Denmark’s national registry office has confirmed a serious security incident that exposed personal details of registered residents. The breach came about because an authorized user at a company misused their access to search the registry’s system, allowing an unauthorized party to see names, addresses, and CPR numbers.
The registry says the breach did not affect the names and addresses of people who chose to enroll in name and address protection.
The Registry System
Det Centrale Personregister is Denmark’s central registry. It holds information on citizens, including names, addresses, and unique CPR numbers used as identifiers.
The registry confirmed the breach after discovering that an authorized user at a company had misused their access to search the system. That misuse allowed an unauthorized party to gain access to the personal data of registered residents.
What Was Exposed
The exposed data included names, addresses, and CPR numbers. The registry says the breach did not affect the names and addresses of people who chose to enroll in name and address protection.
How It Happened
The unauthorized access came through a legitimate login belonging to a company. That company was authorized to search the registry’s system, but someone within it misused that permission to grant access to an unauthorized party.
The registry stopped the company’s access once the breach was discovered. Officials are now working with experts and other government agencies to map out exactly what happened.
Response So Far
The registry’s administration has filed a report with Datatilsynet, the country’s data protection authority. Police are also investigating the matter in cooperation with relevant authorities.
Who Is Affected
The registry has not named the company involved.
Reading More
For more details on the incident, readers can visit the website of the Ministry of Education, Research, and Digitalization. The ministry posted additional information about the breach on its press page.
What Happens Next
The investigation is ongoing. Datatilsynet will review the report filed by the registry’s administration, and police are handling the criminal probe.
The registry has not announced any further steps or timeline for completing the investigation.
Key Facts
| Detail | Figure |
|---|---|
| Data exposed | Names, addresses, CPR numbers |
| Protected group spared | Names and addresses of people with name and address protection |
| Action taken | Company’s access stopped, report filed with Datatilsynet |
| Investigation | Police investigating with relevant authorities |
The Takeaway
This is a serious breach of a national registry. The scale of the exposure is notable, though the registry says the names and addresses of people who chose to enroll in name and address protection were not affected.
The fact that the breach came through a legitimate login rather than a stolen credential makes the incident harder to contain. A trusted user abused their position.
The registry’s quick response — stopping the company’s access and filing a report with Datatilsynet — shows a willingness to act.
The ministry’s press page offers context on the registry and the protection program. For anyone affected, the key question is whether the exposure means their data is now compromised in ways they cannot control.
The investigation will determine that.
Source material: “Denmark Data Breach Exposes 8.8M People's Personal Data,” cpr.dk.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

