Legal
Indlæser…
Data Policy
Last updated: 1 August 2026
This data policy describes the overall principles for how Center for Voldsforebyggelse (CFV) (CVR no. 41393025) processes and protects data internally within the organisation. The policy supplements our privacy policy and cookie policy, and is primarily directed at employees, volunteers, and the board of CFV.
1. Purpose
This data policy is intended to ensure that CFV processes all types of data – including personal data about members, donors, partners, and individuals receiving counselling – responsibly, securely, and in accordance with applicable legislation, including the General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
2. Fundamental principles
CFV follows the fundamental principles of the GDPR in all data processing:
Lawfulness, fairness and transparency: Data is only processed on a lawful basis, and data subjects are informed about the processing
Purpose limitation: Data is collected for specified, explicit and legitimate purposes and is not used for incompatible purposes
Data minimisation: Only the data necessary for the purpose is collected and processed
Accuracy: Data is kept up to date, and inaccurate data is corrected or deleted without undue delay
Storage limitation: Data is not retained for longer than necessary for the purpose
Integrity and confidentiality: Data is protected against unauthorised access, loss, or destruction
Accountability: CFV is able to demonstrate compliance with the above principles at all times
3. What data does CFV process
CFV processes, among others, the following categories of data:
Ordinary personal data about members, donors, partners, and website visitors (e.g. name, contact details, payment information)
Sensitive data (special categories), which may arise in connection with counselling and support for individuals who are subjected to or perpetrate violence
Internal organisational data, including staff data, financial and accounting data
Sensitive data is handled with heightened confidentiality. Access is limited to those employees and volunteers for whom it is strictly necessary for the purposes of counselling or task performance, and anonymisation or pseudonymisation is used wherever possible.
4. Roles and responsibilities
CFV's board and daily management act as data controller and hold overall responsibility for compliance with this data policy. All employees and volunteers are responsible for processing data in accordance with this policy and for referring any uncertainties to management. A data protection contact person is appointed, who can be contacted with questions or in case of suspected breaches of data security.
5. Data processors and third parties
Where CFV uses external providers to process data on our behalf (e.g. IT operations, newsletter distribution, web analytics, or payment processing), a data processing agreement compliant with GDPR Art. 28 is always entered into. CFV continuously assesses its providers to ensure an adequate level of security.
6. Data security
CFV applies technical and organisational security measures, including among others:
Access control, so that only relevant individuals have access to data based on a work-related need
Encryption and password protection of systems, where relevant
Secure storage and backup of data
Ongoing updates to IT systems and security measures
Confidentiality obligations for employees and volunteers regarding sensitive and confidential information
7. Retention and deletion
Data is only retained for as long as necessary for the purpose for which it was collected, or for as long as CFV is legally required to do so (e.g. under the Danish Bookkeeping Act). Ongoing clean-up is carried out, and data that is no longer necessary is deleted or anonymised.
8. Personal data breaches
If it is established that a breach of personal data security has occurred (e.g. loss, hacking, or unauthorised access), this must be reported internally to management immediately. If the breach poses a risk to the rights of data subjects, CFV will report the breach to the Danish Data Protection Agency (Datatilsynet) no later than 72 hours after CFV becomes aware of it, cf. GDPR Art. 33. Affected individuals will be notified if the breach poses a high risk to their rights or freedoms.
9. Review of this data policy
This data policy is evaluated and updated on an ongoing basis, at least once a year, or when organisational or legislative changes make it necessary.
10. Contact
Questions regarding this data policy can be directed to:
Center for Voldsforebyggelse (CFV)
Prinsesse Charlottes Gade 45A, 2200 København N, Denmark
Phone: +45 60 56 46 33
E-mail: [email protected]