GDPR compliance in Denmark: who is in scope and what is owed
How GDPR applies to companies operating in or serving Denmark — scope tests, the obligations that follow, and the primary sources to verify each one against.
Organisations established in Denmark or targeting individuals in Denmark are subject to the General Data Protection Regulation (GDPR) supervised by the European Data Protection Board (EDPB) and local supervisory authorities. Compliance obligations require identifying whether an entity acts as a data controller or data processor, maintaining a record of processing activities, and implementing appropriate technical measures.
Extraterritorial Scope and Applicability in Denmark
The application of the GDPR extends beyond physical establishments within the European Union, reaching entities that process personal data of individuals located in Denmark. Under Regulation (EU) 2016/679, the rules apply to the processing of personal data by controllers or processors established in the Union, regardless of whether the processing takes place in the Union or not. When an organisation outside the Union offers goods or services to data subjects in Denmark, or monitors their behavior as far as their behavior takes place within the Union, the regulation applies.
Organisations must determine their exact operational classification under the framework. Entities that determine the purposes and means of processing act as data controllers, while those processing personal data on behalf of controllers act as data processors. Establishing this status is the foundational step for any compliance project operating within Danish jurisdiction.
Guidance issued by the EDPB — guidelines, recommendations and best practices provides detailed interpretations on jurisdictional reach and the criteria for targeted activities. Compliance teams should consult these regulatory interpretations to verify whether their specific business models fall under supervisory oversight.
Core Obligations for Data Controllers and Processors
Entities falling within the scope of the GDPR must establish lawful bases for processing personal data and maintain documented evidence of compliance. Data controllers carry primary responsibility for demonstrating adherence to the principles relating to processing, such as lawfulness, fairness, transparency, and data minimization.
Where processing is carried out on behalf of a controller, GDPR Article 28 — Processor mandates specific contractual terms between the parties. These contracts must stipulate that the processor acts only on documented instructions from the controller, ensures confidentiality of personnel, implements security measures, and assists the controller with data subject rights.
Organizations must maintain documentation regarding their processing operations. Under GDPR Article 30 — Records of processing activities, controllers and processors must maintain a record of processing activities containing categories of processing, data categories, and descriptions of technical and organizational security measures.
International Data Transfers and Standard Contractual Clauses
When personal data originating from individuals in Denmark is transferred outside the European Economic Area, organizations must ensure an adequate level of protection. If the destination country lacks an adequacy decision, transfer tools must be implemented to safeguard the data against unauthorized access.
The European Commission provides standardized contractual safeguards for international transfers. According to Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses, organizations can utilize approved Standard Contractual Clauses to govern transfers between controllers and processors across international borders.
Compliance teams reviewing cross-border data flows must map all third-country destinations and verify that appropriate supplementary measures are in place. The use of Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses requires careful annex completion to reflect the specific roles of data exporters and data importers accurately.
Comparison of Controller and Processor Responsibilities
Distinguishing between operational roles is essential for assigning legal accountability under the framework. The following table outlines the operational differences between primary actors.
| Attribute | Data Controller | Data Processor | |---|---|---| | Purpose Determination | Decides why and how data is processed | Processes data strictly on instructions | | Primary Accountability | Bears direct responsibility to authorities | Accountable primarily to the controller via contract | | Documentation Duty | Must maintain a comprehensive record of processing activities | Must maintain a processor-specific record of processing activities | | Contractual Requirement | Issues data processing agreements under GDPR Article 28 — Processor | Executes terms and engages sub-processor entities with permission |
Organizations operating in Denmark must ensure their vendor agreements accurately reflect these delineated duties. Misidentifying a role in a contract can lead to regulatory scrutiny during supervisory audits.
Evidencing Compliance and Supervisory Guidance
Demonstrating accountability under the GDPR requires ongoing operational diligence rather than static policy drafting. Organizations should regularly review their processing inventories and ensure that any appointment of a data protection officer is documented where required by statutory thresholds.
Supervisory authorities rely on published interpretations to evaluate enforcement priorities. Compliance officers should monitor updates from the EDPB — guidelines, recommendations and best practices to align internal auditing practices with current regulatory expectations across the European Union.
Maintaining rigorous documentation of data flows, processing agreements, and security safeguards helps organizations evidence their alignment with statutory mandates. Check the cited source for the current figure regarding supervisory powers and administrative fines.
Scope Exceptions and Unresolved Operational Uncertainties
Not all data processing activities fall under the purview of the GDPR. Activities concerning purely personal or household activities, as well as certain law enforcement and national security exemptions, sit outside the standard regulatory scope.
However, determining whether a commercial service directed at Danish consumers triggers extraterritorial reach can involve complex factual analysis. Organizations must evaluate whether their marketing language, currency offerings, and user language demonstrate an explicit intention to target individuals in Denmark.
When ambiguities arise regarding the interpretation of processing obligations or international transfer restrictions, legal counsel should be consulted. Primary legislative texts and regulatory guidance documents should always be reviewed directly to confirm the latest legal standards.
BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.
Frequently asked questions
Does selling software to customers in Denmark trigger GDPR scope?
Yes, if the software offering involves monitoring the behavior of individuals located in Denmark or offering goods and services to them, the extraterritorial provisions of the regulation apply.
What is the primary difference between a controller and a processor?
A [data controller](/glossary/data-controller) determines the purposes and means of processing personal data, whereas a [data processor](/glossary/data-processor) processes personal data exclusively on behalf of and under instructions from the controller.
Are organizations required to maintain written documentation of processing?
Yes, entities must maintain a [record of processing activities](/glossary/record-of-processing-activities) detailing their processing operations pursuant to statutory requirements set forth in the framework.
How should international data transfers out of Denmark be structured?
Transfers outside the European Economic Area require appropriate safeguards, such as utilizing approved mechanisms like [Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), unless an adequacy decision applies.
Where can compliance teams find authoritative interpretations of the rules?
Authoritative guidance and recommendations are published by supervisory bodies, including resources available through the [EDPB — guidelines, recommendations and best practices](https://www.edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en).
Sources
BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.
Last reviewed 2026-10-08.