Danish Data Protection Act (Databeskyttelsesloven)
Denmark's Data Protection Act (Databeskyttelsesloven) implements the EU GDPR and adds national provisions. It is enforced by the Danish Data Protection Agency (Datatilsynet). The Act contains specific rules for processing sensitive data, including health and biometric data, and governs the use of the national civil registration number (CPR). The 2022 amendment incorporated EU Court of Justice rulings (e.g., Schrems II) and clarified data protection impact assessments and cross‑border data transfer requirements.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Applicability
| Code | Title |
|---|---|
| DK-1 | Scope and Supplementation of GDPR |
Balancing
| Code | Title |
|---|---|
| DK-16 | Freedom of Expression and Journalism |
Children
| Code | Title |
|---|---|
| DK-8 | Information Society Services for Children |
Documentation
| Code | Title |
|---|---|
| DK-11 | Records of Processing Activities |
Employment
| Code | Title |
|---|---|
| DK-7 | Employment Context Processing |
Enforcement
| Code | Title |
|---|---|
| DK-18 | Administrative Fines and Sanctions |
Governance
| Code | Title |
|---|---|
| DK-10 | Data Protection Officer |
Incident Management
| Code | Title |
|---|---|
| DK-12 | Personal Data Breach Notification |
Lawful Basis
| Code | Title |
|---|---|
| DK-20 | Consent Quality |
| DK-3 | Age of Consent for Information Society Services |
Marketing
| Code | Title |
|---|---|
| DK-9 | Direct Marketing |
National Identifiers
| Code | Title |
|---|---|
| DK-4 | Processing of National Identification Numbers (CPR) |
Part 1 - General Provisions
| Code | Title |
|---|---|
| Reg 1 | Citation and Commencement |
| Reg 2 | Interpretation and Definitions |
| Reg 3 | Application |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Part 2 - Processing Rules Supplementing the GDPR
| Code | Title |
|---|---|
| Sec. 10 | Powers of the Commission |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 7 | Responsibilities of Organisation |
| Sec. 8 | Functions of the Commission |
Part 3 - Obligations of Controller and Processor
| Code | Title |
|---|---|
| Sec. 11 | Deemed Consent |
| Sec. 12 | Independence |
| Sec. 13 | Appointment of Commissioner |
| Sec. 14 | Collection Without Consent |
Part 4 - Rights of the Data Subject
| Code | Title |
|---|---|
| Sec. 15 | Duty to Register |
| Sec. 16 | Registration Application |
| Sec. 17 | Certificate of Registration |
| Sec. 22 | Accuracy |
Part 5 - Supervisory Authority
| Code | Title |
|---|---|
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
Part 6 - Sanctions and Penalties
| Code | Title |
|---|---|
| Sec. 41 | Administrative Fines |
| Sec. 42 | Automated Decision-Making |
| Sec. 43 | Liability for Damages |
| Sec. 44 | Intelligence Services Processing |
Public Sector
| Code | Title |
|---|---|
| DK-17 | Public Sector Processing |
Retention
| Code | Title |
|---|---|
| DK-19 | Records Retention and Deletion |
Risk Management
| Code | Title |
|---|---|
| DK-13 | Data Protection Impact Assessment |
Special Categories
| Code | Title |
|---|---|
| DK-5 | Sensitive Data and Special Categories |
| DK-6 | Criminal Conviction Data |
Special Purposes
| Code | Title |
|---|---|
| DK-15 | Research and Statistics Exemption |
Supervisory Authority
| Code | Title |
|---|---|
| DK-2 | Datatilsynet Oversight |
Transfers
| Code | Title |
|---|---|
| DK-14 | International Transfers |
Your Compliance Coverage
If you comply with Danish Data Protection Act (Databeskyttelsesloven), you already cover:
Brunei Personal Data Protection Order 2022 (PDPO)
22%
10 controls mapped
Compare →Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
22%
10 controls mapped
Compare →Tanzania Personal Data Protection Act (Draft)
22%
10 controls mapped
Compare →+ 549 more: Kenya Data Protection Act 2019 (22%), Trinidad and Tobago Data Protection Act 2011 (22%)
See all 552 mapped frameworks ↓Maps to 552 other frameworks
Frequently Asked Questions
What is Danish Data Protection Act (Databeskyttelsesloven)?
Danish Data Protection Act (Databeskyttelsesloven) is a compliance framework from Denmark with 24 domains and 46 controls. Denmark's Data Protection Act (Databeskyttelsesloven) implements the EU GDPR and adds national provisions. It is enforced by the Danish Data Protection Agency (Datatilsynet). The Act contains specific rules for processing sensitive data, including health and biometric data, and governs the use of the national civil registration number (CPR). The 2022 amendment incorporated EU Court of Justice rulings (e.g., Schrems II) and clarified data protection impact assessments and cross‑border data transfer requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Danish Data Protection Act (Databeskyttelsesloven) have?
Danish Data Protection Act (Databeskyttelsesloven) has 46 controls organised across 24 domains. The largest domains are Part 1 - General Provisions (6 controls), Part 2 - Processing Rules Supplementing the GDPR (5 controls), Part 3 - Obligations of Controller and Processor (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Danish Data Protection Act (Databeskyttelsesloven) map to?
Danish Data Protection Act (Databeskyttelsesloven) maps to 552 other compliance frameworks. The top mapping partners are Brunei Personal Data Protection Order 2022 (PDPO) (22% coverage), Singapore Payment Services Act (PSA) - Digital Payment Token Regulation (22% coverage), Tanzania Personal Data Protection Act (Draft) (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Danish Data Protection Act (Databeskyttelsesloven) compliance?
Start your Danish Data Protection Act (Databeskyttelsesloven) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Danish Data Protection Act (Databeskyttelsesloven) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 46 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required