Denmark's Central Population Register Breach Affects 8.8 Million Records

Unauthorized access via small private company exposes personal data including CPR numbers

By LineZotpaper
Published
Read Time2 min
An unauthorized party has abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information of approximately 8.8 million people, the CPR administration has confirmed.

The breach was detected on October 2 after irregular activity during September. The CPR administration said it established the scale of the breach over the weekend and has blocked the unnamed company's access. The affected total exceeds Denmark's current population of around 6 million because the register contains about 11 million records, including individuals who have died or moved abroad. The ministry noted that names and addresses of persons who chose name and address protection were not exposed.

Digitization minister Christina Egelund told TV 2 it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed. Danish cybersecurity specialist Jan Kaastrup argued that treating CPR numbers as secrets is a "broken" approach and that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said.

Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions requiring legally entitled processing and advance identification of a defined group of individuals. The CPR administration has asked the ministry why such broad access was granted. The agency has notified the Danish Data Protection Agency, and police are investigating.

§

Analysis

Why This Matters

  • The breach undermines trust in Denmark's digitally enabled public services, which rely on CPR numbers for healthcare, tax, and banking transactions.
  • It highlights risks in allowing private companies access to sensitive national identification data, even when legally entitled.
  • The incident could trigger a national conversation about replacing CPR numbers with more secure authentication methods.

Background

The CPR number is a central identifier in Denmark, used to access public services, open bank accounts, and conduct everyday transactions. The system was designed for efficiency in a digital society, but security experts have long warned that using a single, static number as proof of identity is vulnerable to abuse. Private entities can apply for access under Danish law, but the incident raises questions about oversight and the scope of data sharing.

Key Perspectives

Digitization Minister Christina Egelund: She has acknowledged the severity but declined to commit to reissuing CPR numbers, saying it is too early to decide. She emphasized that the company involved was small, suggesting the breach may stem from inadequate safeguards at the recipient rather than systemic flaws. Cybersecurity Expert Jan Kaastrup: He argues the system is fundamentally broken because CPR numbers were never designed to be secret credentials. He calls for a shift to multi-factor authentication or more robust digital identity systems. Privacy Advocates: The breach underscores the risk of broad data access by private firms. Critics question why any company can obtain a large dataset without stronger verification of security practices.

What to Watch

  • Whether the Danish Data Protection Agency imposes a significant fine or orders changes to access rules.
  • If the government announces a timeline for transitioning to a new digital identity system or mandates additional authentication for CPR-based transactions.
  • The outcome of the police investigation and whether it reveals the origin and intent of the unauthorized party.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.