Law note · Norway
Personal Data Act Chapter 7, Datatilsynet Enforcement in Norway
Unlike Denmark, Norway's Datatilsynet imposes administrative fines directly rather than routing them through the criminal courts.
Chapter 7 of the Act, read directly: Section 26 lets Datatilsynet impose administrative fines under General Data Protection Regulation (GDPR) Article 83; Section 27 gives a four-week compliance deadline from a final fine decision, with court review available; Section 28 sets a five-year limitation period from when the violation ceased; Section 29 lets Datatilsynet impose a daily coercive fine for continued non-compliance; and Section 30 cross-references GDPR Article 82, letting a liable party also be ordered to pay compensation for non-economic harm.
The fetched summary of Section 26 described its fining power in terms of public authorities without fully quoting whether the same or a separate mechanism reaches private controllers; this detail should be re-verified against Section 26's exact Norwegian text before being treated as settled.
What it asks of an app
- Expect Datatilsynet to have direct administrative-fine authority over your processing of personal data of a person in Norway, under Personal Data Act Section 26.
- Expect any person who suffered damage from an infringement, including non-economic harm, to have a right to compensation from you as controller or processor, under Personal Data Act Section 30.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, high_risk_decisions, processes_biometrics, processes_voice
Primary source: Lovdata.no official consolidated-law database, fetched and read directly, Chapter 7