TL;DR for the DPO
In Denmark the authority does not fine: it recommends an amount, reports the case to the police, and a court decides the penalty. A figure announced in a Danish press release is therefore a request, not an imposed fine. Reading Danish decisions through an Italian or French lens leads to the wrong conclusion.
The three points that matter
- Cookie competence is split: the Digitaliseringsstyrelsen applies the Cookiebekendtgorelsen implementing the ePrivacy Directive, while Datatilsynet applies the GDPR. In 2026 the two authorities are coordinating their checks, so a non-compliant banner can attract attention from both.
- Analytics cookies are NOT exempt from consent: if the site loads measurement identifiers on page load and asks for consent afterwards, the breach concerns both the cookie rules and the GDPR.
- The enforcement path is long: authority decision, police report, investigation, possible referral to a court that sets the amount. Courts tend to set figures below those recommended. This makes the financial risk less immediate, but does not remove reprimands, compliance orders and reputational damage.
What to do now, in practice
For anyone with clients present in Denmark or with sites aimed at Danish users: 1) apply the same checks as elsewhere in Europe - one-click refusal, no trackers before the choice, working withdrawal; 2) make sure consent information is understandable to the target audience: the authority does not mandate Danish, but if the site addresses Danish consumers that is the practical choice; 3) remember Danish decisions must be cited correctly: the figure is a recommended amount, not an imposed fine.
Why it matters even outside Denmark
The Danish model is the clearest example that the GDPR is uniform in principle but not in enforcement. Amounts across countries are not directly comparable, and that matters when building a comparative analysis or explaining risk to a client. Knowing these differences is also what separates a consultant who has read the Regulation from one who actually follows what European authorities do.
Official source:Recital 151 of Regulation (EU) 2016/679; Datatilsynet - 2026 supervisory priority on cookie consent, in coordination with the DigitaliseringsstyrelsenLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free