Danish authorities announced on Monday 5 October 2026 that data belonging to about 8.8 million people registered in the Central Population Register had been accessed without authorisation. The data included names, addresses and personal identification numbers, after a Danish private company’s legal privilege to search the register was misused.
Protected names and addresses excluded
The Central Population Register said its initial review showed that the names and addresses of people registered under the name and address protection system had not been included in the unauthorised access. The database includes deceased people and those who have left Denmark, as well as current residents and living people, so the announced figure is not limited to the country’s current population.
The authority suspended the private company’s access privilege used in the incident and began working with specialists and the relevant authorities to establish the full sequence and scope of events. It also notified the data protection authority, while the police are investigating in coordination with the authorities concerned. According to the timeline released by the authority, unusual behaviour inside the register system during September was detected on the evening of Friday 2 October 2026.
Over the weekend, it emerged that unauthorised parties had gained access to data belonging to about 8.8 million registered people. The data protection authority said it received the register’s report of the incident on Sunday 4 October, explaining that the report indicated a very large number of automated searches had been carried out in the system to identify valid personal identification numbers.
The authority added that it had begun examining exactly what had happened, how it had been allowed to happen and which entity was responsible for processing the personal data linked to the case. It stressed that the investigation was still at an early stage, meaning no final assessment of the facts could be issued at this point.
The register’s scope and the limits of legal access
The Central Population Register contains about 11 million people, including those currently living in Denmark, people who have moved abroad and deceased people whose records remain stored in the system. Its number of registered people therefore exceeds the country’s current population. The authority said the access occurred within the scope of information that qualified private companies are legally permitted to view, after unknown parties used one company’s search access.
The identity of the party behind the operation remains under investigation. Under Article 38 of Denmark’s Population Register Act, private companies with a legitimate interest may obtain data concerning a defined group of people whom they have previously identified individually.
Search mechanism and stated responsibility of the unidentified party
Those people can be identified using a personal identification number, or their date of birth and name, or their name and address, provided that the company is eligible to receive the data under information protection rules. Christina Egelund, the minister for research, education and digitalisation, described the incident as extremely serious and said she had briefed Parliament’s Business and Digitalisation Committee.
She added that the relevant authorities were working to establish the full scope of the incident and that measures had already been taken within the register system to prevent similar incidents from recurring. Egelund said she had requested a comprehensive security review of the system to provide the basis for any further measures, and urged citizens to exercise caution during the current period and in the weeks ahead.
She stressed that the facts were still being established in cooperation with the relevant authorities. The authority warned against sharing passwords or any confidential information over the telephone or by email, even if the caller appeared to know the person’s name, address and identification number.
The Danish digital security helpline has also allocated the number 45 33 37 00 37 to provide guidance, with its opening hours extended over the coming days from 8am until midnight.
The authorities said the measures taken included immediate steps within the register, alongside an in-depth security review that could lead to further measures. They noted that the published information could be updated as the investigation progresses and the details of the incident are fully established.