Denmark applies the GDPR to recruitment and adds a distinctive twist: there are two different criminal record certificates, and using the wrong one is a common mistake for employers arriving from other markets.
The two certificates
The straffeattest is the private criminal record certificate. The individual requests it from the police, usually through the national digital identity service, and passes it to the employer. It shows a limited set of recent convictions rather than a full history. The bornattest, or children’s certificate, is different: it is requested by the employer with the candidate’s consent and discloses only sexual offences against children. It is mandatory for roles involving direct contact with children under fifteen, including schools, sports clubs, and childcare.
What employers can check
Identity, right to work, employment history, and academic qualifications are all standard. Danish education records are reliable and straightforward to verify. Requesting a straffeattest for an ordinary commercial role is not customary and needs a justification tied to the work, for example in financial services, private security, or roles with access to significant assets.
Data protection
The GDPR applies alongside the Danish Data Protection Act, supervised by Datatilsynet. Criminal conviction data attracts additional protection, and the Danish rules are specific about the conditions for processing it. Employers should not retain a copy of a certificate without a clear basis, and unsuccessful candidates’ data should be deleted once recruitment closes.
Health information
Danish law restricts what health information an employer can seek before hiring, essentially limiting it to conditions that would affect the candidate’s ability to do the specific job. General health questionnaires are not permitted.
Practical guidance
Work out which certificate the role actually calls for, obtain consent in the correct form, and view rather than store where possible. An employer of record can manage this if you have no Danish entity.

