Denmark - Data Security and Ethics (B 149)
Proposal for Parliamentary Resolution on Better Data Security and Data Ethics
Forslag til folketingsbeslutning om bedre datasikkerhed og dataetik
Denmark
RAI-DK-NA-PPRBDXX-2022Decision proposal B 149 (2021-22) called for strengthened institutional independence for the Danish Data Protection Agency (Datatilsynet), mandatory data-impact assessments in legislative proposals, and a formal role for the Danish Data Ethics Council (Dataetisk Råd) as a consultation body on legislation affecting personal data handling. The proposal was introduced 1 March 2022 and the committee report was delivered 28 June 2022.
Summary
Read full text ↗Plain English
Overview
The Proposal for Parliamentary Resolution on Better Data Security and Data Ethics (B 149), tabled 1 March 2022 in the 2021-22 Folketing session, is a decision proposal authored by members of the Socialistisk Folkeparti. The proposal recommends three interlocking reforms: moving the Danish Data Protection Agency (Datatilsynet) under the parliamentary purview to strengthen its independence; requiring mandatory legislative consequences assessments that specifically address impacts on personal data processing be included in explanatory notes to all future bills; and designating the Data Ethics Council (Dataetisk Råd) as a formal hearing body for any legislative initiatives that touch on the processing of citizens' personal data. The official Folketinget dossier for B 149 records the submission, committee referral and the Retsudvalget's report, and provides background documents, including correspondence from the Ministry of Justice and material concerning consultation with the Data Ethics Council. For the official parliamentary record see Folketinget – B 149 (index) and the background package at Folketinget – B 149 (background). The proposal is positioned within an evolving policy environment that includes national data protection law and the EU's General Data Protection Regulation (GDPR), and it directly engages two national institutions central to Denmark's data governance architecture: Datatilsynet and Dataetisk Råd.
Definitions
For the purposes of B 149, key terms are used as follows: "Datatilsynet" (the Danish Data Protection Agency) denotes the national supervisory authority charged with GDPR enforcement and other national data protection responsibilities; "Dataetisk Råd" (Data Ethics Council) denotes the independent advisory council providing recommendations and ethical analyses of data use; "consequence assessment" refers to a legislative explanatory analysis that systematically examines the impact of a proposed law on the processing of personal data, analogous in part to a Data Protection Impact Assessment (DPIA) but applied at the bill-drafting stage; "processing" and "personal data" have the meanings given in the GDPR and the Danish Data Protection Act. The proposal also uses parliamentary terms such as "beretning" (committee report) and "henvist til udvalg" (referred to committee) in the ordinary legislative / parliamentary process. These definitions are used throughout the committee materials available on the Folketinget website.
Governance and Institutional Framework
B 149 focuses on institutional placement as a governance lever: moving Datatilsynet from the administrative domain of the Ministry of Justice to the Folketinget is proposed to increase autonomy and reduce perceived or actual executive influence over supervisory priorities and case-handling. The proposal does not, in its parliamentary decision format, itself amend statutory competences; rather it is a resolution that recommends institutional realignment and procedural changes. The Retsudvalget (Legal Affairs Committee) handled the dossier; committee documents and the ministerial correspondence describe mechanisms for consultation with the Data Ethics Council and internal ministry processes. The Data Ethics Council is described on its official site as an independent, public administrative authority tasked with monitoring technological developments and advising on data-ethical dilemmas (Dataetisk Råd – English). Datatilsynet’s role and contact information are described on the Danish Data Protection Agency site, which also sets out its supervisory tasks under the GDPR (Datatilsynet – English). The proposal therefore requests a formal change in reporting lines and an integration of ethics consultation into legislative drafting and review processes, thereby altering governance interactions among Parliament, the ministry, the data protection supervisory authority and the Data Ethics Council.
Key Focus Areas
B 149 centers on three mutually reinforcing focus areas. First, independence and oversight: relocating Datatilsynet under Folketinget aims to increase the agency's institutional independence and to strengthen democratic oversight of data protection enforcement decisions. Second, procedural transparency in law-making: the proposal requires that explanatory notes accompanying any future legislative proposal must include mandatory consequence assessments regarding how the proposed measures will affect processing of citizens' personal data—this is intended to make trade-offs visible to legislators and the public at the earliest stage. Third, ethical review and consultation: by establishing the Data Ethics Council as a formal hearing body for legislation affecting personal data, the proposal seeks to ensure that ethical dimensions (including implications for fundamental rights, fairness, and non-discrimination) are systematically considered alongside legal and technical analyses. Collectively, these focus areas aim to reduce regulatory capture, improve anticipatory governance of data-driven public-sector projects, and embed data ethics into parliamentary practice. The proposal also addresses cross-cutting technical and policy issues: it underscores the need for better documentation of automated decision-making systems used by public authorities, for legislative attention to cybersecurity risks associated with large-scale datasets, and for alignment between national parliamentary practice and EU-level protections under the GDPR and related initiatives. While the decision proposal itself is not an implementing statute, it signals parliamentary intent and sets expectations for ministries to adopt stronger impact assessment procedures and to consult the Data Ethics Council where appropriate. The background materials available through the Folketinget portal include committee papers and ministerial correspondence that expand on these points and show how ministries were asked to engage the Data Ethics Council following the committee's report (Folketinget – REU Bilag 333).
Implementation Framework
Because B 149 is a parliamentary resolution rather than a law, its implementation is predominantly procedural and administrative: ministries would be expected to incorporate the mandatory consequence assessments into standard operating procedures for legislative drafting, to provide these assessments in the explanatory notes (bemærkninger) of draft bills, and to make arrangements for early consultation with the Data Ethics Council whenever processing of citizens' personal data is implicated. For the institutional recommendation (moving Datatilsynet under Folketinget) to take legal effect, secondary measures or primary legislation would be required to change Datatilsynet's statutory placement and reporting lines. The implementation framework therefore involves a mix of administrative directives (for drafting practices) and potential statutory reform (for institutional transfer). The proposal and accompanying committee materials recommend concrete administrative steps ministries should adopt, and the ministerial correspondence recorded in the parliamentary dossier confirms that ministers considered formalizing Data Ethics Council consultation on relevant drafts (Folketinget – B 149 background).
Monitoring and Evaluation
Monitoring of the resolution's effects would be twofold: (1) short-term monitoring by parliamentary committees and by ministries of compliance with the new requirement to include consequence assessments in explanatory notes; and (2) medium-term evaluation of whether the Data Ethics Council’s formal involvement leads to measurable improvements in policy quality, fewer data-protection conflicts, or increased public trust. The Retsudvalget’s beretning (committee report) and subsequent documentation in the parliamentary files function as a public record for tracking follow-up actions. If Datatilsynet were to be moved under the Folketinget, oversight metrics could include continuing independence indicators, complaint handling times, enforcement activity, and budgetary autonomy. Public reporting by the Data Ethics Council and Datatilsynet would also form part of an open evaluation ecosystem; both institutions publish reports and guidance on their websites (Dataetisk Råd, Datatilsynet).
Penalties, Liability, and Appeals
The B 149 resolution itself does not introduce specific sanctions or penalty regimes; rather, it seeks to change institutional placement and parliamentary practice. Existing penalty frameworks for violations of data protection law (notably the GDPR administrative fines and national implementing rules) remain applicable and continue to be enforced by Datatilsynet under existing legislation. Should the institutional recommendations lead to legislative change, existing GDPR-derived enforcement mechanisms—investigations, corrective orders, and fines—would continue to be the primary sanctions for unlawful processing. The resolution’s main remedial mechanisms are procedural: improved impact assessments and ethics consultation are intended to prevent unlawful or ethically problematic processing before it occurs, reducing the need for later sanctions. Appeals against administrative decisions remain subject to applicable administrative law and judicial review processes; any transfer of Datatilsynet would likely require careful preservation of appeal routes and judicial oversight to maintain rights protections.
Relationship to Other Instruments
B 149 intersects with national and EU legal instruments. It directly relates to the GDPR (Regulation (EU) 2016/679) and Denmark’s Data Protection Act (Databeskyttelsesloven) because it concerns supervisory structures and procedural safeguards around personal data processing. The proposal also complements other parliamentary initiatives on algorithmic transparency, AI oversight and data governance (for example later proposals and drafts addressing independent AI oversight and registration of algorithmic use). The Folketinget dossier for B 149 cross-references other parliamentary proposals and debates in which data ethics and algorithmic transparency have been central. The Data Ethics Council’s remit and published recommendations sit alongside advisory functions at national level (e.g., the Danish Council on Ethics) and are intended to avoid duplication while adding a dedicated ethics lens to data policy discussions (Dataetisk Råd).
International Alignment
The proposal is consistent with EU-level priorities emphasizing strong, independent data protection authorities and anticipatory governance for data-driven systems. By calling for mandatory legislative consequence assessments and formal ethics consultations, B 149 resonates with wider European debates about algorithmic accountability and the need to combine legal compliance (GDPR) with ethical governance. The recommendation to strengthen supervisory independence reflects principles articulated in EU guidance on independent supervisory authorities and comparative reforms in other Member States. While B 149 is national in scope, it expressly situates Denmark’s approach within the EU framework and seeks to ensure national practices are aligned with European standards for oversight, transparency and fundamental-rights protections.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Proposal presented to Folketinget | 2022-03-01 | Fremsat by members of SF; recorded on Folketinget dossier. |
| First reading / referred to committee | 2022-05-10 | Henvist til Retsudvalget (Legal Affairs Committee). |
| Committee report (beretning) issued | 2022-06-28 | Retsudvalget beretning afgivet. |
| Ministerial correspondence re: Data Ethics Council hearings | 2022-08-12 | Bilag 333: Letter from the Minister for Justice concerning consultation with Dataetisk Råd. |
Compliance Checklist
| Requirement | Compliant action |
|---|---|
| Include consequence assessment in explanatory notes | Ministry/legal drafter prepares and publishes a dedicated section on data-processing impacts when presenting a bill. |
| Consult Data Ethics Council on drafts affecting personal data | Ministry notifies Dataetisk Råd and incorporates its advisory comments into bill preparation. |
| Preserve Datatilsynet independence | If institutional transfer occurs, ensure budgetary and operational independence through statute or parliamentary resolution. |
| Document automated decision-making | Include documentation in bill materials and public registries where automated systems are deployed by public bodies. |
Sources and References
| Source | Type |
|---|---|
| Folketinget – B 149 index (Proposal page) | Primary Source |
| Folketinget – B 149 background materials | Primary Source |
| Folketinget – REU Bilag 333 (ministerial letter re: Data Ethics Council) | Primary Source |
| Danish Data Protection Agency (Datatilsynet) – English | Primary Source (agency) |
| Data Ethics Council (Dataetisk Råd) – English | Primary Source (agency) |
Denmark's B 149 proposal aims to strengthen data protection and ethics by reforming how the government handles personal data in new legislation, primarily affecting Danish ministries and the legislative process. This parliamentary resolution, introduced in March 2022, targets Danish ministries, the Danish Data Protection Agency (Datatilsynet), and the Danish Data Ethics Council (Dataetisk Råd). It recommends three key changes to improve data governance. First, all future legislative proposals affecting personal data must include mandatory "consequence assessments" in their explanatory notes, detailing the impact on data processing. Second, the Data Ethics Council should become a formal consultation body for any new laws touching on citizens' personal data. Third, the Danish Data Protection Agency (Datatilsynet) should be moved under parliamentary oversight to boost its independence from the government.
As a *proposal* or *resolution*, B 149 does not have an immediate effective date for its recommendations; these would require further government action or new legislation to be implemented. The proposal itself does not introduce new penalties. Instead, it aims to prevent data protection issues by embedding ethical and impact considerations into the law-making process. Existing penalties under the EU's General Data Protection Regulation (GDPR) and Danish data protection law, enforced by Datatilsynet, remain in effect for unlawful data processing. A crucial point for product managers and founders is that B 149 is a *recommendation* for how the Danish government *should* legislate, not a new law imposing direct obligations on businesses. Its primary impact is on the internal legislative process, aiming to ensure data protection and ethics are considered early in policy development, rather than creating new compliance burdens for companies directly.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 5 marked completePlain-English obligations under Denmark - Data Security and Ethics (B 149). Not legal advice — verify against the official text before relying on it.
- #1ImportantKey Focus Areas⏰ Before presenting a bill to Parliament
Applies to: Ministries and legislative drafters preparing new bills.
“explanatory notes accompanying any future legislative proposal must include mandatory consequence assessments regarding how the proposed measures will affect processing of citizens' personal data.”
- #2ImportantKey Focus Areas⏰ During legislative drafting
Applies to: Ministries drafting legislation involving personal data.
“ministries would be expected... to make arrangements for early consultation with the Data Ethics Council whenever processing of citizens' personal data is implicated.”
- #3ImportantGovernance and Institutional Framework⏰ If institutional transfer occurs
Applies to: Parliament and Government, if Datatilsynet's institutional transfer occurs.
“relocating Datatilsynet under Folketinget aims to increase the agency's institutional independence”
- #4RecommendedKey Focus Areas
Applies to: Public authorities deploying automated decision-making systems.
“it underscores the need for better documentation of automated decision-making systems used by public authorities”
- #5RecommendedKey Focus Areas⏰ When drafting legislation
Applies to: Legislative drafters.
“it underscores the need for... legislative attention to cybersecurity risks associated with large-scale datasets”
Related Regulations
Proposal for Parliamentary Resolution to Establish an Independent AI Supervisory Authority under the Data Protection Authority (B 90)
Denmark92% similar
Proposal for Parliamentary Resolution to Ensure Transparency in Authorities' Use of Algorithms (B 136)
Denmark91% similar
Proposal for Parliamentary Resolution on Guidelines and Risk Assessments for the Use of Artificial Intelligence (B 42)
Denmark89% similar
National Strategy for Artificial Intelligence (National strategi for kunstig intelligens)
Denmark87% similar
Digital Taskforce for Artificial Intelligence (Digital Taskforce for kunstig intelligens)
Denmark86% similar
© Regulations.AI — created on 13-Jun-2026