Privacy policy requirements in Denmark

What a privacy policy has to say if you operate from Denmark, which law applies, who enforces it, and which other pages you need alongside it.

Updated · Written from the same rules terms.gg uses to generate documents

The facts for Denmark

What GDPR asks for that a generic template will not have

A request for access or deletion has to be answered within one month and free of charge, and that month can be extended by two more when the request is genuinely complex, as long as you say so inside the first month.

Being established here is what makes GDPR your regime. It is not the only way a law reaches you: the GDPR follows the user too, so a company anywhere that offers a service to people in Europe, or watches what they do there, is caught by it as well. Which means GDPR is your floor, and the law of the places you sell into can add to it.

What every privacy policy has to contain

The pages that go with it in Denmark

A privacy policy on its own is rarely the whole requirement. For an app shipping on iOS, Android and the web from Denmark, the set is usually: Privacy Policy, Terms of Service, Account and data deletion page, Cookie Policy, End User License Agreement.

Denmark does not generally require a separate published legal notice, so the operator details live inside the privacy policy and the terms.

The mistakes that cost people a review

Keeping it true after launch

A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. Under GDPR the drift is yours rather than your vendor's, and Datatilsynet is who hears about it.

Common questions

Do I need a privacy policy if my app collects almost nothing?

Yes. Both stores require a working privacy policy URL before your listing goes live, whatever the app does. A short and honest policy is fine; a missing one is not.

Can I use a template from another country?

Only as a starting point. A template written for one regime names the wrong law, the wrong authority and sometimes rights that do not exist where you are. Under GDPR the wording and the rights differ from the American and the Brazilian versions.

Who enforces this in Denmark, and what can they actually do?

Datatilsynet. They take complaints from your users, can order you to change how you process data, and can fine you. In practice most cases start as a complaint from one person who could not get an answer from you, which is the cheapest thing on this page to avoid.

Does it have to be in Danish?

The safe answer is yes for the market you sell to. A policy nobody can read is treated as a policy nobody agreed to, and store reviewers in Denmark read the listing in their own language.

Where should I host it?

Anywhere that will still be there in a year and does not need a login. Store reviewers open the link, and so do the people who use your app.