Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite personopplysningsloven LOV-2018-06-15-38, breach notification provisions
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly
General Data Protection Regulation (GDPR) Articles 33-34, incorporated as Norwegian law through the Personal Data Act: a controller must notify Datatilsynet within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to natural persons, and must notify affected individuals without undue delay for a breach likely to result in a high risk. No Norway-specific narrowing was found in the provisions read directly.
What it asks of an app →
Comprehensive regime
cite Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38, in force 20 July 2018
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly
Norway is not an EU member; General Data Protection Regulation (GDPR) reaches Norway through the EEA Agreement, incorporated by Norway's own Personal Data Act (personopplysningsloven), not as directly applicable EU law. Read directly from lovdata.no, the Act's introductory text states the Regulation is thus part of the Personal Data Act and applies as Norwegian law, and the GDPR text is incorporated in full as part of the Act's own published text.
Chapter 3, read directly, sets the digital age of consent for information society services at 13 (Section 5), governs national identity number (fodselsnummer) processing (Section 12), and permits limited public-authority data sharing to combat workplace crime while preserving GDPR Article 9 protection for sensitive data (Section 12a). Datatilsynet is the supervisory authority, institutionally distinct from Denmark's identically named authority.
What it asks of an app →
Cross border transfer
cite personopplysningsloven LOV-2018-06-15-38, transfer provisions
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly
Transfers within the EEA, including to EU member states, are unrestricted; the restriction applies to transfers to third countries outside the EEA. General Data Protection Regulation (GDPR) Chapter V, incorporated as Norwegian law through the Act, permits such a transfer only on an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.
No Norway-specific provision in Chapter 3 narrowing or broadening this beyond the incorporated GDPR text was found in the provisions read directly.
What it asks of an app →
Data subject rights
cite personopplysningsloven LOV-2018-06-15-38, data subject rights provisions
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly
General Data Protection Regulation (GDPR) Articles 15 to 21, incorporated as Norwegian law through the Personal Data Act: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect. No Norway-specific narrowing of these rights was found in the Chapter 3 provisions read directly.
What it asks of an app →
Enforcement supervision
cite personopplysningsloven, enforcement chapter (Chapter 7)
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly, Chapter 7
Unlike Denmark, Norway's Datatilsynet imposes administrative fines directly rather than routing them through the criminal courts.
Chapter 7 of the Act, read directly: Section 26 lets Datatilsynet impose administrative fines under General Data Protection Regulation (GDPR) Article 83; Section 27 gives a four-week compliance deadline from a final fine decision, with court review available; Section 28 sets a five-year limitation period from when the violation ceased; Section 29 lets Datatilsynet impose a daily coercive fine for continued non-compliance; and Section 30 cross-references GDPR Article 82, letting a liable party also be ordered to pay compensation for non-economic harm.
The fetched summary of Section 26 described its fining power in terms of public authorities without fully quoting whether the same or a separate mechanism reaches private controllers; this detail should be re-verified against Section 26's exact Norwegian text before being treated as settled.
What it asks of an app →
Sensitive categories
cite personopplysningsloven, special categories chapter (Chapter 3)
stage In effect
since 2018-07-20
source Lovdata.no official consolidated-law database, fetched and read directly, Chapter 3
General Data Protection Regulation (GDPR) Article 9(1), incorporated as Norwegian law through the Personal Data Act, classifies biometric data processed for unique identification as a special category. Chapter 3 of the Act, read directly, contains no biometric-specific provision or enumeration; no Norwegian statutory list of biometric examples was found, and none is asserted. An attempted fetch of a Datatilsynet biometrics guidance page returned a 404, so no specific guidance content is recorded here.
What it asks of an app →