{
 "jurisdiction_id": "NO",
 "jurisdiction": "Norway",
 "url": "https://dataprotection.gi/jurisdictions/norway/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 37,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.",
   "claims": [
    {
     "statement": "Datatilsynet is Norway's national supervisory authority responsible for upholding data protection acts and regulations, with the Personal Data Act as its main governing legislation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/about-us/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Although not an EU member, Norway is a member of the EEA; the GDPR was incorporated into the EEA Agreement and became applicable in Norway on 20 July 2018, binding Norway in the same manner as EU Member States.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/regulations-and-tools/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR is implemented as Norwegian law through the Act of 15 June 2018 no. 38 concerning the processing of personal data (the Personal Data Act).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=decisions%2Fno_dpia_list_en_gb_20190316.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet has held that a cookie ID assigned to a user fulfils the criteria of Article 4(1) GDPR and constitutes personal data, bringing tracking/analysis/sharing of such data within GDPR material scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/8311c84c085b424d8d5c55dd4c9e2a4a/advance-notification-of-an-administrative-fine--disqus-inc.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Pursuant to Section 4 of the Personal Data Act, the Act applies to processing of personal data of data subjects in Norway by controllers not established in the EEA where the processing relates to offering goods/services to, or monitoring the behaviour of, such data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/8311c84c085b424d8d5c55dd4c9e2a4a/advance-notification-of-an-administrative-fine--disqus-inc.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Direct GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.",
   "claims": [
    {
     "statement": "In its Meta decision, Datatilsynet applied Article 6(1)(f) GDPR's three cumulative conditions to assess the lawfulness of processing personal data for behavioural advertising targeting.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/36ad4a92100943439df9a8a3a7015c19/urgent-and-provisional-measures--meta_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Norwegian guidance requires that processing consent be a free and informed choice, kept separate from acceptance of terms and conditions, without pre-checked boxes or bundled non-granular consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/36ad4a92100943439df9a8a3a7015c19/urgent-and-provisional-measures--meta_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of special category data such as biometric identifiers is governed by Article 9 GDPR and is generally prohibited unless explicit consent is obtained or another Article 9(2) condition applies, as directly applicable EEA law in Norway.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/regulations-and-tools/regulations/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Multiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).",
   "claims": [
    {
     "statement": "Datatilsynet's decision in SATS ASA relied on EDPB Guidelines 01/2022 on the right of access to assess whether the controller adequately facilitated data subjects' exercise of their access rights under Article 12(2) and 15 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/f974410ee2e142c99cfc208cbae7634e/administrative-fine---sats-asa.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet found that retaining personal data of a fitness-centre member for longer than necessary, or beyond the purpose of the retention, violates the storage limitation principle in Article 5(1)(e) GDPR and engages the right of erasure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/f974410ee2e142c99cfc208cbae7634e/administrative-fine---sats-asa.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/36ad4a92100943439df9a8a3a7015c19/urgent-and-provisional-measures--meta_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Norway is bound by the GDPR's statutory response deadlines for controller responses to data subject requests in the same manner as EU Member States.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/regulations-and-tools/regulations/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.",
   "claims": [
    {
     "statement": "Datatilsynet has made a list of processing activities considered likely to result in high risk to data subjects, which always require a Data Protection Impact Assessment before processing begins.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet's decision on Telenor ASA analysed whether the company's establishment and cross-border processing triggered the obligation to designate a data protection officer under Article 37 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/46e5764f637941b6b4d7666984ae0df8/decision---dpo-role-in-telenor-asa_english-translation_redacted_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet ordered Telenor ASA to revise its record of processing activities under Article 30 GDPR and implement organisational measures ensuring the record remains continuously updated.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/46e5764f637941b6b4d7666984ae0df8/decision---dpo-role-in-telenor-asa_english-translation_redacted_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet found that a third-party widget provider (Disqus) can qualify as a data controller under Article 4(7) GDPR for processing occurring through its presence on client websites, when it determines the means and purposes of such processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/8311c84c085b424d8d5c55dd4c9e2a4a/advance-notification-of-an-administrative-fine--disqus-inc.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet imposed a EUR 200,000 (NOK 2 million) fine on the Norwegian Parliament for failing to implement suitable technical and organisational security measures, including two-factor authentication, following a 2020 data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/norwegian-supervisory-authority-issues-fine-norwegian-parliament_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Storting breach involved unauthorised logins to email accounts of parliamentary representatives and staff, with Datatilsynet emphasising the failure to implement effective security measures as the core violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/norwegian-supervisory-authority-issues-fine-norwegian-parliament_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet found that retaining personal data such as training logs and correspondence for longer than the duration of a membership ban violates the storage limitation principle set out in Article 5(1)(e) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/f974410ee2e142c99cfc208cbae7634e/administrative-fine---sats-asa.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "EEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.",
   "claims": [
    {
     "statement": "Norway, as an EEA state, applies the same GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) as EU Member States by virtue of GDPR's incorporation into the EEA Agreement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission",
     "source_url": "https://www.datatilsynet.no/contentassets/b784f930ec7f4691ab7e40a548a447b5/adequacy-decision-eu-us-data-privacy-framework.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU-US Data Privacy Framework adequacy decision explicitly extends to the EEA/EFTA states, including Norway, on the basis that GDPR is covered by the EEA Agreement and references to the EU/EU Member States are understood to include the EEA states.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission",
     "source_url": "https://www.datatilsynet.no/contentassets/b784f930ec7f4691ab7e40a548a447b5/adequacy-decision-eu-us-data-privacy-framework.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Because Union data protection legislation, including the GDPR, is covered by the EEA Agreement, disclosures by a data importer to a third party located in the EEA (including Norway) do not qualify as an onward transfer under the European Commission's 2021 Standard Contractual Clauses.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission",
     "source_url": "https://www.datatilsynet.no/contentassets/b784f930ec7f4691ab7e40a548a447b5/adequacy-decision-eu-us-data-privacy-framework.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "General GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.",
   "claims": [
    {
     "statement": "Datatilsynet's inspection of Telenor ASA, a telecom-sector controller, examined cross-border processing, establishment, and DPO/ROPA obligations under general GDPR provisions rather than a telecom-specific instrument.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/46e5764f637941b6b4d7666984ae0df8/decision---dpo-role-in-telenor-asa_english-translation_redacted_.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "green",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Multiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.",
   "claims": [
    {
     "statement": "Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on a website that collected children's personal data and sent it to third parties without a valid legal basis or user notification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/norway-datatilsynet-fines-company-nok-250000-part",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following an inspection of six websites using tracking pixels, Datatilsynet imposed one administrative fine of approximately EUR 22,000 and issued reprimands to the remaining five websites for unlawful sharing of personal data without legal basis and breaches of the duty to inform.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/norwegian-sa-issues-one-administrative-fine-and-five-reprimands-unlawful_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet imposed a temporary ban on Meta's processing of personal data of data subjects in Norway for targeting ads on the basis of observed behaviour where Meta relied on Article 6(1)(b) or 6(1)(f) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/36ad4a92100943439df9a8a3a7015c19/urgent-and-provisional-measures--meta_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Marketing Control Act empowers the Consumer Authority to prohibit direct-marketing practices, issue orders, impose suspended penalties, and in some cases administrative fines, with decisions appealable to the Market Council.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/contentassets/36ad4a92100943439df9a8a3a7015c19/urgent-and-provisional-measures--meta_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.",
   "claims": [
    {
     "statement": "At the 2024 Nordic DPA meeting, which Datatilsynet participated in, the Nordic authorities discussed AI governance and noted that while the EU AI Act will address certain aspects of AI, the GDPR will continue to apply.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/news-2024/nordic-cooperation-on-childrens-data-protection-in-gaming-ai-and-administrative-fines/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Active enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.",
   "claims": [
    {
     "statement": "The Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/norway-government-announces-need-impose-age-limit",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Nordic Data Protection Authorities, including Datatilsynet, adopted joint principles on children and online gaming during their 2024 Nordic Meeting.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/news-2024/nordic-cooperation-on-childrens-data-protection-in-gaming-ai-and-administrative-fines/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/norway/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Sustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.",
   "claims": [
    {
     "statement": "Datatilsynet applies the GDPR principle that administrative fines must be effective, proportionate and dissuasive, as articulated in its SATS decision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2023/administrative-fine-imposed-on-sats",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet's fine calculations take into account the turnover of the undertaking to which the controller belongs, as demonstrated in the Elkjøp decision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2026/administrative-fine-imposed-on-elkjop",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2026/administrative-fine-imposed-on-elkjop",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet upheld a notified fine of NOK 10 million against SATS ASA for multiple GDPR violations concerning the right to information, access and erasure, and lack of legal basis for certain processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2023/administrative-fine-imposed-on-sats",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet fined the Norwegian Parliament EUR 200,000 (NOK 2 million) for inadequate security measures following a 2020 data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/norwegian-supervisory-authority-issues-fine-norwegian-parliament_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Datatilsynet's administrative fine decision against Elkjøp may be appealed before the Oslo District Court.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2026/administrative-fine-imposed-on-elkjop",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Elkjøp case was handled as a cross-border matter with the data protection authorities of Sweden, Iceland, Finland and Denmark acting as concerned supervisory authorities under the GDPR's cooperation and consistency mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Datatilsynet",
     "source_url": "https://www.datatilsynet.no/en/news/aktuelle-nyheter-2026/administrative-fine-imposed-on-elkjop",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}