
Privacy Policy
Lorentzen & Partners, Statsautoriserede Revisorer ApS
(CVR no. 45 32 89 88)
1. General considerations
At Lorentzen & Partners, Statsautoriserede Revisorer ApS (“L&P”, “we”, “us”), we take the protection of personal data seriously.
- We only process personal data that is necessary for:
- providing agreed services
- fulfilling contractual obligations
- complying with applicable law
- pursuing legitimate business interests
We process personal data in accordance with the General Data Protection Regulation (GDPR), the Danish Data Protection Act, and other relevant legislation.
This privacy policy applies when we act as a data controller.
2. Data controller or data processor
When we act as a data controller
For assurance engagements (audits, reviews, etc.) and independent advisory services, we are the data controller for the personal data we process.
When we act as a data processor
For services such as bookkeeping, payroll assistance, or other administrative support, we process personal data on behalf of the client and in accordance with their instructions. In these cases, we enter into a written data processing agreement.
3. What personal data do we process?
Depending on the relationship, we may process:
General personal information
- Name
- Address
- Phone number
- Job title
- CVR registration
Identification information (anti-money laundering legislation)
- Civil registration number (CPR)
- Copy of passport or driver's license
- Information on beneficial owners
- Financial and tax information
- Accounting data
- Tax information
- Salary information
- Bank details
Sensitive information (only if necessary)
- Health information
- Trade union membership information
- Criminal convictions (only if required by law)
We do not collect more information than necessary.
4. Purpose and legal basis
We process personal data based on the following legal grounds:
- Performance of a contract (GDPR Art. 6(1)(b))
- Legal obligation (the Auditors Act, the Bookkeeping Act, the Anti-Money Laundering Act, etc.)
- Legitimate interest (e.g., quality assurance, conflict checks)
- Consent, if relevant (can be withdrawn at any time)
5. Storage and deletion
We store personal data for as long as necessary in accordance with:
- The Bookkeeping Act
- The Auditors Act
- The Anti-Money Laundering Act
- Statutes of limitation regarding liability for damages
As a general rule, information is stored for 5 years after the end of the customer relationship, unless longer storage is necessary.
Applications are generally deleted no later than 6 months after receipt, unless consent for longer storage has been provided.
6. Disclosure of information
We only disclose information when:
- This is necessary for the delivery of the service
- This is required by law
- This occurs with sub-processors under a data processing agreement
- This occurs with public authorities (e.g., the Danish Tax Agency, the Danish Business Authority)
During quality control, information may be disclosed to supervisory authorities or network auditors under confidentiality.
We never sell personal data.
7. Anti-money laundering legislation
As an audit firm, we are subject to the Anti-Money Laundering Act and are required to:
- Perform customer due diligence procedures
- Obtain and store identification
- Monitor transactions
- Report suspicions to the Money Laundering Secretariat
When reporting, we are bound by confidentiality and must not inform the affected person.
8. Security
We have implemented appropriate technical and organizational security measures, including:
- Access control
- Encrypted communication
- Backup and logging
- Internal policies and training
However, electronic communication may involve certain risks that cannot be fully eliminated.
9. Your rights
As a data subject, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure (in specific cases)
- Right to restriction of processing
- Right to object
- Right to data portability
- Right not to be subject to automated decision-making
Requests will be processed without undue delay and no later than within 1 month.
10. Complaint
If you are dissatisfied with our processing of your personal data, we encourage you to contact us first.
You also have the right to lodge a complaint with:
The Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
www.datatilsynet.dk
11. Contact
Lorentzen & Partners, State-Authorized Public Accountants ApS
CVR no. 45 32 89 88
Amager Strandvej 60, 2300 Copenhagen S
info@lorentzenpartners.dk

