Birth date access remains open after Danish motor register data leak
Friday 18th September 2026 on 06:15 in
Denmark
More than 71,000 people were affected by a data breach in Denmark’s Motor Register, and access to their birth dates remains open more than a year after the breach was identified, DR reports. The Danish Motor Agency says it will now conduct an internal investigation into the handling of the case.
The breach affected 71,080 people whose names and addresses were protected in the Motor Register, Denmark’s official register of motor vehicles and their owners. Companies were able to access the protected information between 2021 and 15 July 2025.
Although the agency said in April that access to protected names and addresses had been closed, documents obtained through a freedom of information request show that birth dates were also available to unauthorised users.
The Danish Motor Agency has confirmed to DR that birth dates will not be hidden until 22 September 2026. That will be one year and two months after the security flaw was identified on 4 July 2025, and more than five months after affected people were sent letters about the leak of their protected names and addresses.
The agency said changing user roles to prevent birth dates from being disclosed required a larger system change. The implementation was therefore scheduled for the third quarter of 2026.
The agency declined to be interviewed by DR. It also did not explain why people were not told that birth dates had been exposed when the letters were sent in April.
Documents show that the Danish Data Protection Agency required the affected people to be notified, despite the Motor Agency and the Danish Agency for Digitalisation and Efficiency having previously said that no notification was necessary because the risk was considered low.
The breach involving protected names and addresses affected 59 companies with approved terminal access to the Motor Register. They included 26 recycling centres, 22 parking companies, four debt collection companies, four financing companies, an emergency response service, a state-owned company and a guarantee fund.
Experts told DR that the continued access to birth dates was a serious failure. Tanja Kammersgaard Christensen, a lecturer at Aalborg University’s Department of Law, said there was no doubt that the incident breached the General Data Protection Regulation and that the flaw should have been closed as soon as it was discovered.
She said birth dates are classified as ordinary personal data and are not as sensitive as a full personal identification number. However, because the information is protected by law, its exposure still constituted a security breach.
Carsten Schürmann, a professor and head of the Center for Information Security and Trust at the IT University, also criticised the agency’s handling of the case. He said authorities must fix a known data leak that breaches the GDPR as quickly as possible and called it incomprehensible that they had not done so.