In short:

  • The CPR number is not a special category of personal data under GDPR Article 9.
  • It has its own Danish rule: section 11 of the Danish Data Protection Act (databeskyttelsesloven). Private organisations may only process CPR numbers in the cases it lists.
  • The Danish Data Protection Agency (Datatilsynet) treats the CPR number as confidential: it must be protected, e.g. encrypted when sent over the internet.

Is a CPR number sensitive personal data?

No. “Special categories” are a closed list in GDPR Article 9: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health, and sex life or sexual orientation. The CPR number is not on it. But GDPR Article 87 lets member states set specific conditions for national identification numbers, and Denmark did so in section 11.

What does section 11 say?

For companies, associations and other private parties (subsection 2), CPR numbers may be processed when:

  1. it follows from legislation (e.g. reporting salaries to the tax authority),
  2. the data subject has consented in line with GDPR Article 7,
  3. processing is solely for scientific or statistical purposes, or, for disclosure, when it is a natural part of the normal operation of that type of business and decisive for unique identification, or required by a public authority, or
  4. the conditions in section 7 are met (the Danish rules for special-category data, e.g. establishing a legal claim or meeting employment-law obligations).

Subsection 3: CPR numbers may not be published without consent. A file with CPR numbers that “anyone with the link” can open is not necessarily published, but it is close, and it is the kind of risk the GDPR security requirement (Article 32) is about.

Is the CPR number confidential?

In practice, yes. “Confidential data” is not a category in the Act itself, but Datatilsynet uses it for data that needs extra protection and gives the personal ID number as an example. In practice that means encrypting it in email (at least TLS 1.2), not asking customers to send it by text message, and limiting access to files that hold it.

Example: serious criticism for Nuuday

In 2022 Datatilsynet seriously criticised Nuuday (YouSee) because an employee asked for a customer's CPR number when the customer only called to ask whether broadband was available at an address. There was no purpose and no basis under section 11. The lesson for a small company: only ask for a CPR number when you need it and have a basis, and train staff accordingly.

What it means for your company

  • Know your basis. Payroll and statutory reporting usually are. Member, customer and sign-up lists rarely are.
  • Collect less. Use a date of birth or customer number when that is enough.
  • Find the old copies. The problem is rarely the payroll system. It's the 2019 export sitting in a shared folder.
  • Protect the rest. Encrypt, limit access, and delete when the purpose is fulfilled.

Check a file for CPR numbers without it leaving your computer.

Sources

  1. Databeskyttelsesloven § 11 (danskelove.dk)
  2. Lov nr. 502 af 23. maj 2018 om databeskyttelse (retsinformation.dk)
  3. Databeskyttelsesloven § 7 (danskelove.dk)
  4. Databeskyttelsesforordningen (GDPR), forordning (EU) 2016/679 (EUR-Lex)
  5. Datatilsynet: Bed ikke dine kunder sende følsomme eller fortrolige oplysninger på SMS
  6. Datatilsynet: Katalog over foranstaltninger – sikker transmission
  7. Datatilsynet: Nuuday får alvorlig kritik for uberettiget indsamling af personnummer (2022, j.nr. 2020-31-4333)

Not legal advice: this article is general information and does not replace an assessment of your specific situation. Ask a lawyer or your data protection officer if in doubt.