Denmark is reviewing the security framework around its Central Person Register, known as CPR, following unauthorized access to the national database.
Authorities said the incident involved the extraction of personal records linked to around 8 million citizens and residents, including people living abroad and historical entries held in the system. The database contains names, addresses, personal identification numbers and other administrative information used across public services.
Denmark's population is approximately 6 million, while the CPR holds around 11 million records accumulated over several decades. The register plays a central role in identity verification, taxation and access to government services.
The access reportedly occurred in September and was identified on October 2. Officials stated that the system was accessed through the misuse of a Danish company's legitimate authorization to search CPR information. Authorities have not identified the party responsible.
The case has placed renewed focus on how public institutions manage third-party access, verify digital identities and monitor sensitive data environments. It also highlights the importance of continuously updating cybersecurity standards for systems that support everyday public services.
As governments expand digital infrastructure, stronger access controls and real-time oversight could become defining elements of trusted public services in the future.