OAM Privacy Policy

This privacy policy describes the Danish Financial Supervisory Authority’s (the “DFSA”) processing of personal data in connection with OAM.

OAM stands for Officially Appointed Mechanism and is the DFSA’s portal for reporting and storing information in accordance with the applicable capital markets legislation.

OAM also functions as a collection portal under the ESAP legislation. ESAP is the European Single Access Point and shall provide the public with easy and centralised access to information about entities and their products relevant to the financial services, capital markets, sustainability and diversity. Further information about ESAP is available on the Danish Financial Supervisory Authority’s website under ESAP.

This privacy policy supplements the DFSA’s general privacy policy and the privacy policies regarding persons discharging managerial responsibilities and persons closely associated with them and major shareholdings. The DFSA’s general privacy policy describes the overall framework for processing personal data as part of the authority’s duties, while the two separate privacy policies describe how the DFSA’s processes personal data concerning persons discharging managerial responsibilities and persons closely associated with them and major shareholders.

This privacy policy must be read together with the DFSA’s general privacy policy and the two separate privacy policies.

1.   What is personal data?

Personal data means any information relating to an identified or identifiable natural person. This means information that can be attributed, directly or indirectly, to a particular person. For example, a name, address, email address, telephone number, account number, or CPR number.

2.   Purpose and legal basis for processing personal data

When you use OAM, the DFSA processes personal data in order to perform its duties under the applicable rules. This may include when we:

  • receive, register, and process login details, reports, and other information;
  • supervise compliance with relevant notification and disclosure obligations;
  • communicate with reporting entities and users in connection with notifications submitted to OAM; or
  • publish or disclose information in accordance with the applicable legislation, for example where required under the ESAP rules.

The legal basis for processing your personal data is  Article 6(1)(c) and/or (e) of the General Data Protection Regulation. Which provision applies depends on the specific processing activity and the relevant EU or national legislation.

If we process CPR numbers, we do so only where the conditions under applicable EU and national legislation are met. The legal basis for processing CPR numbers is Section 11(1) of the Danish Data Protection Act.

3.   What personal data do we process?

Depending on how OAM is used, the Danish Financial Supervisory Authority may process different types of personal data. These may include:

  • names and contact details;
  • information about user access and powers of attorney;
  • information about your use of OAM, including login and log data;
  • information provided and submitted via OAM, which the DFSA processes and which may contain personal data; and;
  • information contained in enquiries to the Danish Financial Supervisory Authority or OAM.

You can also read about the way we process personal data in connection with notifications submitted by persons discharging managerial responsibilities and persons closely associated with them or major shareholders in separate privacy policies.

4.   When do we disclose personal data?

The DFSA only discloses personal data where there is a legal basis for doing so. Personal data may, among other things, be disclosed to other public authorities where this is necessary for them to perform their duties.

For notification submitted under the ESAP rules, the DFSA, as the designated collection body, is required to forward such a notification to ESAP. Under Article 5(6) of the ESAP Regulation, the reporting entity must inform the DFSA if a notification contains personal data.

For further information about the DFSA’s disclosure of personal data, please refer to the DFSA’s general privacy policy.

5.   How long do we retain your personal data?

We retain your personal data in OAM for as long as necessary for the purposes for which the information is processed, to fulfil our obligations as a public authority, and to comply with applicable legislation, including the Danish Archives Act. When the purpose of the processing no longer applies and our obligations as a public authority have been fulfilled, a copy of the data is transferred to the Danish National Archives in accordance with the Danish Archives Act.

If your notification gives rise to further case processing, your personal data may be transferred to the DFSA’s electronic case and document management system. In that system, we retain the information for as long as necessary to process the case or until a statutory limitation period expires.

Information about you in the DFSA’s electronic case and document management system is transferred to the Danish National Archives after the relevant records period has ended, in accordance with the Danish Archives Act. The DFSA may continue to retrieve the information for a period in a historical version of the retention period. The historical version is deleted no later than 15 years after the end of the retention period.

Special retention rules apply to notifications submitted to ESAP that contain personal data. Under Article 5(1)(g) of the ESAP Regulation, personal data may generally be retained for no more than five years for the purpose of making it available on ESAP, unless otherwise provided by the relevant EU rules.

For further information about the DFSA’s retention of personal data, please refer to the DFSA’s general privacy policy.

6.   Cookies

OAM uses necessary technical cookies and similar technologies to ensure the functionality, security, login, and proper operation of OAM.

For further information about the DFSA’s use of cookies please refer to the DFSA’s general privacy policy and cookie policy.

7.   Your rights

Under the General Data Protection Regulation, you have a number of rights in relation to the DFSA’s processing of your personal data.

If you wish to exercise your rights, you must contact the DFSA.

Right of access

You have the right to access the information we process about you and a range of additional information.

Right to rectification

You have the right to have incorrect personal data corrected. You also have the right to have your data updated or supplemented with additional information if this would make your personal data more complete or up to date.

Right to erasure

In certain cases, you have the right to have your personal data erased.

Right to restriction of processing

In certain cases, you have the right to have the processing of your personal data restricted. If you have the right to restriction, we may in the future only process the information – apart from storage – with your consent, or for the establishment, exercise, or defense of legal claims, or to protect a person or important public interests.

Right to object

In certain cases, you have the right to object to our otherwise lawful processing of your personal data.

You can read more about your rights in the Danish Data Protection Agency’s guidance on the rights of data subjects at  www.datatilsynet.dk/english.

8.   The DFSA as data controller

The DFSA is s the data controller for the processing of the personal data we have received about you.

You can contact the Danish Financial Supervisory Authority in the following ways:

9.   Contact details of the Data Protection Office

If you have questions about our processing of your data, you are always welcome to contact our Data Protection Officer. 

You can contact our Data Protection Officer in the following ways:

  • Email: dpo@sktst.dk
  • Phone: +45 72 37 82 93
  • By post: The Danish Tax Agency, Attn: Databeskyttelsesrådgiveren, Hannemanns Allé 25, 2300 Copenhagen S.

10. Complaint to the Danish Data Protection Agency

You have the right to file a complaint with the Danish Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find the Danish Data Protection Agency’s contact details at www.datatilsynet.dk/english