If your Danish-language site runs a consent banner assembled from a pan-European template, you are the case the regulator described. Cookie consent enforcement in Denmark also runs on two tracks at once: Datatilsynet says it will act here after coordinating with Digitaliseringsstyrelsen, which supervises the same banner under the Danish cookie order.
Key Takeaways
- Datatilsynet published its 2026 focus areas on 7 January 2026. "Danske hjemmesiders sporing af borgere" (Danish websites' tracking of citizens) sits under surveillance through new technologies, and the stated concern is sites "hvor borgerne ikke har en reel mulighed for at sige nej til sporingsteknologier" (where citizens have no real opportunity to say no to tracking technologies). That phrasing targets banner design, not banner existence.
- Datatilsynet's own text says its work here will happen after coordination with Digitaliseringsstyrelsen. Two agencies, two legal bases, one banner: GDPR on one side, the Danish cookie order on the other.
- The substantive standard already exists in writing. Datatilsynet and Digitaliseringsstyrelsen published joint guidance in May 2025 that names specific failure modes: color-based nudging, one bundled consent covering several purposes, pre-checked boxes and on-sliders, cookie walls without an acceptable alternative.
- Digitaliseringsstyrelsen's own 2024 sweep of 200 randomly selected Danish websites found every one of them setting tracking technologies before the user could consent. 196 organizations corrected their setup afterward.
- Denmark requires things most pan-European banner templates omit: a Danish-language consent solution for a Danish-language service, the expiry duration of each technology, and named third parties reachable within one click of the first layer. It also recognizes no analytics exemption, so statistics tags have to wait for consent exactly as marketing tags do.
- Neither Danish authority can hand you a fine directly. Datatilsynet has no power to impose administrative GDPR fines; it reports cases to the police with a recommended amount and a court decides. The sanction that actually lands is an order with a deadline.
What Datatilsynet announced for 2026
On 7 January 2026, Datatilsynet published the areas receiving special priority in its supervision work for the year. Nine topics appear, grouped into two clusters. Under "surveillance through new technologies" sit AI used to monitor people in care settings, IoT measurement devices in home treatment, employee monitoring, and Danish websites' tracking of citizens. The second cluster covers autocomplete in email, supervision of large data processors, data subjects' right to transparency and information, EU information systems, and PNR data.
Two of those nine touch your cookie banner directly. Website tracking is the obvious one. Transparency and information obligations is the quieter one, and it matters because a banner that fails to name the third parties collecting data, or fails to state how long each technology keeps collecting, is an information-duty problem independent of whether consent was validly obtained.
The focus-area page explains the reasoning in one sentence: studies continue to be published showing extensive collection of personal data on Danish websites where citizens have no real opportunity to say no to tracking technologies. It then adds the line that changes the risk calculation. Digitaliseringsstyrelsen also supervises this area, so Datatilsynet's effort will take place after coordination with that agency.
Secure Privacy's 2021 guide to the Danish DPA's cookie guidelines covers the 2020 guidance and the DMI.dk decision that shaped it. Both remain useful history. Neither describes the enforcement structure now in place, and one detail in that older account has since changed: supervision of the Danish cookie order moved from Erhvervsstyrelsen to Digitaliseringsstyrelsen in December 2022.
Two regulators, one cookie banner
The distinctive thing about Denmark is not the substance of its cookie rules, which follow the ePrivacy Directive and the GDPR like everywhere else in the EU. It is that two separate authorities examine the same consent solution under two separate instruments, with different enforcement toolkits.
| Aspect | Datatilsynet | Digitaliseringsstyrelsen |
|---|---|---|
| Legal basis applied | GDPR and the Danish Data Protection Act | Cookiebekendtgørelsen (the Danish cookie order), under the telecommunications act |
| Trigger for jurisdiction | Personal data is processed via the technology | Information is stored on or read from the user's device, whether or not it is personal data |
| Typical questions asked | Is there a lawful basis, is consent valid, is the information duty met, who is controller | Was consent obtained before storage, is the information about each technology complete, can consent be withdrawn |
| Enforcement toolkit | Reprimand, serious criticism, order, processing ban. It cannot impose a GDPR fine itself: it reports the case to the police with a recommended amount, and a court sets the figure | Dialogue-based supervision: hearing letter, then order, then police referral for a fine under section 5 of the cookie order |
| Supervision style in practice | Thematic supervision drawn from published annual focus areas | Risk-based thematic sweeps plus complaint-driven cases |
| 2026 announced focus | Danish websites' tracking of citizens; transparency and information obligations | The most-used Danish apps, selected from the Apple App Store top 200 |
The two 2026 work programs do not cover the same ground. While Datatilsynet turns toward websites, Digitaliseringsstyrelsen has said its 2026 thematic supervision targets the most-used Danish apps, chosen from the App Store's top 200 and filtered to Danish applications. If you run both a Danish website and a Danish app, you are inside both work programs this year, under different rules, with a different regulator on each side. Consent collected in an app raises questions a web banner never does (identifier-based tracking, withdrawal through app settings, SDKs that fire on launch), which is why mobile consent management is worth treating as its own workstream rather than an extension of the website project.
"A real opportunity to say no," concretely
The phrase is not new law. It is shorthand for the voluntariness requirement, and the two authorities spelled out what they mean by it in joint guidance published 15 May 2025. It is the standard both authorities have published as their shared reading of the rules, which makes it a better thing to test your banner against than a generic GDPR checklist.
Declining must be as easy as consenting. The guidance states the requirement directly: it must always be equally easy to refrain from giving consent as it is to give it. A banner offering only "Allow" plus a link to the privacy policy fails, because no choice is offered at all. The mechanism matters here: consent is valid only where the user exercises control, so a layout that makes refusal reachable but slower converts a legal right into an obstacle course, and the consent collected through it is not voluntary. Practically, that means the reject path must be the same number of clicks as the accept path, on the same layer.
Color and contrast count as pressure. The guidance gives an example of an "OK" button marked clearly in green next to a "Decline" button that barely separates from the background, and concludes the option to refuse must appear just as clearly as the option to accept. Buttons that blend into the background are named specifically. So is repetition: re-presenting the consent prompt to the same visitor during a single session is treated as disproportionate pressure. If you are unsure where the line falls, the design patterns that invalidate consent are by now well documented across European supervisory practice.
One bundled consent for several purposes is not granular enough. The guidance's fourth example shows a banner offering a clean OK/NO choice over a description covering both analytics and targeted advertising, and rejects it, because the user cannot accept one purpose and refuse the other. Granularity is treated as an element of voluntariness, not a separate nicety. The related failure is vagueness: a category labeled "third-party technologies" does not state a purpose, so consent given against it is not specific.
Silence and pre-selection are not consent. Continued browsing does not constitute an unambiguous indication of will, because it is not an active choice. Pre-checked boxes and on-sliders fail for the same reason. Neither does burying the consent request inside general terms and conditions, on the reasoning that the user could easily overlook it.
Cookie walls need a genuinely acceptable alternative. Access to your service generally may not be conditioned on consent, but Denmark does permit a paid alternative, subject to four criteria the guidance enumerates: the alternative must be reasonable, reasonably priced, limited to collecting data for the purposes that actually correspond to the payment, and limited to what is necessary to deliver the service to paying users. Datatilsynet applied exactly that framework to Gul og Gratis on 8 February 2023, accepting a 29 kr./month alternative as neither unreasonable nor unreasonably priced, then issuing an order anyway because the company had not shown that statistics collection was a necessary part of the paid model.
A companion decision issued the same day adds a criterion that is easy to miss, because it is about the alternative rather than the banner. Jysk Fynske Medier was ordered to change a wall where visitors who consented reached only a small part of the content that subscribers got for 99 kr./month, and where the payment option appeared only after the visitor had already rejected everything but necessary cookies. What Datatilsynet drew out of it is equivalence: the content reachable by consenting must "i vidt omfang" (to a wide extent) correspond to the content reachable by paying, because two options of unequal value are not alternatives and a choice between them is not free. The sequencing mattered as well, on the same reasoning. An alternative the visitor discovers only after refusing was never offered at the moment the choice was made. Together the two decisions are the clearest available illustration of how cookie walls and consent-or-pay models get assessed criterion by criterion rather than approved or rejected wholesale.
Auditing your own banner against those five failure modes is straightforward once; keeping it true through six months of tag changes is the harder problem. Secure Privacy's Cookie & Consent Solution rescans domains monthly and blocks cookies and trackers from placing until a visitor acts on the banner, which is the control that addresses the single violation Danish supervision finds most often.
What Danish cookie consent enforcement has actually looked like
Both tracks have a documented record, and it is more procedural than punitive.
Digitaliseringsstyrelsen published the result of a sweep on 14 August 2024: of 200 randomly selected Danish websites, all of them used tracking technologies such as pixels and cookies before the user had any opportunity to consent. Beyond that headline, 42.2% carried unclassified tracking technologies, 27.6% lacked required information in the banner, and 18.1% had no banner at all. Following the hearing letters and orders that came out of it, 196 organizations corrected their use of tracking technologies. That is 2024 data, and it is a regulator's own measurement rather than a vendor survey.
The 2025 round is smaller and more revealing about how the process runs: 146 services supervised, comprising 131 websites and 15 apps, with 50% of cases closed during the hearing stage, 11.6% escalating to an order, and 100% of services compliant once supervision concluded. Digitaliseringsstyrelsen states it has not referred any organization to the police, because every one has ultimately corrected course. The practical reading is that the realistic downside in Denmark is rarely a headline fine — it is a hearing letter with a deadline, remediation work on someone else's schedule, and an order on the public record if you miss it.
On the GDPR track, Datatilsynet issued serious criticism of JP/Politiken's consent solution on eb.dk in October 2022 for consent that was not sufficiently informed, and has ordered changes in cookie wall cases including Berlingske. The most instructive case is also the least conclusive: Digitaliseringsstyrelsen ordered Meta and Google on 30 October 2023 to split consent by overarching purpose, provide immediate and clearly marked withdrawal, and disclose every technology in use. Both appealed. On 13 February 2025 the Teleklagenævnet set aside the Google order and remitted it, on the ground that it had not been established that Google LLC was the correct addressee — Google Ireland Limited holds practical and technical control over cookies placed on google.dk. The order fell on the question of who is answerable, not on whether the consent solution complied. For anyone running Danish properties through a group structure, that is the more useful lesson: identify which legal entity actually controls placement before a regulator has to.
Neither track ends with a regulator writing a fine notice, and that is a structural feature of Danish law rather than leniency. Denmark has not given Datatilsynet the power to impose administrative fines under the GDPR, so its most severe step is to report the controller to the police and state the amount it recommends, after which the prosecution decides whether to bring charges and a court sets the final figure. Datatilsynet says so in the fact box attached to each of its fine recommendations: in Denmark, fines under the regulation must for the time being be decided by the courts. The cookie order runs on the same logic, with police referral as Digitaliseringsstyrelsen's last resort. The consequence for planning is that a Danish cookie case rarely produces the fast administrative penalty a French or Spanish case would, and very often produces an order with a compliance deadline instead.
Answering a hearing letter is a documentation exercise before it is a legal one. What decides how long the case runs is what you can produce on request: scan history, stored banner versions, and a log of accepts and declines.
The compliance gap, dated
Third-party measurement points the same direction as the regulator's. Cookie Information's Cookie Compliance in Denmark report found 94% of analyzed Danish sites carrying a banner while 84% showed compliance issues, a three-point rise in banner adoption against a five-point rise in defects compared with the prior year, which describes a market getting better at deploying banners and no better at configuring them. The same report put non-essential cookies firing before consent at 70% of sites, with Sports (89%), E-commerce (83%) and Arts & Culture (82%) worst affected.
Two qualifications belong on those figures. They are 2024 data, not a 2026 measurement, and they come from a consent vendor rather than an independent research body. Read them as a corroborating signal alongside Digitaliseringsstyrelsen's own 2024 sweep, which found the same dominant failure ("Sporingsteknologi sat før brugeren kan give samtykke," tracking technology set before the user can give consent), rather than as a current scoreboard. The direction of both datasets is what carries weight: the common Danish defect is not a missing banner but a banner that does not gate anything, which is the failure a cookie audit surfaces immediately and a visual review of the banner never will.
Requirements that catch non-Danish companies
Most of the joint guidance restates GDPR consent doctrine. A handful of points are either Denmark-specific or specific enough to be missing from a pan-European template.
| Requirement | What the guidance expects | Why templates miss it |
|---|---|---|
| Scope of the consent exemption | Only technologies that are a technical prerequisite for a service the user explicitly requested may fire without consent; web statistics is treated as its own purpose, needing its own consent | Templates carry over an analytics exemption, or a legitimate-interest basis for statistics, that Danish supervision does not recognize |
| Language of the consent solution | A Danish-language service should have its consent solution and privacy policy in Danish, in clear and simple wording | Multi-market rollouts often localize page content but leave the banner in English |
| Duration disclosure | Users must be informed of each technology's functional duration: how long it keeps collecting on the device | Cookie tables frequently list name and purpose but omit expiry |
| First-layer minimum | Identity of your organization and any partners, purposes, categories of data, whether third parties collect or receive data, and the right to withdraw | Partner identity is often buried two layers down instead of one click away |
| Named third parties | Named partners, reachable via an expandable list that is "one click away" in the first layer | Generic references to "advertising partners" do not satisfy this |
| Consent renewal | No fixed deadline, but annually is described as often appropriate, including re-asking users who declined | Indefinite consent storage, or re-prompting decliners every visit |
| Documentation | Retain what users were shown, the procedures used, and evidence those procedures met every validity condition, including screenshots per banner version | Consent records capture the choice but not the interface that produced it |
| Withdrawal access | A visible link or persistent icon reachable from every subpage, as simple as the original consent act | Withdrawal hidden inside a privacy policy page |
| Children's consent | A case-by-case maturity assessment; a child from 15 can generally consent on their own behalf | Age handling absent entirely from web banners |
The documentation requirement deserves its own note, because it is where otherwise-compliant organizations lose an audit. Denmark's documentation expectation is not only "we logged a consent." It is: here are our procedures, here is what the user was actually shown when they consented, and here is our assessment that this met the conditions for validity, updated as the interface changes, with a stored record for each version. Consent records that capture the decision but not the interface cannot answer the question a supervisor asks, which is why proving consent means retaining banner versions alongside timestamps.
Where the Digital Omnibus fits
Not yet, is the short answer. The Commission's Digital Omnibus proposed moving cookie consent rules into the GDPR through new Articles 88a and 88b, including a single-click rejection requirement and legally binding browser-level signals. As of the Council's June 2026 compromise text, those provisions had been removed from the negotiating track after member states failed to agree, and whether they return (in this form or another) is unsettled. The Article 88a proposal is worth tracking, not planning around. The cookie order and the GDPR are what Danish supervision applies in 2026.
A Denmark-specific cookie banner review for 2026
Work through this against the live site, not the design file.
| Check | What passes |
|---|---|
| Pre-consent network activity | Load the site in a clean browser session and confirm no non-essential cookie, pixel, or third-party script fires before an affirmative choice |
| Exemption claims | Every technology that does fire before the banner is documented as a technical prerequisite for a service the visitor explicitly requested; analytics and statistics tags do not qualify |
| Symmetry of paths | Accept and reject reachable in the same number of clicks, on the same layer, at comparable visual weight |
| Purpose granularity | Separate consent available per purpose: statistics and marketing cannot share one control |
| Purpose specificity | Each category names a real purpose; no "third-party technologies" or similar placeholder |
| Active choice only | No pre-checked boxes, no on-sliders defaulting to on, no reliance on continued browsing |
| First-layer information | Identity, purposes, data categories, third-party involvement, and withdrawal right all present before the user chooses |
| Partner transparency | Named partners one click away in the first layer, not deep in a policy page |
| Duration transparency | Functional duration stated for each technology |
| Withdrawal route | Persistent link or icon on every subpage, as easy as the original consent |
| Danish language | Consent solution and policy in Danish where the service is Danish |
| Re-prompt cadence | Roughly annual renewal, no repeated prompting within a session, decliners not re-asked more often than annually |
| Documentation set | Stored screenshots per banner version, procedures, and a written validity assessment |
| Entity accountability | The legal entity that actually controls placement on the Danish domain is identified and documented |
| Third-party role mapping | Controller, joint controller, or processor determined for each embedded plug-in, with the arrangement made available to users |
Most items on that list are one-time fixes. Three are not: pre-consent firing, duration accuracy, and documentation currency all drift every time a marketing team adds a tag. That is the gap between passing a review and being able to prove compliance six months later, and it is the reason cookie consent practice has moved from periodic audits to continuous monitoring.
Common issues and fixes
Some of these need a permission level you may not hold. Tag-manager container changes usually sit with marketing operations, and banner localization with whoever owns the translation pipeline, so scope the handoff before you scope the fix.
| Symptom | Likely cause | Fix |
|---|---|---|
| Trackers fire before any click | Tag manager loads containers on page load, outside the consent gate | Move every non-essential tag behind the consent signal, then retest in a clean session each month |
| Banner is in English on a Danish-language site | Localization covers page content but not the consent tool | Publish Danish banner text and a Danish privacy policy together, and treat the banner as a localized asset |
| Cookie declaration lists names but no expiry | Declaration written by hand from a static list | Regenerate it from a live scan so functional duration stays accurate as tags change |
| A category reads "third-party technologies" | Purposes inherited from a vendor default | Rename each category to its real purpose and split statistics from marketing into separate controls |
| Consent logs exist, but nobody can show what the user saw | Logging captures the decision, not the interface | Store a screenshot and version identifier for every banner change alongside the consent record |
| An order arrives addressed to the wrong group entity | Placement control never mapped to a legal entity | Document which entity controls placement on each Danish domain, and record the arrangement for embedded third parties |
Fix the top row first. It is the single defect Danish supervision has found on every site it looked at, and it is the one a visual review of the banner will never surface.
Three of the drift points above are exactly what a consent platform is for, and Secure Privacy (a Copenhagen-based company, which is a matter of address rather than regulatory standing) covers each one. Monthly compliance scanning across domains catches new trackers before a hearing letter does. Blocking holds cookies and trackers until a visitor acts on the banner, which addresses the violation Danish sweeps find most often. Every consent and every decline is logged and exportable from the dashboard, giving you the evidence half of the documentation requirement. Banners are fully customizable and available in 70+ pre-translated languages including Danish, and a visitor preference center provides the persistent withdrawal route the guidance expects. What no platform supplies is the written assessment that your specific setup satisfies each validity condition — that judgment stays with you, though the Cookie & Consent platform supplies the scan output, consent records, and banner versions it has to rest on.
Frequently asked questions
Is cookie consent actually a Datatilsynet enforcement priority in 2026?
Yes. Datatilsynet listed Danish websites' tracking of citizens as one of nine supervision focus areas for 2026, published on 7 January 2026. It appears under surveillance through new technologies, and a second focus area on transparency and information obligations also bears on banner disclosures.
Which Danish authority enforces cookie rules, Datatilsynet or Digitaliseringsstyrelsen?
Both, under different instruments: Digitaliseringsstyrelsen supervises the Danish cookie order, and Datatilsynet supervises the GDPR. Responsibility for the cookie order moved from Erhvervsstyrelsen to Digitaliseringsstyrelsen in December 2022, so older guidance naming the Danish Business Authority is out of date.
Do analytics cookies need consent in Denmark?
Yes. Denmark recognizes no analytics exemption: Digitaliseringsstyrelsen's guidance for service providers exempts only technologies that are a technical prerequisite for a service the user explicitly requested, and it treats web statistics as one of the distinct purposes a user consents to alongside functional and marketing ones.
What does "a real opportunity to say no" mean for banner design?
It means refusing must be as easy as accepting (same layer, same click count, comparable visual prominence) and separately available per purpose. The joint May 2025 guidance names the specific failures: an accept button colored to dominate a faded reject button, one bundled consent covering analytics and advertising together, pre-checked boxes, and continued browsing treated as agreement.
Are cookie walls legal in Denmark?
Yes, but only where users are offered a genuinely acceptable alternative, and Datatilsynet assesses that alternative against four criteria: it must be reasonable, reasonably priced, limited to purposes that actually correspond to the payment, and limited to data necessary to deliver the service. The Gul og Gratis decision of 8 February 2023 accepted a 29 kr./month alternative on price and equivalence, then ordered changes because statistics collection had not been shown to be a necessary part of the paid model.
What penalties apply if a Danish cookie banner is non-compliant?
Under the cookie order, non-compliance is punishable by fine, but Digitaliseringsstyrelsen runs dialogue-based supervision (a hearing letter first, then an order, then police referral only if the order is ignored) and states it has not referred any organization to date. Datatilsynet cannot impose an administrative fine either, because fines under the GDPR are decided by the Danish courts: it investigates, reports the controller to the police with a recommended amount, and a court sets the figure. Both tracks therefore end in an order long before they end in a penalty, and the same banner can produce two separate proceedings.
Does a cookie banner have to be in Danish?
If the service itself is in Danish, the guidance says the consent solution and privacy policy should be too, in clear and simple language. That is a common gap in multi-market rollouts, where page content is localized but the banner ships in English.
How long is a cookie consent valid in Denmark?
There is no fixed statutory period; the guidance says annual renewal will often be appropriate, and that re-asking a user who declined is likewise appropriate about once a year. A consent also lapses when what you do changes: new purposes, or new third parties receiving data, require a fresh consent regardless of when the last one was collected.
What is Digitaliseringsstyrelsen supervising in 2026?
The most-used Danish apps, selected from the Apple App Store's top 200 and filtered to Danish applications. Its 2025 round covered 146 services (131 websites and 15 apps), of which 11.6% received an order and all reached compliance by the close of supervision.
Getting ahead of the 2026 review
Datatilsynet's focus area will produce hearing letters and orders, not surprises. The standard is already published, the failure it targets is a banner that does not gate anything, and the two authorities have said in writing what a compliant banner looks like. If yours already gates, the remaining work is proving it did so on the day someone asks. That is what continuous scanning, blocking before consent, and versioned consent records exist to do, and it is the gap Secure Privacy is built to close.




