Law note · Norway

Personal Data Act, Breach Notification in Norway

cite personopplysningsloven LOV-2018-06-15-38, breach notification provisions stage In effect since 2018-07-20 reviewed 2026-08-24

General Data Protection Regulation (GDPR) Articles 33-34, incorporated as Norwegian law through the Personal Data Act: a controller must notify Datatilsynet within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to natural persons, and must notify affected individuals without undue delay for a breach likely to result in a high risk. No Norway-specific narrowing was found in the provisions read directly.

What it asks of an app

  • Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice

Primary source: Lovdata.no official consolidated-law database, fetched and read directly

← Back to the example  ·  Lint your app →