Back to Feed
PolicySep 1, 2026

Datatilsynet (Denmark) - 09-07-2026

Danish DPA authorizes AC Horsens football club to use facial recognition for match security.

Summary

The Danish Data Protection Agency (Datatilsynet) has granted AC Horsens football club permission to process biometric data using automatic facial recognition during football matches. This authorization is subject to several strict conditions, including limitations on data storage and usage, and requires the club to conduct data protection impact assessments. The decision also clarifies how the national CCTV Surveillance Act interacts with GDPR regarding data retention for dispute resolution.

Full text

Help Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub): Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit → Revision as of 06:54, 1 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators33 editsmTags: Reverted Visual edit← Older edit Revision as of 07:14, 1 September 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators528 editsm Newer edit → (No difference) Revision as of 07:14, 1 September 2026 Datatilsynet - 09-07-2026 Authority: Datatilsynet (Denmark) Jurisdiction: Denmark Relevant Law: Article 9(1) GDPR Article 9(2)(g) GDPR Article 35 GDPR Article 36 GDPR Type: Other Outcome: n/a Started: Decided: Published: Fine: n/a Parties: AC Horsens National Case Number/Name: 09-07-2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Danish Original Source: Datatilsynet (in DA) Initial Contributor: sf The DPA gave the AC Horsens football club the permission to process biometric data through the use of automatic facial recognition in the conduct of football matches. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission to process biometric data, and thus use automatic facial recognition during football matches. Processing such data would be done on the basis of Article 9(1) GDPR and Article 9(2)(g), that is, necessary for reasons of public interest. Holding The DPA granted the controller authorisation to process biometric data with the use of automatic facial recognition for the purpose of uniquely identifying natural persons. The DPA granted the authorisation under a number of conditions, requires notification of any changes, and reserves the right to review them. The conditions include, inter alia: Authorisation only applies when the controller is in the Danish Super League. Suspensions from matches must be imposed on an objective and proportionate manner following a violation of the controller’s stadium regulations and/or the Super League's code of conduct. Personal data which does not concern an individual on the controller’s suspension list, persons of interest list or police’s suspension list may not be stored. Personal data which concern one of those persons must be deleted after every match. The DPA emphasised that the GDPR and the Data Protection Act apply to the extent that the issue at hand is not regulated by the above conditions. The DPA stressed that a data protection impact assessment must be performed in accordance with Article 35 GDPR. If it results in a high risk the controller must seek prior consultation under Article 36 GDPR. The DPA also maintained its position in handling complaints. The DPA further clarified that the use of images from the surveillance to be covered by the national CCTV Surveillance Act. The DPA declared the controller’s communication and enforcement of the suspension list as, necessary for the purpose of processing a specific dispute following the Danish CCTV Surveillance Act. The DPA thus permits the controller to store the stadium’s security camera footage for longer than 30 days. The DPA emphasises that retention of this footage for longer than 30 days imposes a subsequent obligation on the controller to inform the data subject visible in the footage and allow them to request a copy of such. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Danish original. Please refer to the Danish original for more details. Skip the main navigation Lyngby Boldklub Granted Permission to Use Automated Facial Recognition Date: July 9, 2026 Authorization: Private Companies Following an application from Lyngby Boldklub and AC Horsens, the Danish Data Protection Agency has granted authorization for the clubs to process biometric data and thereby use automatic facial recognition during soccer matches. The above processing involves the processing of biometric data covered by the prohibition in Article 9(1) of the General Data Protection Regulation. Pursuant to Article 9(2)(g) of the Regulation, the prohibition on the processing of sensitive information does not apply if the processing is necessary for reasons of substantial public interest. Pursuant to Section 7(4) of the Data Protection Act, the Danish Data Protection Agency must grant authorization for such processing when it is not carried out by a public authority. The Danish Data Protection Agency hereby grants LYNGBY BOLDKLUB A/S Authorization to process biometric data pursuant to Section 7(4) of the Data Protection Act through the use of automated facial recognition at the LYNGBY BOLDKLUB A/S stadium Authorization to process biometric data for the purpose of uniquely identifying a natural person, through the use of automated facial recognition, is granted under the following conditions: This authorization applies only when LYNGBY BOLDKLUB A/S is the sole data controller for the processing of personal data with respect to the CCTV surveillance and the facial recognition system. This authorization applies only when LYNGBY BOLDKLUB A/S is a member of the Superliga. In this context, the authorization applies to the conduct of soccer matches, including friendly matches, involving teams from the Superliga, the 1st and 2nd divisions, as well as soccer matches organized by UEFA. The imposition of a ban must be based on objective and proportionate grounds in relation to the violation committed of LYNGBY BOLDKLUB A/S’s stadium regulations and/or the Superliga’s rules of conduct. Personal data processed as part of the facial recognition system that does not result in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s ban list and/or watchlist or 2) the police’s general ban list, may not be stored. Personal data processed as part of the facial recognition system that results in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s quarantine list and/or watchlist or 2) the police’s general quarantine list must be deleted immediately after each match. LYNGBY BOLDKLUB A/S must comply with the duty to provide information when collecting personal data. LYNGBY BOLDKLUB A/S must also, through signage or other clear means, provide information that access control is being conducted, including the processing of biometric data using an automated facial recognition system. Personal data processed as part of the facial recognition system must be transmitted to and stored in encrypted form on the server using up-to-date and widely recognized encryption algorithms. Surveillance cameras must be installed on a separate VLAN and must not be exposed to the internet. LYNGBY BOLDKLUB A/S must implement access control using the facial recognition system, including ensuring that employees are authorized to operate the facial recognition software and logging manual lookups during the login process. Use of multi-factor authentication in the login process. 10. Any changes to the conditions covered by this authorization must be reported to the Danish Data Protection Agency. The above terms apply until further notice. The Danish Data Protection Agency reserves the right to review these terms should the need arise. The above terms are supplementary and clarifying in relation to the provisions of the General Data Protection Regulation (GDPR) and the Danish Data Protection Act. It should be emphasized that the General Data Protection Regulation and the Data Protection Act thus apply to the extent that matters are involved that are not regulated by the terms and conditions above. The processing must therefore also be carried out in accordance with

Entities

automatic facial recognition (product)Datatilsynet (vendor)CCTV Surveillance Act (product)Danish Data Protection Act (product)AC Horsens (product)Lyngby Boldklub (product)