---------------------------
Title: Understanding Danish DPA Cookie Consent Guidelines
URL: https://www.cookiebot.com/en/danish-cookie-consent-guidelines/
---------------------------

# Understanding Danish DPA Cookie Consent Guidelines

## At a Glance

- Danish cookie law requires valid consent — freely given, specific, informed, and unambiguous — before setting cookies or processing personal data, except for strictly necessary cookies.
- The framework rests on the GDPR, the ePrivacy Directive, and Denmark's own Cookiebekendtgørelsen (Cookie Order), supplemented by the Danish Data Protection Act.
- Applies to any organization, regardless of location, that offers goods or services to Danish users or monitors their online behavior.
- Cookie banners must let visitors accept or reject with equal ease, avoid pre-checked boxes, and allow granular consent by cookie category.
- Cookie walls are permitted only if a reasonable alternative is offered and any paid option is genuinely comparable.
- Processing a child's data under 15 requires parental or guardian authorization.

## What Are the Danish Cookie Laws?

According to Danish cookie laws, websites and apps must obtain visitors' consent if they use cookies to collect, store, or process their personal data.

These regulations are shaped by the EU’s [General Data Protection Regulation (GDPR)](/en/gdpr/) and the ePrivacy Directive (known as the “[EU cookie law](/en/cookie-law/)”).

### **General Data Protection Regulation (GDPR)**

The GDPR is a cornerstone in data protection within the European Union (EU). Although it doesn’t specifically regulate the use of cookies, it's important in Danish cookie law for three reasons:

- It regulates the handling of personal data, which can include data obtained through cookies
- It includes the legal bases for processing user data, which includes consent
- It lays down a clear definition of “consent”

The Danish Data Protection Act (Act No. 502 of 23 May 2018, consolidated as Act No. 289 of 8 March 2024) supplements the GDPR in Denmark.

### **ePrivacy Directive**

The ePrivacy Directive regulates how websites and apps can use cookies to collect and process data from EU users. The EU cookie law is implemented in Danish cookie law in the [Cookiebekendtgørelsen](https://www.retsinformation.dk/eli/lta/2011/1148) (BEK No. 1148 of 09/12/2011) or “Cookie Order”.

## Who Do the Danish Cookie Laws Apply To?

Danish cookie laws apply to any company, organization or individual, regardless of their location, that collects and processes data from visitors of websites and apps located in Denmark if they:

- Offer goods and services to Danish users, even if no payment is required from the user
- monitor online behavior of Danish users located in Denmark

They also apply to the processing of personal data done by companies, organizations or persons established in Denmark.

The [data controller](https://www.datatilsynet.dk/english/fundamental-concepts-/data-controller-and-processor-), or the entity that determines why and how personal data will be processed, must ensure that personal data processing complies with the GDPR's provisions.

## **Legal Bases for Processing Data**

You must always have a legal basis under Danish law to process users’ data. According to the ePrivacy Directive, the legal basis for processing data through[ tracking cookies](/en/tracking-cookies/) is prior informed consent, unless they are purely functional cookies.

In its [quick guide on the use of cookies](https://www.datatilsynet.dk/Media/E/7/Quickguide.pdf) issued in February 2021, Danish DPA acknowledges that there could be other legal grounds to process personal data under the GDPR (Article 6.1). It emphasizes the importance of conducting a specific assessment to determine the appropriate legal basis and recommends that obtaining consent is the most practical approach.

When it comes to minors, Section 6(3) of the Danish Data Protection Act (Act No. 502 of 23 May 2018, consolidated as Act No. 289 of 8 March 2024) sets the age of digital consent at 13. Processing the data of children under 13 is lawful only if consent is authorized by a parent or guardian.

## **Danish Cookie Law and Consent**

Consent is a central concept in Danish cookie law, and the Danish DPA in February 2020 specifically incorporated the GDPR definition of consent in its[ guidelines](https://www.datatilsynet.dk/Media/F/8/Behandling%20af%20personoplysninger%20om%20hjemmesidebes%C3%B8gende.pdf) on the processing of personal data of website visitors. The GDPR requires that consent must be a freely given, specific, informed and unambiguous indication that the person giving consent agrees to the processing of their personal data.

These guidelines further stipulate that you must obtain consent before you set cookies and process user data, except for cookies that are necessary for a website to function.

[GDPR cookie consent](/en/gdpr-cookies/) must meet a number of strict requirements before it is valid. The DPA’s guidelines on processing of personal data, quick guide and[ guidelines on consent](https://www.datatilsynet.dk/Media/0/C/Samtykke%20(3).pdf) (issued in May 2021) together outline specific criteria that must be met to obtain valid consent as per the GDPR’s definition.

### Freely Given

- Accepting or rejecting cookies should both be equally easy on the first layer
- [Cookie banner](/en/cookie-banner/) design and language should not influence a user to accept cookies
- If a user has given consent, they must be able to withdraw it as easily as they gave it

### Specific

- You must obtain separate consent from visitors for each category of purposes, each with its own checkbox
- Granular consent doesn’t have to be provided for every single cookie, but it should be offered for different categories of cookies, e.g. a user should be able to allow cookies for statistical purposes while rejecting advertising cookies

### Informed

- Users should have access to clear, understandable information about the purpose of cookies
- You must provide transparent access to which parties have set cookies and what information is being transmitted through them, which can be done through a[ cookie policy](/en/cookie-policy/)

### Unambiguous

- Consent for cookies requires an active choice by the user, such as ticking a box or clicking a button to ensure that the user's choice is explicit and deliberate
- Pre-checked consent boxes, which a user must uncheck to reject consent, is not valid consent
- Users scrolling or swiping through a website or app is not valid consent as it may be difficult to distinguish from other user activity and is not an unambiguous indication that the user is accepting cookies

These detailed consent requirements are designed to safeguard user autonomy and privacy, ensuring that consent is an informed choice.

In its guidelines on consent, the Danish DPA also has stipulated that you must be able to demonstrate that the data subject has consented to the processing of their data.

## Need cookie consent compliant with the GDPR? What about globally?

Get a flexible, scalable cookie consent solution with Cookiebot™. Handles opt-in and opt-out requirements by jurisdiction, with automated scanning and updates. Try it free for 14 days.

[Start free trial](https://admin.cookiebot.com/signup)

## **Cookie Wall Guidelines from the Danish DPA**

A[ cookie wall](https://www.cookiebot.com/en/cookie-walls/) is a method by which a company requires visitors to give consent for their data to be processed before accessing a website. In February 2023, the Danish DPA established criteria for implementing cookie walls that comply with data protection rules.

- If you use a cookie wall, you **must provide** **a reasonable alternative** for visitors who do not consent to data processing. The content or service provided must be similar, regardless of the user's choice.
- If the alternative to consent is payment, the **cost must be reasonable**, offering a genuine choice between payment and consent.
- All the purposes for which you're seeking consent should be **limited to what is necessary** for the service offered. Separate consent might be needed for purposes not integral to the paid alternative.
- When visitors have paid, you can **process personal data necessary for providing the service**. However, processing data for purposes beyond what is required for the service is not allowed unless you obtain additional consent.

## Important Rulings Regarding Cookies and Personal Data in Denmark

The Danish DPA has, in recent years, made a number of decisions on the use of cookies to collect personal data from Danish visitors (source: [Datatilsynet, decision archive](https://www.datatilsynet.dk/afgoerelser)). In considering violations of Danish cookie guidelines, the DPA looked at the following issues:

- [A government institution was deploying cookies](https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2018-32-0357) and processing personal data for advertising purposes before obtaining user consent. The DPA held that the institute and Google (as the ads were from Google’s ad platform) were joint controllers, but the institute was responsible for gathering consent.
- [An online marketplace’s use of cookie walls](https://www.datatilsynet.dk/afgoerelser/afgoerelser/2023/feb/gul-og-gratis-brug-af-cookie-walls) was mostly lawful, as it provided a paid access alternative to consent. However, the DPA noted that it had not shown that the processing of personal data for statistical purposes was required in the alternative to payment.
- [A media group website’s consent procedure was found to be inadequate](https://www.datatilsynet.dk/afgoerelser/afgoerelser/2023/feb/jysk-fynske-mediers-brug-af-cookie-walls) as the paid service alternative was not equivalent to the consent-based access and didn’t provide visitors with a free choice. The media group had also not shown that processing of personal data for statistical purposes was required in the alternative to payment.
- [A gardening equipment company was using cookies](https://www.datatilsynet.dk/afgoerelser/afgoerelser/2023/okt/texas-andreas-petersen-indstilles-til-boede) to collect and pass on data to Google and Meta without a legal basis. As per Danish procedure, the DPA reported the company to the police and recommended a minimum fine of no less than DKK 200,000.

## Requirements to Comply with Danish Cookie Guidelines

Complying with Danish cookie guidelines rests on four practical steps: informing visitors clearly, obtaining valid consent, and backing both with a compliant banner and a cookie policy. Each is covered in turn below, starting with what visitors need to be told.

### Inform Visitors About Cookies

Danish cookie guidelines require you to share clear information with visitors about the types of cookies used and their purposes. The minimum requirements, as per the DPA’s consent guidelines, are:

- Identity of the data controller
- Purpose(s) of the intended processing
- Data being collected and processed
- Length of data retention
- Individuals' rights and how to exercise them

This information should be easily accessible and understandable, enabling visitors to make informed decisions. It can be shared in the cookie consent banner, with more detailed information shared in the cookie policy, to provide transparency about your data collection practices.

### Obtain Valid Consent

For consent to be valid under Danish cookie laws, it must comply with the GDPR’s requirements of opt-in consent. This means you must obtain[ cookie consent](https://www.cookiebot.com/en/cookie-consent/) through active and explicit user actions, such as clicking a button or checking a box.

Additionally, you must obtain specific consent for different categories of cookies, such as statistics cookies or marketing cookies, enabling users to make more tailored choices. Importantly, the process should avoid nudging visitors towards giving consent through either design or language presented; the consent mechanism must have a neutral presentation of choices where accepting or rejecting cookies is equally straightforward.

### Design Compliant Cookie Banners

Cookie consent banners should implement the requirements of the Danish cookie guidelines to enable compliance with the GDPR, ePrivacy Directive and local cookie laws,

Your [cookie consent banner](https://www.cookiebot.com/en/cookie-banner/) must offer visitors clear options to accept, reject, or customize their cookie preferences, without using pre-checked boxes or manipulative design patterns. It should provide information as per the consent guidelines’ minimum requirements, in language that’s easy to understand.

### Use Compliant Cookie Walls

The Danish DPA permits the use of cookie walls if they comply with the conditions laid out in its cookie wall guidelines. If your website must use cookie walls, ensure that it complies with these conditions and that all visitors, regardless of whether they choose to accept cookies or not, receive similar content or service.

If you choose a fee as the alternative to consent, make sure that it is a reasonable amount to give visitors a real choice. Don’t process any data from paid visitors that you don’t need to provide the service without their consent for these cookies.

### Have a Cookie Policy or Privacy Notice

Your website should contain an easily accessible cookie policy, either as a separate document or as part of a privacy policy, that provides detailed information about your cookie usage. Include information about any third-party cookies, including who is setting the cookies, for what purposes, and what personal data they collect.

Your cookie policy must also inform visitors about how they can change or withdraw their consent preferences.

The DPA’s quick guide requires you to inform visitors in the cookie policy if you’re using a legal basis other than consent for processing personal data.

## Is your website meeting Danish cookie law requirements?

Try Cookiebot™ free for 14 days — no credit card required. See how automated scanning, geolocation, and custom branded cookie banners support your privacy compliance strategy.

[Start free trial](https://admin.cookiebot.com/signup)

## How Cookiebot™ CMP Helps with Danish Cookie Guidelines and Privacy Compliance

If your website processes data from Danish visitors, you must comply with EU regulations and Danish cookie guidelines or face penalties under the GDPR. Implementing a [consent management platform (CMP)](/en/cookie-consent-solution/) like Cookiebot CMP supports compliance and helps build user trust.

Cookiebot CMP can enable you to obtain consent that complies with Danish cookie guidelines and data privacy laws. With Cookiebot CMP, you can:

- Present visitors with an opt-in cookie banner that requires active action for setting cookies
- Provide visitors with the option to withdraw consent as easily as they provided it
- Enable visitors to give specific consent for different categories of cookies, fulfilling the legal requirements for granular consent
- Use our [cookie checker](/en/cookie-checker/) to scan your website for cookies and provide detailed information in your cookie policy
- Document consent as required by the DPA’s guidelines on consent

Cookiebot™ CMP also supports [Google Tag Manager](/en/google-tag-manager/). With this integration, Cookiebot CMP automatically controls all cookies on your website so that they don’t collect any user data before visitors give consent.

## Do you know what data your website is collecting?

Scan your site for free with our patented cookie scanning tech. Learn what cookies and trackers are active and find out your privacy compliance risk in minutes.

[Start Scan](https://www.cookiebot.com/en/cookie-checker/)

## Preamble

Datatilsynet, the Danish Data Protection Agency (DPA), has published numerous guidelines to help website owners and operators regarding the use of cookies to collect user data.
These guidelines on cookies and consent establish requirements around informing users about cookies, obtaining their consent to use non-essential cookies, enabling them to accept or reject cookies, and more.
For businesses and website operators engaging with users located in Denmark, a clear understanding of European Union (EU) data privacy laws, regional laws, and the Danish cookie guidelines can enable legal compliance and maintain user trust.
We look at data privacy in Denmark, cookie consent laws, and how to comply with the Danish DPA's cookie consent requirements.

## Summary

If you offer goods and services to Danish users or track their website activity using cookies, you need their explicit consent to do so. But what does explicit consent mean, and how can you obtain it? We look at Danish cookie guidelines and how you can collect compliant consent.

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)