- Danish authorities say unauthorized parties abused a company's lawful search access to the CPR register. Data linked to about 8.8 million people was affected.
- How the access came to be misused is not public. The case shows why a partner's search rights belong in your own risk review.
- Leaders should list every outside party that can search their data and ask how quickly unusual lookup volume would be noticed.
The door you hand to a partner
Much security effort goes into the front door. The Danish incident points at a different one: the access an organisation gives to an outside company.
Danish authorities said on Monday that outsiders with no right to the data reached personal information tied to about 8.8 million people. The data sits in the Central Person Register, known as the CPR. It is Denmark's national civil registration system. The Ministry of Research, Education and Digitalisation made the announcement.
The ministry said the unauthorized parties abused a Danish company's lawful ability to search the CPR. The CPR administration has since blocked that company's access.
What was reached, and what was not
The ministry said the exposed data includes names, addresses and CPR numbers. The register can also hold marital status, birth registration details and family relationships. It can hold Church of Denmark affiliation and information about legal incapacitation too.
The ministry did not say which of those extra details were accessed in each case.
The CPR holds records for around 11 million people. That includes people who have died or moved abroad. The affected group is therefore roughly four in five of all records.
According to the review so far, people under name and address protection did not have those details exposed. The report gives no reason for this. It is an early result, not a final one.
Why delegated access is hard to control
The report gives no technical detail on how the CPR search access worked. What follows is general context on controls that matter when an outside company can query a register. It is not a finding about what failed here.
Two questions are separate. Authentication asks whether the caller is the approved company. Authorization asks whether this particular query is one that company should make. Valid credentials answer only the first.
Some controls address the second question. One is a limit on what each partner can search. Another is a cap on how many lookups it can run. A third is a flag when a partner's volume departs from its normal pattern. The report does not say whether the CPR had any of these.
The report also does not say how the unauthorized parties came to use the company's access. The company could have been compromised, careless or involved. The ministry has not said which. It has not said how many searches were run, or over what period. Those facts would explain this case. They are not yet public.
The lesson here is general. A partner's access to your data is part of your own exposure, whatever the cause. Your controls end where the partner's begin, but the data does not.
Timeline and open questions
The ministry said the incident took place during September. The CPR administration became aware of it on Friday evening last week. Datatilsynet, the Danish Data Protection Agency, said it received notification on Sunday. Police are investigating.
The report does not say when in September the access began. It does not say how the access was detected. Datatilsynet said it cannot yet assess the circumstances or comment further.
Minister Christina Egelund briefed a parliamentary committee and ordered a thorough security review of the CPR. She also asked people in Denmark to follow official digital security advice.
Questions for your team
Start with a list. Which outside companies can search, export or query your customer or citizen data? Who approved each one, and when was it last reviewed?
Then ask about volume. What does a normal day of lookups from each partner look like? Would anyone be told if one partner suddenly touched a large share of your records?
Finally, ask about cut-off. Can you block one partner within hours without stopping the rest? The CPR administration has since blocked the company's access. The report does not say when that happened. The question for your own organisation is how soon you would know.
Trusting a partner works as a control only when someone is watching how that trust is used.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: cphpost.dk.





