Download Privacy Needle App

Type to search

Data Breaches

Denmark’s CPR Reports Data Breach Impacting 8.8 Million Citizens

Share

Denmark’s Central Person Register (CPR), the nation’s foundational civil registration system, has announced a significant data breach impacting approximately 8.8 million individuals. Attackers exploited a private Danish company’s lawful access to the CPR system to exfiltrate sensitive personal information.

The incident, discovered on Friday after abnormal system behaviour was noted in September, saw hackers gain unauthorised access to names, addresses, and CPR numbers – the Danish equivalent of Social Security numbers. The stolen data pertains to both living and deceased individuals registered within the system, which holds information on around 11 million people, including residents and emigrants. Individuals who opted for name and address protection within the CPR system were reportedly not affected by the breach.

Under Danish law, private companies with a legitimate interest can be granted access to the CPR to obtain information on specific individuals, in accordance with the country’s Data Protection Regulation and Data Protection Act. It was this legitimate third-party access that hackers reportedly leveraged to infiltrate the system.

Upon discovering the breach, the CPR immediately revoked the private company’s access and initiated an investigation. The Danish Data Protection Agency has been notified, and law enforcement, along with other relevant authorities, are now involved in probing the incident. The CPR has advised affected individuals to exercise caution regarding unsolicited communications that request personal information, passwords, or other sensitive data.

The national registrar has committed to reviewing its current security policies and implementing enhanced protections to prevent similar incidents in the future. At this stage, the entity responsible for the cyberattack has not been identified.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.