Understanding the Two Types of MitID in a Business Context
MitID has become the central digital identity solution in Denmark, replacing NemID and reshaping how citizens and companies access public and private digital services. For businesses, the crucial distinction is between Personal MitID (Personlig MitID) and Business MitID (MitID Erhverv). While both are based on the same national identity infrastructure, they serve fundamentally different purposes, have different legal implications, and are managed in different ways.
Personal MitID is tied to an individual's CPR number and is first and foremost a private digital identity. That same individual might also act on behalf of a company using their Personal MitID in some limited situations, but the identity remains personal and the legal responsibility usually rests with the individual.
Business MitID, on the other hand, is a structured solution for companies and organizations. It works with roles, rights, and central administration, and is designed to make sure that when someone logs in or signs on behalf of a company, it is clear that the action is corporate rather than private. Choosing the right combination of Personal and Business MitID is critical for legal compliance, security, and smooth daily operations in any Danish company.
What Is Personal MitID – and When Is It Used in Business?
Personal MitID is the digital ID that every Danish resident uses for private matters such as online banking, communication with the authorities through borger.dk, health data, and private contracts. It is based on the person's CPR and is strictly personal. In principle, no one else may use that identity, not even a spouse, colleague, or accountant.
However, in business life, Personal MitID still appears frequently. The owner of a one-person business may log in to certain solutions with their Personal MitID. Board members, directors, and sole proprietors often use their personal identity to access self-service solutions at the Danish Business Authority or SKAT, especially when they are acting in a dual role as both private person and authorized representative.
In these cases, the distinction between private and business action can be blurred, but technically the login still happens with the personal identity first. Some systems then attach a “business context” to that login, for example when you choose which company you act on behalf of, or which CVR number you represent. It remains essential that the person themselves controls and uses their Personal MitID; delegating it to employees or external consultants is not allowed and can carry serious consequences.
What Is Business MitID (MitID Erhverv) – Core Features
Business MitID (MitID Erhverv) is built specifically for legal entities with a CVR number: companies, associations, public institutions, and other organizations. Instead of being directly tied to private data and CPR, Business MitID operates through user and role administration under the company's CVR.
Each user in Business MitID is still a real person with their own private identity in the background, but their business access, roles, and rights are configured centrally by an administrator. This allows the company to decide exactly who may log in to which systems, and who may sign documents or agreements on behalf of the company.
An important characteristic of Business MitID is traceability. Every login and every signature can be connected to a specific user and a specific role within the company. This is invaluable for compliance, auditing, and internal governance. It also makes it much easier to handle employee changes, because access can be deactivated or modified without any intervention in the person's private MitID.
Legal Perspective: Who Is Actually Signing – You or the Company?
From a legal standpoint, the difference between Personal MitID and Business MitID is particularly important when it comes to binding agreements, declarations, and approvals. When someone uses Personal MitID, they sign as themselves, even if the signature concerns a business matter. This is generally acceptable if that person is authorized to represent the company (for example, as a director or owner), but the line of responsibility can be less transparent.
With Business MitID, the signature is clearly connected to the company's digital identity and the user's assigned role. Many public and private systems explicitly require Business MitID when the action “comes from” the company as a legal entity. This ensures that the counterparty can rely on the fact that the signer is acting in a predefined capacity and has been given the relevant rights through the company's access administration.
If a company relies too heavily on Personal MitID for business activities, it may increase the risk of disputes about authorization, mandate, and internal approvals. For example, if a former employee has used their Personal MitID to sign a contract, and their mandate was unclear or undocumented, the company may have difficulty proving what was actually approved internally and by whom.
Security and Risk: Sharing Personal MitID vs Structured Access
Security is another decisive factor when choosing between Business MitID and Personal MitID in a corporate setting. A frequent problem in smaller companies is that owners, managers, or bookkeepers share the same Personal MitID credentials to “make things easier.” This is strictly prohibited and highly risky. If multiple people have access to the same private MitID, it becomes almost impossible to determine who has carried out which actions, and it increases vulnerability to misuse or fraud.
Business MitID is designed to solve this problem by separating roles and logins. Each employee gets their own access based on their tasks. An accountant may get rights to financial portals and accounting systems. A HR employee may receive access to salary reporting services. The IT manager may be made administrator and handle user lifecycles. All of this can be done without ever giving other people access to anyone's Personal MitID.
When you operate with Business MitID, you also gain stronger control in risk situations. If an employee leaves or a consultant's assignment ends, their access can be revoked centrally and immediately. You don't need to depend on them to “stop using” a personal identity, because the business roles and rights are decoupled from their private usage.
Access Management and Internal Controls
Good access management is not only a security issue; it is also an important part of internal controls and corporate governance. In many industries, auditors, banks, and authorities expect that companies can document who has had which access, when it was granted, and why.
Business MitID supports precisely this kind of structured access governance. Administrators can define standard roles, such as “finance,” “payroll,” “management,” or “IT admin,” and assign them to users according to the company's organization. Over time, the company can refine rights as processes evolve, and they can document these decisions as part of their control environment.
If a company instead relies primarily on Personal MitID, they quickly lose that overview. Access is then defined more by personal relationships and informal agreements than by systematic governance. That may work temporarily in a very small business, but it scales poorly and conflicts with basic principles of segregation of duties and traceability.
Typical Use Cases: When Personal MitID Is Enough – and When It Is Not
In some situations, especially in the smallest businesses, a mixture of Personal and Business MitID is common. For example, a self-employed person without employees may use their Personal MitID for a number of business-related self-service tasks, particularly in public systems that allow private login to handle business matters under the same profile.
If the business has no employees, no external users, and very simple processes, it may be practically manageable. Still, as soon as you introduce more people, external bookkeepers, or multiple banks and suppliers, the need for Business MitID grows very quickly.
Think of the following scenarios:
An external accountant needs ongoing access to tax and reporting portals.
Several employees in finance must be able to approve payments or submit reports.
Multiple managers must sign contracts or major agreements on behalf of the company.
The company works with sensitive data and must be able to document access controls.
In all these cases, Business MitID is the natural choice. It enables you to assign users precise rights without sharing personal identities and to manage changes systematically over time.
Onboarding, Offboarding and Daily Administration
The administrative side is often underestimated when companies decide between using private logins and introducing Business MitID. At first glance, it may seem “easier” just to continue with Personal MitID. But over time, onboarding and offboarding employees becomes complex and risky if everything is tied to private identities and informal access.
With Business MitID, there is a clear process. When a new employee joins, the administrator creates or activates a user, assigns the right roles, and ensures that the person can log in to the necessary systems. When the employee leaves, access is deactivated centrally. This reduces the risk that former employees can still access bank accounts, reporting portals, or sensitive business data.
The daily administration may require some discipline and possibly a designated internal MitID administrator, but the payoff is greater security, better governance, and a simpler relationship with auditors, banks, and external partners.
Compliance, Audits and Documentation Requirements
Many Danish companies are subject to increasing documentation requirements from banks, auditors, and authorities. Anti-money laundering rules, data protection regulations, and sector-specific requirements all push towards clear control over who can act on behalf of the company digitally.
Business MitID makes it significantly easier to meet such requirements. The company can document their access structure, log who has signed what, and show that role assignment follows internal policies. For some types of financial services or public digital solutions, the use of Business MitID is even a formal requirement.
If the company is audited, it is far more convincing to present a structured Business MitID setup than to explain that managers and staff “just use their own Personal MitID and coordinate among themselves.” Over time, the latter approach is likely to attract critical comments from auditors and may affect your risk assessment with banks and other partners.
Small vs Large Companies: Does Size Matter for the Choice?
Company size is an important factor when considering whether Business MitID is necessary, but it is not the only one. A micro-business with no employees, simple finances, and low regulatory pressure may manage quite well with a minimal setup in which the owner's Personal MitID plays a central role.
However, as soon as the company grows beyond a handful of people, or operates in a regulated sector such as finance, health, or IT services with sensitive data, Business MitID becomes much more than a “nice-to-have.” It is almost a prerequisite for maintaining control and ensuring that digital processes mirror the company's real responsibilities and roles.
Even start-ups with high growth ambitions should think ahead. Implementing Business MitID early can prevent many problems later, because access structures and responsibilities grow naturally with the organization instead of being patched together after rapid expansion.
Practical Decision Guide: Which MitID Setup Does Your Company Need?
The central question for any Danish company is not whether to use Personal MitID or Business MitID exclusively, but how to combine them correctly. Personal MitID will always exist for every individual employee and owner, but business-related actions should gradually move to Business MitID as the organization becomes more complex.
If your company has only one or two people and very simple processes, you may for a period rely primarily on Personal MitID, especially for systems where that is still supported. But you should already begin planning how Business MitID will be introduced as soon as you hire staff or involve external professionals.
If your company has multiple employees, external advisers, regulated activities, or a need for clear internal controls, Business MitID should be a central element of your digital infrastructure. Each employee should keep their Personal MitID strictly private and use Business MitID when acting in their professional role for the company.
By deliberately choosing Business MitID as the backbone for business access and signatures, and reserving Personal MitID for purely private matters, your company gains better security, clearer responsibilities, and a more robust foundation for growth and compliance in the Danish digital ecosystem.