{
  "case_id": "TRACE-CPR-2026-10-05",
  "generated": "2026-10-05",
  "purpose": "Control and audit-trail matrix derived from CPR public pages captured on 2026-10-05 and CPR standard terms effective 2026-06-16.",
  "important_limit": "The breached CPR product has not been publicly identified. Each control applies only if the corresponding access path was used.",
  "captured_pages": [
    {
      "id": "CAP-PAGE-ACCESS-APPLICATION",
      "url": "https://www.cpr.dk/kunder/ansoegning-om-adgang",
      "sha256": "84fc56168d05030a3236f7a95acf7676e0df69f960d4279cfefb0dcdf2cba36c",
      "observation": "Application requires CVR, controller identity, named security officer contact, billing contact and requested products."
    },
    {
      "id": "CAP-PAGE-PRODUCTS",
      "url": "https://www.cpr.dk/kunder/ansoegning-om-adgang/kort-beskrivelse-af-produkter",
      "sha256": "00bff6b3461f3ce40cf7097a591386274dc516b0b2865819bd3a1a3bb7e8a403",
      "observation": "Public product map distinguishes CPRWeb, FTP extracts, CPR Direkte, CPR Services and Datafordeler REST/GraphQL."
    },
    {
      "id": "CAP-PAGE-CPRWEB-TECH-PUBLIC",
      "url": "https://www.cpr.dk/kunder/offentlige-myndigheder/cprweb/tekniske-forudsaetninger",
      "sha256": "9cd25fac65defdfd7edb18745fe81d2db23f9674254a1ba30c2e8dc0353190cd",
      "observation": "Public-authority CPRWeb page states that all searches and transactions are logged in CPR and outgoing IP addresses are allow-listed."
    },
    {
      "id": "CAP-PAGE-CPRWEB-PRICE-PRIVATE",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/cprweb/priser-for-cprweb-til-private",
      "sha256": "b509651f02d3189808d198c7f8050b5b8cce22fbc2d1c3d18cee970dbc8fd7ab",
      "observation": "Private CPRWeb pricing is per person search and says no-result queries are billed."
    },
    {
      "id": "CAP-PAGE-CPRDIRECT-PRICE",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/cpr-direkte/priser-for-cpr-direkte",
      "sha256": "77a96fc4443ea148d7002158dfad72b2170ee4956bb75d2790dc57e45b0dbe50",
      "observation": "Private CPR Direkte pricing is per lookup."
    },
    {
      "id": "CAP-PAGE-CPRSERVICES-PRICE",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/cpr-services/priser-for-cpr-services",
      "sha256": "7cdccf41991d5c0669dbee58f4f8f26a18b8d97fcfef1d46780465a43f0f2292",
      "observation": "Private CPR Services pricing is per transaction."
    },
    {
      "id": "CAP-PAGE-DATAFORDELER-PRICE",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/datafordeler/priser-for-datafordeler",
      "sha256": "79b632e4f073f4faccdfa8bb4c5c692dcda1a5526bb6ea5f0457c18edc583338",
      "observation": "REST counts all transactions including zero-entity results; GraphQL pricing is per returned person object."
    },
    {
      "id": "CAP-PAGE-BATCH-PRICE",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/personnummerudtraek/priser-for-udtraek",
      "sha256": "83e8e3f7e172819a7ba0ac1160d24568800a8527867d6042441570a4ad145c2e",
      "observation": "CPR explicitly supports large batch deliveries with flat pricing independent of output volume for status extracts."
    },
    {
      "id": "CAP-PAGE-MATCH-ANALYSIS",
      "url": "https://www.cpr.dk/kunder/private-virksomheder/adressematch-udtraek/match-analyse",
      "sha256": "9d3504b431884455fc27e040ad8a0a36bea41055af480d2758a3972de563c826",
      "observation": "Before matching a large population, CPR recommends a match analysis on up to 5,000 persons."
    }
  ],
  "official_terms": [
    {
      "id": "TERM-S2S",
      "document": "Standard terms and conditions for data deliveries from CPR to private enterprises and individuals",
      "effective": "2026-06-16",
      "url": "https://www.cpr.dk/Media/639171945708056248/vk65-private-udtraek_pr_20260616-eng-.pdf",
      "sections": [
        "3 Requirements for data communication",
        "4 Authorisation and access control"
      ],
      "control_summary": [
        "System-to-system online batches require prior CPR approval.",
        "Client designates a security officer.",
        "Client keeps employee and solution authorisation records.",
        "All CPR searches are attributed to individual employee IDs in the client system.",
        "Monthly transaction statistics by transaction type are produced and checked by the security officer."
      ]
    },
    {
      "id": "TERM-CPRWEB",
      "document": "Standard terms and conditions for private CPRWeb access",
      "effective": "2026-06-16",
      "url": "https://www.cpr.dk/Media/639172749611807957/vk60-private-cprweb_pr_20260616-eng.pdf",
      "sections": [
        "3 Authorisation and access control"
      ],
      "control_summary": [
        "Every query is logged with user ID, date and time, and the data the query concerns.",
        "Per-user transaction statistics are available.",
        "Security officer checks transaction statistics monthly.",
        "Detailed terminal traffic can be requested for defined user IDs and periods."
      ]
    },
    {
      "id": "TERM-DATAFORDELER",
      "document": "Standard terms and conditions for CPR data deliveries from the Data Distributor to private enterprises and individuals",
      "effective": "2026-06-16",
      "url": "https://www.cpr.dk/Media/639171982276669647/vk65-private-vilkaar_datafordeleren_pr_20260616-eng-.pdf",
      "sections": [
        "3 Authorisation and access control",
        "5 Client control of authorisations and queries"
      ],
      "control_summary": [
        "User profile and client certificate are controlled by the client security officer.",
        "All system-to-system searches are attributed to individual employee IDs in the client system.",
        "Monthly transaction statistics are produced and checked.",
        "All searches and queries are recorded in the Data Distributor Logpoint solution with user, transaction type, date/time and query target.",
        "Security users can generate reports for selected or all searches and transaction statistics.",
        "Ongoing control is required at least quarterly, with similar monthly statistics and controls for system-to-system access.",
        "Data Distributor access is IP-whitelisted."
      ]
    }
  ],
  "editorial_consequence": "Once the breached product is identified, the corresponding mandatory or contractual audit trail can be requested and compared with the incident timeline. These documents do not identify the breached product or prove which control failed.",
  "accountability_focus": [
    "Private system-to-system terms say monthly transaction statistics are used in cases of suspected abuse and must be checked by the security officer.",
    "Private CPRWeb terms say all queries are logged with user ID, date/time and query target and form the basis of a report in suspected-abuse cases.",
    "Datafordeler terms say all searches and queries are recorded in Logpoint, security users can report selected or all searches, periodic controls are required, and system-to-system use requires similar monthly statistics.",
    "CPR private pricing creates usage counters across several products, including REST transactions that return zero persons and GraphQL returned person objects.",
    "The CPR product used during the breach remains undisclosed, so the applicable audit trail cannot yet be selected with certainty."
  ],
  "restoration_question": {
    "fact": "CPR published that private companies’ access was restored at 11:57 on 5 October 2026.",
    "question": "Which monitoring, rate, suspension, credential, product-specific or approval controls were changed and validated before restoration?"
  }
}
