Skip to content

Evidence request lists

Danish Data Protection Act (Databeskyttelsesloven)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DK 502/2018: Controller Obligations

DK-502-§24
Data protection officer (databeskyttelsesrådgiver)

Sets national specifics on the data protection officer, including the confidentiality and secrecy obligations of DPOs designated under the GDPR.

Artefacts an auditor will ask for
  • DPO designation and confidentiality undertakings
Where this commonly fails
  • No DPO where required, or DPO without the confidentiality obligation
DK-502-§26
Prior consultation with Datatilsynet

Requires prior consultation with the Datatilsynet before certain high-risk processing carried out for a public authority commences.

Artefacts an auditor will ask for
  • Records of prior consultation with the Datatilsynet where required
  • DPIA outputs supporting the consultation
Where this commonly fails
  • Commencing high-risk public-authority processing without prior consultation

DK 502/2018: Datatilsynet (Supervisory Authority)

DK-502-§27
Datatilsynet establishment and supervision

Establishes the Datatilsynet (consisting of a council and a secretariat) as the independent supervisory authority that supervises compliance with the Act and the GDPR.

Artefacts an auditor will ask for
  • Awareness of Datatilsynet jurisdiction and contact points
  • Records of interaction with the Datatilsynet
Where this commonly fails
  • No designated supervisory-authority contact
DK-502-§29
Datatilsynet information and inspection powers

The Datatilsynet may require any information of significance for its activities and has powers of access for the purpose of supervision.

Artefacts an auditor will ask for
  • Readiness to provide information and access to the Datatilsynet
  • Records produced during supervision
Where this commonly fails
  • Failure to cooperate with a Datatilsynet information request or inspection
DK-502-§31
Third-country transfer determinations (post Schrems II)

Provides for the Datatilsynet's role where no adequacy decision exists, supporting the assessment of transfers consistent with CJEU case law (Schrems II) and the GDPR transfer rules.

Artefacts an auditor will ask for
  • Transfer-impact assessments aligned with the Datatilsynet guidance
  • Records of supplementary measures for third-country transfers
Where this commonly fails
  • Relying on a transfer mechanism without a Schrems II-style assessment
DK-502-§37-38
Supervision of the courts (Domstolsstyrelsen)

Assigns supervision of the courts' processing of personal data to the Domstolsstyrelsen (Danish Court Administration) in accordance with the GDPR, rather than the Datatilsynet.

Artefacts an auditor will ask for
  • For court bodies: awareness of Domstolsstyrelsen as supervisory authority
Where this commonly fails
  • Court processing assuming Datatilsynet supervision instead of Domstolsstyrelsen

DK 502/2018: Lawful Basis and Special Categories

DK-502-§10
Health and genetic data for research and statistics

Permits processing of health and genetic data for scientific or statistical purposes subject to safeguards, including restrictions on further use and disclosure.

Artefacts an auditor will ask for
  • Safeguards for research/statistical processing of health/genetic data
  • Restrictions on secondary use
Where this commonly fails
  • Research processing of health data without the required safeguards
DK-502-§11
Processing of national identification numbers (CPR)

Governs the processing of the Danish civil registration number (CPR-nummer): public authorities may process it for identification or as a journal number, and private bodies only on specified grounds (consent, statutory basis, or for legitimate purposes with adequate safeguards).

Artefacts an auditor will ask for
  • Documented legal basis for any CPR-number processing
  • Controls preventing unlawful publication/disclosure of CPR numbers
Where this commonly fails
  • Processing or publishing CPR numbers without a valid basis
DK-502-§12
Processing in the employment context

Permits processing of employee personal data where necessary for compliance with employment-law obligations or for the establishment, exercise or defence of legal claims, subject to the GDPR principles.

Artefacts an auditor will ask for
  • Lawful-basis and necessity records for employee-data processing
  • Employee privacy notices
Where this commonly fails
  • Processing employee data beyond what employment obligations require
DK-502-§13
Disclosure of consumer data and direct marketing

Restricts a business from disclosing consumer personal data to another business for marketing purposes, or using it on behalf of another business, without consent, with exceptions for general customer information subject to objection.

Artefacts an auditor will ask for
  • Consent records for marketing disclosures
  • Opt-out / objection handling
Where this commonly fails
  • Disclosing consumer data for marketing without consent
DK-502-§5
Purpose limitation

Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

Artefacts an auditor will ask for
  • Purpose-specification records per processing activity
Where this commonly fails
  • Repurposing data beyond the original specified purpose
DK-502-§6
Lawful basis for processing

Processing of personal data may take place where at least one of the lawful bases under GDPR Article 6 is met; the Act adds national specifics for certain bases.

Artefacts an auditor will ask for
  • Record of the lawful basis relied on per processing
  • Necessity assessment where a public-interest basis is used
Where this commonly fails
  • No documented lawful basis
  • Public-task basis without an identified legal duty
DK-502-§7
Sensitive and special categories of data

Sets the conditions for processing special categories of personal data (including health, genetic and biometric data), supplementing GDPR Article 9.

Artefacts an auditor will ask for
  • Identification of special-category processing and the specific Article 9 / national exception relied on
  • Heightened safeguards for sensitive data
Where this commonly fails
  • Processing special categories without a valid exception
DK-502-§8
Public-sector processing of criminal-offence data

Restricts the processing of data on criminal offences by public authorities to cases of necessity for the performance of their tasks, with conditions on disclosure.

Artefacts an auditor will ask for
  • Necessity and legal-basis records for any criminal-offence-data processing
  • Disclosure controls
Where this commonly fails
  • Processing criminal-offence data without the required necessity basis

DK 502/2018: Remedies and Penalties

DK-502-§39-40
Complaints and right to compensation

Provides that a data subject may complain to the Datatilsynet and that any person who has suffered material or non-material damage from unlawful processing is entitled to compensation.

Artefacts an auditor will ask for
  • Complaint-handling readiness and records
  • Liability/insurance consideration for compensation claims
Where this commonly fails
  • No process to respond to a Datatilsynet complaint
DK-502-§41
Penalties (fines and imprisonment)

Provides for penalties for breaches of the Act and the GDPR, including fines and, in the most serious cases, imprisonment of up to six months, in addition to the GDPR administrative-fine regime.

Artefacts an auditor will ask for
  • Risk assessment of penalty exposure including criminal liability
  • Compliance evidence available for an enforcement proceeding
Where this commonly fails
  • Underestimating exposure (criminal penalties apply in serious cases)
DK-502-§46-48
Commencement, transitional and territorial scope

Sets the commencement (25 May 2018), transitional provisions for processing authorised before entry into force, and the territorial scope (the Act does not apply to the Faroe Islands and Greenland).

Artefacts an auditor will ask for
  • Awareness of territorial limits (not Faroe Islands/Greenland) where relevant
Where this commonly fails
  • Assuming the Act applies in the Faroe Islands or Greenland

DK 502/2018: Scope and Supplementation

DK-502-§1
Supplementation and implementation of the GDPR

The Act supplements and implements the GDPR in Danish law, laying down provisions that apply alongside the directly applicable Regulation.

Artefacts an auditor will ask for
  • Determination that processing is governed by the GDPR as supplemented by the Danish Act
  • Mapping of the national provisions relevant to the entity
Where this commonly fails
  • Treating the GDPR alone without the Danish supplementary rules
DK-502-§2-4
Scope, relationship to other law, and deceased persons

Defines the scope of the Act, its relationship to other legislation, and special cases including the processing of personal data of deceased persons (covered for 10 years after death).

Artefacts an auditor will ask for
  • Scoping analysis including any processing of deceased persons' data within the 10-year window
Where this commonly fails
  • Ignoring the 10-year rule for deceased persons' data
DK-502-§3-AGE
Age of consent for information society services (13)

Sets the age at which a child can validly consent to processing in relation to information society services at 13 years; below that, consent must be given or authorised by the holder of parental responsibility.

Artefacts an auditor will ask for
  • Age-verification and parental-consent mechanism using the 13-year threshold
Where this commonly fails
  • Applying the GDPR default of 16 instead of the Danish 13

DK 502/2018: Transfers and Credit Information

DK-502-§14
Transfers of personal data to third countries

Supplements the GDPR rules on transfers of personal data to third countries and international organisations, including national specifics following the GDPR transfer regime.

Artefacts an auditor will ask for
  • Transfer mechanism records (adequacy, SCCs, derogations)
  • Transfer impact assessments where required
Where this commonly fails
  • Transfers without a valid GDPR transfer mechanism
DK-502-§19-21
Credit information agencies (kreditoplysningsbureauer)

Sets specific rules for businesses that process data for the assessment of financial standing and creditworthiness, including permission requirements, data-quality limits, and restrictions on the information that may be processed and disclosed.

Artefacts an auditor will ask for
  • Permission/registration for credit-information activity where applicable
  • Controls on the categories of credit data processed and disclosed
Where this commonly fails
  • Operating credit-information processing outside the permitted categories
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Danish Data Protection Act (Databeskyttelsesloven) framework page.