Data breach in Danish population register affects 8.8 million people
Unauthorised parties gained access to names, addresses and identification numbers through a legitimate corporate connection.
Unauthorised parties have gained access in Denmark to the data of approximately 8.8 million registered people. Danish authorities say that names, addresses and CPR numbers were viewed through the misuse of a private company’s legitimate access to the central population register.
The people affected are not only those currently living in Denmark. The CPR register also contains data on people who have moved abroad and on deceased people. In total, approximately 11 million registered people are listed in the system, while Denmark itself has more than six million inhabitants.
The CPR administration discovered anomalous behaviour on 2 October that had taken place in September. It later emerged that unauthorised parties had carried out automated searches on a large scale. According to the authorities, the company involved had valid access to the register, but that access has since been closed.
According to an initial investigation, people with a protected residential address were not affected as far as their names and addresses are concerned. The authorities are still investigating exactly which data were retrieved and how long the unauthorised access lasted.
Denmark’s Datatilsynet, the privacy regulator, received a notification from the CPR administration on 4 October. The regulator says it is not yet able to assess exactly what happened, who was responsible and which processing of personal data was unlawful. The police are also investigating the case.
The scale makes the incident particularly sensitive. A CPR number can be used to link data to individuals and is therefore an important part of digital identity. The authorities have opened a cyber support hotline and are working on additional security measures for the register.
For now, it is not known who was behind the access, whether the data were copied for fraud or whether any misuse has already been established. The authorities are therefore not warning of a specific fraud pattern, but advise those affected to be alert to unexpected messages and requests for personal data.
One story, several perspectives
What is established
- Unauthorised access to the CPR register was obtained through a legitimate corporate connection.
- The authorities are investigating the scale, cause and responsibility.
- The authorities have not yet disclosed a perpetrator or any specific misuse.
Left
Arguments The state collects highly sensitive data and must therefore provide stricter access restrictions, maximum transparency and broader protection for citizens.
Values Privacy, digital fundamental rights and oversight of powerful institutions.
Consequences More security may make public systems more expensive and less easily accessible, but limits the damage caused by large-scale breaches.
Centre
Arguments A central register can be efficient, but access must be demonstrably necessary, auditable and quickly revocable; the investigation must first establish the facts.
Values Proportionality, reliability and administrative due care.
Consequences Targeted improvements are likely to be more effective than replacing the system entirely.
Right
Arguments The government must handle personal data responsibly, but organisations must also secure their own access and be liable in cases of negligence.
Values Responsibility, security and efficient administration.
Consequences Stricter contractual and financial incentives could encourage companies to secure their connections more effectively.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The core facts come from the Danish government notification and the privacy regulator. Unknown aspects, such as the perpetrator and possible misuse, are explicitly described as uncertain.
- confirmed Unauthorised parties gained access to data belonging to approximately 8.8 million registered people. — This is stated in the notification from the Danish CPR administration. source
- confirmed The data included names, addresses and CPR numbers. — The Danish government explicitly names these data. source
- confirmed The access took place through a legitimate corporate connection. — The government says that a private company had valid access which was misused. source
- confirmed Datatilsynet received a notification on 4 October. — This is stated in the regulator’s publication. source
Editor's note
The scale, access route and response of the authorities have been confirmed. The perpetrator, motive, precise dataset and any misuse remain unknown.Sources
- Omfattende uautoriseret adgang til borgeres CPR-oplysninger — Forsknings-, Uddannelses- og Digitaliseringsministeriet
- Datatilsynet er opmærksom på sag om opslag i CPR — Datatilsynet
More on this in Dutch media
- RTL Nieuws — „denemarken datalek”
- FD — „denemarken datalek”
- Trouw — „denemarken datalek”