Coming in October 2026: Inside Personal Data Breaches in Denmark

Eight years of reported breaches in Denmark, examined in seven chapters

Preface

My journey in IT began in the mid-1990s with dBase V and FoxPro 2.6 and eventually led to my current role as a Cybersecurity and Data Lifecycle Architect. Throughout my career, I have worked extensively with data in various capacities, including managing personal, confidential, and sensitive data, often under strict regulatory requirements.

I often say that I have unwittingly touched personal data, sensed its presence within systems, and witnessed its movement across networks, not only from a technical perspective but with a deep, holistic understanding of its entire lifecycle. From creation to secure deletion, data is both inherently valuable and highly vulnerable: it can be a business’s greatest asset and its greatest exposure. Managing it effectively requires technical proficiency and a firm commitment to regulatory compliance.

In the early years, personal data was left exposed: stored in unsecured formats, shared openly by email, or kept in databases without encryption or access controls. I refer to data managed this way as ‘naked data’—personal data unprotected, unmasked, and vulnerable to misuse. Sensitive data was in plain sight, easily accessible with minimal effort.

May 2018 marked a significant turning point: the General Data Protection Regulation (GDPR) became applicable across the EU. The GDPR introduced stricter consent rules, empowering individuals with stronger data rights and making organisations accountable for how they process personal data.

At a seminar during this transition period, I vividly recall a speaker emphasising the Danish phrase ‘Slette, slette, slette’. It was a defining moment, and it still echoes in my mind. In English, this means ‘Delete, delete, delete’: if you do not need the data, delete it. It is a simple yet powerful principle that continues to guide my work, helping to minimise data risk, improve compliance, and build trust.

As the GDPR reshaped the landscape, I deepened my expertise through research, hands-on experience, and professional training, including a Certificate in Data Privacy and Technology from Harvard Online, which broadened my strategic understanding of how organisations handle personal data.

Over time, I became engaged with personal data breaches in Denmark. Year after year, statistics from the Danish Data Protection Agency (DDPA), also known as Datatilsynet, revealed that personal data breaches remained high, affecting organisations, individuals, and stakeholders across industries. I recognised the need for a comprehensive book analysing these breaches, their causes, and emerging risks.

What began as a series of LinkedIn posts grew into a more ambitious project. Initially, I planned to publish an independent report, now Part II of this book, that focused exclusively on personal data breach trends in Denmark. However, I quickly realised the need for a foundation that explored the broader context of the breach data. This required a more structured book format. With Part I now covering the essential GDPR foundation, Personal Data Breaches in Denmark (2018–2026): A Comprehensive Overview was born.

This book is written for anyone who works with personal data, whether you are new to the field or have many years of experience in data protection. It offers an accessible introduction to GDPR fundamentals, a real-world analysis of personal data breaches in Denmark, and a concluding discussion of the key challenges facing data protection today.

Drawing on my experience leading data-driven projects, I have developed extensive expertise in cybersecurity, data privacy, and data protection within key regulatory frameworks such as the GDPR. That experience has given me the practical understanding to support professionals and organisations working to uphold data privacy and security.

Understanding the incident types that lead to personal data breaches and the risks they pose is the first step towards prevention. I hope this book provides the practical insight that individuals and organisations need to make informed decisions.

About The Author

Pradip Shrestha is a seasoned IT professional with more than 25 years of experience helping organisations protect and manage their most valuable asset: data. With a strong background in systems engineering and cybersecurity, he has led data-driven projects that improve organisational processes, with a focus on safeguarding data privacy and strengthening protection throughout the personal data lifecycle.

As the founder of Alpha Data Consult, Pradip works closely with start-ups, non-profits, and organisations across sectors. He guides them through the full data-processing journey, from classifying data to building secure systems aligned with privacy regulations such as the GDPR. His expertise spans cybersecurity, data protection, and AI-enabled data tools, helping organisations remain resilient, compliant, and prepared in a changing digital landscape.

Pradip also holds a master's degree in computer science, specialising in data security and protection. His commitment to continuous learning and professional development is reflected in his certifications:

  • Data Privacy and Technology, Harvard Online (2024)
  • Cybersecurity Architect Expert, Microsoft (2022)
  • Azure Solutions Architect Expert, Microsoft (2019)

Driven by curiosity and a passion for innovation, Pradip believes that data protection is not just a technical challenge but a shared responsibility. This book reflects his mission to make complex topics clear, actionable, and relevant for everyone.

Part I

Chapter 1: Denmark's Digital Society and Personal Data Fundamentals

This chapter provides the foundation for understanding the General Data Protection Regulation (GDPR) within the Danish context. It explains the core principles of personal data processing, data classification, and levels of sensitivity. It also distinguishes the main types of personal data breaches, covers breach notification, and outlines the proposed Single Entry Point (SEP).

Chapter 2: Incident Types and Risk Categorisation

This chapter explains the incident types defined by the Danish Data Protection Agency (DDPA) and the risks they pose to personal data. It then introduces the MEO Framework (Mistakes, Errors, and Omissions), which categorises unintentional breaches by failure mode. Together, these classifications help organisations understand how breaches occur and identify appropriate safeguards.

Chapter 3: Sectors and Industries

This chapter explains how the DDPA classifies data controllers by sector and industry. It also identifies the industries with the most reported personal data breaches between 2018 and 2026.

Part II

Chapter 4: Dataset Overview and Insights

This chapter describes the source of the dataset used to analyse personal data breaches reported in Denmark. It explains the methodology for collecting and categorising the data to examine trends across sectors, industries, and incident types. It also addresses the dataset's limitations and their implications for interpreting the findings.

Chapter 5: Summary of Findings

This chapter summarises the key findings, highlighting major trends and recurring patterns in personal data breaches reported in Denmark. It identifies the most common incident types and the sectors with the most notifications, and provides an overview before the detailed analysis in Chapter 6.

Chapter 6: Breach Patterns: Analysis and Interpretation

This chapter examines the dataset across sectors and years, exploring the practical implications of the findings. It applies the MEO Framework to examine patterns of Mistakes, Errors, and Omissions in reported unintentional breaches. The results help organisations prioritise their data security measures.

Chapter 7: Breach Insights and Measures: Strengthening Data Security

This chapter brings together insights from earlier chapters to present a clear approach to protecting personal data throughout its lifecycle. It draws on the MEO Framework to explain why Mistakes, Errors, and Omissions require different safeguards. The chapter connects prevention, breach response, and organisational learning to help organisations strengthen data security in everyday practice.

Staying Informed and Connected

For the latest data protection decisions, regulatory updates, and news, visit the official website of the Danish Data Protection Agency (Datatilsynet).

Each chapter includes shortened links for quick reference, with the full URLs listed in the Endnotes.

This book is intended for informational purposes only and does not constitute legal advice. For GDPR-related legal guidance, consult a qualified legal professional in your jurisdiction.

If you have questions, feedback, or suggestions on presenting data breach findings, I would welcome hearing from you. You can contact me on LinkedIn.

Endnotes

The endnotes are organised by chapter, with full URLs and supporting resources for further reading.

Explore the Book Further

The chapter introductions above give an overview of the book. Visit the pre-release page for an early look at its findings. The full book will be published in October 2026.

Read the pre-release →