The Danish authority severely criticizes the tax administration's handling of access requests in 2025

The Danish Data Protection Authority reiterates its firm position that internal organizational difficulties, such as lack of resources or a backlog of cases, do not constitute a valid justification for failing to meet the response deadlines for access requests.

Facts and context

The Danish Data Protection Authority (Datatilsynet) today published a decision issuing a serious criticism against the Danish Tax Administration (Skatteforvaltningen) for repeated failures related to meeting the response deadlines for access requests.

The case was initiated ex officio by the authority in November 2024, following a complaint, and concerned the widespread processing delays of access requests. A first decision dated 30 September 2025 had already issued a serious criticism for the period 2019-2024.

Grounds for the decision

  • Obligation to respond to access requests within deadlines (Article 12(3) of the GDPR): The authority's investigation revealed that for the year 2025, out of 152 access requests received, the average processing time was 59.05 days. Many requests exceeded the legal deadlines: 62 were processed in more than 30 days, 44 in more than 60 days, and 23 in more than 90 days, with the longest delay reaching 189 days. To justify these delays, the administration invoked the complexity of the files, the large number of documents, the need for interdepartmental coordination, and a general backlog due to processing previous requests. The authority rejected these arguments by recalling that lack of resources or prioritization choices by a controller are not valid grounds under the GDPR to justify such delays. Referring to recital 59 of the GDPR, it emphasized that the need to extend the response time must be assessed on a case-by-case basis for each request, depending on its own complexity, and not due to an overall workload or backlog. The controller is required to allocate sufficient resources to comply with its legal obligations.

Decision of the authority

Consequently, the authority issued a serious criticism against the Danish Tax Administration.

Furthermore, the authority ordered the organization to submit, in January 2027, a new report on the processing times of access requests for the year 2026 in order to monitor progress made.

Lessons learned

This decision reminds that:

  • Insufficient resources (staff, tools, procedures) are not a mitigating circumstance or a valid justification for failing to meet the legal deadlines for responding to rights exercise requests.
  • The existence of a backlog of complex requests does not justify delaying the processing of new requests; each request must be individually assessed regarding its complexity.
  • An extension of the response time from one month to three months can only be justified by the complexity or number of requests from the *same* data subject, and not by the overall workload of the controller.
  • The controller must organize technically and organizationally to be able to process requests, including the most complex or voluminous, within the deadlines set by the GDPR.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire