Norway

Comprehensive

Personal Data Act 2018 (implementing GDPR)

Authority: Datatilsynet (Norwegian Data Protection Authority) | Enforcement: Active | Enacted: July 2018

Overview

Norway, as an EEA member, directly implements the GDPR through the Personal Data Act 2018 (Personopplysningsloven). Datatilsynet is one of Europe's most active and influential data protection authorities, known for early and significant enforcement actions including a landmark fine against Grindr. Norway applies the full GDPR framework with some national adaptations for government processing and research.

14-Topic Coverage

Data Protection Authority

Fully Addressed

Datatilsynet is the independent supervisory authority with a strong enforcement record. Known for proactive guidance and early adoption of enforcement measures.

Datatilsynet has been a pioneer in digital privacy enforcement, issuing a landmark NOK 65 million fine against Grindr in 2021 for illegal consent practices. The authority also led early action on the use of Google Analytics and provides extensive sector-specific guidance on AI, cookies, and children's data.

Personal Data Act Chapter 6, GDPR Articles 51-59

Data Subject Rights

Fully Addressed

Full GDPR rights: access, rectification, erasure, restriction, data portability, objection, and automated decision-making rights.

All GDPR data subject rights apply directly. Datatilsynet provides detailed guidance on handling access requests and implements the right to be forgotten within Norwegian context. The Personal Data Act provides specific provisions for processing for archiving, research, and statistics.

GDPR Articles 12-22, Personal Data Act Chapter 3

Cross-Border Transfer

Fully Addressed

GDPR transfer mechanisms: adequacy decisions, SCCs, BCRs, and derogations. Part of the EEA, so free data flow within EEA.

As an EEA member, data flows freely to EU/EEA countries. Datatilsynet has been active post-Schrems II, issuing guidance on supplementary measures and transfer impact assessments. The authority temporarily banned transfers to certain processors using US-based sub-processors.

GDPR Articles 44-49, Personal Data Act Section 2

Breach Notification

Fully Addressed

Must notify Datatilsynet within 72 hours of becoming aware of a breach likely to pose risk. Data subjects must be notified without undue delay if high risk.

Datatilsynet has published detailed breach notification guidance including a risk assessment methodology. The authority receives approximately 2,000-3,000 breach notifications annually. Systematic under-reporting can lead to enforcement action.

GDPR Articles 33-34

DPO Requirements

Fully Addressed

DPO required per GDPR criteria: public authorities, organisations with core activities involving large-scale systematic monitoring, or large-scale processing of special categories.

Datatilsynet provides guidance on when DPO appointment is mandatory. DPOs must be registered with Datatilsynet. The authority maintains a DPO registry. DPO independence requirements are strictly enforced.

GDPR Articles 37-39, Personal Data Act Section 2

Children's Data

Fully Addressed

Norway has set the age of digital consent at 13 (GDPR allows member states to lower from 16). Active guidance from Datatilsynet on children's data in education and gaming.

The Personal Data Act sets 13 as the age for consent to information society services. Datatilsynet has issued specific guidance on children's data in schools, EdTech, gaming, and social media. The authority has investigated TikTok and other platforms regarding children's privacy.

Personal Data Act Section 5, GDPR Article 8

Penalties & Enforcement

Fully Addressed

GDPR fines up to EUR 20 million or 4% of global turnover. Active enforcement with significant fines including NOK 65M against Grindr.

Notable enforcement includes: Grindr (NOK 65M for illegal consent), Municipality of Bergen (NOK 3.7M for school data breach), and multiple decisions on Google Analytics use. Datatilsynet also uses warnings, reprimands, and processing bans as enforcement tools.

GDPR Articles 83-84, Personal Data Act Section 26

Sector-Specific Rules

Fully Addressed

Finanstilsynet (Financial Supervisory Authority) governs financial sector data. Health data regulations under the Health Register Act. Telecom rules under the Electronic Communications Act.

The Health Register Act and Patient Rights Act govern health data processing with specific consent and security requirements. The Electronic Communications Act addresses metadata retention and privacy in telecommunications. Employment data has specific guidance from Datatilsynet.

Health Register Act, Electronic Communications Act, Personal Data Act Chapter 5

AI & Automated Decisions

Fully Addressed

GDPR Article 22 rights apply. Datatilsynet has published comprehensive AI guidance and sandbox programme for responsible AI development.

Datatilsynet operates a regulatory sandbox for AI projects, helping organisations develop privacy-compliant AI. The authority has published detailed guidance on AI and GDPR compliance. Norway's national AI strategy emphasises responsible AI development with privacy as a core principle.

GDPR Article 22, Datatilsynet AI Sandbox

Data Localisation

Not Addressed

No general data localisation requirement. Free flow of data within EEA. GDPR transfer restrictions apply for transfers outside EEA.

GDPR Chapter V

Significant Data Fiduciary

Not Addressed

No equivalent concept beyond GDPR categories. DPO requirements and DPIA obligations apply based on scale and risk of processing.

GDPR Articles 35, 37

Government Data

Fully Addressed

GDPR applies to all government processing. Public Archives Act and Freedom of Information Act supplement with transparency requirements. Specific provisions for police and national security processing.

The Personal Data Act Chapter 4 provides specific rules for processing in the public interest, research, and archiving. The Police Data Act governs law enforcement processing. National security processing has separate provisions with Datatilsynet oversight.

Personal Data Act Chapter 4, Police Data Act, Public Archives Act

Key Statistics

Maximum Penalty
EUR 20 million or 4% of global turnover (GDPR)
Sections in Law
33
Authority
Datatilsynet

Coverage Summary

Fully Addressed12/14
Partially Addressed0/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Norway's regulations.

Book a Consultation