Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation July 28, 2026 4 min

Denmark: cookies are the 2026 priority, and fines are decided by a court

Datatilsynet cannot impose administrative fines: it reports cases to the police and a court decides. A model unique in Europe, expressly provided for by Recital 151 GDPR

TL;DR for the DPO

In Denmark the authority does not fine: it recommends an amount, reports the case to the police, and a court decides the penalty. A figure announced in a Danish press release is therefore a request, not an imposed fine. Reading Danish decisions through an Italian or French lens leads to the wrong conclusion.

The three points that matter

  • Cookie competence is split: the Digitaliseringsstyrelsen applies the Cookiebekendtgorelsen implementing the ePrivacy Directive, while Datatilsynet applies the GDPR. In 2026 the two authorities are coordinating their checks, so a non-compliant banner can attract attention from both.
  • Analytics cookies are NOT exempt from consent: if the site loads measurement identifiers on page load and asks for consent afterwards, the breach concerns both the cookie rules and the GDPR.
  • The enforcement path is long: authority decision, police report, investigation, possible referral to a court that sets the amount. Courts tend to set figures below those recommended. This makes the financial risk less immediate, but does not remove reprimands, compliance orders and reputational damage.

What to do now, in practice

For anyone with clients present in Denmark or with sites aimed at Danish users: 1) apply the same checks as elsewhere in Europe - one-click refusal, no trackers before the choice, working withdrawal; 2) make sure consent information is understandable to the target audience: the authority does not mandate Danish, but if the site addresses Danish consumers that is the practical choice; 3) remember Danish decisions must be cited correctly: the figure is a recommended amount, not an imposed fine.

Why it matters even outside Denmark

The Danish model is the clearest example that the GDPR is uniform in principle but not in enforcement. Amounts across countries are not directly comparable, and that matters when building a comparative analysis or explaining risk to a client. Knowing these differences is also what separates a consultant who has read the Regulation from one who actually follows what European authorities do.

Official source:Recital 151 of Regulation (EU) 2016/679; Datatilsynet - 2026 supervisory priority on cookie consent, in coordination with the Digitaliseringsstyrelsen

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free