Skip to content

Regulatory Pulse

Datatilsynet examines automated CPR lookups: identity enumeration and incident evidence

On 5 October 2026, Datatilsynet said it was examining a reported incident involving automated CPR lookups aimed at identifying valid numbers. The notification arrived on 4 October. Responsibility, mechanism and impact remain under examination.

Denmark
Breach response
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Regulator incident announcement · Reviewed 7 October 2026 · 6 min read

The 60-second summary

On 5 October 2026, Datatilsynet said it was examining a reported incident involving automated CPR lookups aimed at identifying valid numbers. The notification arrived on 4 October. Responsibility, mechanism and impact remain under examination. This is an early regulatory examination, not an infringement decision or new compliance deadline.

Timeline that matters

  1. 4 October 2026

    Notification received

    Datatilsynet received a notification from the CPR register.

  2. 5 October 2026

    Announcement published

    The regulator confirmed it was examining the incident.

  3. Not specified

    Further findings

    Further communication will follow when justified; no timetable was announced.

What changed

The official announcement confirms receipt of a notification from the CPR register and examination of what happened, how it happened and who was responsible for the processing. It reports a very large number of automated lookups but gives no verified count, affected-person total or final findings. Claims of a specific number of stolen records should not be attributed to this announcement.

Who should pay attention?

Platform security

Assess enumeration paths and distributed abuse.

Privacy and legal

Evaluate evidence and notification duties.

Vendor management

Clarify provider access and incident responsibilities.

What the guidance clarifies

Early-stage status
The regulator has not yet assessed the concrete circumstances.
Unknown scale
The official notice does not quantify affected people.
No new rule
The announcement creates no new general compliance date.

Global relevance — control lookup abuse

Why this matters for global organisations.

Identity validation can reveal sensitive information through repeated queries even when each response is small. Teams should connect API controls, fraud detection, privacy impact assessment and vendor accountability.

  • Assess what a response reveals, not only what it returns.
  • Detect coordinated requests across accounts and networks.
  • Retain enough evidence to establish incident scope.
  • Separate verified facts from initial incident claims.

14 actions to start now

  1. Inventory identity lookup and validation interfaces.
  2. Document the minimum information each interface needs to return.
  3. Test whether response differences reveal valid identifiers.
  4. Review authentication, authorisation and service-account privileges.
  5. Assess rate controls across accounts, sessions, networks and tenants.
  6. Monitor coordinated patterns rather than only single-account volumes.
  7. Set alerts for abnormal lookup sequences and failed requests.
  8. Review supplier access and downstream copying permissions.
  9. Prepare containment actions that preserve essential service access.
  10. Preserve relevant logs and configuration versions securely.
  11. Assess personal-data impact and notification obligations with specialists.
  12. Coordinate security, fraud, privacy and provider communications.
  13. Test restoration and control changes before resuming normal operations.
  14. Track official findings and correct unverified incident assumptions.

Suggested next steps

  • Recheck official incident findings and scope disclosures.

Evidence worth retaining

  • Interface and provider inventory.
  • Data-flow and response-field documentation.
  • Authorisation review.
  • Enumeration and abuse-test results.
  • Rate-control settings and alert thresholds.
  • Access and request logs with retention controls.
  • Incident timeline and containment decisions.
  • Impact and notification assessments.
  • Provider correspondence.
  • Remediation tests and approval records.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Can validation responses expose identifier validity?
  • What bulk lookup purposes are authorised?
  • Can controls detect abuse split across identities?
  • Which party controls each processing activity?
  • Which logs establish scope without unnecessary collection?
  • What notification thresholds and clocks apply?
  • What evidence must be preserved?
  • How should service continuity and containment be balanced?
  • Which public statements are supported by verified evidence?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.