Chat on WhatsApp

How is Datatilsynet different from other EU GDPR regulators?

Datatilsynet is the Danish Data Protection Agency, the GDPR enforcement body in Denmark. While the underlying law is the same GDPR, Datatilsynet has a reputation for being thorough on documentation and has issued some of the EU’s most-cited cookie-consent decisions:

  • Cookie consent, Datatilsynet (with Erhvervsstyrelsen on the e-Privacy side) requires granular, per-purpose opt-in. No pre-ticked checkboxes. “Reject all” must be as prominent as “Accept all”. Continued-browsing-equals-consent is not valid. The Danish guidance closely mirrors CNIL (France).
  • Documentation requirement, fortegnelse over behandlingsaktiviteter (record of processing activities) is heavily enforced. Stores get audited on this.
  • Data-processor agreements (databehandleraftaler), every third-party processor (Magento host, Klaviyo, GA, MobilePay processor) needs a signed DPA. Datatilsynet has issued fines for missing DPAs.
  • International transfers, Datatilsynet has been notably strict on Google Analytics + US transfers (2022 guidance discouraged GA + recommended server-side alternatives).

What we ship: a Datatilsynet-aligned cookie banner (Cookiebot is Danish-founded, very common locally; Axeptio + OneTrust also work), full DPA pack, processing-record template, and a GA4 server-side / privacy-friendly analytics alternative if needed.

Was this helpful?