In short: A CPR number sent to the wrong person or shared more widely than intended is a personal data breach. As a rule it must be notified to Datatilsynet without undue delay and within 72 hours of becoming aware of it, unless you can document that it is unlikely to result in a risk to the person. Every breach must be documented internally.
Is it a breach?
Yes. A breach is not only hacking; it includes personal data accidentally made available to someone who shouldn't have it. Datatilsynet's guidance uses “data sent to the wrong recipient” as an example, and it is the most common kind of notification: a payslip emailed to the wrong address, a file shared with “anyone with the link”, a document published with a CPR number hidden in a signature.
First hours: stop it
- Close access. Remove the sharing link, restrict the file, or take the document offline.
- Ask the recipient to delete. Get written confirmation that the email and any copies are deleted. It feeds into the risk assessment.
- Establish the scope. How many people, which data, how long was it exposed, and to whom? In SharePoint and OneDrive, access and activity logs can show whether the file was actually opened.
Assess the risk
Consider what else sits next to the CPR number (name, address, salary, health), how many people are affected, and how trustworthy the recipient is. Datatilsynet stresses that if the recipient's trustworthiness is what makes the risk low, you should be sure of it, and ideally hold proof of deletion.
Notify Datatilsynet within 72 hours
The clock starts when you become aware of the breach; weekends and holidays don't extend it. You can notify before you know every detail and supplement later, via Datatilsynet's breach notification page. A late notification must explain the delay.
Tell the person?
If the breach is likely to result in a high risk, you must also inform the person without undue delay (GDPR Article 34).
Always document
Breaches you don't notify must still be documented internally: what happened, the effects and what you did (Article 33(5)), including why you judged the risk unlikely.
Prevent the next one
In 2021 Datatilsynet criticised a municipality that published a CPR number hidden in a signature certificate. It had a CPR checker, but ran it only after publishing; Datatilsynet noted that running it beforehand would have greatly reduced the risk. The same goes for companies: find CPR numbers before a file is shared, not after.Check a file before you share it.
Sources
- Datatilsynet: Håndtering af brud på persondatasikkerheden
- Datatilsynet: Vejledning om håndtering af brud på persondatasikkerheden (PDF, maj 2025)
- Datatilsynet: Anmeld sikkerhedsbrud
- Datatilsynet: E-mails skal sendes til den rigtige modtager
- Datatilsynet: Klage over offentliggørelse af personnummer på kommunal hjemmeside (2021)
- Databeskyttelsesforordningen (GDPR), forordning (EU) 2016/679 (EUR-Lex)
Not legal advice: this article is general information and does not replace an assessment of your specific situation. Ask a lawyer or your data protection officer if in doubt.