The Central Person Register (CPR) in Denmark has identified a serious security incident in which unauthorized parties obtained personal data from the register. According to the CPR administration, the breach occurred after a Danish company’s legitimate permission to query the CPR system was misused. By exploiting that access, the intruders were able to retrieve names, addresses, CPR numbers and other registered details for approximately 8.8 million individuals listed in the CPR database.

The CPR administration’s internal review determined that the unauthorized access did not include the names and addresses of persons who had opted for name‑and‑address protection, a voluntary service that shields those specific data points from disclosure. Consequently, while the majority of the population’s basic identification data were exposed, the protected subset remained outside the scope of the breach.
In response, the CPR administration has immediately terminated the company’s access to the CPR system and is working alongside IT specialists, government agencies and law‑enforcement officials to map the full sequence of events. The administration has formally notified the Danish Data Protection Agency (Datatilsynet) of the incident, as required by national data‑protection legislation.
Police authorities have opened an investigation into the breach, collaborating with relevant governmental bodies to determine how the misuse occurred and whether any further data were compromised. The CPR administration has directed the public to a press release on the Ministry of Research, Education and Digitization’s website for additional details and updates on the investigation.
As of the latest statement, no evidence has been presented suggesting that the exposed data have been misused or disseminated beyond the initial unauthorized access. The CPR administration continues to monitor the situation and advises citizens to remain vigilant about potential phishing or identity‑theft attempts that could exploit the leaked information.
Key facts
- Unauthorized access obtained via a Danish company’s legitimate CPR query permission.
- Approximately 8.8 million residents had names, addresses and CPR numbers exposed.
- Individuals with name‑address protection were excluded from the exposed data.
- CPR administration reported the incident to Datatilsynet and police are investigating.
