Welcome to The Calibre Brief, a Calibre Code USA production. A national identity register can remain unbreached while millions of records escape. The harder question is where security ends when access is lawful. On Friday evening, October 2, a CPR administration employee in Denmark noticed an unusual pattern: a huge number of automated lookups. The channel itself was authorized. Within days, officials said data linked to roughly 8.8 million people had been accessed during September. Names, addresses, and CPR numbers had left a register that nobody had hacked. That channel is the operating model. A state keeps the record, while verification agents receive permission to check it. Every check extracts data. In Nigeria, a reopened service saw identity lookups sold for ₦100. One resale site drew an estimated 567,990 visits in a month. Repeated queries formed a partial copy no regulator saw whole. These systems are not inherently unsafe. Denmark caught the misuse within days; Nigeria’s channel ran for months. That difference points to oversight, not simply cryptography. Yet Denmark leaves a sharp unresolved boundary: official guidance says private parties never receive CPR numbers, but CPR numbers were accessed. The route and actors remain unknown. Nigerian staff links were reported, not proven. The vault held. The consequence is institutional. A register can have strong controls and still be exposed by the people licensed to query it. The safer direction is governance: return only what a transaction needs, make every query attributable, audit it independently, and place the cost of misuse on the accessor. The real perimeter is the access ecosystem. The lesson is not that lawful access must disappear. It is that permission without visibility turns a protected vault into a system whose weakest licensed doorway defines its security. This is The Calibre Brief from Calibre Code USA. Who should pay when licensed access leaks population data: the accessor, the state, or the regulator? Comment, like and subscribe on YouTube, and follow the podcast.