In short: A company may send a CPR number by email when it has a basis to process it, but the email must be encrypted. Datatilsynet's minimum is transport-layer encryption with TLS 1.2. Ordinary SMS is not a secure channel for CPR numbers.

What Datatilsynet says

GDPR doesn't mention email, but Article 32 requires appropriate security. Datatilsynet considers encryption a baseline appropriate measure when confidential or sensitive personal data is emailed over the internet, at a minimum TLS 1.2, and uses the personal ID number as an example of confidential data. Two details are often missed:

  • Consent doesn't lower the bar. Neither the person nor the company can agree to less security than the risk assessment requires.
  • Forced vs opportunistic TLS. Opportunistic TLS falls back to plain text if the receiving server can't do it. Forced TLS won't send unless strong enough encryption can be established.

Payslips and attachments

The requirement covers content, including attachments. A payslip, an employment contract or a spreadsheet with CPR numbers is covered. Use an encrypted connection, Danish Digital Post/e-Boks, or a secure portal.

If you receive a CPR number by ordinary email

  • Don't reply in the same thread and send the number back. Write a new email without it.
  • Don't keep the email longer than needed, and don't move it into shared folders.
  • Tell the sender about a secure channel for next time.

The most common mistake: the wrong recipient

Many breaches reported to Datatilsynet are data sent to the wrong recipient, often because of address autocomplete. Encryption doesn't help when the email reaches the wrong person. See what to do if a CPR number was sent by mistake.

Checklist

  1. Do we have a basis to process the CPR number (section 11)?
  2. Do we need the full number, or is a date of birth or customer number enough?
  3. Is it sent encrypted (forced TLS 1.2 or better, or a secure portal)?
  4. Is the recipient address checked, and autocomplete off where it makes sense?
  5. Does the copy afterwards live somewhere with limited access?

Sources

  1. Datatilsynet: Katalog over foranstaltninger – sikker transmission
  2. Datatilsynet: Bed ikke dine kunder sende følsomme eller fortrolige oplysninger på SMS
  3. Datatilsynet: Auto-complete af e-mailadresser
  4. Datatilsynet: E-mails skal sendes til den rigtige modtager
  5. Databeskyttelsesloven § 11 (danskelove.dk)
  6. Databeskyttelsesforordningen (GDPR), forordning (EU) 2016/679 (EUR-Lex)

Not legal advice: this article is general information and does not replace an assessment of your specific situation. Ask a lawyer or your data protection officer if in doubt.