Denmark - AI Use by Public Authorities
Public authorities' use of artificial intelligence: Before you start
Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang
Denmark
RAI-DK-NA-DGPAUXX-2023Datatilsynet's October 2023 guidance 'Inden I går i gang' provides practical, data-protection-focused guidance for Danish public authorities that design, develop or deploy AI systems that process personal data. It explains lifecycle stages, lawful bases, DPIA requirements, transparency obligations and risk-minimisation measures to ensure AI use respects fundamental rights and GDPR requirements.
Summary
Read full text ↗Plain English
Overview
Datatilsynet's guidance "Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang" (October 2023) provides practical, stepwise recommendations for Danish public authorities before they start developing or deploying AI-based systems that process personal data. The guidance frames AI projects as a lifecycle of scoping, design, development & testing, and operational use, and stresses that data protection rules are technology-neutral: the same legal principles apply whether processing is performed by AI or traditional IT. The guidance is available from Datatilsynet as a published PDF (Datatilsynet guidance (PDF)) and is supported by a national regulatory sandbox co‑run with Digitaliseringsstyrelsen (regulatory sandbox page).
Definitions
The guidance adopts practical working definitions oriented to data protection: an "AI system" is described consistent with international practice (OECD/EU formulations) as a machine-based system that can generate outputs such as predictions, recommendations or decisions for human-defined objectives. It differentiates between development/training (when the system learns from datasets) and deployment/operation (when the system processes live inputs). Important processing concepts (profiling, automated decision-making, pseudonymisation, anonymisation, special categories of personal data) are defined and discussed for the public-sector context so authorities can assess legal bases and mitigation measures.
Governance and Institutional Framework
Datatilsynet recommends clear governance arrangements for AI projects. That includes: assigning a project owner and data protection owner (DPO or equivalent), involving legal and sector specialists early, establishing oversight committees for high‑impact systems, and documenting responsibilities across lifecycle phases. The guidance highlights vendor and procurement controls when third-party models, cloud services or foundation models are used: procurement contracts should include data protection clauses, model update/monitoring obligations and security requirements. For complex or high-risk projects Datatilsynet points to the national AI regulatory sandbox (Datatilsynet & Digitaliseringsstyrelsen) as a resource for tailored advice. Governance must also ensure transparency to affected individuals and set internal escalation/approval gates to prevent premature deployment.
Key Focus Areas
The guidance organises technical and legal obligations into cross-cutting focus areas: (1) Lawful basis and purpose limitation – treat AI development as a separate processing purpose and select an appropriate lawful basis (e.g., public task, legal obligation, research/statistics exceptions where relevant); (2) Data minimisation & dataset selection – prefer anonymised or pseudonymised data and limit sensitive data; (3) Profiling & automated decision-making – avoid fully automated individual decisions without human intervention where Article 22 GDPR applies; (4) Transparency & information duties – ensure data subject notices describe AI use, logic and rights; (5) DPIA & risk assessment – perform Data Protection Impact Assessments where processing is likely to result in high risk; (6) Security & model robustness – adopt measures against model inversion, membership inference, and adversarial manipulation; (7) Monitoring, validation & bias mitigation – establish testing, performance thresholds, retraining policies and bias checks; and (8) Documentation & accountability – maintain records of processing, datasets, testing results, and governance decisions. These areas are discussed with examples and procedural checklists to help authorities operationalise obligations.
Implementation Framework
Datatilsynet sets out practical steps to operationalise the guidance: start with scoping and a preliminary legal assessment to identify objectives and data flows; conduct a proportionality analysis on whether AI is necessary and whether anonymised approaches are feasible; prepare a DPIA if the project is likely to present high risks to rights and freedoms; document lawful basis and information obligations; define technical architecture and security measures for development and testing (including isolated test environments and minimised production data use); and plan for human oversight in decision points where individual rights may be affected. The guidance also recommends contractual clauses for suppliers (access limits, deletion obligations, incident reporting) and points to the regulatory sandbox for complex procurements or high-risk classification questions.
Monitoring and Evaluation
Operational monitoring receives substantial attention: Datatilsynet recommends continuous validation of model outputs (accuracy, fairness, drift detection), scheduled audits, logging of model decisions where relevant, end‑user training about model limitations, and processes for retraining or decommissioning. Authorities are advised to define KPIs for model reliability and to keep records of monitoring outcomes. Where models adapt or learn during operation, authorities must reassess legal bases and DPIAs and document changes. The guidance also advises that monitoring plans include user-facing redress options and explainability measures appropriate to context and risk.
Penalties, Liability, and Appeals
While the guidance itself does not create novel sanctions, it reminds authorities that non‑compliance with GDPR/data protection obligations can lead to corrective powers, orders, and fines enforced by Datatilsynet under applicable law. Datatilsynet may issue remedial orders, temporary bans or corrective measures and can refer matters for sanctions under national implementing legislation. The guidance also emphasises that public authorities should implement internal appeals and redress mechanisms for individuals affected by AI-driven decisions, and that procurement and public law regimes can create additional accountability and liability channels.
Relationship to Other Instruments
Datatilsynet situates the guidance within the EU and Danish legal landscape. It explicitly references the GDPR (Regulation (EU) 2016/679) as the primary legal framework for personal data protections and notes intersections with sectoral laws (health, social services, administrative law). The guidance also anticipates the EU AI Act and cross-references its risk-based approach where relevant. Authorities are urged to coordinate with sectoral regulators and to seek legal counsel when other statutes (e.g., health law, public administration law) interplay with data protection obligations.
International Alignment
Datatilsynet emphasises alignment with international developments and standards: the guidance references OECD and EU definitional work and encourages Danish authorities to monitor the EU AI Act developments and to use the national sandbox (in cooperation with Digitaliseringsstyrelsen) to ensure cross-border legal and technical conformity. The guidance underscores that providers from third countries remain subject to EU data protection obligations where processing affects persons in the EU and encourages contractual and technical safeguards for cross-border model supply and cloud services.
Implementation Timeline
| Event | Date / Note |
|---|---|
| Datatilsynet guidance published | October 2023 (see PDF) |
| Datatilsynet decision referencing guidance (example case) | 2024-01-19 (Sønderborg decision) |
| Regulatory sandbox operational (ongoing) | Established by Datatilsynet & Digitaliseringsstyrelsen (see sandbox page) |
| DPIA template (expected) | Datatilsynet indicated a template was expected in H1 2024; consult the Datatilsynet site for the latest template. |
Compliance Checklist
| Action | Status/Notes |
|---|---|
| Document project scope and purpose | Required – record as separate processing purpose |
| Legal basis assessment | Required – justify public task / legal obligation or other ground |
| Perform DPIA where likely high risk | Required where threshold met; use Datatilsynet guidance |
| Data minimisation & anonymisation | Prefer anonymised/pseudonymised data for training/testing |
| Transparency & information to data subjects | Update privacy notices describing AI use and rights |
| Human oversight & redress mechanisms | Required where individual rights are materially affected |
| Procurement & vendor controls | Include contractual clauses on security, access, updates |
| Monitoring & validation plan | Define KPIs and retraining thresholds |
Sources and References
| Source | Type |
|---|---|
| Datatilsynet, "Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang" (October 2023) | Primary Source |
| Datatilsynet – Kunstig intelligens overview | Primary Source |
| Regulation (EU) 2016/679 (GDPR) | Primary Source |
| Regulation (EU) 2024/1689 (EU Artificial Intelligence Act) | Primary Source |
The Danish Data Protection Agency (Datatilsynet) has issued guidance to help Danish public authorities responsibly design, develop, and deploy Artificial Intelligence (AI) systems that process personal data, ensuring compliance with existing privacy regulations. This guidance, published in October 2023 and currently in force, specifically targets all Danish public authorities engaging with AI.
The core message is that established data protection rules, particularly the General Data Protection Regulation (GDPR), apply fully to AI, regardless of its technological sophistication. Authorities must ensure they have a clear legal basis and purpose for processing personal data with AI, treating AI development itself as a distinct processing activity. Data minimisation is paramount, urging the use of anonymised or pseudonymised data whenever possible, especially during AI training and testing. For any AI system likely to pose a high risk to individuals' rights, a thorough Data Protection Impact Assessment (DPIA) is mandatory. Furthermore, authorities are obligated to maintain transparency, informing individuals about how AI is used, its underlying logic, and their rights, while also ensuring human oversight for any AI-driven decisions that significantly affect individuals.
While this guidance doesn't introduce new penalties, it serves as a firm reminder that non-compliance with GDPR and other data protection laws can lead to serious consequences. Datatilsynet has the power to issue corrective orders, temporary bans, and significant fines. A key practical takeaway for authorities is the substantial ongoing commitment required for continuous monitoring and validation of AI models. This includes regularly checking model accuracy, fairness, and potential "drift" over time, along with establishing clear plans for retraining or decommissioning systems. This continuous oversight, often overlooked, is critical to maintaining compliance and trust.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 14 marked completePlain-English obligations under Denmark - AI Use by Public Authorities. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before processing likely to result in high risk
Applies to: Danish public authorities deploying AI systems.
“perform Data Protection Impact Assessments where processing is likely to result in high risk”
- #2Critical⏰ Before processing personal data
Applies to: Danish public authorities processing personal data with AI.
“select an appropriate lawful basis (e.g., public task, legal obligation, research/statistics exceptions where relevant)”
- #3Critical⏰ Before deploying AI for automated decision-making
Applies to: Danish public authorities using AI for decision-making.
“avoid fully automated individual decisions without human intervention where Article 22 GDPR applies”
- #4Critical⏰ Before processing personal data with AI
Applies to: Danish public authorities using AI to process personal data.
“ensure data subject notices describe AI use, logic and rights”
- #5Critical
Applies to: Danish public authorities deploying AI systems.
“maintain records of processing, datasets, testing results, and governance decisions.”
- #6Critical⏰ Before signing procurement contracts
Applies to: Danish public authorities procuring AI systems or services.
“procurement contracts should include data protection clauses, model update/monitoring obligations and security requirements.”
- #7Critical⏰ Before deploying AI for decision-making
Applies to: Danish public authorities deploying AI systems.
“plan for human oversight in decision points where individual rights may be affected.”
- #8Critical⏰ When AI models adapt or learn
Applies to: Danish public authorities operating adaptive AI systems.
“authorities must reassess legal bases and DPIAs and document changes.”
- #9Important⏰ Before starting AI projects
Applies to: Danish public authorities deploying AI systems.
“assigning a project owner and data protection owner (DPO or equivalent)...”
- #10Important⏰ Before data collection/processing for AI
Applies to: Danish public authorities developing or deploying AI systems.
“prefer anonymised or pseudonymised data and limit sensitive data”
- #11Important⏰ Before deploying AI systems
Applies to: Danish public authorities deploying AI systems.
“adopt measures against model inversion, membership inference, and adversarial manipulation”
- #12Important⏰ Before deploying AI systems
Applies to: Danish public authorities deploying AI systems.
“establish testing, performance thresholds, retraining policies and bias checks”
- #13Important
Applies to: Danish public authorities operating AI systems.
“continuous validation of model outputs (accuracy, fairness, drift detection), scheduled audits, logging of model decisions where relevant...”
- #14Important⏰ Before starting AI projects
Applies to: Danish public authorities initiating AI projects.
“start with scoping and a preliminary legal assessment to identify objectives and data flows”
Related Regulations
Digitaliseringsstyrelsen Guides for Responsible Use of Generative AI (Guides til ansvarlig anvendelse af generativ kunstig intelligens)
Denmark94% similar
National Strategy for Artificial Intelligence (National strategi for kunstig intelligens)
Denmark91% similar
Digital Taskforce for Artificial Intelligence (Digital Taskforce for kunstig intelligens)
Denmark91% similar
Strategic Approach for Artificial Intelligence (Strategisk indsats for kunstig intelligens)
Denmark91% similar
Regulatory Sandbox for Artificial Intelligence (Regulatorisk sandkasse for AI) – Datatilsynet & Digitaliseringsstyrelsen
Denmark91% similar
© Regulations.AI — created on 13-Jun-2026