This page covers the Danish framework, the cookie order that governs the device layer, and how a Danish B2B review usually runs.
At a glance
- Framework
- GDPR + Databeskyttelsesloven (Act no. 502/2018)
- Supervision
- Datatilsynet, the Danish Data Protection Agency
- Usual legal basis
- Legitim interesse, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing location
- ISO-certified EU data centres
The legal framework in Denmark
Regulation at a glance
- FrameworkGDPR + Databeskyttelsesloven (Act no. 502/2018)
- SupervisionDatatilsynet, the Danish Data Protection Agency
- Usual legal basisLegitim interesse, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing locationISO-certified EU data centres
Denmark applies the GDPR together with the Databeskyttelsesloven, the Danish Data Protection Act that accompanies it. The act is mostly procedural and supplementary: it sets national rules where the GDPR allows them, including on processing of national identification numbers, employment-related processing and the age of digital consent, which Denmark set at 13.
The most distinctive Danish feature is enforcement architecture rather than substance. Datatilsynet supervises and investigates, but it cannot itself impose administrative fines; in Denmark, fines are pursued through the courts via the police and prosecution service. The practical consequence is a supervisory culture built on guidance, dialogue and published criticism rather than on rapid penalties. For a vendor this means Datatilsynet's guidance documents carry a lot of weight in reviews, and a buyer will often quote them directly.
The device layer is governed by the Danish cookie order — the executive order on information and consent for storing and accessing information on end-user terminal equipment — which implements the ePrivacy rule. It requires clear information and consent before storing or accessing information on a visitor's device, with an exemption for what is strictly necessary to deliver a requested service. Danish practice puts particular emphasis on the banner being an actual choice and on documenting the consents you collect.
Datatilsynet has also been notably active on the question of where data is processed and on the use of non-EU cloud providers in the public sector, which has raised general awareness of processing location across the Danish market. A clear statement that visitor data stays in ISO-certified EU data centres tends to be the single most reassuring line in a Danish review.
Denmark also has strong marketing rules that surface in the same conversation: the Marketing Act's provisions on unsolicited electronic approaches are strict and well known, so Danish buyers will want to know that identification informs their outreach rather than replacing consent where consent is required.
How Danish buyers review it
Danish reviews are efficient and low-ceremony. The recurring questions are whether individuals are identified, where processing happens, who the sub-processors are, and how a visitor objects. English documentation is entirely acceptable; Danish B2B works in English without friction.
What Danish buyers dislike is overstatement. A vendor claiming to identify every visitor invites scepticism. Stating that identification works at company level, that a meaningful share of traffic cannot be resolved, and that the customer remains controller of their own site is the version that builds trust.
Larger Danish organisations will run a formal processor assessment, and because Datatilsynet's guidance is detailed, having a published data processing agreement and a versioned sub-processor list available up front removes most of the back-and-forth.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Danish B2B SaaS, industrial and cleantech exporters, shipping and logistics suppliers, and consultancies benefit most. Deal sizes are meaningful, buying groups are small, and much of the evaluation happens quietly on the website.
For companies selling from Denmark into the wider Nordic and European market, the same setup covers every country without additional tooling — the identification runs on the same snippet regardless of where the visitor sits.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Datatilsynet, the Danish Data Protection Agency, is the supervisory authority for processing under the GDPR and the Databeskyttelsesloven. It investigates complaints, publishes detailed guidance and issues public criticism, but it does not itself impose administrative fines — those are pursued through the ordinary courts via the police and the public prosecutor. That architecture means Datatilsynet's published guidance carries unusual weight in commercial reviews: buyers routinely quote it directly, and a vendor that can point to the same guidance and show how its product fits within it will move through a Danish review much faster than one that simply asserts compliance.
The Databeskyttelsesloven is a supplementary act, not a separate regime: it fills the gaps the GDPR deliberately leaves to member states, covering processing of national CPR identification numbers, processing in an employment context, journalistic and research exemptions, and the digital age of consent, which Denmark set at 13 rather than the default 16. For company-level website visitor identification none of those national additions actually change the operative requirements — the governing rules remain the GDPR's own: a documented lawful basis, transparent information to visitors, and a written data processing agreement with any processor, lead.box included.
The Danish cookie order — the executive order on information and consent for storing and accessing information on end-user terminal equipment — implements the ePrivacy rule and requires clear information plus prior consent before anything is stored on or read from a visitor's device, unless it is strictly necessary to deliver a service the visitor requested. lead.box identifies the visiting company from network-level information rather than by placing an identifier on the device, so it sits outside the scope of that consent requirement. Assessing the rest of your site's cookies and scripts, and documenting the consents your banner collects, remains a task for you as the site operator, not for lead.box.
In ISO-certified EU data centres, with no transfer outside the EU/EEA as part of the standard setup. Datatilsynet has been unusually vocal about processing location, particularly around the use of non-EU cloud infrastructure in the Danish public sector, and that scrutiny has raised the bar for what Danish B2B buyers expect a vendor to be able to document. The data processing agreement and a versioned list of sub-processors are published so your reviewer can check exactly where data flows before anyone signs anything, rather than taking a verbal assurance on trust.
Every active Danish company is registered with a CVR number in the Central Business Register (Det Centrale Virksomhedsregister), and that register is what makes company-level identification genuinely useful in Denmark: a resolved visitor can be matched against public CVR data to confirm the legal entity, industry code and address behind a domain before a rep ever picks up the phone. It also matters on the receiving end — when your own company appears in someone else's identification data, the same CVR-linked registry is how a Danish counterpart would be able to describe your organisation accurately, so accuracy at that level is treated as a baseline expectation, not a nice-to-have.
Company-level website visitor identification does not process personal data about employees and is not employee monitoring, so it does not, on its own, trigger the information and consultation duties that apply under the Danish cooperation agreement (samarbejdsaftalen) between DA and LO or an individual samarbejdsudvalg. Where it can become relevant is if a Danish organisation later links identified companies to individual contact enrichment or feeds outbound activity into performance tracking for sales staff — those downstream uses are workplace-monitoring questions the customer needs to assess internally, separately from the identification service itself, and lead.box's role stops at company-level data.
Danish B2B procurement is pragmatic: a short vendor questionnaire, a look at the data processing agreement and sub-processor list, and a check of where the answers to Datatilsynet's own guidance points land — done in days rather than weeks for a tool at this scale. On the tooling side, Danish sales teams commonly run HubSpot, Pipedrive or Microsoft Dynamics 365, and identified companies need to reach whichever of those is already in daily use rather than sit in a separate dashboard nobody opens. A webhook or native CRM handover that pushes named companies straight into the pipeline your team already works from is what actually gets adopted.
You add one JavaScript snippet to your site, and identified companies typically start appearing within the first day of traffic — no server changes, no cooperation from IT beyond a tag-manager or code edit. From there you can route matches to CRM via webhook, export lists as CSV, Excel or JSON for a sales or marketing run, and add teammates as seats as adoption grows. If the tool does not earn its place, cancellation is self-service from account settings with no retention call or contract negotiation required, which matches how Danish buyers expect to be able to leave a subscription as easily as they entered it.
See which Danish companies read your site
Install the snippet, get named companies within a day, and answer the processing-location question with a document.