Major shareholdings - notification on the collection of personal data

In connection with your submissions in the Danish Financial Supervisory Authority’s OAM system, we must inform you that we process your personal data. This follows from Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation[1]). The Danish Financial Supervisory Authority is the data controller for the processing of the personal data we receive about you. 

We must provide you with the following information:

  1. We are the data controller – how to contact us
  2. Contact details of the Data Protection Officer
  3. The purposes and legal basis for processing your personal data
  4. Categories of personal data
  5. Recipients or categories of recipients
  6. Statutory notification of personal data
  7. Storage of your personal data
  8. Your rights
  9. Complaint to the Danish Data Protection Agency

Information about our processing of your personal data, etc.

1.    We are the data controller – how to contact us

The Danish Financial Supervisory Authority is the data controller for the processing of the personal data we have received about you.

You can contact the Danish Financial Supervisory Authority in the following ways:

2.    Contact details of the Data Protection Officer 

If you have questions about our processing of your data, you are always welcome to contact our Data Protection Officer. 

You can contact our Data Protection Officer in the following ways:

  • Email: dpo@sktst.dk
  • Phone: +45 72 37 82 93
  • By post: The Danish Tax Agency, Attn: Databeskyttelsesrådgiveren, Hannemanns Allé 25, 2300 Copenhagen S.

We recommend that you do not send your civil registration number (CPR number) or other confidential or sensitive personal information to the Data Protection Officer by unencrypted email.

3.    The purposes and legal basis for processing your personal data

We process your personal data for the following purposes:

  • The Danish Financial Supervisory Authority processes your personal data to ensure compliance with the rules on reporting of major shareholder notifications pursuant to Sections 38-40 of the Capital Markets Act and the Executive Order on Major Shareholders.

The legal basis for processing your personal data is as follows:

  • Section 211(1) of the Capital Markets Act. According to this provision, the Danish Financial Supervisory Authority supervises compliance with the Capital Markets Act and rules issued pursuant thereto.
  • Executive Order on Major Shareholders

The legal basis for our processing of your national identification number/CPR number is as follows:

  • Section 15(1)(3) of the Executive Order on Major Shareholders and Section 11(1) of the Danish Data Protection Act.

4.    Categories of personal data

We process the following categories of personal data about you:

  • General personal data, including: name, address, telephone number, email address, as well as your holdings of share capital and/or financial instruments in companies admitted to trading on a regulated market, and the number of voting rights.
  • Confidential information: national identification number/CPR number.

5.    Recipients or categories of recipients

As a rule, we do not disclose your personal data to others. However, we may disclose your personal data if it is necessary for the performance of our regular duties. Data may also be disclosed if necessary for other authorities to perform their tasks, or in accordance with the rules on access to documents under the Danish Public Information Act and the Danish Public Administration Act.

6.    Statutory notification of person data

Sections 38–40 of the Capital Markets Act stipulate that a shareholder in a company whose shares are admitted to trading on a regulated market must notify both the company and the Danish Financial Supervisory Authority when the shareholder’s holdings of shares and/or financial instruments reach, exceed, or fall below the thresholds of 5, 10, 15, 20, 25, 50, or 90 percent, and the thresholds of 1/3 or 2/3 of the company’s total share capital or voting rights.

A shareholder’s notification obligation applies to both direct and indirect holdings, e.g., where the shareholder holds the shares through ownership of a subsidiary.

The notification must be submitted immediately to the company and the Danish Financial Supervisory Authority, but no later than four business days after the shareholder becomes or should have become aware that the transaction has been completed, cf. section 41 of the Capital Markets Act.

A violation of section 38(1), section 39(1), and section 40 of the Capital Markets Act may, under certain circumstances, be punishable by a fine, cf. section 247 of the Capital Markets Act.

7.    Storage of your personal data

We store and process your personal data in the Danish Financial Supervisory Authority’s OAM system for as long as necessary for the purpose for which we use the data, to fulfill our obligations as a public authority, and to comply with applicable legislation, including the Archives Act. When the purpose of the processing no longer exists, and we have fulfilled our obligations as a public authority, a copy of the data from the system will be transferred to the Danish National Archives in accordance with the Danish Archives Act.

Furthermore, your personal data may also be transferred to our electronic case and document management system if your submission gives rise to further case processing. We store your personal data in our electronic case and document management system for as long as necessary in relation to the processing of the case, or as long as necessary for the purpose for which we use the data, or until a statutory deadline expires. Information about you in the Danish Financial Supervisory Authority’s electronic case and document management system is transferred in accordance with the Danish Archives Act to the Danish National Archives after the end of the journal period in which the case containing the information is closed. After a journal period is closed, the Danish Financial Supervisory Authority will, for a period, still have access to retrieve the information in a historical version of the journal period. The historical version of the journal will be deleted no later than 15 years after the end of the journal period in which the case was closed.

8.    Your rights

Under the General Data Protection Regulation, you have a number of rights in relation to the Danish Financial Supervisory Authority’s processing of your personal data.

If you wish to exercise your rights, you must contact the Danish Financial Supervisory Authority.

Right of access
You have the right to access the information we process about you, as well as a range of additional information.

Right to rectification
You have the right to have incorrect personal data corrected. You also have the right to have your data updated or supplemented with additional information if this would make your personal data more complete or up to date.

Right to erasure
In certain cases, you have the right to have your personal data erased.

Right to restriction of processing
In certain cases, you have the right to have the processing of your personal data restricted. If you have the right to restriction, we may in the future only process the information – apart from storage – with your consent, or for the establishment, exercise, or defense of legal claims, or to protect a person or important public interests.

Right to object
In certain cases, you have the right to object to our otherwise lawful processing of your personal data.

You can read more about your rights in the Danish Data Protection Agency’s guidance on the rights of data subjects at  www.datatilsynet.dk/english.

9.    Compliant to the Danish Data Protection Agency

You have the right to file a complaint with the Danish Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find the Danish Data Protection Agency’s contact details at www.datatilsynet.dk/english



[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Article 13(1) states that the data controller must provide the data subject with a range of information when personal data is collected from the data subject.

 

Last updated 22-09-2026