Is Google Analytics Legal in Denmark? Cookie Consent, 84% Non-Compliant, and What's Coming

Dark hero with the Clickport brand mark and the kicker GA4 IN DENMARK. On the right, a ghosted recreation of a Google Analytics 4 report screen blended into a soft Danish flag, a red field with a white Nordic cross, with a red line reading Sep 2022: declared non-compliant by Datatilsynet and an amber line reading 2026: cookie consent tops the enforcement plan. Four labels: Datatilsynet won't call GA4 lawful, Every analytics cookie needs consent, Cookie enforcement tops the 2026 plan, Cookieless analytics needs no banner.
Legal status re-verified against primary sources in July 2026. Every ruling and figure below links to the original decision or report.

84% of Danish websites violate cookie consent rules. 70% fire tracking cookies before asking permission. In plain English: 7 sites in 10 track first and ask later. Datatilsynet just made cookie enforcement a 2026 priority. If you run a website in Denmark and use cookie-based analytics, the question isn't whether you're compliant. It's whether you get caught before you fix it. And Google Analytics isn't in the clear.

Key Takeaways
  • Datatilsynet declared Google Analytics non-compliant in September 2022. The EU-US Data Privacy Framework made US transfers lawful again in July 2023, but Datatilsynet has refused to call GA4 lawful: valid consent and the rest of GDPR still apply, and the DPF itself is under appeal at the CJEU.
  • Denmark has zero consent exemptions for analytics cookies. Unlike France (a formal analytics exemption) or Spain (first-party exemption), every analytics cookie on a Danish website requires prior opt-in consent under the Cookiebekendtgorelsen.
  • 84% of Danish websites have cookie compliance violations, and 70% fire tracking cookies before consent. Datatilsynet made cookie enforcement a top priority for 2026, coordinating inspections with Digitaliseringsstyrelsen.
  • Denmark cannot issue GDPR fines directly (GDPR Recital 151). Datatilsynet recommends fines to police, who prosecute through courts. The largest court-imposed GDPR fine to date: DKK 1 million (Arp-Hansen Hotels, 2023). Datatilsynet proposed DKK 15 million against Netcompany in 2024.
  • Denmark pushed for an EU-wide analytics consent exemption during its 2025 Council Presidency. The Digital Omnibus (proposed November 2025) would allow aggregated audience measurement without consent. Google Analytics would not qualify. Cookieless, first-party analytics would.

The rules you're subject to

Cookie consent in Denmark is governed by two overlapping laws, enforced by two separate authorities. I'll untangle them for you first.

The first is the Cookiebekendtgorelsen (BEK nr 1148 af 09/12/2011), Denmark's implementation of the EU ePrivacy Directive. Issued under Section 9 of the Teleloven (Telecommunications Act), it requires consent before any non-essential data is stored on or read from a visitor's device. Supervised by Digitaliseringsstyrelsen (the Danish Agency for Digital Government, which took over from the Danish Business Authority in December 2022).

The second is the GDPR, enforced by Datatilsynet. It governs how you process any personal data collected through those cookies. The two operate in parallel. You need to comply with both.

In May 2025, Datatilsynet and Digitaliseringsstyrelsen published joint guidance on cookies and tracking technologies, confirming the overlap and coordinating their enforcement approach for 2026.

Only two exemptions exist. A cookie is exempt if its sole purpose is transmitting a communication over a network, or if it's strictly necessary to deliver a service the user explicitly requested. Session management, shopping carts, language settings, consent status storage. That's it. The Cookiebekendtgorelsen Section 4 is exhaustive.

Analytics cookies aren't exempt. Not for first-party analytics. Not for privacy-friendly analytics. Not for self-hosted analytics. If your tool stores data on or reads data from the visitor's device, you need consent.

One nuance worth knowing: the old Business Authority said in 2021 it would deprioritize enforcing simple first-party statistics cookies. The legal requirement never changed, and Digitaliseringsstyrelsen now holds the pen. This is the critical difference from France. CNIL maintains a formal consent exemption for analytics: qualifying tools can operate without a cookie banner if they meet strict conditions (first-party only, no cross-site tracking, 13-month cookie limit; CNIL evaluated 23 tools before moving to self-assessment in 2026). Denmark has no such framework. No approved list. No exemption criteria. Every analytics cookie requires consent, period.

Denmark vs. France: analytics consent requirements
Denmark (Cookiebekendtgorelsen)
No consent exemption for analytics
No approved tools list
All analytics cookies need prior consent
Legitimate interest does not apply
Two enforcement bodies (Datatilsynet + Digitaliseringsstyrelsen)
France (CNIL)
Formal consent exemption since 2013 (updated 2020)
22 tools evaluated and approved
Exempt tools: no banner needed for analytics
Self-assessment framework from 2026
Single enforcer (CNIL handles both cookie + GDPR)
Cookieless analytics (no device storage at all) avoid the Cookiebekendtgorelsen consent requirement entirely, because no data is stored on or read from the user's device.

"Legitimate interest" doesn't bypass this. Even if you argue legitimate interest as your GDPR legal basis, the Cookiebekendtgorelsen consent requirement applies independently at the device-access layer. Consent is the only legal basis for placing a non-essential cookie on a Danish visitor's device.

And the rules are technology-neutral. Cookies, local storage, fingerprinting, pixel tags, device identifiers, SDKs. If it reads from or writes to your visitor's device, you need consent.

Datatilsynet: 74 people, a unique enforcement model, and a Supreme Court judge

Datatilsynet is Denmark's data protection authority. It has 74 employees working on a budget of DKK 59.1 million (~EUR 7.9 million). That means roughly EUR 107,000 per head to police a whole country's data. In 2024, they handled 18,816 new cases, including 9,624 data breach notifications. That means about 254 new cases per employee per year. The caseload has nearly doubled since 2020.

What makes Denmark truly unusual is its enforcement model. Under the Danish Constitution, administrative fines aren't permitted. GDPR Recital 151 explicitly carves out Denmark (and Estonia) from the standard EU administrative fine system. Datatilsynet can't issue fines. It investigates, concludes, and then files a police report with a recommended fine amount. The police investigate further. If charges are brought, the case goes to a court that determines guilt and the fine.

This three-step process creates a dramatic gap between what Datatilsynet recommends and what courts impose.

Datatilsynet proposed vs. court-imposed fines
Netcompany (mit.dk digital mailbox)
Security failures in national digital mail system. Users accessed others' government mail.
DKK 15M proposed
Court pending
Danske Bank
No deletion rules for personal data across 400+ systems. Millions affected.
DKK 10M proposed
Court pending
IDdesign (ILVA furniture)
350,000 customer records kept without deletion deadlines.
DKK 1.5M proposed
DKK 100K imposed
Taxa 4x35 (taxi company)
8.9 million taxi trips with phone numbers retained 3+ years beyond necessary.
DKK 1.2M proposed
DKK 250K imposed
Arp-Hansen Hotel Group
500,000 customer profiles stored without legitimate purpose.
DKK 1.1M proposed
DKK 1M imposed

IDdesign: proposed DKK 1.5 million, court imposed DKK 100,000. Taxa 4x35: proposed DKK 1.2 million, court imposed DKK 250,000 on appeal. In plain English: courts pay out 5 to 25 cents on the regulator's krone. An INPLP analysis warned that Denmark risks becoming a "safe haven" for GDPR violations because "the fine for non-compliance is much lower than the costs" of compliance.

But I wouldn't let the fine gap mislead you. Datatilsynet's approach is shifting. As Danish privacy consultant Henrik Rubaek Jorgensen told Openli: "There used to be an understanding in the Danish Data Protection Agency that the rules were complex and difficult to understand, and at that time they wanted to be more of a guiding authority than a sanctioning one. But the approach has now started to change, and they are now reporting companies and municipalities to the police."

The Data Council that decides precedent-setting cases is chaired by Supreme Court Judge Kristian Korfits Nielsen. When the regulator's decision-making body is led by a Supreme Court judge, the guidance carries weight beyond the fines.

Google Analytics: the transfer ban fell, the tool was never cleared

On September 21, 2022, Datatilsynet declared Google Analytics non-compliant with GDPR. Denmark became the fourth EU country to reach this conclusion, after Austria (December 2021), France (February 2022), and Italy (June 2022). Nordic neighbours Sweden and Norway followed soon after. The rulings were coordinated through an EDPB task force responding to noyb's 101 complaints filed in August 2020.

Datatilsynet's chief consultant Makar Juhl Holst stated: "We have carefully reviewed the possible settings of Google Analytics and have come to the conclusion that you cannot use the tool in its current form without implementing supplementary measures."

The ruling explicitly covered both Universal Analytics and GA4. Datatilsynet evaluated GA4's privacy settings released in summer 2022 and found them insufficient. Even though GA4 uses IP addresses only to determine location and then discards them, there's still a direct connection to American servers before discarding occurs. US authorities could access the data during that window.

The only approved supplementary measure: a reverse proxy server that strips all identifying data before it reaches Google. Dansk Erhverv (the Danish Chamber of Commerce) estimated that at least 8 out of 10 Danish companies used GA at the time. Which means the ruling touched nearly every business in the country. Their digital commerce director Carsten Rose Lundberg called the proxy approach "cost-heavy" and warned it produces "a worse end product."

Then came the Data Privacy Framework. In July 2023, the European Commission adopted the EU-US Data Privacy Framework (DPF). Google certified. The specific transfer problem that Datatilsynet flagged was technically resolved.

But Datatilsynet's response wasn't "Google Analytics is legal again." Their July 31, 2023 statement accepted that transfers to DPF-certified companies, Google included, are lawful again. But it pushed back on the conclusion everyone wanted to draw: Datatilsynet "has not taken a position on whether Google Analytics is lawful" and stressed that organizations must still satisfy every other GDPR requirement. Legal basis for processing (consent). Data processor agreements. Data subject rights. Transparency. In plain English: the transfer objection fell, the tool never got a clean bill of health.

Google Analytics legal status in Denmark: timeline
Jul 2020
CJEU strikes down Privacy Shield (Schrems II). US data transfers lose their legal basis.
Aug 2020
noyb files 101 complaints across 30 EU/EEA states, including 3 targeting Danish companies.
Jan 2022
Datatilsynet issues "serious criticism" of Den Bla Avis for consent and GA data transfers.
Sep 2022
Datatilsynet declares Google Analytics non-GDPR-compliant. 4th EU country after Austria, France, Italy.
Jul 2023
EU-US Data Privacy Framework adopted. Google certified. Transfer issue temporarily resolved.
Jul 2023
Datatilsynet warns: "has not taken a position on whether GA is lawful." Other GDPR requirements remain.
Jan 2025
Trump fires PCLOB members. The oversight board the DPF relies on can no longer function.
2026
Datatilsynet makes cookie consent a top enforcement priority. CJEU reviewing Latombe's DPF challenge.

The DPF's durability is uncertain. The US Privacy and Civil Liberties Oversight Board (PCLOB), referenced 31 times in the European Commission's adequacy decision, was gutted by the Trump administration in January 2025. It can't form a quorum, can't conduct investigations, and can't perform the annual DPF review the adequacy decision relies on. French MP Philippe Latombe's appeal to the CJEU is pending. This is the same court that struck down both Safe Harbor and Privacy Shield.

If the DPF falls and you're on Google Analytics, you're back in September 2022 overnight. No legal basis for transfers. No transition period. Norway's Datatilsynet has already warned businesses to prepare exit strategies.

Datatilsynet's 2026 enforcement plan is blunt: "Studies are still being published regularly showing extensive collection of personal data continues on Danish websites, and where citizens do not have a real opportunity to say no to tracking technologies." Our cookie banner decision flowchart walks through the design choices Datatilsynet keeps flagging.

The numbers I found back this up, with one caveat: the big study comes from Cookie Information, a consent-platform vendor, so it's measuring the problem it sells the cure for. Their 2024 compliance report found that 94% of Danish websites have a cookie banner (up from 91% in 2023). The government's own 200-site sweep found pre-consent tracking almost everywhere, so the direction holds. But 84% of those banners have compliance issues (up from 79% in 2023). In plain English: 5 in 6 Danish banners fail. The direction is wrong: more banners, more violations. And the most common violation is the most serious one: 70% of analyzed sites set non-essential cookies before the visitor makes any choice at all. That means the banner is theater on 7 sites in 10.

The worst sectors: Sports (89% violation rate), E-commerce (83%), Arts and Culture (82%). Put another way: 9 sports sites in 10 are breaking the rules.

Danish website cookie compliance
84%
of Danish websites have cookie compliance violations
up from 79% in 2023
70%
fire cookies before consent
94%
have a cookie banner
89%
sports sites violate

Datatilsynet has already acted on cookie violations, and the three cases I keep coming back to say it all. JP/Politikens Hus (publisher of eb.dk) received "serious criticism" in October 2022 for a cookie banner that used a traffic-light color scheme: green "Accept All," red "Only necessary," grey "Customize." Datatilsynet ruled the color coding was impermissible nudging. Consent information was hidden behind a second layer. The consent was invalid.

An illustration of a Danish news site with a cookie consent banner using a traffic-light button pattern: a small grey Tilpas button, a red Kun nodvendige button, and a large green Accepter alle button, annotated with the nudging problems Datatilsynet identified.
Recreated for illustration: the traffic-light consent pattern Datatilsynet faulted at eb.dk. Color-coding the buttons steers the click, and steered consent isn't valid consent. One correction to the annotations in this graphic: the decision came in October 2022, and the formal sanction was "serious criticism," not a reprimand.

Berlingske was ordered to change its practice of blocking embedded video and blog content unless users consented to statistics and marketing cookies. Datatilsynet found that forcing users to accept analytics tracking as the price for watching a video doesn't produce valid consent.

DMI (Denmark's Meteorological Institute, the national weather service) received "serious criticism" for running Google's advertising platform on dmi.dk. Consent was bundled into a single "OK" button, with insufficient information and asymmetric friction for declining. A government weather website, running behavioral advertising, with invalid consent. That, I think, is where the bar sits in Denmark.

Anette Hoyrup of the Danish Consumer Council (Forbrugerradet Taenk) put it plainly: "The law doesn't work. Five years have passed, and consumers simply do not know what is going on."

An illustration of a Chrome browser with DevTools docked at the bottom, viewing a generic Danish news site with the AVISEN wordmark, in Danish UI. A cookie consent banner is visible at the bottom of the viewport in the not-yet-clicked state with a green 'Accepter alle' button and a pale 'Kun nødvendige' button. The DevTools Application panel is selected, showing the Cookies inspector with the Storage > Cookies node highlighted in the left tree. Six yellow-highlighted tracker cookies are visible in the cookies table: _ga, _ga_XXXXXXXX, _gid, _gat_UA-XXXXX-X, _fbp, and _hjSessionUser, all set before the consent banner was clicked. Two non-highlighted essential cookies are also present: cookieconsent_status set to deny, and PHPSESSID. Three red annotations read 'Cookie banner not yet clicked,' '6 tracking cookies already set. Pre-consent.,' and '70% of Danish sites do this. Datatilsynet's #1 enforcement target for 2026.'
Recreated for illustration: Chrome DevTools on a Danish news site, before the cookie banner is touched. Six tracking cookies (_ga, _gid, _fbp, _hjSessionUser, and two more) are already on the device. This is the 70% pattern Datatilsynet is going after in 2026.

What you lose when visitors click "Reject"

Even if your cookie banner is perfectly compliant, it's costing you most of your data. You paid for compliance and you still lost the numbers.

Denmark's population is among the most digitally sophisticated in the EU. The country ranks number one globally in e-government for the fourth consecutive year. 99% internet penetration. 96% of adults use MitID, the national digital ID. 46% of Danish internet users actively manage cookie settings according to Eurostat, well above the EU average. Which means nearly every 2nd Danish visitor curates what you may track.

This isn't a population that blindly clicks "Accept All." Under a compliant cookie banner (equal-prominence accept and reject buttons, no dark patterns), the majority of Danish visitors will decline. Combined with ad blocker adoption in the high 30s for Nordic countries and Safari at 28.4% of Danish browser traffic (with Intelligent Tracking Prevention blocking third-party cookies), cookie-based analytics on a Danish website see a fraction of actual traffic. In practice you're often counting roughly 1 visitor in 4.

If Clickport tracks your site, you'd see nearly all of your visitors from day one. No consent wall, nothing for the banner to reject, and far less surface for ad blockers to catch. Our privacy-friendly analytics guide walks through how this works across the Nordics and EU.

Your analytics blind spot in Denmark
Estimate how much of your Danish traffic you never see in cookie-based analytics.
39,150
Invisible visitors
10,850
Visible to GA4
Your Danish traffic data covers just 22% of your actual traffic.

Carsten Rose Lundberg of Dansk Erhverv captured the practical impact: "Data has value only if it can be compared with something." When your analytics see 22% of your traffic, you're not just missing data. You're making decisions on a sample that's systematically biased toward visitors who accept cookies, which skews toward repeat visitors, loyal customers, and the least privacy-conscious segment of your audience. New visitors, privacy-aware users, and the majority of your actual traffic are invisible to you.

The country that armed both sides

Here's the part of Denmark's privacy story that I never see anyone connect.

Denmark produced two of the world's largest cookie consent platforms. Cookiebot (Cybot A/S) was founded in Copenhagen in 2012 by Daniel Johannsen. It now runs on over 2 million websites globally and merged with Usercentrics in 2021 to become the world's largest consent management platform. Cookie Information launched its consent management platform in Copenhagen in 2017, became the second-largest third party on the 100 most visited Danish websites (surpassed only by Google), and merged with Piwik PRO in 2023 to create a combined consent-plus-analytics platform.

Two of Europe's most significant consent management companies, both from Copenhagen, both selling the world the paperwork for a problem their home market still fails at.

Key insight
Denmark built the tools the world uses to manage cookie consent. Then it declared Google Analytics non-compliant, made cookie enforcement a 2026 priority, and discovered that 84% of its own websites still violate the rules it helped pioneer. Denmark armed both sides of the cookie war.
An editorial reconstruction of the TastSelv Borger CPR leak. The upper portion shows an oversized Chrome address bar with a URL broken into color-coded segments: 'https://', a blurred Danish tax portal domain '[BLURRED-DOMAIN].dk', the path '/borger/profil/opdater?', the highlighted parameter 'cpr=XXXXXX-XXXX' in red bold, and the trailing 'utm_source=mail&utm_campaign=profil' query string. Four red annotations point at the URL: 'TASTSELV BORGER LEAK. 2015 to 2020. 1.26 million Danes.,' 'Your national ID number, in plain text, in the URL.,' 'Sent to Google Analytics on every page-view request. For 5 years.,' and 'Format: DDMMYY-XXXX. Birth date plus four digits. Used for taxes, healthcare, banking, voting.' The lower portion shows two side-by-side cards titled THE SOFTWARE BUG and WHY IT MATTERS, each with three body lines and a red footer line ('One-fifth of Denmark's population.' and 'Datatilsynet's institutional memory.'). A bottom footnote credits Infosecurity Magazine, January 2020, and discloses that the CPR numbers shown are placeholders only.
Recreated for illustration: the TastSelv Borger leak in one frame. The CPR (Danish national ID) number was appended to every profile-update URL and sent to Google Analytics on every page-view event from 2015 to 2020. One-fifth of Denmark's population.

And here's the irony I can't get past. Between 2015 and 2020, Denmark's own tax portal (TastSelv Borger) leaked the CPR numbers of 1.26 million Danish citizens through Google Analytics. A software bug appended citizens' national ID numbers to the URL every time they updated account settings, sending those numbers to Google and Adobe analytics. One-fifth of Denmark's population. For five years. In plain English: 1 Dane in 5 had their national ID sitting in a US analytics tool. The country learned firsthand what happens when analytics tools access data they shouldn't.

Denmark doesn't just regulate cookie consent. It experienced the consequences of getting it wrong, built the tools to fix it, and then set some of the strictest rules in Europe. That history is why I'd take Datatilsynet's 2026 enforcement push seriously. It isn't regulatory posturing.

What's coming: the Digital Omnibus and Denmark's own push

Denmark is simultaneously enforcing strict cookie consent rules domestically while pushing to loosen them at the EU level. That's not a contradiction, as I read it. It's strategy.

During its EU Council Presidency (July-December 2025), Denmark circulated a non-paper proposing targeted revisions to the GDPR and ePrivacy Directive. The key proposal: exempt companies from cookie consent where personal data is collected for "technical purposes and simple statistics." Justice Minister Peter Hummelgaard told Euronews: "We will set a focus on modernising the regulatory landscape, by specially focusing on the GDPR."

The resulting Digital Omnibus reflects Denmark's push. As a Regulation, it would partially supersede the Cookiebekendtgorelsen. I'd pencil in mid-2027 to 2028.

Until the Omnibus passes, Denmark's current rules remain in force. Every analytics cookie requires consent. The fastest way to see your whole audience again without waiting for EU legislation: use analytics that don't store anything on the visitor's device in the first place.

Check your own site
See what your site loads before consent.
Paste your URL into the free GDPR checker. It reads your page source, identifies every tracking script, and checks whether each one is gated behind consent, which is where Datatilsynet's guidance starts. No signup, about thirty seconds.
Scan your site for trackers →

What this means for your website

If you run a website that serves Danish visitors, here's where you stand.

If you're using Google Analytics with a cookie banner: Your US data transfers are covered by the DPF (for now), but you need valid cookie consent under the Cookiebekendtgorelsen. That means equal-prominence accept and reject buttons, no pre-loaded cookies, granular purpose selection, and easy withdrawal. If your banner fails any of these, Datatilsynet's 2026 enforcement priority targets exactly this. And even with a perfect banner, the majority of your Danish visitors will be invisible to you.

If your cookie banner isn't compliant: You're in the 84%. Datatilsynet and Digitaliseringsstyrelsen are coordinating inspections in 2026. The most common violation (cookies before consent) affects 70% of Danish sites; a free scan shows in seconds whether yours is one of them. Even under Denmark's court-based enforcement model, non-compliance carries real consequences: reprimands, compliance orders, police reports, and fines up to 4% of global revenue under GDPR.

If you want accurate data without the compliance risk: cookieless analytics, the category I build in, falls outside the Cookiebekendtgorelsen entirely. No device access means no consent trigger. Datatilsynet's 2026 cookie enforcement priority becomes irrelevant for your analytics setup. We compared the leading tools in this category in our GA alternatives breakdown.

Cookie-based vs. cookieless analytics under Danish law
Cookie-based analytics
Requires consent banner (Cookiebekendtgorelsen)
65%+ of visitors invisible after rejection
Ad blockers block GA: ~38%
Datatilsynet 2026 enforcement target
DPF dependency for US data transfers
Cookieless analytics
Falls outside Cookiebekendtgorelsen entirely
No consent gate, so no rejected-visitor data gap
Counts the visitors who click Reject All
Server-side processing, no device access
Not affected by Datatilsynet's 2026 enforcement sweep
The Cookiebekendtgorelsen targets device access. Analytics that process only server-side HTTP request data avoid the consent trigger at its source.

Denmark ranks number one in the world for digital government. Its citizens are among the most digitally literate in Europe. That sophistication is why cookie-based analytics fail harder here than almost anywhere else. The visitors you're missing aren't random. They're the ones who know what "Reject All" means and aren't afraid to click it.

Frequently asked questions

Datatilsynet declared Google Analytics non-compliant with GDPR in September 2022. The EU-US Data Privacy Framework (July 2023) made the US transfers lawful again, but Datatilsynet has pointedly declined to call the tool lawful as a whole. You still need valid cookie consent under the Cookiebekendtgorelsen, a data processor agreement with Google, and compliance with all GDPR requirements. The DPF itself is being challenged at the CJEU.

Yes, for any analytics tool that stores data on or reads data from the visitor's device (cookies, local storage, fingerprinting). The Cookiebekendtgorelsen Section 4 provides only two narrow exemptions: cookies for transmitting communications and cookies strictly necessary for a requested service. Analytics cookies are explicitly not exempt. Unlike France, Denmark has no consent exemption framework for privacy-friendly analytics tools. Cookieless analytics that don't touch the visitor's device fall outside the Cookiebekendtgorelsen entirely.

What is the Cookiebekendtgorelsen?

The Cookiebekendtgorelsen (BEK nr 1148 af 09/12/2011) is Denmark's implementation of the EU ePrivacy Directive. It requires prior informed consent before storing information on or accessing information from a user's terminal equipment. It's supervised by Digitaliseringsstyrelsen (not Datatilsynet). The GDPR applies on top of it for any personal data processing. A non-compliant cookie banner can trigger enforcement from both authorities simultaneously.

Analytics tools that don't set cookies, don't fingerprint visitors, and don't track across sites avoid the Cookiebekendtgorelsen's consent trigger. The law applies to "storage of or access to information on end-user terminal equipment." If the tool also processes no personal data (anonymous aggregation only), the GDPR consent requirement doesn't apply either. This is why cookieless, privacy-first analytics can operate without a consent banner in Denmark.

Which analytics tools can I use without a banner in Denmark?

Any tool that doesn't store or read anything on the visitor's device and doesn't process personal data. That's the whole test. You don't get a French-style approved list in Denmark, so you check the two conditions yourself: no device access, no personal data. Clickport was built to pass both, but I'd rather you verify than take my word for it: run the free scanner on any tool's demo page and look at what it stores.

Denmark has a unique enforcement model: Datatilsynet can't issue fines directly (GDPR Recital 151). It recommends fines to police, who prosecute through courts. Courts have historically imposed much lower fines than recommended (IDdesign: DKK 1.5M proposed, DKK 100K imposed). The largest court-imposed GDPR fine is DKK 1 million (Arp-Hansen Hotels, 2023). Datatilsynet's largest recommendation is DKK 15 million against Netcompany (2024, court pending). Under GDPR, fines can reach 4% of global annual turnover or EUR 20 million. In plain English: the EU ceiling dwarfs anything a Danish court has imposed so far.

The DPF (adopted July 2023) resolved the specific US data transfer issue from Datatilsynet's September 2022 ruling. But Datatilsynet explicitly warned that "using Google Analytics requires not only lawful transfers to the USA." You still need valid cookie consent, a data processor agreement, and compliance with all GDPR requirements. And the DPF's durability is uncertain: the PCLOB has been gutted, and the framework is being challenged at the CJEU. If it falls, there would likely be no transition period.

One more thing, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or the source it came from. If your setup is complicated, show this to your DPO or lawyer.

And if you're staring at a Danish cookie banner decision right now and something here doesn't match what you're seeing, email me.

David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment