Labora Advokatfirma

Privacy Policy

Introduction

We process a range of personal data about you when you or your company establish a client relationship with us, or as part of the practice of our legal profession. Such processing is necessary in order for us to register the client relationship in accordance with the rules governing us as attorneys, and to enable us to handle the specific matter(s) and provide legal advice to our clients, as well as to market our services.

We take the protection of your personal data very seriously. As attorneys, we are subject to strict duties of confidentiality, professional secrecy, and ethical rules. It is therefore an inherent part of our practice to respect you and your privacy.

We only process personal data that we are required to process under applicable law, or that are necessary for us to provide our legal services to our clients.

Data Controller

LABORA consists of independent, cooperating law firms. When we process personal data, the data controller is the attorney who has entered into the agreement with the client and/or handles the matter and provides the legal advice.

You can find our contact details here and here.

Processing of Personal Data

We process your personal data if:

Who We Share Personal Data With

As attorneys, we are obliged to share all relevant information, including personal data, with our client and other parties involved in the legal handling of a case.

We may share personal data with other attorneys within LABORA or disclose them for registration in public authorities’ databases, such as virk.dk, the courts (minretssag.dk), or for use in proceedings before an arbitral tribunal, the Equal Treatment Board, or other dispute resolution bodies. These recipients are, as a rule, independent data controllers for their own processing of the personal data.

In addition, we may share personal data with our suppliers who process personal data on our behalf for the purposes described. These recipients must comply with our security requirements and may not use personal data for purposes other than ours. When we engage other companies to process personal data, e.g. Microsoft and our case management systems, we enter into data processing agreements governing their processing of personal data on our behalf.

We require that our client and case data are not stored or processed outside Denmark. Furthermore, we only transfer personal data for processing outside the EU and EEA if such transfer is made to a client, counterparty, or court.

Erasure

We erase personal data when they are no longer necessary for the purpose for which the data were collected and processed, or for our documentation of the legal advice we have provided. The retention period may therefore vary depending on the specific purpose. As a general rule, data used for case handling will be stored for 25 years, although shorter or longer retention periods may apply.

Security

We have implemented appropriate technical and organizational measures regarding confidentiality and information security to protect the collected personal data from destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

This includes restricting physical and system access to personal data to colleagues who have a work-related need for such access and who have received training and instructions in the processing of personal data. Access will only be granted to individuals who are subject to duties of confidentiality and secrecy.

Personal data in physical form or on portable media (USB or similar) are stored in locked facilities when not in use, while personal data in digital form are protected by access control, personal passwords, encryption, backup systems, as well as updated firewalls and antivirus protection.

We also have processes in place for handling potential security breaches and for notifying you and the Danish Data Protection Agency thereof.

Your Rights as a Data Subject

If we process your personal data, you have a number of specific rights under the data protection legislation.

Right of Access

You have the right to be informed of which personal data we process about you, the purpose of the processing, the recipients or categories of recipients to whom the personal data have been or will be disclosed, the period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period. You are also entitled to be informed of the source of the personal data if they were not collected from you, information regarding automated decision-making if we use such processes, as well as information about any transfer for processing outside the EU or EEA and the safeguards applicable to such transfer.

However, LABORA’s attorneys are subject to duties of confidentiality under the Danish Administration of Justice Act and the rules of legal ethics, and we may refrain from fulfilling the duty of disclosure to you if the processing of your personal data must remain confidential. We may also refrain from fulfilling the duty of disclosure in order to protect overriding private or public interests, including your own, if such interests are deemed to outweigh your interest in receiving the information. This exception will be relevant if the duty of disclosure would negatively affect the protection of our clients’ interests, for example in connection with litigation and enforcement of civil claims or criminal acts, supervisory or regulatory functions, internal investigations, and similar situations.

Furthermore, we may refrain from fulfilling the duty of disclosure if you are already aware of the information, if it is impossible or would involve a disproportionate effort, or if providing the information would prevent the achievement of the purposes of the processing.

Right to Rectification

You have the right to have any personal data that we process and that are inaccurate or incomplete rectified or supplemented by us. In such case, you must inform us of the nature of the inaccuracies and how they should be rectified.

Right to Restriction of Processing

You have the right to have our processing of your personal data restricted if
(i) you contest the accuracy of the personal data, unless we can establish that the personal data are correct, or
(ii) the processing is unlawful, but instead of erasure you request that the processing of the personal data be restricted,
(iii) we no longer need the personal data for the stated purposes, unless the processing of the personal data is necessary for the establishment, exercise, or defence of legal claims, or
(iv) you have objected to processing carried out in the interests of society or others, unless such interests override your interests.

Right to Erasure

You have the right to request erasure of your personal data if the processing is no longer necessary to fulfil the purposes for which the data were collected, or if our processing was based on your consent and you have withdrawn that consent and no other legal basis for the processing exists, or if you make a legitimate objection to processing carried out in the interests of society or others, or if the processing is carried out for the purpose of direct marketing. You also have the right to request erasure of your personal data if the processing is unlawful, or if erasure is required under Danish law.

However, you do not have the right to request erasure of your personal data if the processing is necessary for us to perform a contract to which you are a party, to exercise the right to freedom of expression and information, to comply with a legal obligation to which we are subject under Danish law, or for the establishment, exercise, or defence of legal claims.

Right to Withdraw Consent

If we process your personal data on the basis of your consent, you have the right to withdraw your consent. Withdrawal of consent will not, however, affect the lawfulness of the processing already carried out on the basis of the consent.

Right to Notification

You have the right to be informed of the recipients to whom we have disclosed or shared your personal data, and to have those recipients notified of any rectification, erasure, or restriction of your personal data, unless this proves impossible or involves a disproportionate effort.

Right to Data Portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit those data to another data controller where the processing is based on consent or on a contract and the processing is carried out by automated means. Where technically feasible, you also have the right to request that we transmit the personal data directly to the other data controller.

Right to Object

You have the right to object to the processing of your personal data carried out in the interests of society or others, and in such case the personal data may no longer be processed unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims. You also have the right, at any time, to object to the processing of your personal data for direct marketing purposes, in which case the personal data may no longer be processed for such purposes.

Right Not to Be Subject to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right does not apply if the decision is necessary for entering into or performing a contract to which you are a party, if the decision is based on your consent, or if the decision is authorised by Danish law.

Right to Notification of a Personal Data Breach

You have the right to be notified if we experience a personal data breach that is likely to result in a high risk to your rights and freedoms. However, this right does not apply if we have implemented appropriate technical and organizational protection measures with respect to the personal data affected by the breach, such as measures that render your personal data unintelligible to anyone not authorized to access them, if we have taken subsequent measures ensuring that the high risk to your rights and freedoms is no longer likely to materialize, or if direct notification to you would involve a disproportionate effort. In the latter case, a public communication or a similar measure must instead be made, whereby you are informed in an equally effective manner.

Right to Lodge a Complaint Regarding the Processing of Your Personal Data

You have the right to lodge a complaint with the Danish Data Protection Agency if you believe that our processing of your personal data infringes Danish data protection law, via their website. However, we hope that you will contact us first if you are dissatisfied, so that we may attempt to resolve the matter together.

***

You can read more about your rights in the Danish Data Protection Agency’s guidance on the rights of data subjects.

If you wish to exercise one or more of your rights, you may contact the responsible attorney at LABORA or write to info@laboralegal.com. You must provide your full name and the reason why you believe LABORA is processing your personal data.

Once we have received your request, we will examine whether we can identify you and whether the conditions for exercising the right are fulfilled. If so, we will ensure that the right is fulfilled as quickly as possible, and you will hear from us within 30 days.

As a rule, you may exercise your rights free of charge. However, if you request additional copies of information, we may charge a fee for this. If your request is manifestly unfounded or excessive, we may also either charge a fee for complying with your request or refuse to comply with it.

The exercise of your rights must not infringe the rights and freedoms of others. As the information may be subject to our duty of confidentiality and the rules of legal ethics, there may be cases where we must refuse to comply with your request in whole or in part.

14 September 2025

If You Are or Represent a Client or Potential Client

We process your personal data in order to establish a client relationship and to designate the relevant contact person for conflict checks, case registration, correspondence and communication in connection with our advice and case management, as well as invoicing. We may also use the data in connection with marketing and to tailor our services.

In this context, we normally process the following categories of personal data: name, address (or business address), title, email address, and telephone number. The legal basis is our agreement with the client, cf. GDPR Article 6(1)(b), or our legitimate interests in establishing a client relationship and managing the case and our legal advice as well as invoicing, cf. GDPR Article 6(1)(f).

If we are required to use the data to carry out a mandatory anti-money laundering check, we also process your passport and/or driving licence details, which contain your national identification number (CPR number). The legal basis for this processing is our legal obligation, cf. GDPR Article 6(1)(c).

We normally receive the data from you. However, we may also receive them from others, such as your employer or counterparty, or collect them from publicly available sources, such as your employer’s website, LinkedIn, or CVR.dk.

The personal data are stored for the duration of the client relationship and for a subsequent period of 10 years, unless special circumstances make it necessary to store the personal data for a shorter or longer period.

If Your Personal Data Form Part of Our Practice of the Legal Profession, e.g. if You Are a Counterparty or Witness

We process personal data concerning our clients’ potential, current, and former employees, as well as private individuals seeking advice as part of our legal counselling and case management, and other individual persons involved in the matters we handle.

In this context, we normally process the following categories of personal data: identification and contact details, information on salary and employment terms, educational background, warnings and other disciplinary measures, including breaches of employment terms, trade union membership, pregnancy, parental leave, sickness absence and health data, religion, as well as criminal matters. If you are an immigration applicant and we advise you or your employer (or potential employer) in that regard, we also process your passport details and bank details, as well as, in certain cases, family photographs and other personal data that may reveal information about your affiliations. The legal basis is our legal obligations and/or legitimate interests in the practice of the legal profession, cf. GDPR Article 6(1)(c) and (f).

We only process special categories of personal data where necessary for the above purposes and for the establishment, exercise, or defence of legal claims, cf. GDPR Article 9(2)(f).

We only process data concerning criminal matters where it is deemed necessary to safeguard our or our client’s legitimate interest, and such interest clearly overrides the interests of the data subject, cf. the Danish Data Protection Act, Section 8(3). Processing may also take place for the purpose of pursuing a legal claim, cf. the Danish Data Protection Act, Section 8(5), cf. Section 7(1).

We only process Danish CPR numbers (civil registration numbers) where necessary for unambiguous identification and required by law, cf. the Danish Data Protection Act, Section 11(2)(1), or for the establishment, exercise, or defence of legal claims, cf. the Danish Data Protection Act, Section 11(2)(4), cf. Section 7(1).

We normally receive the personal data from our clients. However, we may also receive them from you, from others such as your current employer or the courts, or we may collect them from publicly available sources such as your employer’s website, LinkedIn, or CVR.dk.

The personal data are stored for the duration of the client relationship and for 10 years thereafter, unless special circumstances make it necessary to store the personal data for a shorter or longer period.

If You Represent an External Party

LABORA has communication and other contact with individuals who represent external parties that are not our client relationships, e.g. representatives of our clients’ counterparties (attorneys, trade unions, or unemployment insurance funds), employees of public authorities and the courts, as well as our own cooperation partners and suppliers.

In this context, we process personal data such as names, work email addresses, work telephone numbers, job titles, employer and work address, as well as work-related correspondence.

The legal basis for processing personal data about you in this context is our legitimate interests in fulfilling our obligations as attorneys and providing proper advice to our clients, as well as maintaining cooperative relationships, cf. GDPR Article 6(1)(f), and, where applicable, Article 6(1)(c).

We normally receive the personal data directly from you or from our clients. However, we may also receive them from our cooperation partners and your employer, or we may collect them from publicly available sources such as your employer’s website, LinkedIn, or CVR.dk.

If the personal data form part of an ongoing case, they are stored until the case is closed and for a subsequent period of 10 years, unless special circumstances make it necessary to store the personal data for a shorter or longer period.

If the personal data form part of an ongoing contractual or cooperative relationship, they are stored until the contractual relationship ends and for a subsequent period of 3 years.

Other personal data are stored for as long as the parties are in communication.

If Your Personal Data Form Part of Our Administration of a Whistleblower Scheme for Our Clients

We process all types of personal data concerning individuals mentioned in reports submitted under clients’ whistleblower schemes that we administer, other affected individuals, and whistleblowers, if they are not anonymous.

The legal basis for the processing of ordinary personal data is our legitimate interest in assessing the report and determining which measures it requires for our clients, as well as safeguarding the interests of other affected individuals and society, cf. GDPR Article 6(1)(f).

If the report contains special categories of personal data, the legal basis for the processing is the above, as well as GDPR Article 9(2)(f) (and Section 22 of the Danish Whistleblower Protection Act for schemes that are mandatory), as the processing will be necessary for the establishment, exercise, or defence of legal claims.

We only process Danish CPR numbers (civil registration numbers) if required for the purpose of carrying out our assessment or any mandatory reporting, cf. the Danish Data Protection Act, Section 11(2)(1), or for the establishment, exercise, or defence of legal claims, cf. the Danish Data Protection Act, Section 11(2)(4), cf. Section 7(1).

If the report contains personal data concerning criminal matters or potential criminal matters, the legal basis is the Danish Data Protection Act, Section 8(3), second sentence, or Section 8(5), cf. Section 7(1), and the legal basis for any disclosure will be the Danish Data Protection Act, Section 8(4), second sentence.