Is Google Analytics Legal in Denmark? Cookie Consent, 84% Non-Compliant, and What's Coming

84% of Danish websites violate cookie consent rules. 70% fire tracking cookies before asking permission. In plain English: 7 sites in 10 track first and ask later. Datatilsynet just made cookie enforcement a 2026 priority. If you run a website in Denmark and use cookie-based analytics, the question isn't whether you're compliant. It's whether you get caught before you fix it. And Google Analytics isn't in the clear.
- Datatilsynet declared Google Analytics non-compliant in September 2022. The EU-US Data Privacy Framework made US transfers lawful again in July 2023, but Datatilsynet has refused to call GA4 lawful: valid consent and the rest of GDPR still apply, and the DPF itself is under appeal at the CJEU.
- Denmark has zero consent exemptions for analytics cookies. Unlike France (a formal analytics exemption) or Spain (first-party exemption), every analytics cookie on a Danish website requires prior opt-in consent under the Cookiebekendtgorelsen.
- 84% of Danish websites have cookie compliance violations, and 70% fire tracking cookies before consent. Datatilsynet made cookie enforcement a top priority for 2026, coordinating inspections with Digitaliseringsstyrelsen.
- Denmark cannot issue GDPR fines directly (GDPR Recital 151). Datatilsynet recommends fines to police, who prosecute through courts. The largest court-imposed GDPR fine to date: DKK 1 million (Arp-Hansen Hotels, 2023). Datatilsynet proposed DKK 15 million against Netcompany in 2024.
- Denmark pushed for an EU-wide analytics consent exemption during its 2025 Council Presidency. The Digital Omnibus (proposed November 2025) would allow aggregated audience measurement without consent. Google Analytics would not qualify. Cookieless, first-party analytics would.
The rules you're subject to
Cookie consent in Denmark is governed by two overlapping laws, enforced by two separate authorities. I'll untangle them for you first.
The first is the Cookiebekendtgorelsen (BEK nr 1148 af 09/12/2011), Denmark's implementation of the EU ePrivacy Directive. Issued under Section 9 of the Teleloven (Telecommunications Act), it requires consent before any non-essential data is stored on or read from a visitor's device. Supervised by Digitaliseringsstyrelsen (the Danish Agency for Digital Government, which took over from the Danish Business Authority in December 2022).
The second is the GDPR, enforced by Datatilsynet. It governs how you process any personal data collected through those cookies. The two operate in parallel. You need to comply with both.
In May 2025, Datatilsynet and Digitaliseringsstyrelsen published joint guidance on cookies and tracking technologies, confirming the overlap and coordinating their enforcement approach for 2026.
Only two exemptions exist. A cookie is exempt if its sole purpose is transmitting a communication over a network, or if it's strictly necessary to deliver a service the user explicitly requested. Session management, shopping carts, language settings, consent status storage. That's it. The Cookiebekendtgorelsen Section 4 is exhaustive.
Analytics cookies aren't exempt. Not for first-party analytics. Not for privacy-friendly analytics. Not for self-hosted analytics. If your tool stores data on or reads data from the visitor's device, you need consent.
One nuance worth knowing: the old Business Authority said in 2021 it would deprioritize enforcing simple first-party statistics cookies. The legal requirement never changed, and Digitaliseringsstyrelsen now holds the pen. This is the critical difference from France. CNIL maintains a formal consent exemption for analytics: qualifying tools can operate without a cookie banner if they meet strict conditions (first-party only, no cross-site tracking, 13-month cookie limit; CNIL evaluated 23 tools before moving to self-assessment in 2026). Denmark has no such framework. No approved list. No exemption criteria. Every analytics cookie requires consent, period.
"Legitimate interest" doesn't bypass this. Even if you argue legitimate interest as your GDPR legal basis, the Cookiebekendtgorelsen consent requirement applies independently at the device-access layer. Consent is the only legal basis for placing a non-essential cookie on a Danish visitor's device.
And the rules are technology-neutral. Cookies, local storage, fingerprinting, pixel tags, device identifiers, SDKs. If it reads from or writes to your visitor's device, you need consent.
Datatilsynet: 74 people, a unique enforcement model, and a Supreme Court judge
Datatilsynet is Denmark's data protection authority. It has 74 employees working on a budget of DKK 59.1 million (~EUR 7.9 million). That means roughly EUR 107,000 per head to police a whole country's data. In 2024, they handled 18,816 new cases, including 9,624 data breach notifications. That means about 254 new cases per employee per year. The caseload has nearly doubled since 2020.
What makes Denmark truly unusual is its enforcement model. Under the Danish Constitution, administrative fines aren't permitted. GDPR Recital 151 explicitly carves out Denmark (and Estonia) from the standard EU administrative fine system. Datatilsynet can't issue fines. It investigates, concludes, and then files a police report with a recommended fine amount. The police investigate further. If charges are brought, the case goes to a court that determines guilt and the fine.
This three-step process creates a dramatic gap between what Datatilsynet recommends and what courts impose.
IDdesign: proposed DKK 1.5 million, court imposed DKK 100,000. Taxa 4x35: proposed DKK 1.2 million, court imposed DKK 250,000 on appeal. In plain English: courts pay out 5 to 25 cents on the regulator's krone. An INPLP analysis warned that Denmark risks becoming a "safe haven" for GDPR violations because "the fine for non-compliance is much lower than the costs" of compliance.
But I wouldn't let the fine gap mislead you. Datatilsynet's approach is shifting. As Danish privacy consultant Henrik Rubaek Jorgensen told Openli: "There used to be an understanding in the Danish Data Protection Agency that the rules were complex and difficult to understand, and at that time they wanted to be more of a guiding authority than a sanctioning one. But the approach has now started to change, and they are now reporting companies and municipalities to the police."
The Data Council that decides precedent-setting cases is chaired by Supreme Court Judge Kristian Korfits Nielsen. When the regulator's decision-making body is led by a Supreme Court judge, the guidance carries weight beyond the fines.
Google Analytics: the transfer ban fell, the tool was never cleared
On September 21, 2022, Datatilsynet declared Google Analytics non-compliant with GDPR. Denmark became the fourth EU country to reach this conclusion, after Austria (December 2021), France (February 2022), and Italy (June 2022). Nordic neighbours Sweden and Norway followed soon after. The rulings were coordinated through an EDPB task force responding to noyb's 101 complaints filed in August 2020.
Datatilsynet's chief consultant Makar Juhl Holst stated: "We have carefully reviewed the possible settings of Google Analytics and have come to the conclusion that you cannot use the tool in its current form without implementing supplementary measures."
The ruling explicitly covered both Universal Analytics and GA4. Datatilsynet evaluated GA4's privacy settings released in summer 2022 and found them insufficient. Even though GA4 uses IP addresses only to determine location and then discards them, there's still a direct connection to American servers before discarding occurs. US authorities could access the data during that window.
The only approved supplementary measure: a reverse proxy server that strips all identifying data before it reaches Google. Dansk Erhverv (the Danish Chamber of Commerce) estimated that at least 8 out of 10 Danish companies used GA at the time. Which means the ruling touched nearly every business in the country. Their digital commerce director Carsten Rose Lundberg called the proxy approach "cost-heavy" and warned it produces "a worse end product."
Then came the Data Privacy Framework. In July 2023, the European Commission adopted the EU-US Data Privacy Framework (DPF). Google certified. The specific transfer problem that Datatilsynet flagged was technically resolved.
But Datatilsynet's response wasn't "Google Analytics is legal again." Their July 31, 2023 statement accepted that transfers to DPF-certified companies, Google included, are lawful again. But it pushed back on the conclusion everyone wanted to draw: Datatilsynet "has not taken a position on whether Google Analytics is lawful" and stressed that organizations must still satisfy every other GDPR requirement. Legal basis for processing (consent). Data processor agreements. Data subject rights. Transparency. In plain English: the transfer objection fell, the tool never got a clean bill of health.
The DPF's durability is uncertain. The US Privacy and Civil Liberties Oversight Board (PCLOB), referenced 31 times in the European Commission's adequacy decision, was gutted by the Trump administration in January 2025. It can't form a quorum, can't conduct investigations, and can't perform the annual DPF review the adequacy decision relies on. French MP Philippe Latombe's appeal to the CJEU is pending. This is the same court that struck down both Safe Harbor and Privacy Shield.
If the DPF falls and you're on Google Analytics, you're back in September 2022 overnight. No legal basis for transfers. No transition period. Norway's Datatilsynet has already warned businesses to prepare exit strategies.
The cookie consent gap: 84% non-compliant
Datatilsynet's 2026 enforcement plan is blunt: "Studies are still being published regularly showing extensive collection of personal data continues on Danish websites, and where citizens do not have a real opportunity to say no to tracking technologies." Our cookie banner decision flowchart walks through the design choices Datatilsynet keeps flagging.
The numbers I found back this up, with one caveat: the big study comes from Cookie Information, a consent-platform vendor, so it's measuring the problem it sells the cure for. Their 2024 compliance report found that 94% of Danish websites have a cookie banner (up from 91% in 2023). The government's own 200-site sweep found pre-consent tracking almost everywhere, so the direction holds. But 84% of those banners have compliance issues (up from 79% in 2023). In plain English: 5 in 6 Danish banners fail. The direction is wrong: more banners, more violations. And the most common violation is the most serious one: 70% of analyzed sites set non-essential cookies before the visitor makes any choice at all. That means the banner is theater on 7 sites in 10.
The worst sectors: Sports (89% violation rate), E-commerce (83%), Arts and Culture (82%). Put another way: 9 sports sites in 10 are breaking the rules.
Datatilsynet has already acted on cookie violations, and the three cases I keep coming back to say it all. JP/Politikens Hus (publisher of eb.dk) received "serious criticism" in October 2022 for a cookie banner that used a traffic-light color scheme: green "Accept All," red "Only necessary," grey "Customize." Datatilsynet ruled the color coding was impermissible nudging. Consent information was hidden behind a second layer. The consent was invalid.
Berlingske was ordered to change its practice of blocking embedded video and blog content unless users consented to statistics and marketing cookies. Datatilsynet found that forcing users to accept analytics tracking as the price for watching a video doesn't produce valid consent.
DMI (Denmark's Meteorological Institute, the national weather service) received "serious criticism" for running Google's advertising platform on dmi.dk. Consent was bundled into a single "OK" button, with insufficient information and asymmetric friction for declining. A government weather website, running behavioral advertising, with invalid consent. That, I think, is where the bar sits in Denmark.
Anette Hoyrup of the Danish Consumer Council (Forbrugerradet Taenk) put it plainly: "The law doesn't work. Five years have passed, and consumers simply do not know what is going on."
What you lose when visitors click "Reject"
Even if your cookie banner is perfectly compliant, it's costing you most of your data. You paid for compliance and you still lost the numbers.
Denmark's population is among the most digitally sophisticated in the EU. The country ranks number one globally in e-government for the fourth consecutive year. 99% internet penetration. 96% of adults use MitID, the national digital ID. 46% of Danish internet users actively manage cookie settings according to Eurostat, well above the EU average. Which means nearly every 2nd Danish visitor curates what you may track.
This isn't a population that blindly clicks "Accept All." Under a compliant cookie banner (equal-prominence accept and reject buttons, no dark patterns), the majority of Danish visitors will decline. Combined with ad blocker adoption in the high 30s for Nordic countries and Safari at 28.4% of Danish browser traffic (with Intelligent Tracking Prevention blocking third-party cookies), cookie-based analytics on a Danish website see a fraction of actual traffic. In practice you're often counting roughly 1 visitor in 4.
If Clickport tracks your site, you'd see nearly all of your visitors from day one. No consent wall, nothing for the banner to reject, and far less surface for ad blockers to catch. Our privacy-friendly analytics guide walks through how this works across the Nordics and EU.
Carsten Rose Lundberg of Dansk Erhverv captured the practical impact: "Data has value only if it can be compared with something." When your analytics see 22% of your traffic, you're not just missing data. You're making decisions on a sample that's systematically biased toward visitors who accept cookies, which skews toward repeat visitors, loyal customers, and the least privacy-conscious segment of your audience. New visitors, privacy-aware users, and the majority of your actual traffic are invisible to you.
The country that armed both sides
Here's the part of Denmark's privacy story that I never see anyone connect.
Denmark produced two of the world's largest cookie consent platforms. Cookiebot (Cybot A/S) was founded in Copenhagen in 2012 by Daniel Johannsen. It now runs on over 2 million websites globally and merged with Usercentrics in 2021 to become the world's largest consent management platform. Cookie Information launched its consent management platform in Copenhagen in 2017, became the second-largest third party on the 100 most visited Danish websites (surpassed only by Google), and merged with Piwik PRO in 2023 to create a combined consent-plus-analytics platform.
Two of Europe's most significant consent management companies, both from Copenhagen, both selling the world the paperwork for a problem their home market still fails at.
And here's the irony I can't get past. Between 2015 and 2020, Denmark's own tax portal (TastSelv Borger) leaked the CPR numbers of 1.26 million Danish citizens through Google Analytics. A software bug appended citizens' national ID numbers to the URL every time they updated account settings, sending those numbers to Google and Adobe analytics. One-fifth of Denmark's population. For five years. In plain English: 1 Dane in 5 had their national ID sitting in a US analytics tool. The country learned firsthand what happens when analytics tools access data they shouldn't.
Denmark doesn't just regulate cookie consent. It experienced the consequences of getting it wrong, built the tools to fix it, and then set some of the strictest rules in Europe. That history is why I'd take Datatilsynet's 2026 enforcement push seriously. It isn't regulatory posturing.
What's coming: the Digital Omnibus and Denmark's own push
Denmark is simultaneously enforcing strict cookie consent rules domestically while pushing to loosen them at the EU level. That's not a contradiction, as I read it. It's strategy.
During its EU Council Presidency (July-December 2025), Denmark circulated a non-paper proposing targeted revisions to the GDPR and ePrivacy Directive. The key proposal: exempt companies from cookie consent where personal data is collected for "technical purposes and simple statistics." Justice Minister Peter Hummelgaard told Euronews: "We will set a focus on modernising the regulatory landscape, by specially focusing on the GDPR."
The resulting Digital Omnibus reflects Denmark's push. As a Regulation, it would partially supersede the Cookiebekendtgorelsen. I'd pencil in mid-2027 to 2028.
Until the Omnibus passes, Denmark's current rules remain in force. Every analytics cookie requires consent. The fastest way to see your whole audience again without waiting for EU legislation: use analytics that don't store anything on the visitor's device in the first place.
What this means for your website
If you run a website that serves Danish visitors, here's where you stand.
If you're using Google Analytics with a cookie banner: Your US data transfers are covered by the DPF (for now), but you need valid cookie consent under the Cookiebekendtgorelsen. That means equal-prominence accept and reject buttons, no pre-loaded cookies, granular purpose selection, and easy withdrawal. If your banner fails any of these, Datatilsynet's 2026 enforcement priority targets exactly this. And even with a perfect banner, the majority of your Danish visitors will be invisible to you.
If your cookie banner isn't compliant: You're in the 84%. Datatilsynet and Digitaliseringsstyrelsen are coordinating inspections in 2026. The most common violation (cookies before consent) affects 70% of Danish sites; a free scan shows in seconds whether yours is one of them. Even under Denmark's court-based enforcement model, non-compliance carries real consequences: reprimands, compliance orders, police reports, and fines up to 4% of global revenue under GDPR.
If you want accurate data without the compliance risk: cookieless analytics, the category I build in, falls outside the Cookiebekendtgorelsen entirely. No device access means no consent trigger. Datatilsynet's 2026 cookie enforcement priority becomes irrelevant for your analytics setup. We compared the leading tools in this category in our GA alternatives breakdown.
Denmark ranks number one in the world for digital government. Its citizens are among the most digitally literate in Europe. That sophistication is why cookie-based analytics fail harder here than almost anywhere else. The visitors you're missing aren't random. They're the ones who know what "Reject All" means and aren't afraid to click it.
Frequently asked questions
Is Google Analytics legal in Denmark?
Datatilsynet declared Google Analytics non-compliant with GDPR in September 2022. The EU-US Data Privacy Framework (July 2023) made the US transfers lawful again, but Datatilsynet has pointedly declined to call the tool lawful as a whole. You still need valid cookie consent under the Cookiebekendtgorelsen, a data processor agreement with Google, and compliance with all GDPR requirements. The DPF itself is being challenged at the CJEU.
Do I need cookie consent for analytics in Denmark?
Yes, for any analytics tool that stores data on or reads data from the visitor's device (cookies, local storage, fingerprinting). The Cookiebekendtgorelsen Section 4 provides only two narrow exemptions: cookies for transmitting communications and cookies strictly necessary for a requested service. Analytics cookies are explicitly not exempt. Unlike France, Denmark has no consent exemption framework for privacy-friendly analytics tools. Cookieless analytics that don't touch the visitor's device fall outside the Cookiebekendtgorelsen entirely.
What is the Cookiebekendtgorelsen?
The Cookiebekendtgorelsen (BEK nr 1148 af 09/12/2011) is Denmark's implementation of the EU ePrivacy Directive. It requires prior informed consent before storing information on or accessing information from a user's terminal equipment. It's supervised by Digitaliseringsstyrelsen (not Datatilsynet). The GDPR applies on top of it for any personal data processing. A non-compliant cookie banner can trigger enforcement from both authorities simultaneously.
Can I use cookieless analytics without consent in Denmark?
Analytics tools that don't set cookies, don't fingerprint visitors, and don't track across sites avoid the Cookiebekendtgorelsen's consent trigger. The law applies to "storage of or access to information on end-user terminal equipment." If the tool also processes no personal data (anonymous aggregation only), the GDPR consent requirement doesn't apply either. This is why cookieless, privacy-first analytics can operate without a consent banner in Denmark.
Which analytics tools can I use without a banner in Denmark?
Any tool that doesn't store or read anything on the visitor's device and doesn't process personal data. That's the whole test. You don't get a French-style approved list in Denmark, so you check the two conditions yourself: no device access, no personal data. Clickport was built to pass both, but I'd rather you verify than take my word for it: run the free scanner on any tool's demo page and look at what it stores.
What are the penalties for cookie violations in Denmark?
Denmark has a unique enforcement model: Datatilsynet can't issue fines directly (GDPR Recital 151). It recommends fines to police, who prosecute through courts. Courts have historically imposed much lower fines than recommended (IDdesign: DKK 1.5M proposed, DKK 100K imposed). The largest court-imposed GDPR fine is DKK 1 million (Arp-Hansen Hotels, 2023). Datatilsynet's largest recommendation is DKK 15 million against Netcompany (2024, court pending). Under GDPR, fines can reach 4% of global annual turnover or EUR 20 million. In plain English: the EU ceiling dwarfs anything a Danish court has imposed so far.
Does the EU-US Data Privacy Framework make Google Analytics legal in Denmark?
The DPF (adopted July 2023) resolved the specific US data transfer issue from Datatilsynet's September 2022 ruling. But Datatilsynet explicitly warned that "using Google Analytics requires not only lawful transfers to the USA." You still need valid cookie consent, a data processor agreement, and compliance with all GDPR requirements. And the DPF's durability is uncertain: the PCLOB has been gutted, and the framework is being challenged at the CJEU. If it falls, there would likely be no transition period.
One more thing, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or the source it came from. If your setup is complicated, show this to your DPO or lawyer.
And if you're staring at a Danish cookie banner decision right now and something here doesn't match what you're seeing, email me.

Comments
Loading comments...
Leave a comment