Danish Data Protection Act (Databeskyttelsesloven)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DK 502/2018: Controller Obligations
Sets national specifics on the data protection officer, including the confidentiality and secrecy obligations of DPOs designated under the GDPR.
- DPO designation and confidentiality undertakings
- No DPO where required, or DPO without the confidentiality obligation
Requires prior consultation with the Datatilsynet before certain high-risk processing carried out for a public authority commences.
- Records of prior consultation with the Datatilsynet where required
- DPIA outputs supporting the consultation
- Commencing high-risk public-authority processing without prior consultation
DK 502/2018: Datatilsynet (Supervisory Authority)
Establishes the Datatilsynet (consisting of a council and a secretariat) as the independent supervisory authority that supervises compliance with the Act and the GDPR.
- Awareness of Datatilsynet jurisdiction and contact points
- Records of interaction with the Datatilsynet
- No designated supervisory-authority contact
The Datatilsynet may require any information of significance for its activities and has powers of access for the purpose of supervision.
- Readiness to provide information and access to the Datatilsynet
- Records produced during supervision
- Failure to cooperate with a Datatilsynet information request or inspection
Provides for the Datatilsynet's role where no adequacy decision exists, supporting the assessment of transfers consistent with CJEU case law (Schrems II) and the GDPR transfer rules.
- Transfer-impact assessments aligned with the Datatilsynet guidance
- Records of supplementary measures for third-country transfers
- Relying on a transfer mechanism without a Schrems II-style assessment
Assigns supervision of the courts' processing of personal data to the Domstolsstyrelsen (Danish Court Administration) in accordance with the GDPR, rather than the Datatilsynet.
- For court bodies: awareness of Domstolsstyrelsen as supervisory authority
- Court processing assuming Datatilsynet supervision instead of Domstolsstyrelsen
DK 502/2018: Lawful Basis and Special Categories
Permits processing of health and genetic data for scientific or statistical purposes subject to safeguards, including restrictions on further use and disclosure.
- Safeguards for research/statistical processing of health/genetic data
- Restrictions on secondary use
- Research processing of health data without the required safeguards
Governs the processing of the Danish civil registration number (CPR-nummer): public authorities may process it for identification or as a journal number, and private bodies only on specified grounds (consent, statutory basis, or for legitimate purposes with adequate safeguards).
- Documented legal basis for any CPR-number processing
- Controls preventing unlawful publication/disclosure of CPR numbers
- Processing or publishing CPR numbers without a valid basis
Permits processing of employee personal data where necessary for compliance with employment-law obligations or for the establishment, exercise or defence of legal claims, subject to the GDPR principles.
- Lawful-basis and necessity records for employee-data processing
- Employee privacy notices
- Processing employee data beyond what employment obligations require
Restricts a business from disclosing consumer personal data to another business for marketing purposes, or using it on behalf of another business, without consent, with exceptions for general customer information subject to objection.
- Consent records for marketing disclosures
- Opt-out / objection handling
- Disclosing consumer data for marketing without consent
Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Purpose-specification records per processing activity
- Repurposing data beyond the original specified purpose
Processing of personal data may take place where at least one of the lawful bases under GDPR Article 6 is met; the Act adds national specifics for certain bases.
- Record of the lawful basis relied on per processing
- Necessity assessment where a public-interest basis is used
- No documented lawful basis
- Public-task basis without an identified legal duty
Sets the conditions for processing special categories of personal data (including health, genetic and biometric data), supplementing GDPR Article 9.
- Identification of special-category processing and the specific Article 9 / national exception relied on
- Heightened safeguards for sensitive data
- Processing special categories without a valid exception
Restricts the processing of data on criminal offences by public authorities to cases of necessity for the performance of their tasks, with conditions on disclosure.
- Necessity and legal-basis records for any criminal-offence-data processing
- Disclosure controls
- Processing criminal-offence data without the required necessity basis
DK 502/2018: Remedies and Penalties
Provides that a data subject may complain to the Datatilsynet and that any person who has suffered material or non-material damage from unlawful processing is entitled to compensation.
- Complaint-handling readiness and records
- Liability/insurance consideration for compensation claims
- No process to respond to a Datatilsynet complaint
Provides for penalties for breaches of the Act and the GDPR, including fines and, in the most serious cases, imprisonment of up to six months, in addition to the GDPR administrative-fine regime.
- Risk assessment of penalty exposure including criminal liability
- Compliance evidence available for an enforcement proceeding
- Underestimating exposure (criminal penalties apply in serious cases)
Sets the commencement (25 May 2018), transitional provisions for processing authorised before entry into force, and the territorial scope (the Act does not apply to the Faroe Islands and Greenland).
- Awareness of territorial limits (not Faroe Islands/Greenland) where relevant
- Assuming the Act applies in the Faroe Islands or Greenland
DK 502/2018: Scope and Supplementation
The Act supplements and implements the GDPR in Danish law, laying down provisions that apply alongside the directly applicable Regulation.
- Determination that processing is governed by the GDPR as supplemented by the Danish Act
- Mapping of the national provisions relevant to the entity
- Treating the GDPR alone without the Danish supplementary rules
Defines the scope of the Act, its relationship to other legislation, and special cases including the processing of personal data of deceased persons (covered for 10 years after death).
- Scoping analysis including any processing of deceased persons' data within the 10-year window
- Ignoring the 10-year rule for deceased persons' data
Sets the age at which a child can validly consent to processing in relation to information society services at 13 years; below that, consent must be given or authorised by the holder of parental responsibility.
- Age-verification and parental-consent mechanism using the 13-year threshold
- Applying the GDPR default of 16 instead of the Danish 13
DK 502/2018: Transfers and Credit Information
Supplements the GDPR rules on transfers of personal data to third countries and international organisations, including national specifics following the GDPR transfer regime.
- Transfer mechanism records (adequacy, SCCs, derogations)
- Transfer impact assessments where required
- Transfers without a valid GDPR transfer mechanism
Sets specific rules for businesses that process data for the assessment of financial standing and creditworthiness, including permission requirements, data-quality limits, and restrictions on the information that may be processed and disclosed.
- Permission/registration for credit-information activity where applicable
- Controls on the categories of credit data processed and disclosed
- Operating credit-information processing outside the permitted categories
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Danish Data Protection Act (Databeskyttelsesloven) framework page.