Denmark - AI Use by Public Authorities

Public authorities' use of artificial intelligence: Before you start

Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang

Denmark

RAI-DK-NA-DGPAUXX-2023
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and Oversight
Export PDF

Datatilsynet's October 2023 guidance 'Inden I går i gang' provides practical, data-protection-focused guidance for Danish public authorities that design, develop or deploy AI systems that process personal data. It explains lifecycle stages, lawful bases, DPIA requirements, transparency obligations and risk-minimisation measures to ensure AI use respects fundamental rights and GDPR requirements.

Overview

Datatilsynet's guidance "Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang" (October 2023) provides practical, stepwise recommendations for Danish public authorities before they start developing or deploying AI-based systems that process personal data. The guidance frames AI projects as a lifecycle of scoping, design, development & testing, and operational use, and stresses that data protection rules are technology-neutral: the same legal principles apply whether processing is performed by AI or traditional IT. The guidance is available from Datatilsynet as a published PDF (Datatilsynet guidance (PDF)) and is supported by a national regulatory sandbox co‑run with Digitaliseringsstyrelsen (regulatory sandbox page).

Definitions

The guidance adopts practical working definitions oriented to data protection: an "AI system" is described consistent with international practice (OECD/EU formulations) as a machine-based system that can generate outputs such as predictions, recommendations or decisions for human-defined objectives. It differentiates between development/training (when the system learns from datasets) and deployment/operation (when the system processes live inputs). Important processing concepts (profiling, automated decision-making, pseudonymisation, anonymisation, special categories of personal data) are defined and discussed for the public-sector context so authorities can assess legal bases and mitigation measures.

Governance and Institutional Framework

Datatilsynet recommends clear governance arrangements for AI projects. That includes: assigning a project owner and data protection owner (DPO or equivalent), involving legal and sector specialists early, establishing oversight committees for high‑impact systems, and documenting responsibilities across lifecycle phases. The guidance highlights vendor and procurement controls when third-party models, cloud services or foundation models are used: procurement contracts should include data protection clauses, model update/monitoring obligations and security requirements. For complex or high-risk projects Datatilsynet points to the national AI regulatory sandbox (Datatilsynet & Digitaliseringsstyrelsen) as a resource for tailored advice. Governance must also ensure transparency to affected individuals and set internal escalation/approval gates to prevent premature deployment.

Key Focus Areas

The guidance organises technical and legal obligations into cross-cutting focus areas: (1) Lawful basis and purpose limitation – treat AI development as a separate processing purpose and select an appropriate lawful basis (e.g., public task, legal obligation, research/statistics exceptions where relevant); (2) Data minimisation & dataset selection – prefer anonymised or pseudonymised data and limit sensitive data; (3) Profiling & automated decision-making – avoid fully automated individual decisions without human intervention where Article 22 GDPR applies; (4) Transparency & information duties – ensure data subject notices describe AI use, logic and rights; (5) DPIA & risk assessment – perform Data Protection Impact Assessments where processing is likely to result in high risk; (6) Security & model robustness – adopt measures against model inversion, membership inference, and adversarial manipulation; (7) Monitoring, validation & bias mitigation – establish testing, performance thresholds, retraining policies and bias checks; and (8) Documentation & accountability – maintain records of processing, datasets, testing results, and governance decisions. These areas are discussed with examples and procedural checklists to help authorities operationalise obligations.

Implementation Framework

Datatilsynet sets out practical steps to operationalise the guidance: start with scoping and a preliminary legal assessment to identify objectives and data flows; conduct a proportionality analysis on whether AI is necessary and whether anonymised approaches are feasible; prepare a DPIA if the project is likely to present high risks to rights and freedoms; document lawful basis and information obligations; define technical architecture and security measures for development and testing (including isolated test environments and minimised production data use); and plan for human oversight in decision points where individual rights may be affected. The guidance also recommends contractual clauses for suppliers (access limits, deletion obligations, incident reporting) and points to the regulatory sandbox for complex procurements or high-risk classification questions.

Monitoring and Evaluation

Operational monitoring receives substantial attention: Datatilsynet recommends continuous validation of model outputs (accuracy, fairness, drift detection), scheduled audits, logging of model decisions where relevant, end‑user training about model limitations, and processes for retraining or decommissioning. Authorities are advised to define KPIs for model reliability and to keep records of monitoring outcomes. Where models adapt or learn during operation, authorities must reassess legal bases and DPIAs and document changes. The guidance also advises that monitoring plans include user-facing redress options and explainability measures appropriate to context and risk.

Penalties, Liability, and Appeals

While the guidance itself does not create novel sanctions, it reminds authorities that non‑compliance with GDPR/data protection obligations can lead to corrective powers, orders, and fines enforced by Datatilsynet under applicable law. Datatilsynet may issue remedial orders, temporary bans or corrective measures and can refer matters for sanctions under national implementing legislation. The guidance also emphasises that public authorities should implement internal appeals and redress mechanisms for individuals affected by AI-driven decisions, and that procurement and public law regimes can create additional accountability and liability channels.

Relationship to Other Instruments

Datatilsynet situates the guidance within the EU and Danish legal landscape. It explicitly references the GDPR (Regulation (EU) 2016/679) as the primary legal framework for personal data protections and notes intersections with sectoral laws (health, social services, administrative law). The guidance also anticipates the EU AI Act and cross-references its risk-based approach where relevant. Authorities are urged to coordinate with sectoral regulators and to seek legal counsel when other statutes (e.g., health law, public administration law) interplay with data protection obligations.

International Alignment

Datatilsynet emphasises alignment with international developments and standards: the guidance references OECD and EU definitional work and encourages Danish authorities to monitor the EU AI Act developments and to use the national sandbox (in cooperation with Digitaliseringsstyrelsen) to ensure cross-border legal and technical conformity. The guidance underscores that providers from third countries remain subject to EU data protection obligations where processing affects persons in the EU and encourages contractual and technical safeguards for cross-border model supply and cloud services.

Implementation Timeline

EventDate / Note
Datatilsynet guidance publishedOctober 2023 (see PDF)
Datatilsynet decision referencing guidance (example case)2024-01-19 (Sønderborg decision)
Regulatory sandbox operational (ongoing)Established by Datatilsynet & Digitaliseringsstyrelsen (see sandbox page)
DPIA template (expected)Datatilsynet indicated a template was expected in H1 2024; consult the Datatilsynet site for the latest template.

Compliance Checklist

ActionStatus/Notes
Document project scope and purposeRequired – record as separate processing purpose
Legal basis assessmentRequired – justify public task / legal obligation or other ground
Perform DPIA where likely high riskRequired where threshold met; use Datatilsynet guidance
Data minimisation & anonymisationPrefer anonymised/pseudonymised data for training/testing
Transparency & information to data subjectsUpdate privacy notices describing AI use and rights
Human oversight & redress mechanismsRequired where individual rights are materially affected
Procurement & vendor controlsInclude contractual clauses on security, access, updates
Monitoring & validation planDefine KPIs and retraining thresholds

Sources and References

SourceType
Datatilsynet, "Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang" (October 2023)Primary Source
Datatilsynet – Kunstig intelligens overviewPrimary Source
Regulation (EU) 2016/679 (GDPR)Primary Source
Regulation (EU) 2024/1689 (EU Artificial Intelligence Act)Primary Source
Plain English

The Danish Data Protection Agency (Datatilsynet) has issued guidance to help Danish public authorities responsibly design, develop, and deploy Artificial Intelligence (AI) systems that process personal data, ensuring compliance with existing privacy regulations. This guidance, published in October 2023 and currently in force, specifically targets all Danish public authorities engaging with AI.

The core message is that established data protection rules, particularly the General Data Protection Regulation (GDPR), apply fully to AI, regardless of its technological sophistication. Authorities must ensure they have a clear legal basis and purpose for processing personal data with AI, treating AI development itself as a distinct processing activity. Data minimisation is paramount, urging the use of anonymised or pseudonymised data whenever possible, especially during AI training and testing. For any AI system likely to pose a high risk to individuals' rights, a thorough Data Protection Impact Assessment (DPIA) is mandatory. Furthermore, authorities are obligated to maintain transparency, informing individuals about how AI is used, its underlying logic, and their rights, while also ensuring human oversight for any AI-driven decisions that significantly affect individuals.

While this guidance doesn't introduce new penalties, it serves as a firm reminder that non-compliance with GDPR and other data protection laws can lead to serious consequences. Datatilsynet has the power to issue corrective orders, temporary bans, and significant fines. A key practical takeaway for authorities is the substantial ongoing commitment required for continuous monitoring and validation of AI models. This includes regularly checking model accuracy, fairness, and potential "drift" over time, along with establishing clear plans for retraining or decommissioning systems. This continuous oversight, often overlooked, is critical to maintaining compliance and trust.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 14 marked complete

Plain-English obligations under Denmark - AI Use by Public Authorities. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore processing likely to result in high risk

    Applies to: Danish public authorities deploying AI systems.

    perform Data Protection Impact Assessments where processing is likely to result in high risk
  2. #2CriticalBefore processing personal data

    Applies to: Danish public authorities processing personal data with AI.

    select an appropriate lawful basis (e.g., public task, legal obligation, research/statistics exceptions where relevant)
  3. #3CriticalBefore deploying AI for automated decision-making

    Applies to: Danish public authorities using AI for decision-making.

    avoid fully automated individual decisions without human intervention where Article 22 GDPR applies
  4. #4CriticalBefore processing personal data with AI

    Applies to: Danish public authorities using AI to process personal data.

    ensure data subject notices describe AI use, logic and rights
  5. #5Critical

    Applies to: Danish public authorities deploying AI systems.

    maintain records of processing, datasets, testing results, and governance decisions.
  6. #6CriticalBefore signing procurement contracts

    Applies to: Danish public authorities procuring AI systems or services.

    procurement contracts should include data protection clauses, model update/monitoring obligations and security requirements.
  7. #7CriticalBefore deploying AI for decision-making

    Applies to: Danish public authorities deploying AI systems.

    plan for human oversight in decision points where individual rights may be affected.
  8. #8CriticalWhen AI models adapt or learn

    Applies to: Danish public authorities operating adaptive AI systems.

    authorities must reassess legal bases and DPIAs and document changes.
  9. #9ImportantBefore starting AI projects

    Applies to: Danish public authorities deploying AI systems.

    assigning a project owner and data protection owner (DPO or equivalent)...
  10. #10ImportantBefore data collection/processing for AI

    Applies to: Danish public authorities developing or deploying AI systems.

    prefer anonymised or pseudonymised data and limit sensitive data
  11. #11ImportantBefore deploying AI systems

    Applies to: Danish public authorities deploying AI systems.

    adopt measures against model inversion, membership inference, and adversarial manipulation
  12. #12ImportantBefore deploying AI systems

    Applies to: Danish public authorities deploying AI systems.

    establish testing, performance thresholds, retraining policies and bias checks
  13. #13Important

    Applies to: Danish public authorities operating AI systems.

    continuous validation of model outputs (accuracy, fairness, drift detection), scheduled audits, logging of model decisions where relevant...
  14. #14ImportantBefore starting AI projects

    Applies to: Danish public authorities initiating AI projects.

    start with scoping and a preliminary legal assessment to identify objectives and data flows

© Regulations.AI — created on 13-Jun-2026