A man lurking behind closed blinds.

Digitalisation: Lost Privacy by Design

Niclas Hedam

PhD, Computer Science

· 11 min read · 8 sources · Corrected 9 July 2026

  • Public records can serve legitimate transparency goals, but digitisation changes the risk profile from manual access to mass extraction and automated abuse.
  • Convenience-driven systems like payment apps, business registers, and property records can together expose home addresses, finances, and identity to anyone willing to query them.
  • Privacy harms in public datasets are often not about a single record, but about how multiple datasets can be linked and weaponised.

Someone I did not recognise once called me, and instead of calling back I typed the number into MobilePay. Up came a name, full and correct, verified against the civil register, handed to me by a payments app in about a second. Denmark still has a digital phone book, and you can ask to be left out of it; more and more people do. But MobilePay now sits on most phones in the country, and because it is tied to your civil identity for know-your-customer and anti-fraud reasons, it has quietly become the phone book instead. There is no opting out of the one everybody actually uses.

So a few years ago I tried to opt out of something larger. I turned on CPR protection, the state’s own setting for people who would rather not be looked up, and kept it on for a while in the late 2010s. It works, and it is miserable. Banks could not verify me, onboarding at a new job stalled, and an automated insurance quote came back empty, because as far as their systems were concerned I had stopped existing. That is the lesson I took from it, long before I could have argued it cleanly: in Denmark, being findable is the default, and the only way out is a switch so blunt it half-removes you from ordinary life.

4.4M users

By 2022 almost three-quarters of the country had MobilePay, enough for a single payments app to work as a national phone book.

MobilePay is continuing the rapid growth in Denmark and Finland — MobilePay’s own announcement that it had passed 4.43 million users in Denmark in 2022.

Protection of name and address — The official description of CPR name and address protection: once registered, your name and address are as a rule not released from the CPR to private parties, the protection lapses after a year unless you renew it, and public authorities keep their access throughout.

No Single Record Is the Problem

I want to be careful here, because the easy version of this argument is the wrong one. Public registers are not a mistake. They exist for good reasons — accountability, fraud prevention, a property market that is not run on rumour — and I am not asking for any of that to go behind a wall. Nothing I can look up about you is, on its own, a scandal. A business registration is mundane. A property sale is a matter of record. A phone number is just a number.

The trouble is what happens when these records stop taking effort to reach. When a record is public but physical, a folder in a municipal office or a file at the local court, it is open to everyone in principle and to almost no one in practice, because collecting it costs a morning and a train ticket. When the same record is public and digital, it can be copied, scraped, cross-referenced and resold at the speed of a script. The leap from a dusty archive to a JSON API looks like a convenience upgrade. It is really a change in kind, because the thing it makes easy is not reading one record but joining many. I have argued before, about the profiles advertisers build, that the harm is almost never a single fact and almost always the linkage between them. This is that same argument, wearing the state’s clothes.

A Dossier Anyone Can Assemble

Take the pieces Denmark leaves open, and watch them line up. If you have run a business here in the last five years, a freelance income, a side company, a one-person consultancy, your details sit in the Central Business Register, mirrored onto commercial sites like Proff.dk and free endpoints like the CVR API, and among those details is your home address, tied to your name, listed until five years after you last held a role there. You can shield it, but only behind the same blunt CPR protection from the opening; by default it is simply published, and registering the business in the first place is not optional.

Bekendtgørelse af lov om Det Centrale Virksomhedsregister — § 18 — The CVR Act: names of fully liable participants, founders, owners and management members are published at all times, and their address stays listed until five years after they leave the entity, unless the person already holds CPR name and address protection.

Add property. Through OIS and the land register, anyone can pull up who owns an address, what they paid for it, the mortgage they carry, and the history behind it all. Point that at a person rather than a house and it stops being market transparency and becomes a fairly precise read on their wealth, their debt, and when their life last changed. Add the bad weeks, too. A bankruptcy, a foreclosure, a death in the family are all published in Statstidende, and the death notice goes furthest: it carries the deceased’s full CPR number next to their name and last address, the closest thing Denmark has to a master key to a person’s identity, printed beside the worst week their family will have.

OIS — Din genvej til ejendomsdata — The state’s public property server, where anyone can look up a property’s sale prices, public valuations and area.

Statstidende — The official state gazette, where insolvency, death and forced-sale notices are published; a death notice carries the deceased’s full CPR number alongside their name and last address.

None of these is alarming alone. Together they are a dossier: a name, a home address, a rough net worth, a company, and a phone number that resolves back to the name you started with. Nobody assembled it on purpose. The state published each part for its own good reason, and the joining was left as an exercise for whoever wanted to do it.

Who This Actually Hurts

For most of us, most of the time, this sits in the background as a low hum of exposure we never think about. For some people it is the whole problem. A survivor of stalking or domestic abuse does not need their attacker to break into any archives; a handful of free, official queries can return where they live, where they work, what they own, and how to reach them again. Safety plans are built on the assumption that finding someone takes effort. When the registers act as directory assistance for whoever asks, that assumption no longer holds, and the state’s own transparency becomes the thing that undoes it.

This is not hypothetical. A system error in Denmark’s motor register exposed the protected addresses of just under 73,000 people, some of whom held that protection precisely because they had fled a violent ex-partner, and let 487 private companies look them up. The hole itself was closed twelve days after it was discovered; the people affected were not told for nine months. The people the protection existed to shield were the ones it exposed.

One detail is worth reflecting on, not as a criticism of anyone involved, but because it shows how deeply the default of publishing runs. One option raised for reaching the affected was a notice in Statstidende, the same public gazette from earlier: an ordinary channel for official notices, except that it is itself a public record. To warn these people that their protected details had leaked, the state would have had to name them in a public register they had chosen to stay out of. Telling them their data had been exposed would have meant publishing more of it. The Data Protection Authority set the idea aside and required that each person be told directly.

»Nogle sager er så vilde, at det er svært at sætte ord på«: Nye afsløringer om datalæk i Skat chokerer førende ekspert — Reporting on a system error that exposed the protected addresses of just under 73,000 citizens through the motor register, among them people who had fled violent ex-partners, letting 487 private companies look them up; those affected were not told for months.

The same visibility feeds harassment, and it has reached the everyday tools too. Stalkers turned MobilePay, the app from the opening, into a way to keep reaching people who had cut them off, sending small transfers only to attach a message. In 2024 the company responded, adding blocking and requiring every account to carry a verified full name. That last change cuts both ways: it stops a blocked user from returning under a nickname, but it is also what makes the lookup from the opening reliable, because the name behind a number is now guaranteed to be a real one. It solved one problem and created another.

MobilePay griber ind for at stoppe stalking — Reporting on how MobilePay was used to harass and stalk people through its transfers and messages, and the changes it made in 2024 to curb it: blocking, and a requirement that every account carry a verified full name.

And what individuals can do by hand, companies do at scale: data brokers enrich these state-verified records with everything else they hold, and because the source is the state, the result is pre-validated, correct, and trusted. Once data can be scraped, it will be, and public records are the cleanest raw material there is.

The Fix Is Not Secrecy

The answer is not to hide the registers. Markets do need transparency, journalists do need to follow ownership, and fraud does get caught this way. The answer is to change the default from exposure to accountability, and the striking thing is that this is not hypothetical. Norway publishes personal income, all of it, for every citizen. But since 2014 you have to log in to search the lists, every search is recorded, and the person you looked up can see that you did. Access stays public; it simply stops being anonymous and effortless. The lookup leaves a trace.

Search the tax lists — The Norwegian Tax Administration’s own page: the tax lists are public, but you must log in to search them, a log of searches is kept, and the person you look up can see who has searched for them.

That is the whole principle, and it generalises. Let the context stay open, the price of a house, the existence of a company, the fact of a bankruptcy, while the identity behind it sits one accountable step further back: reachable for a real reason, with the reveal logged and visible to the person it concerns, and not left live on the open web forever. A newsroom or a bank clears that bar without noticing. A stalker or a scraper does not. If a register cannot tell you who looked you up, and why, it is not finished.

The Default We Never Chose

Denmark digitised faster than almost anyone, and it did so for an honest reason: a high-trust society was willing to hand its data to institutions it broadly believed in, in exchange for services that genuinely work. I do not want to give that up, and I do not think most Danes do either. But trusting an institution is not the same as agreeing that everything about you should stay queryable by anyone, forever, and the two got bundled together while no one was really asked.

Denmark being digital is not the thing to argue about; it already is, and mostly for the better. The decision we never got a say in is a narrower one: that being findable should be the default, automatic and universal unless you go out of your way to opt out. A country this good at building these systems could build the next ones so that transparency serves the market and the public without also serving whoever wants to assemble a map of you. Nobody asked us the first time. There is still time to ask before the next register goes online.

  • This brief has been substantially rewritten. The earlier version worked through Denmark's registers one by one, each followed by a list of open questions, and closed with a page of proposed fixes; this version keeps the same facts but is built around a single argument, opened from personal experience, and ends on a principle rather than a checklist.

The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information. Artificial intelligence is used on some posts to identify sources, draft structure, and assist with quality assurance; the final article is always the author's own work. The AI assists, but never authors.

Niclas Hedam

PhD, Computer Science

Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.