Law / Denmark

GDPR Articles 82-83 and Datatilsynet Enforcement in Denmark

Regulation (EU) 2016/679, Arts. 82-83

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect Datatilsynet to hold General Data Protection Regulation (GDPR) Article 58 corrective powers directly over your processing of personal data of a person in Denmark, but to route any fine it recommends through the Danish police and courts rather than imposing it directly.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Databeskyttelsesloven Section 41 punishes, with a fine or imprisonment of up to 6 months, violations of the GDPR's core obligations (controller and processor duties under Articles 8, 11, 25 to 39, 42 or 43; the basic processing principles and consent conditions under Articles 5 to 7 and 9; data-subject rights under Articles 12 to 22; and international transfer rules under Articles 44 to 49) and of a parallel list of Danish Act provisions and supervisory-authority orders (Section 41(2)). This is Denmark's mechanism for enforcing conduct that GDPR Article 83 elsewhere treats as an administrative fine: the same conduct can draw both a fine and up to 6 months' imprisonment, imposed through the ordinary criminal courts or a police fine notice (boedeforelaeg) under Section 42, rather than through a Datatilsynet administrative decision. Corporate criminal liability runs through Criminal Code chapter 5 (Section 41(6)); notwithstanding Criminal Code Section 27(2), which otherwise exempts public authorities from corporate criminal liability, a Danish public authority or institution covered by the Public Administration Act Section 1(1) or (2) can be punished under Section 41 for a violation committed in an activity that does not correspond to, or is not comparable with, activity carried out by a private party, meaning ordinary public-sector administrative activity is effectively shielded while business-like public activity is not.

Penalty structure

GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher; Article 83(4) sets the narrower EUR 10,000,000 or 2 percent tier for the Article 25 to 39 obligations. Denmark implements this fine through its own criminal law rather than a separate administrative-fine track: Databeskyttelsesloven Section 41(3) requires GDPR Article 83(2)'s proportionality factors to be followed when imposing punishment under Section 41, and Section 41 itself sets the punishment as a fine or imprisonment of up to 6 months (see criminal_exposure_note), with Datatilsynet referring cases to the police and public prosecutor rather than issuing an administrative fine decision itself. The Danish statute does not restate a separate Danish-law fine ceiling; the operative monetary ceiling remains the GDPR's own EUR 20,000,000 / 4 percent figure via the Article 83(2) cross-reference.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Datatilsynet (the Danish Data Protection Agency), Denmark's supervisory authority under the GDPR. Unlike most EU supervisory authorities, Datatilsynet does not itself issue administrative fine decisions: it investigates and, where it finds a Section 41 violation warranting a fine or possible imprisonment, refers the matter to the police and public prosecutor, who bring it as a criminal case through the ordinary courts or resolve it by a police fine notice (boedeforelaeg) under Databeskyttelsesloven Section 42 if the offender accepts guilt and the stated fine.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Datatilsynet holds the General Data Protection Regulation (GDPR) Article 58 corrective toolkit directly, warnings, reprimands, compliance orders and processing bans, but GDPR Recital 151 records that Denmark's legal system does not allow the supervisory authority itself to impose an administrative fine. In practice, Datatilsynet reports a violation it considers fine-worthy to the Danish police with a recommended amount, and the fine is set and imposed by the Danish courts as a criminal penalty rather than by Datatilsynet directly.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • processes_biometrics
  • processes_voice

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
GDPR Recital 151

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app