Law / Denmark

Denmark

European Union law applies in Denmark Denmark is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Denmark, described on this page below, applies here too.

14 of 15 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 15 September 2026.

When they take effect11 of 14 carry a date, 3 do not.
2018: 6 instruments (6 in force) ’18 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 3 instruments (3 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (166 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Denmark and is not restated here as Danish law.

Denmark's own addition is Lov nr. 467 af 14. maj 2025, in effect since 2 August 2025, which designates Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen as national competent authorities under the Regulation, splits market-surveillance responsibility for the Article 5 prohibited practices between them, gives those authorities information, inspection and order powers, and makes an intentional or grossly negligent violation of Article 5 punishable by a court-set fine with no statutory ceiling stated in the Danish text.

A further bill, 2025/1 LSF 111 ('AI-loven'), introduced 18 February 2026, would extend Danish supervisory arrangements to the Regulation's remaining obligations; its current legislative status is not confirmed in the primary text.

A separate bill would add a personality right against unauthorized, realistic AI-generated likenesses of a person's face, voice and body as a new Ophavsretsloven section 73a, following a June 2025 political agreement; its current legislative status is likewise not confirmed here.

AI prohibited practices

Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement

Lov nr. 467 af 14. maj 2025 om supplerende bestemmelser til forordningen om kunstig intelligens (AI-loven) Folketingets sagsforlob 2024/1 LF 154Lov om supplerende bestemmelser til forordningen om kunstig intelligens, official text, Retsinformation.dk

In force since 2 August 2025. Binds public and private bodies.

What this law does

Denmark's supplementary AI Act law designates Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen as the national competent authorities under Article 70(1) of the EU AI Act.

Digitaliseringsstyrelsen is the notifying authority and central contact point and is the market-surveillance authority for Article 5(1)(a) to (c), (e) and (f) of the prohibited-practices list, which includes the untargeted scraping of facial images from the internet or CCTV footage to build a facial-recognition database.

Datatilsynet is the market-surveillance authority for Article 5(1)(d) and (g), covering individual predictive-policing profiling and biometric categorization that infers a protected characteristic. Domstolsstyrelsen covers the courts' own use of AI systems outside their judicial capacity. The authorities may demand information, enter business premises without a court order, run technical inspections of an AI system, publish their decisions, and issue compliance orders or temporary bans.

An intentional or grossly negligent violation of Article 5's prohibited practices, a failure to give accurate information on request, obstruction of an inspection, or non-compliance with an order is punishable by a fine set by the courts, with no statutory ceiling stated in this law; the limitation period is 5 years.

What it requires

Privacy law6 instruments, 6 in force

Research summary (100 words)

Denmark's private-sector regime is the General Data Protection Regulation (GDPR) plus the Danish Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018, consolidated as Act No. 289 of 8 March 2024), which supplies Denmark's national derogations and Datatilsynet as supervisory authority.

Denmark's most distinctive feature is its enforcement mechanism: GDPR Recital 151 records that Denmark's legal system does not allow Datatilsynet itself to impose an administrative fine, so a fine is instead set by the Danish courts as a criminal penalty after Datatilsynet refers the case to police. As at 24 August 2026; later amendment to the Databeskyttelsesloven is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Denmark

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Danish derogation from this timeline is confirmed.

What it requires

Comprehensive regime

Danish Data Protection Act (Databeskyttelsesloven)

Lov nr. 502 af 23. maj 2018 om supplerende bestemmelser til forordningen om beskyttelse af fysiske personer i forbindelse med behandling af… personoplysninger og om fri udveksling af sadanne oplysninger (databeskyttelsesloven), consolidated as Act No. 289 of 8 March 2024Retsinformation.dk official consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Danish Data Protection Act gives the General Data Protection Regulation (GDPR) domestic effect in Denmark and supplements it with Denmark-specific derogations for matters GDPR leaves to member states, including the digital age of consent, processing of CPR (civil registration) numbers, CCTV, and journalism. Datatilsynet, the Danish Data Protection Agency, enforces it, with the distinctive feature that Denmark cannot itself impose an administrative fine (see the enforcement instrument below).

The Act's specific derogation sections were not independently read against the Act's own text; the sections named in secondary commentary are not restated here as confirmed provisions.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Denmark

Regulation (EU) 2016/679, Arts. 44-50Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Denmark outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Danish derogation broadening or narrowing General Data Protection Regulation (GDPR) Chapter V is confirmed.

What it requires

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Denmark

Regulation (EU) 2016/679, Arts. 12-23; DatabeskyttelseslovenOfficial Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Denmark: access, rectification, erasure, restriction, portability, and objection, generally exercisable against the controller within one month. Article 22 gives a qualified right against a decision based solely on automated processing that produces legal or similarly significant effects, applied in Denmark through the Databeskyttelsesloven. No Danish derogation narrowing these rights was confirmed against the Act's own text.

What it requires

Enforcement supervision

GDPR Articles 82-83 and Datatilsynet Enforcement in Denmark

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Datatilsynet holds the General Data Protection Regulation (GDPR) Article 58 corrective toolkit directly, warnings, reprimands, compliance orders and processing bans, but GDPR Recital 151 records that Denmark's legal system does not allow the supervisory authority itself to impose an administrative fine. In practice, Datatilsynet reports a violation it considers fine-worthy to the Danish police with a recommended amount, and the fine is set and imposed by the Danish courts as a criminal penalty rather than by Datatilsynet directly.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Denmark

Regulation (EU) 2016/679, Art. 9Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for the purpose of uniquely identifying a natural person as a special category of personal data, prohibited absent an Article 9(2) ground such as explicit consent.

No Danish statutory enumeration or illustrative list of biometric identifier types is confirmed, and none is asserted; Datatilsynet has engaged case by case with facial recognition deployments through its authorization and guidance practice, but no voiceprint specific guidance or enforcement decision was located.

What it requires

Scraping law3 instruments, 3 in force

Research summary (233 words)

Denmark has no scraping-specific statute, so general law governs each dimension separately.

Straffeloven (the Criminal Code) section 263 criminalizes unauthorized access to another's data system or to data intended for use in a data system, with no requirement in its text that the offender circumvent a technical security measure, so a plain reading does not exclude access to an unauthenticated public page; no published Danish court decision addressing web scraping of public pages under this section is confirmed in the primary text.

Ophavsretsloven (the Copyright Act) section 71 gives the maker of a catalogue, table, database or similar compilation resulting from a substantial investment an exclusive right against reproduction or making available of the whole or a substantial part, for 15 years, which reaches unauthorized bulk extraction by a scraper regardless of copyright in the underlying content.

Ophavsretsloven sections 11b and 11c, transposing Articles 3 and 4 of the EU Digital Single Market Copyright Directive, let a person with lawful access to a work extract and copy it for text and data mining, including for AI training, unless the rights holder has expressly reserved that use in an appropriate machine-readable manner, with a separate, non-waivable exception for scientific research by research organizations and cultural heritage institutions.

No Danish statute or reported case establishing a scraping-specific unfair-competition or trespass doctrine, or assigning legal weight to a robots.txt directive, is confirmed in the primary text.

Computer misuse

Straffeloven Section 263, Unauthorized Access to a Data System

Straffeloven, section 263 (Uberettiget adgang til et datasystem), Lovbekendtgorelse nr. 1851 af 20. september 2021Straffeloven, official consolidated text, Retsinformation.dk

In force. Binds public and private bodies.

What this law does

Section 263, subsection 1, punishes with a fine or imprisonment of up to 1 year and 6 months whoever unlawfully obtains access to another's data system or to data intended for use in a data system. The provision does not state that the access must defeat a security measure, so its text does not on its face exclude reading a public, unauthenticated page.

Subsection 3 raises the maximum to imprisonment of up to 6 years where the access is made with intent to learn a business's trade secrets or under other especially aggravating circumstances, including systematic or organized offending. A related section, 263a, separately punishes commercial trafficking in access credentials to a data system.

What it requires

Copyright and text and data mining (TDM)

Ophavsretsloven Sections 11b-11c, Text and Data Mining Exception

Ophavsretsloven sections 11 b-11 c (Tekst- og datamining), Lovbekendtgorelse nr. 1093 af 20. august 2023, inserted by Lov nr. 680 af 6. juni 2023Ophavsretsloven, official consolidated text, Retsinformation.dk

In force. Binds public and private bodies.

What this law does

A person with lawful access to a work may extract from it and make copies of it for text and data mining, defined as any automated analytical technique for analysing text and data in digital form to generate information such as patterns, trends and correlations, provided the rights holder has not expressly reserved the use of the work in an appropriate manner, and the resulting copies may be kept as long as needed for the mining.

A separate, non-waivable exception in section 11c lets a research organization or cultural heritage institution with lawful access extract from and copy a work for text and data mining carried out for scientific research, including within a public-private partnership, without the reservation that limits the general exception.

Lov nr. 680 af 6. juni 2023, which inserted these sections, provides that it takes effect on publication in Lovtidende; a specific commencement day beyond that is not confirmed in the primary text.

What it requires

Database right

Ophavsretsloven Section 71, Sui Generis Database Right

Ophavsretsloven, section 71 (Fremstillere af kataloger m.v.), Lovbekendtgorelse nr. 1093 af 20. august 2023Ophavsretsloven, official consolidated text, Retsinformation.dk

In force. Binds public and private bodies.

What this law does

Whoever produces a catalogue, table, database or similar compilation in which a large number of items of information are assembled, or which results from a substantial investment, has the exclusive right to control the whole work or a substantial part of it, by reproducing it or by making it available to the public.

The right also reaches a repeated and systematic reproduction or making available of insubstantial parts of the compilation's content where that conflicts with normal exploitation of the compilation or unreasonably harms the maker's legitimate interests.

The protection lasts 15 years from the end of the year the work was made, extended to 15 years from the end of the year it was first made available to the public if that made-available date falls within the original term, and a contract term that extends the maker's right beyond that to a published work is void.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (609 words)

Denmark transposed the NIS2 Directive through Lov nr 434 af 6. maj 2025 (Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau, styled NIS 2-loven), signed 6 May 2025, published in Lovtidende A on 7 May 2025, and in force since 1 July 2025 under its own Section 33(1).

The Act binds an essential entity (Section 4) or an important entity (Section 5) drawn from its Annex 1 (sectors of particular critical importance) or Annex 2 (other critical sectors), except an entity the Act itself routes to a separate regime: Section 1(2) excludes an entity covered by Denmark's Act on strengthened preparedness in the energy sector, an entity covered by its Act on security and preparedness in the telecommunications sector, and a financial entity the Financial Business Act's Section 333(1) designates, each of which runs under its own parallel security regime rather than being folded into this one.

Annex 1's digital-infrastructure entry (item 8) names an internet-exchange-point provider, a DNS provider other than a root-server operator, a top-level-domain registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider, and a provider of a public electronic-communications network or service, reached as essential entities by the general size test (250 employees, or annual turnover over EUR 50 million and a balance sheet over EUR 43 million), except that a qualified trust-service provider, a top-level-domain registry and a DNS provider are essential entities regardless of size (Section 4(3)(1)).

Annex 2's digital-provider entry (item 6) separately names an online marketplace, an online search engine, and a social-networking-services-platform provider, reached as important entities at the smaller size test (50 employees, or turnover and balance sheet each over EUR 10 million) once they clear that bar (Section 5(1)).

The wider sector classes both Annexes list by industry (energy, transport, drinking water, health, waste, chemicals, food, manufacturing, space, postal and courier services, and the rest) are a designation and size class no activity in this vocabulary expresses, and none is flagged on that account; nor is a row filed for the energy-sector, telecom-sector or financial-entity regimes Section 1(2) excludes, since no activity in the vocabulary expresses a financial entity, an energy operator, or a telecommunications operator either.

This Act repeals, on the date it took effect, all four of Denmark's 2018 NIS1-era security laws: Lov nr 436 (domain-name-system and digital-service security), Lov nr 437 (internet-exchange-point-operator security), Lov nr 440 (healthcare-sector security), and Lov nr 441 (transport-sector security), each af 8. maj 2018 (Section 33(4) to (7)), so none of those four survives alongside the general Act the way a predecessor NIS1 regime does in some other Member States.

No instrument here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Denmark has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Databeskyttelsesloven's own breach-notification duties to Datatilsynet, both of which sit in the privacy topic rather than here.

A violation of the risk-management, registration, incident-notification or recipient-notice duties below (Sections 6, 9, 10, 11, 12(1), 13 or 15) is punished with a criminal fine (bøde) under Section 32, not an administrative fine the competent authority itself may impose, a departure from the EUR 10 million/2 percent (essential entity) and EUR 7 million/1.4 percent (important entity) administrative-fine ceilings most other Member States' own NIS2 transpositions enact; the Act states no fixed monetary maximum or turnover percentage of its own, leaving the amount to Denmark's ordinary criminal-sentencing process, and corporate (legal-person) liability attaches under Chapter 5 of the Criminal Code (straffeloven).

Sector security regimes

NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

NIS 2-loven, §§ 6-10Consolidated text, retsinformation.dk, NIS 2-loven, LOV nr 434 af 06/05/2025, gældende (current) version

In force since 1 July 2025. Binds public and private bodies.

What this law does

Section 6 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its operations or to provide its services, and to prevent an incident or minimise its impact on the recipients of its services and on other services, covering at minimum risk-analysis and information-system-security policy, incident handling, operational continuity, supply-chain security, secure acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, and, where relevant, multi-factor or continuous authentication and secured communications (Section 6(1)); an entity that falls short must take corrective measures without undue delay (Section 6(2)).

Section 7 requires the entity's management board (ledelsesorgan) to approve these measures, oversee their implementation, and ensure its own members receive cybersecurity risk-management training.

Section 9 requires a DNS provider, a top-level-domain registry, a domain-name-registration-service provider, and a provider of cloud-computing, data-centre, content-delivery-network, managed, managed-security, online-marketplace, online-search-engine or social-networking-services-platform services to register with the relevant competent authority within 3 months of first falling within the Act's scope; Section 10 requires other essential and important entities to register within 2 weeks.

This Act, Lov nr 434 af 6. maj 2025 (NIS 2-loven), transposes NIS2 Directive Articles 21 and 24. By Section 1(2), it does not apply to an entity covered by Denmark's separate energy-sector preparedness Act, its telecommunications-sector security and preparedness Act, or the financial entities the Financial Business Act's Section 333(1) designates, each of which runs its own parallel regime.

By Section 33(4) to (7), it also repeals Denmark's four 2018 NIS1-era security laws (Lov nr 436, 437, 440 and 441 af 8. maj 2018).

What it requires

Vulnerability and incident reporting

NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties

NIS 2-loven, §§ 12-13, 15Consolidated text, retsinformation.dk, NIS 2-loven, LOV nr 434 af 06/05/2025, gældende (current) version

In force since 1 July 2025. Binds public and private bodies.

What this law does

Section 12 requires an essential entity or an important entity to notify the relevant competent authority and Denmark's CSIRT of every significant incident, defined as one that has caused or can cause serious operational disruption or financial loss for the entity, or that has affected or can affect another person through significant physical or non-physical harm.

Section 13 sets the notification clock: an early warning without undue delay and no later than 24 hours after becoming aware of the incident (Section 13(1)(1)); a notification without undue delay and in any case within 72 hours, updating the early warning with an initial severity and impact assessment (Section 13(1)(2)); an interim report on the CSIRT's request (Section 13(1)(3)); and a final report no later than one month after the notification, or, if the incident is still ongoing, a status report at that point and a final report within one month of the incident being handled (Section 13(1)(4) and (5)).

A trust-service provider instead sends only the Section 13(1)(2) notification, without undue delay and within 24 hours (Section 13(2)); the CSIRT must acknowledge an early warning within 24 hours and, on request, can offer guidance and operational advice (Section 13(3)).

Section 15 separately requires an essential or important entity to notify its service recipients, without undue delay, of a significant incident likely to adversely affect the delivery of their service, and to inform any recipient potentially affected by a significant cyber threat of the protective or responsive measures available to them.

This Act, Lov nr 434 af 6. maj 2025 (NIS 2-loven), transposes NIS2 Directive Articles 23 and 30 and, by Section 33(4) to (7), repeals Denmark's four 2018 NIS1-era security laws (Lov nr 436, 437, 440 and 441 af 8. maj 2018).

What it requires

Age gating law1 instrument, 1 in force

Research summary (159 words)

Denmark has no adult-content age-verification statute, social-media minor-access restriction, or app-store age-verification requirement addressed to a developer or platform outside the EU Audiovisual Media Services Directive framework.

Denmark's own addition to that EU baseline is sections 51a to 51c of Lov om radio- og fjernsynsvirksomhed m.v., inserted by Lov nr. 805 af 9. juni 2020 with effect from 1 July 2020, which requires a video-sharing platform provider under Danish jurisdiction to register with Radio- og tv-naevnet and comply with ministerial rules on measures to protect minors and the public from harmful content, including content depicting child sexual abuse as defined by Straffeloven section 235.

The specific age and parental-control measures a provider must take are set by ministerial regulation under that provision rather than by the Act itself, and that regulation's own text is not described here. The digital age of consent for a minor's own personal data is addressed under the privacy topic and is not restated here.

Adult content age verification (AV)

Radio- og fjernsynsloven Sections 51a-51c, Video-Sharing Platform Minor Protection

Lov om radio- og fjernsynsvirksomhed m.v., sections 51 a-51 c (Videodelingsplatformstjenester), inserted by Lov nr. 805 af 9. juni 2020Lov om radio- og fjernsynsvirksomhed m.v., official text of the amending act, Retsinformation.dk

In force since 1 July 2020. Binds private bodies.

What this law does

A provider of a video-sharing platform service under Danish jurisdiction must register with Radio- og tv-naevnet. The Culture Minister sets rules requiring such a provider to take appropriate measures to protect minors generally from harmful content.

The Culture Minister separately sets rules requiring such a provider to take appropriate measures to protect minors and the public from content that incites violence, hatred or terrorism, or that depicts child sexual abuse material within the meaning of Straffeloven section 235, racism or xenophobia, and bars a provider from processing a minor's personal data, collected or generated through its age or parental-control tools, for commercial purposes.

Radio- og tv-naevnet enforces the registration duty and these rules, and may order a provider to suspend its activity for a gross or repeated violation.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (139 words)

Denmark transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through Ophavsretsloven section 69a, inserted by Lov nr. 1121 af 4. maj 2021, which entered into force 7 June 2021: an information-society service provider may not reproduce a press publication online or make it available to the public without the publisher's consent, for 2 years after the end of the year the publication appeared.

Denmark's text-and-data-mining opt-out, Ophavsretsloven sections 11b and 11c, which also bears on an aggregator's indexing and training use of news text, is analyzed under the scraping topic rather than restated here. Denmark has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act.

No hot-news or misappropriation doctrine distinct from ordinary law, and no Danish case law construing section 69a, is confirmed in the primary text.

Press publishers' right

Ophavsretsloven Section 69a, Press Publisher Right

Ophavsretsloven section 69 a (Udgivere af pressepublikationer), Lovbekendtgorelse nr. 1093 af 20. august 2023, inserted by Lov nr. 1121 af 4. maj 2021Ophavsretsloven, official consolidated text, Retsinformation.dk

In force since 7 June 2021. Binds private bodies.

What this law does

A press publication may not be reproduced online, or made available to the public at a place and time individually chosen by them, by a provider of an information-society service without the publisher's consent, until 2 years have elapsed after the end of the year the publication or announcement occurred. The right does not apply to a press publication first published or announced before 6 June 2019, regardless of any later use after the provision's own entry into force. The right binds a publisher established in a European Economic Area country.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.