Denmark tightens security rules for over a thousand firms with CPR access
The CPR administration sent a warning letter to 1,039 companies with access to the civil registration system, demanding stricter security measures.
The Danish CPR administration issued a formal admonition to 1,039 organisations that are permitted to use the civil registration database, instructing them to reinforce their data protection practices. The notice, circulated by Minister Christina Egelund to two Folketing committees, comes after an unauthorized party accessed the register through a Funen-based IT company. Although the intruder did not exploit the access throughout the entire period, the incident exposed weak safeguards, such as simple passwords like ‘123456’ used by several accounts, including an administrator profile.
The new rules require each firm to designate a security manager, continuously audit staff access, and monitor the number of monthly CPR transactions to spot potential abuse. The affected entities span the financial sector, telecoms, law firms, unions and insurers, all of which rely on CPR data for address verification and similar purposes.
Why it matters
Weak controls over Denmark's personal ID database could expose millions of citizens to identity theft.
In this story
Related stories
2 in this thread