Denmark is investigating a breach of its Central Person Register (CPR) that exposed the names, addresses and 10-digit CPR numbers of about 8.8 million people. The government announced it on Monday, October 5, 2026. According to The Record, the perpetrators exploited an unnamed domestic company's legitimate access to the register. They carried out unauthorized searches during September. Minister Christina Egelund called it "a deeply serious incident" and ordered a broad security review.
What happened, and what did not
This was not, on the facts reported so far, a break-in against the register's core infrastructure. The attackers used credentials and access that the state had granted to a private company. Officials first detected irregular activity on Friday. Investigators concluded over the weekend that the breach took place during September. Denmark's Data Protection Agency says it was notified on Sunday.
The register holds records on around 11 million people, including residents, people who have moved abroad, and the deceased. Denmark's population is just over six million. About 8.8 million records is therefore roughly four in five of everything the register holds. The exposed fields are the ones that matter most. A CPR number begins with the holder's date of birth and is used for healthcare, banking and government services. It is designed to last a lifetime.
That last point is the core of the harm. A leaked password can be changed. A leaked lifelong identifier cannot, and the CPR number is widely treated as a semi-public lookup key. Its exposure creates a durable risk of impersonation and social-engineering fraud, and of targeted phishing that uses correct names, addresses and birth dates.
The strongest case for tougher rules
Regulators and privacy advocates will make a serious argument, and it deserves a fair statement. Governments compel citizens to hold these identifiers and cannot offer an opt-out. A state that creates a single national key and then lets hundreds of private firms query it carries a special duty of care. On that view, strict liability, mandatory penalties and sweeping new access limits are justified. Denmark has also been here before. In 2015 the State Serum Institute sent data on more than five million people, on unencrypted CDs, to a Chinese visa centre. In 2016, Altinget reported that the Danish government intended to exempt public authorities from GDPR fines. Critics said that removed the incentive to invest in security.
The EU framework already leans this way. The European Data Protection Board's Guidelines 9/2022 on personal data breach notification, adopted in final form on April 4, 2023, set out how controllers should assess and report breaches under the GDPR. The NIS2 Directive extended cybersecurity duties to public administration at central and regional levels. Member States were due to transpose it by October 17, 2024.
Where proportionality matters
The lesson here is narrower than "more regulation", and it is more useful. The reported failure was in access governance: who may query a national register, at what volume, and with what monitoring. Several measures address that directly, and none of them requires a new law.
- Rate limits and anomaly detection. The attack depended on unauthorized searches. A register that permits bulk enumeration of valid identifiers through a legitimate account has a design problem. An alert that fires on enumeration-style query patterns would have caught this long before 8.8 million records were exposed.
- Least-privilege access. Many companies need to verify that a CPR number matches a name. Few need to search the register. Narrow, purpose-bound query types shrink the damage if one account is compromised.
- Fast detection. The breach occurred in September but was detected only on October 2. The review should ask how long a monitored system should take to notice a month of abnormal traffic.
- Reducing the identifier's power. CPR numbers still work as both an identifier and a quasi-authenticator in many private-sector flows. Services that treat knowledge of a CPR number as proof of identity turn every leak into a fraud opportunity. Stronger authentication elsewhere in the system does more good than any penalty imposed after the fact.
Blunt responses carry costs. Banning private-sector access to the register would break legitimate services such as credit checks, healthcare administration and address verification. It would also push firms toward worse, less accountable data sources. Disproportionate liability on small access-holders may deter them from holding data at all, while doing little about the state's own monitoring gaps. The company whose access was abused should be examined, but responsibility is shared. The state decided who gets access and what the access allows.
What to watch
Three questions will decide whether Denmark's response is credible. Will the security review be published, so that other EU administrations can learn from it? Will the Danish Data Protection Agency treat the state as a controller with the same exposure as a private firm? And will the government address the dependence on the CPR number as proof of identity, or only tighten the register's front door?
The Record notes that the breach is the most significant CPR incident since 2015. That is the wrong benchmark. The 2015 incident was a handling mistake involving physical media. This one shows that a well-run, widely trusted digital register can be drained through its own approved channels. Other EU member states that run population registers, or are building digital identity wallets, should be asking the same questions now.
The pro-innovation position is neither to freeze access nor to shrug. Digital public infrastructure works because many parties can build on it. Making that safe means treating every authorised user as a potential point of compromise and monitoring the register accordingly.