This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Authorities, organizations, and companies should supplement their identity checks after leak from the CPR register
The Danish Agency for Civil Protection urges authorities, organizations, and companies to enhance their verification processes to prevent sensitive information from being disclosed solely based on data from the Central Person Register. In light of unauthorized access to the CPR register, there is a need for these entities to review their procedures for identifying and verifying citizens' identities. They should focus on situations where CPR numbers, names, or addresses are used to confirm identity. As a general rule, identity checks should rely on other information than CPR data or previous contact details with the citizen, especially when sensitive personal data is shared or in cases with potential financial consequences for the individual.