VMTech
Discuss a project →

Denmark Investigates CPR Register Access Affecting 8.8 Million Records

Denmark Investigates CPR Register Access Affecting 8.8 Million Records

Denmark is investigating unauthorized access to names, addresses and personal identification numbers for about 8.8 million people recorded in its Central Person Register (CPR). The Ministry of Digitalization said the access was obtained through a private Danish company that had a lawful right to query the register. The company’s access has been stopped, the matter has been reported to Datatilsynet, Denmark’s data protection authority, and police are investigating.

The access lasted for about 10 days in September, Minister for Digitalization Christina Egelund told Ritzau. An employee of the register’s administration detected unusual activity on Friday, October 2. Over that weekend, the administration determined the scale of the records involved.

Automated lookups and an unusually broad exposure

Datatilsynet said a very large number of automated queries were made to identify valid CPR numbers. Its October 5 notice, based on a notification from the register administration the preceding day, describes the data as allegedly retrieved and says the authority has not yet completed its assessment.

The ministry’s 8.8 million estimate is not final. It includes living residents, people who have emigrated, deceased people and other registered individuals. The CPR contains roughly 11 million records, meaning the access may have reached about four-fifths of the register. Denmark had just under 6 million residents at the start of 2025, according to Statistics Denmark.

The ministry said the queried data remained within the categories private companies are permitted to receive. Names and addresses of people with name-and-address protection were not included. The statements do not clarify whether CPR numbers for those protected individuals were accessed, whether affected people will receive individual notifications, how the company’s systems were accessed, or whether the data has been retained or used.

Rules designed for identified customers and employees

Under Denmark’s CPR Act, companies may receive register data about people they have already identified individually. A CPR number can identify a person for that purpose, while returned information may include a current name and address, unless protected, and events such as death, emigration or a credit warning. The register’s guidance says businesses should only request information on people with whom they already have a relationship, such as customers or employees.

CPR numbers consist of 10 digits: six representing date of birth and four serial digits. Datatilsynet said the automated activity sought valid numbers, but neither the authority nor the ministry explained how the queries were conducted or how one company’s access could have extended across such a large share of the register.

Egelund said the safeguards around this type of access had not been adequate and that alarms should have been triggered during the activity. The ministry has begun unspecified measures intended to prevent a recurrence, while the minister has requested a full security review of the register. Datatilsynet is examining how the incident happened and who was responsible for processing the data.

Identity-fraud precautions and business response

The ministry advised people to be particularly cautious about unexpected calls, texts and emails that use personal details; not to follow links in unsolicited messages; and never to share MitID credentials, one-time codes, passwords or card information. Individuals aged 15 or older can also set a credit warning through borger.dk, although it may take time to reach companies’ systems and can make credit applications harder to approve.

For organisations that use national-register data or depend on identity checks, the incident underscores the operational importance of volume-based alerts, narrowly scoped third-party permissions and verification methods that do not rely on a personal identifier alone. The CPR administration’s own guidance states that a CPR number must not be the sole proof of identity, a principle businesses can apply when reviewing fraud controls and supplier access.

#databreach#identitysecurity#privacy#denmark
Open analytics
On the site 0 views
min read 5 06.10.2026
Instagram

Denmark Investigates CPR Register Access Affecting 8.8 Million Records

Open the post on Instagram ↗