Privacy and data ethics
Danes are among the most digitally connected populations in the world. We are quick to embrace new technologies and digital services, creating significant benefits for society. However, our online activities should be protected by the highest possible standards of security and privacy.
According to an IDA survey, more than half of Danes are concerned about the safety of their personal data online, and many believe that protecting their privacy on the internet is virtually impossible.
The right to privacy is a fundamental freedom protected by the Danish Constitution, the European Convention on Human Rights, and the United Nations International Covenant on Civil and Political Rights.
As a society, we have a responsibility to create a safe online environment. This applies not least to children and young people, many of whom spend a significant part of their social lives on social media platforms whose practices are often questionable.
Trust and confidence in the digital world are essential if people are to embrace technologies that can strengthen public services, improve education, and enhance Denmark’s competitiveness.
IDA’s Recommendations to the Danish Privacy Commission
Recent legislation concerning data retention, CCTV surveillance, automatic number plate recognition, genomic data, and related initiatives has increased pressure on citizens’ privacy. The Danish Privacy Commission should assess the cumulative impact of existing legislation and proposed measures – including a potential new PET Act – on civil liberties and public trust in government authorities.
IDA recommends a two-year review process supported by regular interim reports and public debate.
At a hearing before the Danish Parliament’s Legal Affairs Committee on 19 February 2026, IDA presented a set of recommendations to support this work.
Research into Danes’ Online Behaviour
The Population Behaviour Online study [Befolkningens adfærd på nettet] examines how Danes use digital technologies and the challenges they encounter online.
The study was first conducted in 2015 in collaboration with the Danish Business Authority and again in 2017 with the Danish Consumer Council. A more recent report was prepared in cooperation with the Danish Consumer Council.
Data logging and consent
More extensive session logging is high on the police's list of priorities. According to the police, it would make it easier to investigate serious offences such as terrorism and child sexual abuse offences.
Session logging data can map an individual's online activities and communications with remarkable precision, often down to the minute. On the other hand, even intensive monitoring is unlikely to prevent extremely rare events such as terrorist attacks unless a very large number of people are placed under surveillance.
This raises an important question: how far should society be willing to go in monitoring law-abiding citizens in order to identify a small number of individuals engaged in criminal activity?
Another challenge is whether criminals would even be identified through session logging if they use tools such as Tor browsers or VPN services. If offenders are able to remain undetected, extensive logging may end up monitoring the wrong people entirely.
IDA surveyed a number of experts to gather their views on session logging.
The research is based on responses from members of IDA Tele, a professional community within IDA that promotes knowledge sharing, technological development, and national and international cooperation in telecommunications and related fields.
The community has more than 2,200 members, including engineers, IT specialists, marketers, economists and legal professionals.
The published results include responses only from 170 specialists who reported having advanced or expert-level knowledge of session logging.
IDA’s consent project
Consent is crucial to our ability to control how our personal data is used online.
However, just as consent can ensure that our data is only used for the purposes we intend, it can also become extremely cumbersome and hinder, for example, important research projects.
IDA, together with Konsensusmaskinen and a wide range of excellent partners, is working to identify the criteria for striking a balance in the use of consent that ensures an efficient public sector, high-quality research and the protection of privacy.
GDPR
The EU General Data Protection Regulation (GDPR) entered into force on 25 May 2018.
IDA and FSR – Danish Auditors conducted a study to assess how prepared Danish organisations were for GDPR and how well they were addressing cybersecurity challenges.
The study focused primarily on IDA members working in both the public and private sectors. The findings suggest that effective personal data protection depends on three key elements:
- Employees understanding the rules and the reasons behind them.
- Well-defined procedures that employees know and follow, or a clear understanding of who is responsible for carrying them out.
- IT systems that support compliance and facilitate the implementation of these procedures.
Overall, none of these three elements appeared to be fully in place.
- Employee knowledge of data protection requirements was limited. Fewer than half of those working with personal data understood key obligations such as the duty to inform individuals about how their data is used.
- Awareness of procedures was also relatively low. For example, only around half of employees knew how to respond to a data breach.
- Responsibilities and roles relating to data security were often unclear, and system support for compliance processes was insufficient.
- Medium-sized private-sector organisations appeared to face particular challenges in ensuring that knowledge was shared effectively across the organisation.
- Although slightly more than half of respondents appeared to have a general understanding of GDPR principles, only a small minority demonstrated a strong level of expertise.
IDA’s concerns about a public contact register
The Ministry of Public Sector Innovation proposed establishing a national public contact register containing citizens’ telephone numbers and email addresses.
The purpose of the register is to allow public authorities to contact citizens regarding appointments, deadlines and case-related matters.
As Digital Post (formerly e-Boks) already contains citizens’ CPR numbers, email addresses and mobile phone numbers could potentially be linked directly to personal identification records.
IDA has expressed reservations about this proposal.
In our view, citizens who believed they were providing their contact details solely to Digital Post may in practice find those details transferred to a new central government database.
This could enable a wide range of public authorities to contact individuals even though they never intended to share their information beyond its original purpose.
National Genome Centre
On 1 March 2018, IDA and several other organisations sent an open letter to the Minister for Health regarding plans to establish a National Genome Centre.
The letter highlighted several key requirements:
Consent
Citizens should have the right to provide informed consent before sensitive genetic information is transferred to the National Genome Centre, where it may be combined with data from Danish public registers.
Consent should be based on clear information about what data is stored; whether the data can be linked back to an individual; and the purposes for which the data may be used. If any of these conditions change, the original consent should no longer be considered valid.
Security
Genetic data held by the National Genome Centre should be stored securely and anonymised wherever possible. Genetic information linked to CPR numbers presents a significant information security risk, including where pseudonymisation techniques are used. Anonymous storage does not prevent future analysis alongside other anonymised datasets.
Transparency
Citizens deserve full transparency regarding all intended uses of a National Genome Centre, including both commercial and governmental purposes.
If the objectives of the Centre or the ways in which its data is used are expanded or altered, existing consent should only remain valid for the purposes originally approved.
Any significant changes relating to data storage, identifiability, or new uses of the data should require fresh consent after individuals have been informed of the changes.
Following the introduction of the legislation, questions were raised about whether the police could gain access to information held by the National Genome Centre.
Although the Minister initially rejected this possibility during the first parliamentary reading of the bill, a number of experts – including representatives of the Danish National Police – subsequently stated that access could be granted under existing criminal procedure legislation with a court order.
It is essential that this issue is thoroughly examined by Parliament before the Centre becomes operational.
Public trust in personalised medicine and genetic research could be seriously undermined if the National Genome Centre were, in practice, to function as a searchable DNA database for law enforcement purposes.