Norway
ComprehensivePersonal Data Act 2018 (implementing GDPR)
Authority: Datatilsynet (Norwegian Data Protection Authority) | Enforcement: Active | Enacted: July 2018
Overview
Norway, as an EEA member, directly implements the GDPR through the Personal Data Act 2018 (Personopplysningsloven). Datatilsynet is one of Europe's most active and influential data protection authorities, known for early and significant enforcement actions including a landmark fine against Grindr. Norway applies the full GDPR framework with some national adaptations for government processing and research.
14-Topic Coverage
Data Protection Authority
Fully AddressedDatatilsynet is the independent supervisory authority with a strong enforcement record. Known for proactive guidance and early adoption of enforcement measures.
Datatilsynet has been a pioneer in digital privacy enforcement, issuing a landmark NOK 65 million fine against Grindr in 2021 for illegal consent practices. The authority also led early action on the use of Google Analytics and provides extensive sector-specific guidance on AI, cookies, and children's data.
Consent Requirements
Fully AddressedGDPR consent requirements apply in full. Must be freely given, specific, informed, and unambiguous. Datatilsynet takes strict position on consent validity.
Norwegian authorities strictly interpret consent, especially for behavioural advertising and location data. The Grindr decision established that bundled consent (consent wall) violates GDPR. Pre-ticked boxes and implied consent are invalid. Legitimate interest is available but interpreted cautiously.
Data Subject Rights
Fully AddressedFull GDPR rights: access, rectification, erasure, restriction, data portability, objection, and automated decision-making rights.
All GDPR data subject rights apply directly. Datatilsynet provides detailed guidance on handling access requests and implements the right to be forgotten within Norwegian context. The Personal Data Act provides specific provisions for processing for archiving, research, and statistics.
Cross-Border Transfer
Fully AddressedGDPR transfer mechanisms: adequacy decisions, SCCs, BCRs, and derogations. Part of the EEA, so free data flow within EEA.
As an EEA member, data flows freely to EU/EEA countries. Datatilsynet has been active post-Schrems II, issuing guidance on supplementary measures and transfer impact assessments. The authority temporarily banned transfers to certain processors using US-based sub-processors.
Breach Notification
Fully AddressedMust notify Datatilsynet within 72 hours of becoming aware of a breach likely to pose risk. Data subjects must be notified without undue delay if high risk.
Datatilsynet has published detailed breach notification guidance including a risk assessment methodology. The authority receives approximately 2,000-3,000 breach notifications annually. Systematic under-reporting can lead to enforcement action.
DPO Requirements
Fully AddressedDPO required per GDPR criteria: public authorities, organisations with core activities involving large-scale systematic monitoring, or large-scale processing of special categories.
Datatilsynet provides guidance on when DPO appointment is mandatory. DPOs must be registered with Datatilsynet. The authority maintains a DPO registry. DPO independence requirements are strictly enforced.
Children's Data
Fully AddressedNorway has set the age of digital consent at 13 (GDPR allows member states to lower from 16). Active guidance from Datatilsynet on children's data in education and gaming.
The Personal Data Act sets 13 as the age for consent to information society services. Datatilsynet has issued specific guidance on children's data in schools, EdTech, gaming, and social media. The authority has investigated TikTok and other platforms regarding children's privacy.
Penalties & Enforcement
Fully AddressedGDPR fines up to EUR 20 million or 4% of global turnover. Active enforcement with significant fines including NOK 65M against Grindr.
Notable enforcement includes: Grindr (NOK 65M for illegal consent), Municipality of Bergen (NOK 3.7M for school data breach), and multiple decisions on Google Analytics use. Datatilsynet also uses warnings, reprimands, and processing bans as enforcement tools.
Sector-Specific Rules
Fully AddressedFinanstilsynet (Financial Supervisory Authority) governs financial sector data. Health data regulations under the Health Register Act. Telecom rules under the Electronic Communications Act.
The Health Register Act and Patient Rights Act govern health data processing with specific consent and security requirements. The Electronic Communications Act addresses metadata retention and privacy in telecommunications. Employment data has specific guidance from Datatilsynet.
Cookie/Tracking
Fully AddressedElectronic Communications Act (Ekomloven) requires prior informed consent for cookies and tracking. Active enforcement by NKOM and Datatilsynet.
Norway implements ePrivacy requirements through the Electronic Communications Act. NKOM (Norwegian Communications Authority) and Datatilsynet jointly oversee cookie compliance. The authorities have been active in challenging consent management platforms that use dark patterns.
AI & Automated Decisions
Fully AddressedGDPR Article 22 rights apply. Datatilsynet has published comprehensive AI guidance and sandbox programme for responsible AI development.
Datatilsynet operates a regulatory sandbox for AI projects, helping organisations develop privacy-compliant AI. The authority has published detailed guidance on AI and GDPR compliance. Norway's national AI strategy emphasises responsible AI development with privacy as a core principle.
Data Localisation
Not AddressedNo general data localisation requirement. Free flow of data within EEA. GDPR transfer restrictions apply for transfers outside EEA.
Significant Data Fiduciary
Not AddressedNo equivalent concept beyond GDPR categories. DPO requirements and DPIA obligations apply based on scale and risk of processing.
Government Data
Fully AddressedGDPR applies to all government processing. Public Archives Act and Freedom of Information Act supplement with transparency requirements. Specific provisions for police and national security processing.
The Personal Data Act Chapter 4 provides specific rules for processing in the public interest, research, and archiving. The Police Data Act governs law enforcement processing. National security processing has separate provisions with Datatilsynet oversight.
Key Statistics
- Maximum Penalty
- EUR 20 million or 4% of global turnover (GDPR)
- Sections in Law
- 33
- Authority
- Datatilsynet
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Norway's regulations.
Book a Consultation