Privacy and Cookie Policy
Below you will find further information about Romme Law Firm's processing of personal data and use of cookies on the website www.rommelaw.com.
1. Data Controller
Romme Law Firm is the data controller responsible for the processing of your personal data in connection with our business activities, case handling, legal advice and marketing. You can contact us here:
Romme Law Firm
Attn.: Henning Romme-Mølby
E-mail: hrm@rommelaw.com
Telephone: +45 40886225
Website: www.rommelaw.com
The firm has not appointed a Data Protection Officer (DPO), as we are not obliged to do so. Any enquiries regarding our processing of personal data may be addressed directly to Henning Romme-Mølby using the contact details above.
2. When are we the data controller, and when are we the data processor?
In most situations, we are the data controller for the processing of personal data that takes place in connection with our general business activities, case handling and legal advice, as well as the marketing of our services.
Only in connection with specific services – for example, where we store documents or process data on behalf of our clients in accordance with their specific instructions – are we regarded as a data processor, in which case a data processing agreement is entered into with the client concerned. As a data processor, we act exclusively in accordance with the documented instructions of the data controller.
3. Categories of personal data and sources
We process the following categories of personal data, depending on the specific situation:
-
General personal data: Name, contact details (e-mail, address, telephone number), position/role, company registration number, correspondence and case documents.
-
Special categories of personal data (sensitive data): In certain cases, it may be necessary to process information concerning, for example, health, trade union membership, ethnic origin or other sensitive data. Such information is processed only where there is a valid exception under Article 9(2) of the GDPR – in particular where processing is necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f)).
-
Information relating to criminal offences: In certain cases, it may be necessary to process information relating to criminal convictions and offences. Such processing is carried out exclusively on the basis of Article 10 GDPR and Section 8(3) of the Data Protection Act — i.e. on the basis of explicit consent, or where a legitimate interest clearly overrides the interests of the data subject.
Where does the information come from?
Personal data is typically collected from:
-
You (e.g. through direct contact, use of the website or the establishment of a client relationship)
-
Your employer or the companies you represent
-
Your advisers or counterparties in the matter
-
Public authorities, courts and publicly available registers (e.g. the Danish Central Business Register (CVR), the land register)
-
Auditors, financial institutions or other relevant third parties, depending on the nature of the matter
If we have obtained your personal data from sources other than yourself, we will – unless otherwise exempted – inform you of this in accordance with Article 14 of the GDPR, including the source of the data and whether it originates from publicly available sources.
4. Purposes, legal basis and retention periods
The processing situations typically encountered at Romme Law Firm are described below, including purposes, legal basis and retention periods.
4.1 Establishment and administration of client relationships
Purpose: To establish and administer client relationships, including conflict checks, case creation, KYC checks (Anti-Money Laundering Act) and ongoing client communication.
Legal basis: Article 6(1)(b) of the GDPR (performance of a contract or pre-contractual measures) and/or (f) (legitimate interest in client administration and the operation of the law firm). Our legitimate interest is to be able to establish and manage client relationships in a responsible and prudent manner.
Retention: Client data is retained for as long as the client relationship is active and thereafter typically for up to ten years from the conclusion of the case, taking into account limitation periods, documentation requirements and the rules of professional conduct for lawyers. Specific time limits are set out in our internal data retention policy.
4.2 Case handling and legal advice (practice of the legal profession)
Purpose: To handle the client's case, provide legal advice, conduct negotiations and/or litigation, and otherwise perform legal services.
Legal basis: Article 6(1)(b) of the GDPR (performance of a contract) and/or (f) (legitimate interest in handling the client's case and ensuring correct legal advice). For the processing of special categories of data: Article 9(2)(f) of the GDPR (legal claims) or another relevant basis in Article 9(2), depending on the nature of the case.
Retention: Case files and documentation are typically retained for up to ten years from the conclusion of the case. The specific retention period is set out in our internal data retention policy, taking into account limitation periods, legal claims and documentation requirements.
4.3 Representation of a client, opposing party, authority or other external party
Purpose: Communication and conduct of proceedings in connection with the specific case – including written and oral correspondence with opposing parties, authorities and other relevant parties.
Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in safeguarding the client's interests and providing legal assistance). Our legitimate interest is to represent the client properly, including through contact with opposing parties and authorities.
If you are a data subject in connection with this processing (e.g. as an opposing party, witness or contact person), you have the right to object to the processing on grounds relating to your particular situation; see section 7 below for further details.
Retention: The data is retained for as long as the case is active and thereafter typically for up to ten years, depending on the nature of the case and applicable limitation periods and documentation requirements.
4.4 Invoicing, bookkeeping and debt collection
Purpose: To issue invoices, fulfil accounting obligations and, where necessary, recover payments.
Legal basis: Article 6(1)(b) of the GDPR (contract), (c) (legal obligation, including the Danish Bookkeeping Act) and/or (f) (legitimate interest in the recovery of receivables).
Retention: Accounting documents and invoices are retained for five years following the end of the financial year to which the material relates, in accordance with the Danish Bookkeeping Act. Other information is retained in accordance with internal retention periods.
4.5 Marketing (newsletters, invitations and events)
Purpose: To send out newsletters, invitations to events and other marketing material relating to our services.
Legal basis: Article 6(1)(a) of the GDPR (consent) and/or (f) (legitimate interest in marketing the firm's services), depending on the specific activity and the applicable marketing legislation.
Objection to direct marketing: You may object at any time, without giving a reason, to the processing of your personal data for direct marketing purposes. If you object, we will cease processing your data for this purpose. You can unsubscribe via the unsubscribe link in our e-mails or by contacting us directly.
Retention: The data is retained until you unsubscribe, object, or we no longer have a legitimate need for it, in accordance with our internal retention periods.
4.6 Recruitment (job applications)
Purpose: To receive and process job applications and to carry out the recruitment process.
Legal basis: Article 6(1)(b) of the GDPR (pre-contractual measures, including the conduct of the recruitment process) and/or (f) (legitimate interest in recruitment). Our legitimate interest is to identify and assess suitable candidates for vacant positions.
Retention: Application documents are typically deleted six months after the end of the recruitment process. Retention beyond this period will only take place with separate consent.
4.7 Use of the website (www.rommelaw.com)
Purpose: Technical operation and security of the website and – subject to consent – statistics and improvement of the user experience.
Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in operating and ensuring a well-functioning website) for necessary technical purposes. For non-essential cookies and statistics, Article 6(1)(a) of the GDPR (consent) applies; see section 9 on cookies for further details.
Retention: Technical log files and cookie data are retained in accordance with the periods specified in the cookie declaration; see section 9.
5. Recipients and categories of recipients
We only disclose personal data to recipients who have a legitimate need for it. Typical recipients include:
-
IT suppliers and system providers (as data processors): e.g. providers of hosting, e-mail systems, case management systems and document management – all subject to a data processing agreement requiring adequate security safeguards.
-
Auditors and accounting systems: in connection with invoicing and accounting.
-
Courts, the Danish Bar and Law Society and public authorities: where this is necessary as part of the handling of a case or to comply with legal requirements.
-
Opposing parties' solicitors and other relevant parties: where necessary in connection with a specific case.
-
Collaborating law firms: to the extent relevant to the specific case.
Public authorities that receive personal data as part of an isolated statutory enquiry are not considered "recipients" within the meaning of the GDPR.
6. Transfer of personal data to countries outside the EU/EEA
As a general rule, Romme Law Firm does not transfer personal data to countries outside the EU/EEA.
If necessary in a specific case, the transfer will only take place on a valid legal basis in accordance with Chapter V of the GDPR – for example, via the European Commission's standard contractual clauses or, if the European Commission has adopted an adequacy decision, on that basis.
You can obtain information about the specific legal basis for the transfer and any safeguards by contacting Henning Romme-Mølby at hrm@rommelaw.com.
7. Your rights as a data subject
As a data subject, you have a number of rights under the GDPR, which you can exercise by contacting us.
You have the right to:
-
Access: To request access to the personal data we process about you, including the purposes, categories, recipients, retention periods and other information.
-
Rectification: To request the correction of inaccurate or incomplete data.
-
Erasure: To request erasure ("the right to be forgotten") if the conditions for this are met.
-
Restriction: To request the restriction of processing in certain situations.
-
Data portability: To receive your data in a structured, commonly used and machine-readable format, provided that the processing is based on consent or a contract and is carried out by automated means.
-
Objection: To object to processing based on legitimate interests (Article 6(1)(f) of the GDPR) on grounds relating to your particular situation. We may then only continue the processing if we can demonstrate compelling legitimate grounds that override your interests and rights, or if the processing is necessary for the establishment, exercise or defence of legal claims.
Consent: If the processing is based on your consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. Withdrawing your consent is just as easy as giving it.
Restrictions on rights: The exercise of your rights may in certain cases be restricted, for example, in the interests of solicitor-client privilege, the client's interests or other significant private or public interests; see section 8 below for further details.
You can read more about your rights on the Danish Data Protection Agency's website: www.datatilsynet.dk.
8. Exceptions to the duty to provide information and restrictions on rights (duty of confidentiality)
The staff of Romme Law Firm, including solicitors, trainee solicitors and administrative staff, are subject to a duty of confidentiality in accordance with the Danish Administration of Justice Act and the rules of professional conduct for solicitors. The duty to provide information under Article 14 of the GDPR may, in certain cases, be restricted if the personal data must remain confidential as a result of this statutory duty of confidentiality.
Furthermore, restrictions on the data subject's rights may, in certain cases, be justified under the Danish Data Protection Act if the data subject's interests are deemed to have to give way to overriding considerations relating to other private interests, including the client's interests, or to substantial public interests, for example in connection with legal proceedings, investigations or the enforcement of civil law claims.
Such restrictions always require a specific assessment. We cannot generally derogate from the duty to provide information or the data subject's rights solely on the grounds of the duty of confidentiality.
9. Automated decisions and profiling
We do not make decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you, in accordance with Article 22 of the GDPR.
10. Security
We use appropriate technical and organisational security measures to protect your personal data against unauthorised access, loss, alteration, disclosure or other unlawful processing. These measures are regularly adapted to the current risk and may include, amongst other things, encryption, access control and internal security procedures.
11. Contact and complaints
If you have any questions regarding our processing of personal data, or if you wish to exercise your rights, please feel free to contact:
Henning Romme-Mølby
Romme Law Firm
Hammerensgade 6, 2nd floor, 1267 Copenhagen
E-mail: hrm@rommelaw.com
Telephone: +45 40886225
Website: www.rommelaw.com
If you believe that we are processing your personal data in breach of data protection regulations, you may lodge a complaint with the Danish Data Protection Agency, which is the competent supervisory authority in Denmark:
Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35, 2500 Valby
Cookie Policy
What is a cookie?
A cookie is a small text file that is stored on your computer, smartphone or other IT device when you visit a website. Cookies may contain personal data, including a unique identifier, IP address and information about your behaviour on the website.
What cookies do we use?
We use the following categories of cookies on www.rommelaw.com:
Essential cookies ensure the website's basic functionality, including session management and security. These cookies are necessary for the website to function correctly and do not require your consent.
Preference and functionality cookies store your preferences, such as your language choice, so that you do not have to re-enter them on your next visit. These cookies are only placed if you have given your consent, in accordance with Article 6(1)(a) of the GDPR.
Statistical and analytical cookies are used to compile anonymised statistics on the use of the website with a view to optimising and improving your experience. These cookies are only placed if you have given your consent, in accordance with Article 6(1)(a) of the GDPR.
In the cookie banner, you can choose to give or withhold consent for each category separately. You do not therefore need to accept all cookies to use the website.
A full list of the specific cookies – including name, provider, purpose and expiry date – is set out in our Cookie Declaration, which you can access at any time via the link in the cookie banner on the website.
Consent
We only place non-essential cookies once you have given your explicit consent via our cookie banner. Passivity, continued use of the website or pre-ticked boxes do not constitute valid consent.
You may withdraw your consent at any time by clicking on the cookie link/banner on the website. Withdrawing your consent is just as easy as giving it. If you withdraw your consent, the relevant cookies will be automatically deleted or blocked.
Please note that certain features on the website may be restricted if you choose not to accept certain cookies.
Documentation of consent
We document your cookie consent, including the time, version of the cookie banner and the purposes to which you have consented, in accordance with the GDPR's accountability principle.
Third-party cookies and transfers
If we use third-party plug-ins or services that set cookies (e.g. analytics tools), situations of joint data control may arise. In such cases, the specific plug-in's entry in the cookie declaration will state who is the data controller and who you can contact.
If cookies result in the transfer of personal data to third countries (outside the EU/EEA), this will only take place on a valid legal basis for such transfers; see the section on transfers to countries outside the EU/EEA above for further details.
Updates
This privacy and cookie policy is updated on an ongoing basis. Last updated: 3 August 2026.
.png)