The 60-second summary
On 5 October 2026, Datatilsynet said it was examining a reported incident involving automated CPR lookups aimed at identifying valid numbers. The notification arrived on 4 October. Responsibility, mechanism and impact remain under examination. This is an early regulatory examination, not an infringement decision or new compliance deadline.
Timeline that matters
4 October 2026
Notification received
Datatilsynet received a notification from the CPR register.
5 October 2026
Announcement published
The regulator confirmed it was examining the incident.
Not specified
Further findings
Further communication will follow when justified; no timetable was announced.
What changed
The official announcement confirms receipt of a notification from the CPR register and examination of what happened, how it happened and who was responsible for the processing. It reports a very large number of automated lookups but gives no verified count, affected-person total or final findings. Claims of a specific number of stolen records should not be attributed to this announcement.
Who should pay attention?
Platform security
Assess enumeration paths and distributed abuse.
Privacy and legal
Evaluate evidence and notification duties.
Vendor management
Clarify provider access and incident responsibilities.
What the guidance clarifies
- Early-stage status
- The regulator has not yet assessed the concrete circumstances.
- Unknown scale
- The official notice does not quantify affected people.
- No new rule
- The announcement creates no new general compliance date.
Global relevance — control lookup abuse
Why this matters for global organisations.
Identity validation can reveal sensitive information through repeated queries even when each response is small. Teams should connect API controls, fraud detection, privacy impact assessment and vendor accountability.
- Assess what a response reveals, not only what it returns.
- Detect coordinated requests across accounts and networks.
- Retain enough evidence to establish incident scope.
- Separate verified facts from initial incident claims.
14 actions to start now
- Inventory identity lookup and validation interfaces.
- Document the minimum information each interface needs to return.
- Test whether response differences reveal valid identifiers.
- Review authentication, authorisation and service-account privileges.
- Assess rate controls across accounts, sessions, networks and tenants.
- Monitor coordinated patterns rather than only single-account volumes.
- Set alerts for abnormal lookup sequences and failed requests.
- Review supplier access and downstream copying permissions.
- Prepare containment actions that preserve essential service access.
- Preserve relevant logs and configuration versions securely.
- Assess personal-data impact and notification obligations with specialists.
- Coordinate security, fraud, privacy and provider communications.
- Test restoration and control changes before resuming normal operations.
- Track official findings and correct unverified incident assumptions.
Suggested next steps
- Recheck official incident findings and scope disclosures.
Evidence worth retaining
- Interface and provider inventory.
- Data-flow and response-field documentation.
- Authorisation review.
- Enumeration and abuse-test results.
- Rate-control settings and alert thresholds.
- Access and request logs with retention controls.
- Incident timeline and containment decisions.
- Impact and notification assessments.
- Provider correspondence.
- Remediation tests and approval records.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Can validation responses expose identifier validity?
- What bulk lookup purposes are authorised?
- Can controls detect abuse split across identities?
- Which party controls each processing activity?
- Which logs establish scope without unnecessary collection?
- What notification thresholds and clocks apply?
- What evidence must be preserved?
- How should service continuity and containment be balanced?
- Which public statements are supported by verified evidence?
Official sources
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.