Skip to the content
Global Data RulesData governance rules, country by country

Denmark

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Denmark — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Denmark follows the European Union rulebook. Personal data can leave the country once you have the right legal paperwork. There is no general rule that data must stay in Denmark. But there are three real limits. Named Danish state computer systems must run inside Denmark. Every business must keep a backup of its accounting records on a server inside Europe. And Denmark treats data protection breaches as crimes, not as something you just get fined for.

Data governance in Denmark

The eight things that decide how you handle data about people in Denmark. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Danish data protection law reaches you even with no office in Denmark. It applies if you offer goods or services to people in Denmark. It also applies if you watch what they do here. There is no size or revenue threshold to stay under. If your company is based entirely outside Europe, you must appoint a representative inside Europe. That comes from European Union rules. Denmark does not add a second Denmark-only representative for ordinary businesses.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes. Denmark is an ordinary European Union member. Data can go abroad once the standard European paperwork is in place. No Danish rule says personal data must stay in Denmark. But four areas override that. Named Danish state computer systems must run inside Denmark. Accounting backups must sit on a server inside Europe. Detailed population statistics given to researchers can never leave the government's own machines. And schools and town halls have been told their cloud classroom setups did not meet the rules.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Denmark adds nothing of its own. You use the European Union machinery. Send data to a country the European Commission has approved. Or sign the European standard contract. Or use approved group-wide rules. There is no Danish permit, no Danish filing and no waiting period. The Danish twist comes at the other end. Sending data abroad without a proper legal basis is a crime here, not just something you get fined for.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
What it costs if you get it wrong:
Criminal liability

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Danish Data Protection Agency, and it is fully staffed and busy. It opened 20,536 new cases in 2025. It received 9,849 breach reports. But it cannot fine you. Denmark is almost alone in Europe in treating data protection breaches as crimes. So the agency has to hand the case to the police. The police then prosecute in court. In all of 2025 it did that just twice. Expect orders, bans and public criticism rather than large fines.

What it costs if you get it wrong:
Criminal liability · Order to stop

How long you must keep it — and when to delete it

Denmark sets several minimum keeping periods. Accounting records: five years after the financial year ends. Patient records: ten years for doctors and dentists, five for other health professionals. Gambling records: five years. Telephone and internet traffic records: one year. The European rules push the other way. Delete personal data once you no longer need it. Where the two clash, the specific Danish keeping duty wins for as long as it runs. You delete after it expires.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least three clocks, and they run at different speeds. For a personal data breach you have 72 hours to tell the Danish Data Protection Agency. You must tell affected people without delay if the risk to them is high. If the Danish cyber security law covers your company, you have only 24 hours to send an early warning. Then 72 hours for a fuller report. Then one month for the final report. Financial firms report separately under the European resilience rules.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, a child in Denmark is anyone under 15 for online consent. Not 13 and not 16. Second, breaking the data rules is a crime here, with prison on the books. Third, the Danish personal identity number has its own rulebook and must never be published. Fourth, your accounting backup must be on a European server, and getting that wrong is a crime. Fifth, the Justice Minister can order any government system to run only in Denmark, overnight, with no consultation.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Three things are already law and already in force. Those are the cyber security rules, the new health digitisation body, and the last stage of the digital bookkeeping rules. One big thing is promised but not yet law. Politicians agreed an age limit of 15 for social media in November 2025. We found no bill as of August 2026. Two more things can change without warning. One is the list of government systems that must stay in Denmark. The other is the telephone logging order, which has to be renewed every year.

What to do: Diarise 29 March 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Bekendtgørelse om hel eller delvis opbevaring her i landet af personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning · Executive order no. 220 of 11 February 2022, amended by order no. 817 of 3 June 2022 and order no. 302 of 15 March 2023 · Directly binding regulation

In forceNo — it stays put

A short government order with a long reach. Personal data in a list of named Danish government computer systems must be held inside Denmark, with no copy abroad. The Minister of Justice can add systems to the list at any time by issuing a new order. There is no consultation, and it has already been done once.

In force since 14 February 2022Enforced from 1 April 2023

Enforced by Ministry of Justice

How this country controls where data goes: Not allowed

Telecoms

Telecoms rules

Official name: Bekendtgørelse om generel og udifferentieret registrering af trafikdata fra og med den 30. marts 2026 til og med den 29. marts 2027 og opbevaring til og med den 29. marts 2028 · Executive order no. 397 of 20 March 2026, made under sections 786 e and 786 j of the Administration of Justice Act · Directly binding regulation

In forceYes, with paperwork

Denmark makes every telecoms provider record who called whom, from where and when. It covers everyone, for a year at a time. A fresh national security threat assessment justifies it each year. The current order only covers 30 March 2026 to 29 March 2027, so it must be renewed annually. We found no rule requiring the logs to be stored in Denmark.

In force since 30 March 2026

Enforced by Ministry of Justice

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Cyber security rules

Official name: Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven) · Act no. 434 of 6 May 2025 · Act of parliament

In forceYes, with paperwork

Denmark's cyber security law started on 1 July 2025. It covers essential and important organisations across most of the economy. It adds a 24-hour early warning duty on top of the 72-hour privacy breach clock. It does not require data to stay in the country. Enforcement is again criminal rather than a fine from a regulator.

In force since 1 July 2025Enforced from 1 October 2025

Enforced by Danish Agency for Societal Security

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Data rules

Official name: Databeskyttelsesloven · Act no. 502 of 23 May 2018, consolidated as LBK no. 289 of 8 March 2024 · Act of parliament

In forceYes, with paperwork

Denmark's national companion to the European rules. Two things are specific to Denmark. The age of online consent is 15. And breaking the rules is a crime carrying up to six months in prison. So cases go to the police and the courts rather than ending in a fine from the regulator. Danish law also has its own rulebook for the Danish personal identity number.

In force since 25 May 2018

Enforced by Danish Data Protection Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data needs a copy kept in the country

Official name: Bekendtgørelse om krav til virksomheders digitale bogføringssystemer der ikke er registreret efter bogføringsloven · Executive order no. 205 of 29 February 2024, made under the Bookkeeping Act no. 700 of 24 May 2022 · Directly binding regulation

In forceA copy must stay

Does your business use a bookkeeping system that is not on the official Danish register? Then you must take a full backup at least weekly. You must keep it with an unrelated third party, on a server inside the European Union or European Economic Area. The same duty applies to registered standard systems. Breaking it is a crime.

In force since 1 January 2025Enforced from 1 January 2026

Enforced by Danish Business Authority

How this country controls where data goes: Only approved countries · Accepted routes: Nothing required

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Databeskyttelsesforordningen (General Data Protection Regulation) · Regulation (EU) 2016/679, Chapter V · Directly binding regulation

In forceYes, with paperwork

The European Union baseline. Personal data can leave Europe once you have an approved destination, the European standard contract, or approved group-wide rules. Where you store data is a risk factor, never a ban. Denmark has the European fine levels on paper. But the money is collected through the criminal courts, not by the regulator.

In force since 25 May 2018

Enforced by Danish Data Protection Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Who you would hear from

  • Datatilsynet

    General data protection law, all sectors

    Fully staffed and busy. In 2025 it opened 20,536 new cases and received 9,849 personal data breach reports. It ran 3,653 supervision and enforcement cases and opened 525 cases on its own initiative. It cannot fine you itself. It must report the matter to the police with a recommended amount, and it did that twice in 2025. Its practical tools are orders, bans and public criticism. The clearest example is the February 2026 decision against 51 municipalities.

  • Justitsministeriet

    Data protection legislation, the storage-in-Denmark power for public systems, telecoms data retention orders

    Issued the current traffic data retention order in March 2026 and maintains the list of government systems that must stay in Denmark.

  • Erhvervsstyrelsen

    Bookkeeping, digital bookkeeping systems, company records

    Runs the register of approved digital bookkeeping systems and a risk-based control programme.

  • Styrelsen for Samfundssikkerhed

    Cyber security regime coordination and registration; competent authority for several sectors

    Ran the registration process that opened 1 July 2025 and closed 1 October 2025. Sector authorities supervise. The Danish Defence Intelligence Service acts as the national computer security incident response team.

  • Center for Cybersikkerhed, Forsvarets Efterretningstjeneste

    National computer security incident response team; recipient of 24-hour cyber early warnings

    Publishes threat assessments and incident handling guidance. It must respond to an early warning within 24 hours.

  • Finanstilsynet

    Banking, payments, insurance, securities; technology and outsourcing supervision

    Operates notification of planned technology outsourcing contracts and the register of technology suppliers under the European digital operational resilience rules.

  • Spillemyndigheden

    Gambling licences, technical requirements, the SAFE data warehouse

  • Digitaliseringsstyrelsen

    Public sector digitalisation, cloud guidance, digital sovereignty programme

    Publishes guidance and case material rather than binding rules. Has 80 million Danish kroner for a digital sovereignty action plan covering 2026 to 2029.

  • Styrelsen for Patientsikkerhed

    Health record keeping and retention

  • Danmarks Statistik

    National register microdata for research; controls the research machines

    You can only reach person-level register data on its own machines. You cannot copy it off them.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether any bill implementing the November 2025 political agreement on a social media age limit of 15 has been introduced in the Danish parliament

    The Ministry of Digital Affairs confirms the political agreement on its own site. We could not find a bill on the parliament's site or the legal information portal as of 18 August 2026. Treat this as policy, not law, and check parliament's site before you plan around it.

  • Whether the Danish Data Protection Agency has ever actually used its power to issue a settlement fine notice under section 42 of the Danish Data Protection Act

    The power to offer a settlement fine exists in the consolidated 2024 Danish text. We found no confirmed example of the agency using it. The 2025 annual report does not mention it, and the agency's fines page still says fines go through the courts.

  • Whether any Danish rule requires health records or genomic data to be stored inside Denmark

    We confirmed the keeping periods with the Danish Patient Safety Authority. We found no rule saying health records must stay in Denmark in the health laws we reviewed. We did not check the National Genome Centre's database arrangements in the law itself. If you handle Danish health or genomic data, check before you rely on this.

  • Whether the Danish telecoms security and preparedness law imposes location or personnel requirements beyond the cyber security law

    The Danish telecoms security and preparedness law is expressly left out of the 2025 cyber security law. We did not review it on its own. If you are a telecoms provider, check it for rules about where data and staff must sit.

  • The current version and exact wording of the Danish Gambling Authority's technical requirements document

    We could not open the regulator's own copy of the technical requirements document. So the rule content here comes from two places. The June 2025 online betting order, which is primary law. And a European Commission notification recording version 2.5 of 1 January 2025. Check the regulator's current document before you build to it.

  • Whether any Danish national rule survives alongside the European digital operational resilience rules for financial sector outsourcing

    The Danish Financial Supervisory Authority's own pages describe the European rules and their notification duties. We could not confirm from a government source what happened to the 2020 Danish outsourcing order. Check with the authority if you outsource financial technology.

  • Whether the storage-in-Denmark annex has been amended again since March 2023

    We confirmed the March 2023 amending order from the official gazette. We searched for later amendments and found none. A search alone cannot prove that no later order exists. Check the gazette if you run a system for a Danish public authority.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.