When must a personal data breach be reported to the Danish Data Protection Agency?
The controller must report the breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects. Where the risk is high the data subjects must also be informed. Every breach must be documented internally, including those that are not reported.
Source
- Source
- GDPR Articles 33 and 34, together with the Danish Data Protection Act
- Acts
- Danish Data Protection Act
- Area
- Data protection
- Checked
- 2026-09-10
Questions
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.