Digitaliseringsstyrelsen – Violation Found (Denmark, 2023)

Violation Found
Datatilsynet (Norway)8 November 2023Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Danish Agency for Digital Government was found to be processing personal data of many citizens without their consent. This is significant because it raises concerns about how government apps handle personal information.

What happened

The agency processed personal data of approximately 3.96 million citizens without their consent for a driving licence app.

Who was affected

Danish citizens who had not registered for the driving licence app but whose data was still processed.

What the authority found

The authority found that the agency did not have a valid legal basis for processing the personal data of citizens.

Why this matters

This case emphasizes the need for government agencies to ensure they have proper consent before processing personal data, setting a precedent for how public services handle privacy.

GDPR Articles Cited

AI-verified

Art. 5(1)(c) GDPR
Art. 58(2)(b) GDPR
Art. 58(2)(f) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 58(2)(b) GDPR
Art. 58(2)(f) GDPR

Original data from scraper before AI verification against source document.

Source verified 13 April 2026
verified correct
Full Legal Summary
Detailed

A Danish citizen lodged a complaint with the Danish DPA regarding the Danish Agency for Digital Government's (the controller) processing of his personal data in their Driving Licence app, which he had not registered for or used. The app is a digital alternative to the physical driving licence and contains information about the licence holder's name, birth data, place of birth, nationality, licence number, passport number, passport photo, social security number, health, and data relating to criminal convictions and offences. Following the complaint, on 7 September 2022, the DPA started an own-volition investigation of the matter. They found that the controller was processing the personal data of approximately 3.96 million Danish citizens with a driving licence, yet only 1.7 million had registered for the app, while the remaining group had not joined the app. The controller attributed the excessive processing to technical constraints of the driving licence database, built on an outdated mainframe system, which gave it access to all valid Danish driving licenses. They explained to have initially considered three possible solutions for the app but deemed only the one adopted realistically viable. The one adopted complied with certain operational and performance requirements while allowing for the digital driving licence, updated with the latest information, to be made accessible to citizens. Consequently, they claimed that the processing was in line with Article 5(1)(c) GDPR. The DPA concluded that the controller violated the data minimisation principle of Article 5(1)(c) GDPR. The principle should have been complied with despite the system being the only possible solution according to the current technical structure of the driving licence register. It further stated that the accessibility needs described by the controller and the mere fact that it is convenient for citizens to have the Driving Licence app, as they can leave their physical driving licence at home, ca

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Digitaliseringsstyrelsen in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

8 November 2023

Authority

Datatilsynet (Norway)

GDPRhub ID

gdprhub-6535

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Digitaliseringsstyrelsen - Denmark (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: