Privacy notice for MitID Complaints

Information about our processing of your personal data in MitID.

1. The Danish Agency for Digital Government is the data controller

The Danish Agency for Digital Government is the data controller for the processing of your personal data in connection with the handling of complaint cases in which decisions are made pursuant to the Executive Order on MitID for Private Individuals.

You will find our contact details below.

The Danish Agency for Digital Government

Landgreven 4

1301 Copenhagen K

Denmark

CVR no.: 34 05 11 78

Telephone: +45 33 92 52 00.

E-mail: digst@digst.dk

2. Contact details of the Data Protection Officer

If you have any questions about our processing of your data, you are always welcome to contact our Data Protection Officer.

You may contact our Data Protection Officer in the following ways:

  • Via Digital Post: Send a message to the Danish Agency for Digital Government via Digital Post, stating “Att. Data Protection Officer” in the subject field.
  • By e-mail: dpo@digst.dk. If you wish to contact the Data Protection Officer by e-mail, we ask that you do not include your CPR number or other sensitive/confidential information.
  • By letter: Danish Agency for Digital Government, attn.: Data Protection Officer, Landgreven 4, 1301 Copenhagen K, Denmark.
  • By telephone: +45 33 92 52 00.

3. Legal basis for the Danish Agency for Digital Government’s processing of your personal data

  • The processing of your personal data is carried out on the basis of Article 6(1)(c) of the General Data Protection Regulation concerning compliance with a legal obligation.
  • The processing of information about civil registration numbers (CPR numbers) is carried out for the purpose of unambiguous identification, cf. section 11(1) of the Danish Data Protection Act.
  • The processing of special categories of personal data is carried out on the basis of Article 9(2)(f) of the General Data Protection Regulation, cf. section 10 of the Executive Order on MitID for Private Individuals (Executive Order no. 1778 of 1 September 2021).

4. Purposes of the processing of your personal data in complaint handling

The purpose of the Danish Agency for Digital Government’s processing of your personal data is to carry out the necessary processing for handling your complaint.

5. Categories of personal data

The Danish Agency for Digital Government processes personal data in the following overall categories in connection with complaint handling:

  • Identity data
  • Contact data

Confidential information:

  • CPR number

Special categories of personal data:

  • Health information

Identity and contact data concern information about your full name, date of birth, residential address, information about your telephone number and e-mail address, and your CPR number. This information is obtained from the MitID solution. Information from the Danish Civil Registration System (the CPR Register) is continuously and automatically updated in the MitID solution.

Registration data concerns information about when, how and for what purposes you use your MitID. In this context, information about IP address is included, including information about geographical location based on the registered IP address.

Health information and other special categories of personal data are processed only to the extent that they are provided in connection with the handling of the complaint.

6. Recipients or categories of recipients of personal data

The Danish Agency for Digital Government only discloses your personal data if the Agency is required to do so by law, or if the disclosure takes place as part of clarifying your complaint case.

In certain cases, the Danish Agency for Digital Government may be required to transfer data to other public authorities. The transfer will be limited to the personal data necessary for the exercise of official authority.

7. Recipients in third countries, including international organisations

We do not transfer your personal data to recipients outside the EU and the EEA, unless you reside in Greenland or the Faroe Islands, or if an authority that holds relevant information in your complaint case is physically located in Greenland or the Faroe Islands.

In the event of transfer of personal data to Greenland, the transfer basis is the European Commission’s standard contractual clauses on data protection, cf. Article 46(2)(c) of the General Data Protection Regulation.

In the event of transfer of personal data to the Faroe Islands, the transfer basis is Article 45 and Article 46(2)(c).

8. Storage of your personal data

When the Danish Agency for Digital Government receives an enquiry from you, your enquiry will be registered in the Agency’s case and document management system.

Information about you in the Danish Agency for Digital Government’s case and document management system will be transferred for storage in the Danish National Archives after the end of the journal period in which the case is closed, cf. the applicable legislation on archiving in the Danish National Archives.

For a period after the end of the journal period in which the case is closed and transferred for storage in the Danish National Archives, the Danish Agency for Digital Government will continue to have access to retrieve the information in a historical version of the journal period in the system.

9. Where your personal data comes from

Your personal data is collected directly from you if you provide personal data in your complaint to the Danish Agency for Digital Government. We may also receive personal data from the registration unit or support organisation that made the decision in your complaint case. Finally, we may collect information about your MitID through the system that registers information about your MitID.

10. Automated decision-making, including profiling

The Danish Agency for Digital Government does not carry out any automated decision-making, including profiling, in connection with the handling of complaint cases concerning refusal to issue, suspension or blocking of MitID.

11. Right of access, rectification, erasure, restriction, objection and data portability

Below you can read about your rights of access, rectification, erasure, restriction, objection and data portability.

You can also read more about your rights in the Danish Data Protection Agency’s “Guidance on the rights of data subjects”, which is available at datatilsynet.dk.

If you wish to exercise your rights, please contact the Danish Agency for Digital Government.

Right of access
You have the right to access the information that we process about you, as well as certain additional information.

Right to rectification
You have the right to have inaccurate information about yourself corrected. You also have the right to have your information supplemented with additional information if this will make your personal data up to date or more complete.

Right to erasure
In certain cases, you have the right to have information about you erased.

Right to restriction of processing
In certain cases, you have the right to have the processing of your personal data restricted.

If you have the right to have processing restricted, the Danish Agency for Digital Government may in future only process the data — apart from storage — with your consent, or for the purpose of establishing, exercising or defending legal claims, or in order to protect a person or important public interests.

Right to object
In certain cases, you have the right to object to the Danish Agency for Digital Government’s otherwise lawful processing of your personal data.

Right to transmit data — data portability
This right does not apply to complaint handling, as the processing is carried out as part of a duty imposed on the Danish Agency for Digital Government by law.

12. Complaint to the Danish Data Protection Agency

If you wish to complain about the Danish Agency for Digital Government’s processing of your personal data, the complaint must be submitted to the Danish Data Protection Agency.

You can find the Danish Data Protection Agency’s contact details at datatilsynet.dk.