept
stps.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 397 of 20 March 2026 on general and undifferentiated recording of traffic data — one-year retention
retsinformation.dk
“De oplysninger, der er registreret i medfør af stk. 1, skal opbevares i 1 år fra registreringstidspunktet.”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting, sections 4 and 30 — five-year retention
retsinformation.dk
Link checked 18 August 2026
If something goes wrong
Count at least three clocks and they run at different speeds. For a personal data breach you have 72 hours to tell the Danish Data Protection Agency, and you must tell affected people without delay if the risk to them is high. If you are a company covered by the Danish cyber security law, you have only 24 hours to send an early warning, then 72 hours for a fuller report, then one month for the final report. Financial firms report separately under the European resilience rules.
Clock one, personal data: 72 hours from awareness to the Danish Data Protection Agency under Article 33 of the European rules, plus notification to affected individuals without undue delay where the risk to their rights is high. The Agency received 9,849 such notifications in 2025, so this is a heavily used channel and the reporting form is well established. Clock two, cyber security: under the Danish network and information security law in force since 1 July 2025, essential and important entities must send an early warning to the relevant sector authority and to the national computer security incident response team without undue delay and within 24 hours of becoming aware of a significant incident, saying whether it is suspected to be malicious or to have cross-border effects; a fuller incident notification with an initial severity assessment and indicators of compromise follows within 72 hours; an interim report on request; and a final report within one month of the incident notification. The incident response team must respond within 24 hours of the early warning. Affected service recipients must also be told without undue delay. Failure to notify is punishable by a criminal fine, and companies can be held criminally liable. Clock three, finance: the European digital operational resilience rules have applied to financial entities since 17 January 2025 and run their own major incident reporting timetable through the Danish Financial Supervisory Authority. Clock four, telecoms: the separate Danish law on security and preparedness in the telecoms sector sits outside the cyber security law and was not examined in detail here. The overlap is the usual failure point: the 24-hour cyber warning fires long before the 72-hour privacy report is ready.
Sources
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalDanish network and information security law no. 434 of 6 May 2025, sections 12, 13, 15, 32 and 33
retsinformation.dk
“En tidlig varsling ... sendes uden unødigt ophold, og senest inden for 24 timer efter at enheden har fået kendskab til den væsentlige hændelse.”
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — questions and answers on the network and information security law, including who acts as the national incident response team
samsik.dk
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency annual report 2025 — 9,849 personal data breach notifications received
datatilsynet.dk
Link checked 18 August 2026
- Official sourceFinanstilsynetDanish Financial Supervisory Authority — the European digital operational resilience regulation
finanstilsynet.dk
Link checked 18 August 2026
What catches people out
Five things catch people out. A child in Denmark is anyone under 15 for online consent, not 13 and not 16. Breaking the data rules is a crime here, with prison on the books. The Danish personal identity number has its own rulebook and must never be published. Your accounting backup must be on a European server, and getting that wrong is a criminal offence. And the Justice Minister can order any government system to run only in Denmark, overnight, with no consultation.
Trap one, the age. Denmark set the age at which a child can consent to online services at 15, in the middle of the range the European rules allow. Most global age gates are built for 13 or 16, so both settings are wrong for Denmark. Below 15, consent must be given or approved by the holder of parental responsibility. Trap two, criminal not administrative. The Danish Act punishes breaches of the core principles, the individual rights provisions, the controller and processor duties, and the third-country transfer rules with a fine or imprisonment for up to six months. Obstructing the regulator, or failing to comply with its orders, is a separate offence. A court can also disqualify someone from operating a business that stores personal data. This changes how you handle an investigation: it is a criminal matter, so the file is not open to inspection and the ordinary right of access to case documents does not apply. Trap three, the personal identity number. The Danish civil registration number has a dedicated regime. Public authorities may use it for unique identification or as a file number. Private organisations may use it only where a law requires it, where the person has consented, for scientific or statistical purposes, where passing it on is a natural part of normal operations of that kind of business and is decisive for unique identification, or where an authority requires it. It must never be published without consent. Danish systems are full of this number and foreign-built systems routinely treat it as an ordinary customer reference. Trap four, the accounting backup. A business that uses a bookkeeping system not on the Danish register must take a full weekly backup and keep it with a party unrelated to the business, presumed to meet recognised information security standards, on a server in a European Union or European Economic Area country. Breach is punished by fine. This is a genuine European residency requirement hiding inside company law rather than privacy law, and it bites hardest on foreign groups running a single global accounting platform. Trap five, the dormant switch. The Danish Act lets the Minister of Justice, after consulting the relevant minister, decree that personal data processed in specified information technology systems run for the public administration may only be stored in Denmark. There is no consultation requirement, no threshold and no list of qualifying systems in the statute. The power has already been used to capture eleven system groups, and the annex was expanded once in 2023. Any organisation running a system for a Danish public authority should treat this as a live commercial risk.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, sections 3, 6, 11, 41 and 43
retsinformation.dk
“er behandling af personoplysninger om et barn lovlig, hvis barnet er mindst 15 år. Stk. 3. Er barnet under 15 år, er behandling kun lovlig, hvis og i det omfang samtykke gives eller godkendes af indehaveren af forældremyndigheden over barnet.”
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024, sections 4 and 6 — European server backup and criminal fine
retsinformation.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022 — the storage-in-Denmark power in use
retsinformation.dk
Link checked 18 August 2026
What's changing next
Three things are already law and biting now: the cyber security regime, the new health digitisation body, and the last stage of the digital bookkeeping rules. One big thing is promised but not yet law: an age limit of 15 for social media, agreed by politicians in November 2025 but with no bill found as of August 2026. And two switches can flip without warning: the list of government systems that must stay in Denmark, and the telephone logging order, which has to be renewed every year.
Already in force. The Danish network and information security law started on 1 July 2025; registration through the business portal opened the same day and closed on 1 October 2025, with a two-week window for entities that become covered later and a three-month deadline to report changes. Digital Sundhed Danmark, a new self-governing institution for health digitisation, was passed on 29 December 2025 and started on 1 January 2026. The digital bookkeeping duty reached its final phase on 1 January 2026, extending to non-financial businesses with net revenue above 300,000 Danish kroner, roughly 45,000 United States dollars, in two consecutive years. Proposed, no legal effect. On 7 November 2025 the government and a broad group of parties agreed a package on digital protection of children, funded with 160 million Danish kroner, roughly 24 million United States dollars, across fourteen measures. The centrepiece is an age limit of 15 for certain social media, with parental consent possible from 13. As of 18 August 2026 no bill implementing it was located on the parliament's own site. Treat it as policy, not law. Also in motion. The Agency for Digital Government has 80 million Danish kroner, roughly 12 million United States dollars, for a digital sovereignty action plan covering 2026 to 2029, with public-sector parties due to agree next steps in spring 2026. Today this is analysis and guidance, not binding rules; the risk is that it hardens into procurement requirements. Dormant switches, the ones that matter most. First, the Minister of Justice can add any public administration system to the must-stay-in-Denmark list by executive order, with no consultation. Second, the general telephone and internet logging duty rests on an annual national security assessment; the current order runs only from 30 March 2026 to 29 March 2027 and must be re-made each year, so it can lapse or be widened with a single ministerial signature. Third, at European level the digital operational resilience rules give supervisors escalating powers over cloud suppliers, and the European Union Data Act requires all cloud switching and data egress charges to fall to zero by 12 January 2027.
Sources
- Official sourceDanish Ministry of Digital AffairsPolitical agreement on digital child protection, 7 November 2025 — age limit of 15 for social media, parental consent from 13
digmin.dk
Link checked 18 August 2026
- Official sourceMinistry of the Interior and Health, via the official Danish legal information portalAct no. 1758 of 29 December 2025 on Digital Sundhed Danmark, section 36 — in force 1 January 2026
retsinformation.dk
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — registration under the network and information security law
samsik.dk
Link checked 18 August 2026
- Official sourceDigitaliseringsstyrelsenDanish Agency for Digital Government — digital sovereignty work and the 2026 to 2029 action plan
digst.dk
Link checked 18 August 2026
- Official sourceErhvervsstyrelsenDanish Business Authority guidance on the Bookkeeping Act, including the 1 January 2026 phase-in
erhvervsstyrelsen.dk
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Bekendtgørelse om hel eller delvis opbevaring her i landet af personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning
Directly binding regulation · Executive order no. 220 of 11 February 2022, amended by order no. 817 of 3 June 2022 and order no. 302 of 15 March 2023
A short executive order with a long reach: personal data in a list of named Danish government computer systems must be held inside Denmark, with no copy abroad. The Minister of Justice can add systems to the list at any time by issuing a new order, without consultation, and has already done so once.
Enforced by Ministry of Justice
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryEleven named system groups must be operated inside Denmark: the defence resource system, Digital Post, the national identity login MitID, the login gateway NemLog-in3, the state payroll solution, the national police systems portfolio, the common public data distributor, the civil registration system, the public case and document handling system, the credit register, and the emergency call system.
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 220 of 11 February 2022
retsinformation.dk
“It-systemer, der er nævnt i bilag 1, skal føres her i landet.”
Link checked 18 August 2026
- Official sourceLovtidende, the official Danish gazetteExecutive order no. 302 of 15 March 2023 — annex replaced, list extended to eleven system groups, in force 1 April 2023
lovtidende.dk
Link checked 18 August 2026
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, section 3 subsection 9 — the enabling power
retsinformation.dk
“Justitsministeren kan efter forhandling med vedkommende minister fastsætte regler om, at personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning, helt eller delvis alene må opbevares her i landet.”
Link checked 18 August 2026
Bekendtgørelse om generel og udifferentieret registrering af trafikdata fra og med den 30. marts 2026 til og med den 29. marts 2027 og opbevaring til og med den 29. marts 2028
Directly binding regulation · Executive order no. 397 of 20 March 2026, made under sections 786 e and 786 j of the Administration of Justice Act
Denmark reimposes blanket recording of who called whom, from where and when, on every telecoms provider, for a year at a time. It is justified each year by a fresh national security threat assessment, and the current order only covers 30 March 2026 to 29 March 2027, so it has to be renewed annually. No rule was found requiring the logs to be stored in Denmark.
Enforced by Ministry of Justice
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep logs — 1 yearBlanket recording of calling and called numbers with subscriber names and addresses, device identifiers, cell locations at start and end of a call, message receipts, the provider's own email sender and recipient addresses, and internet telephony traffic. Kept one year from recording.
- Keep data for a minimum period — 1 year
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableFailure to record and retain
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalExecutive order no. 397 of 20 March 2026, sections 1 to 7 and annex 1
retsinformation.dk
“Regler om registreringspligt i medfør af retsplejelovens § 786 e kan fastsættes for en periode på højst ét år ad gangen ... og oplysninger registreret i medfør af de fastsatte regler skal opbevares i ét år”
Link checked 18 August 2026
Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven)
Act of parliament · Act no. 434 of 6 May 2025
Denmark's cyber security law started on 1 July 2025 and covers essential and important organisations across most of the economy. It adds a 24-hour early warning duty on top of the 72-hour privacy breach clock. It imposes no data localisation. Enforcement is again criminal rather than administrative.
Enforced by Danish Agency for Societal Security
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Register or notify — from 1 July 2025Registration through the business portal opened 1 July 2025 and closed 1 October 2025. Entities that become covered later have two weeks; changes must be reported within three months.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours, incident notification within 72 hours, interim report on request, final report within one month.
- Secure the data
- Tell affected peopleService recipients must be told without undue delay where the incident is likely to affect the service.
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableFailure to notify, to register, to implement measures, or to comply with an order
- Order to stopOrders and prohibitions from the sector authority
Sources
- Official sourceMinistry for Societal Security and Emergency Management, via the official Danish legal information portalAct no. 434 of 6 May 2025 on measures to secure a high level of cyber security
retsinformation.dk
“§ 33. Loven træder i kraft den 1. juli 2025.”
Link checked 18 August 2026
- Official sourceStyrelsen for SamfundssikkerhedDanish Agency for Societal Security — registration duty and deadlines
samsik.dk
Link checked 18 August 2026
Bekendtgørelse om online væddemål
Directly binding regulation · Executive order no. 684 of 11 June 2025, replacing order no. 1276 of 29 November 2019
Contrary to a widely repeated claim, Denmark does not require a gambling operator's data to be stored in Denmark. What it requires is a data warehouse called SAFE holding a standard record of every game, that the regulator can reach online, sealed against tampering, with five-year retention. The local-presence duty is on the company, not the servers.
Enforced by Danish Gambling Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 5 yearsPlayer identity and control information for five years after the customer relationship ends; all data about the offering of betting in the gambling system for five years.
- Independent auditGambling systems and random number generators must be tested and certified by an approved test house before use.
- Appoint a local representativeA licence holder not established in the European Union or European Economic Area must appoint a representative approved by the regulator who is resident or established in Denmark.
- Register or notify
What it costs if you get it wrong
- Criminal liability: Fine; companies can be held criminally liableBreach of the retention, system or player protection provisions
- Loss of your licenceLoss of the conditions on which the licence was granted
Sources
- Official sourceMinistry of Taxation, via the official Danish legal information portalExecutive order no. 684 of 11 June 2025 on online betting, sections 4, 28 to 33 and annex
retsinformation.dk
“SAFE er tilladelsesindehavers eget datalager (en filserver), hvor tilladelsesindehaver skal opbevare spildata ... Spillemyndigheden skal kunne få online adgang til datalagret hos tilladelsesindehaver.”
Link checked 18 August 2026
- Official sourceMinistry of Taxation, via the official Danish legal information portalConsolidated Danish Gambling Act, LBK no. 1182 of 22 September 2025, sections 26, 27, 30 and 41
retsinformation.dk
Link checked 18 August 2026
- Official sourceSpillemyndighedenDanish Gambling Authority — online casino licence requirements
spillemyndigheden.dk
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Databeskyttelsesloven
Act of parliament · Act no. 502 of 23 May 2018, consolidated as LBK no. 289 of 8 March 2024
Denmark's national companion to the European rules. Its two Denmark-specific features are that the age of online consent is 15, and that breaking the rules is a criminal offence carrying up to six months in prison, so cases go to the police and the courts rather than ending in an administrative fine. It also has a dedicated rulebook for the Danish personal identity number.
Enforced by Danish Data Protection Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 15Denmark set the age of digital consent at 15, not 13 or 16.
- Get consent
- Secure the data
- Delete data after a periodThe Act extends data protection to information about deceased people for ten years after death.
- Appoint a data protection officerEuropean Union rules apply; Denmark adds no separate national appointment duty for ordinary businesses.
What it costs if you get it wrong
- Criminal liability: Fine or imprisonment up to 6 monthsBreach of core principles, individual rights, controller and processor duties, or the third-country transfer rules
- Criminal liability: Fine or imprisonment up to 6 monthsObstructing the regulator or ignoring its orders
Sources
- Official sourceMinistry of Justice, via the official Danish legal information portalConsolidated Danish Data Protection Act, LBK no. 289 of 8 March 2024
retsinformation.dk
“§ 11. Offentlige myndigheder kan behandle oplysninger om personnummer med henblik på en entydig identifikation eller som journalnummer.”
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — how fines work in Denmark
datatilsynet.dk
Link checked 18 August 2026
Bekendtgørelse om krav til virksomheders digitale bogføringssystemer der ikke er registreret efter bogføringsloven
Directly binding regulation · Executive order no. 205 of 29 February 2024, made under the Bookkeeping Act no. 700 of 24 May 2022
Every Danish business using a bookkeeping system that is not on the official Danish register must take a full backup at least weekly and keep it with an unrelated third party on a server inside the European Union or European Economic Area. The equivalent duty applies to registered standard systems. Breaking it is a criminal offence.
Enforced by Danish Business Authority
Transfer model: Allowlist · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryThe weekly full backup must sit with a party unconnected to the business, on a server in a European Union or European Economic Area country. The residency floor is Europe, not Denmark.
- Keep data for a minimum period — 5 yearsFive years from the end of the financial year the material relates to.
- Secure the dataThe backup holder must be presumed to meet recognised information security standards.
What it costs if you get it wrong
- Criminal liability: FineFailure to hold the backup with an unrelated party on a European server
Sources
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 205 of 29 February 2024, sections 4, 6 and 7
retsinformation.dk
“Virksomheden skal opbevare sikkerhedskopien efter stk. 1 hos en ikke nærtstående part, jf. § 2, stk. 4, som må formodes at opfylde anerkendte standarder for it-sikkerhed, på en server i et EU- eller EØS-land”
Link checked 18 August 2026
- Official sourceDanish Business Authority, via the official Danish legal information portalExecutive order no. 97 of 26 January 2023 on requirements for digital standard bookkeeping systems — matching European server rule for registered systems
retsinformation.dk
Link checked 18 August 2026
- Official sourceErhvervsstyrelsenDanish Business Authority guidance on the Bookkeeping Act, including that paper records no longer have to be kept in Denmark or the Nordic countries
erhvervsstyrelsen.dk
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Databeskyttelsesforordningen (General Data Protection Regulation)
Directly binding regulation · Regulation (EU) 2016/679, Chapter V
The European Union baseline. Personal data may leave Europe once you have an approved destination, the European standard contract, or approved group-wide rules. Storage location is a risk factor, never a ban. In Denmark the fine tiers exist on paper but the money is collected through the criminal courts, not by the regulator.
Enforced by Danish Data Protection Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in placeTransfer risk assessment still expected on top of the chosen mechanism.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Keep records of processing
- Assess high-risk projects
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20 million — about $22 millionSame tier, whichever is higher
- Order to stopOrder to stop processing or suspend third-country flows
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions — list verified 18 August 2026
commission.europa.eu
Link checked 18 August 2026
- Official sourceDatatilsynetDanish Data Protection Agency — the rules it applies
datatilsynet.dk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether any bill implementing the November 2025 political agreement on a social media age limit of 15 has been introduced in the Danish parliament
The agreement itself is confirmed on the Ministry of Digital Affairs' own site, and further government statements were reported in 2026, but no bill text was located on the parliament's or the legal information portal's own sites as of 18 August 2026. Treated as policy, not law.
Whether the Danish Data Protection Agency has ever actually used its power to issue a settlement fine notice under section 42 of the Danish Data Protection Act
The power exists in the consolidated 2024 text, but the 2025 annual report does not mention any use of it and the agency's fines page still describes fines as going through the courts. No confirmed example found.
Whether any Danish rule requires health records or genomic data to be stored inside Denmark
Retention periods are confirmed from the Danish Patient Safety Authority, but no storage-location rule was located in the health legislation reviewed. The National Genome Centre's database arrangements were not verified in the statute text. No rule found, checked 18 August 2026, confidence medium.
Whether the Danish telecoms security and preparedness law imposes location or personnel requirements beyond the cyber security law
That law is expressly carved out of the scope of the 2025 cyber security law but was not examined in its own right in this pass.
The current version and exact wording of the Danish Gambling Authority's technical requirements document
The regulator's own document links returned 404 errors during this run. The rule content is therefore taken from the June 2025 online betting executive order, which is primary law, and from a European Commission notification recording version 2.5 of 1 January 2025.
Whether any Danish national rule survives alongside the European digital operational resilience rules for financial sector outsourcing
The Danish Financial Supervisory Authority's own pages describe the European regime and its notification duties, but the fate of the 2020 Danish outsourcing executive order was not confirmed from a government source.
Whether the storage-in-Denmark annex has been amended again since March 2023
The March 2023 amending order is confirmed from the official gazette. A search for later amendments returned nothing, but absence of a later order cannot be proven from a search alone.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Denmark versus
Compare