Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

When must a personal data breach be reported to the Danish Data Protection Agency?

The controller must report the breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects. Where the risk is high the data subjects must also be informed. Every breach must be documented internally, including those that are not reported.

Share this page

Source

Source
GDPR Articles 33 and 34, together with the Danish Data Protection Act
Acts
Danish Data Protection Act
Area
Data protection
Checked
2026-09-10

Questions

Next step

Three ways to put the register to work in your own practice.

Start with your task