Law / Norway

Norway

privacy

Norway is not an EU member; General Data Protection Regulation (GDPR) reaches Norway through the EEA Agreement, incorporated by Norway's own Personal Data Act (personopplysningsloven, LOV-2018-06-15-38), which is the controlling instrument recorded here rather than the EU Regulation directly.

Read directly from lovdata.no, the Act incorporates the GDPR text in full and adds Chapter 3 supplementary provisions (digital consent age of 13, national identity number processing) and Chapter 7 sanctions provisions under which Datatilsynet imposes administrative fines directly, unlike Denmark's criminal-court route. As at 2026-08-24; later amendment to the Act is not independently confirmed.

13 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Act, Breach Notification in Norway

cite personopplysningsloven LOV-2018-06-15-38, breach notification provisions stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly

General Data Protection Regulation (GDPR) Articles 33-34, incorporated as Norwegian law through the Personal Data Act: a controller must notify Datatilsynet within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to natural persons, and must notify affected individuals without undue delay for a breach likely to result in a high risk. No Norway-specific narrowing was found in the provisions read directly.

What it asks of an app

Comprehensive regime

Personal Data Act (personopplysningsloven)

cite Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38, in force 20 July 2018 stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly

Norway is not an EU member; General Data Protection Regulation (GDPR) reaches Norway through the EEA Agreement, incorporated by Norway's own Personal Data Act (personopplysningsloven), not as directly applicable EU law. Read directly from lovdata.no, the Act's introductory text states the Regulation is thus part of the Personal Data Act and applies as Norwegian law, and the GDPR text is incorporated in full as part of the Act's own published text.

Chapter 3, read directly, sets the digital age of consent for information society services at 13 (Section 5), governs national identity number (fodselsnummer) processing (Section 12), and permits limited public-authority data sharing to combat workplace crime while preserving GDPR Article 9 protection for sensitive data (Section 12a). Datatilsynet is the supervisory authority, institutionally distinct from Denmark's identically named authority.

What it asks of an app

Cross border transfer

Personal Data Act and GDPR Chapter V, Cross-Border Transfer from Norway

cite personopplysningsloven LOV-2018-06-15-38, transfer provisions stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly

Transfers within the EEA, including to EU member states, are unrestricted; the restriction applies to transfers to third countries outside the EEA. General Data Protection Regulation (GDPR) Chapter V, incorporated as Norwegian law through the Act, permits such a transfer only on an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

No Norway-specific provision in Chapter 3 narrowing or broadening this beyond the incorporated GDPR text was found in the provisions read directly.

What it asks of an app

Data subject rights

Personal Data Act, Data Subject Rights in Norway

cite personopplysningsloven LOV-2018-06-15-38, data subject rights provisions stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly

General Data Protection Regulation (GDPR) Articles 15 to 21, incorporated as Norwegian law through the Personal Data Act: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect. No Norway-specific narrowing of these rights was found in the Chapter 3 provisions read directly.

What it asks of an app

Enforcement supervision

Personal Data Act Chapter 7, Datatilsynet Enforcement in Norway

cite personopplysningsloven, enforcement chapter (Chapter 7) stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly, Chapter 7

Unlike Denmark, Norway's Datatilsynet imposes administrative fines directly rather than routing them through the criminal courts.

Chapter 7 of the Act, read directly: Section 26 lets Datatilsynet impose administrative fines under General Data Protection Regulation (GDPR) Article 83; Section 27 gives a four-week compliance deadline from a final fine decision, with court review available; Section 28 sets a five-year limitation period from when the violation ceased; Section 29 lets Datatilsynet impose a daily coercive fine for continued non-compliance; and Section 30 cross-references GDPR Article 82, letting a liable party also be ordered to pay compensation for non-economic harm.

The fetched summary of Section 26 described its fining power in terms of public authorities without fully quoting whether the same or a separate mechanism reaches private controllers; this detail should be re-verified against Section 26's exact Norwegian text before being treated as settled.

What it asks of an app

Sensitive categories

Personal Data Act Chapter 3 and GDPR Article 9, Special Categories in Norway

cite personopplysningsloven, special categories chapter (Chapter 3) stage In effect since 2018-07-20 source Lovdata.no official consolidated-law database, fetched and read directly, Chapter 3

General Data Protection Regulation (GDPR) Article 9(1), incorporated as Norwegian law through the Personal Data Act, classifies biometric data processed for unique identification as a special category. Chapter 3 of the Act, read directly, contains no biometric-specific provision or enumeration; no Norwegian statutory list of biometric examples was found, and none is asserted. An attempted fetch of a Datatilsynet biometrics guidance page returned a 404, so no specific guidance content is recorded here.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.