Traffic-light rationale — GreenFully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.
Sub-modules (5)
Regulator And AuthorityGreen
Datatilsynet is Norway's data protection authority and enforces the GDPR/Personal Data Act.
Claims: CLM-NO-a1b2c3d4
Act And InstrumentsGreen
GDPR incorporated into the EEA Agreement (Annex XI) and applicable in Norway since 20 July 2018; implemented domestically via the Personal Data Act.
Claims: CLM-NO-b2c3d4e5, CLM-NO-c3d4e5f6
Material ScopeGreen
Material scope follows GDPR Art 2/4 definitions of personal data and processing; confirmed in Datatilsynet enforcement practice (e.g. cookie IDs held to be personal data).
Claims: CLM-NO-d4e5f6a7
Territorial ScopeGreen
Section 4 of the Personal Data Act extends application to non-EEA-established controllers offering goods/services to, or monitoring the behaviour of, data subjects in Norway, mirroring GDPR Art 3(2).
Claims: CLM-NO-e5f6a7b8
Regulator Registration And FilingAmber
No general prior-notification/registration regime exists post-GDPR; obligations are accountability-based (ROPA, DPO designation) rather than filing-based.
Absence provenance: not recorded. Searched: Datatilsynet registration filing requirements Norway.
Category narrative52 words
Norway is not an EU Member State but implements the GDPR in full via the EEA Agreement. Datatilsynet is the competent supervisory authority. The Personal Data Act (Act of 15 June 2018 no. 38) is the national implementing statute, and territorial scope mirrors GDPR Art 3(2) via Section 4 of that Act.
Sources and claims (5)
ConfirmedDatatilsynet — Datatilsynet is Norway's national supervisory authority responsible for upholding data protection acts and regulations, with the Personal Data Act as its main governing legislation.
ConfirmedDatatilsynet — Although not an EU member, Norway is a member of the EEA; the GDPR was incorporated into the EEA Agreement and became applicable in Norway on 20 July 2018, binding Norway in the same manner as EU Member States.
ConfirmedDatatilsynet / EDPB — The GDPR is implemented as Norwegian law through the Act of 15 June 2018 no. 38 concerning the processing of personal data (the Personal Data Act).
ConfirmedDatatilsynet — Datatilsynet has held that a cookie ID assigned to a user fulfils the criteria of Article 4(1) GDPR and constitutes personal data, bringing tracking/analysis/sharing of such data within GDPR material scope.
ConfirmedDatatilsynet — Pursuant to Section 4 of the Personal Data Act, the Act applies to processing of personal data of data subjects in Norway by controllers not established in the EEA where the processing relates to offering goods/services to, or monitoring the behaviour of, such data subjects.
Traffic-light rationale — GreenDirect GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.
Sub-modules (4)
Lawful BasesGreen
Datatilsynet's Meta decision applies the cumulative three-condition test under Art 6(1)(f) and analyses Art 6(1)(b) contractual necessity for behavioural advertising.
Claims: CLM-NO-f6a7b8c9
Consent ThresholdsGreen
Consent must be a free and informed choice, distinguished from contractual acceptance of terms; the Norwegian Consumer Authority and Datatilsynet jointly guide on this standard, and pre-checked boxes/bundled consent are prohibited.
Claims: CLM-NO-a7b8c9d0
Special CategoriesGreen
Special category data (biometric, health etc.) is governed by GDPR Art 9 as in other EEA states; processing is prohibited absent explicit consent or another Art 9(2) condition.
Claims: CLM-NO-b8c9d0e1
Pseudonymisation And AnonymisationAmber
No Norway-specific pseudonymisation/anonymisation safe-harbour beyond GDPR Art 4(5)/Recital 26 was identified in the sources reviewed.
Absence provenance: not recorded. Searched: Datatilsynet pseudonymisation anonymisation guidance.
Category narrative43 words
Norway applies GDPR Arts 6-9 directly (via EEA incorporation) with no material derogation identified in the sources reviewed. Datatilsynet enforcement (Meta, SATS) confirms orthodox application of the Art 6(1) lawful-basis test, and Norwegian Consumer Authority guidance separately governs consent quality for digital-service contracts.
Sources and claims (3)
ConfirmedDatatilsynet — In its Meta decision, Datatilsynet applied Article 6(1)(f) GDPR's three cumulative conditions to assess the lawfulness of processing personal data for behavioural advertising targeting.
ConfirmedDatatilsynet — Norwegian guidance requires that processing consent be a free and informed choice, kept separate from acceptance of terms and conditions, without pre-checked boxes or bundled non-granular consent.
ProbableDatatilsynet — Processing of special category data such as biometric identifiers is governed by Article 9 GDPR and is generally prohibited unless explicit consent is obtained or another Article 9(2) condition applies, as directly applicable EEA law in Norway.
Traffic-light rationale — GreenMultiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).
Sub-modules (5)
Access RightGreen
SATS decision addressed the right of access under Art 15/EDPB Guidelines 01/2022, including the controller's duty to demonstrate a documented response.
Claims: CLM-NO-c9d0e1f2
Rectification And ErasureGreen
Datatilsynet found SATS in breach of the storage-limitation principle (Art 5(1)(e)) for retaining personal data beyond what was necessary, engaging the right to erasure.
Claims: CLM-NO-d0e1f2a3
Restriction And ObjectionGreen
In the Meta case, Datatilsynet found additional violations of Article 21 GDPR (right to object), treating the right as unconditional regardless of the legal basis relied upon.
Claims: CLM-NO-e1f2a3b4
Data PortabilityAmber
No Norway-specific portability enforcement action was identified in this research pass; GDPR Art 20 applies directly.
Absence provenance: not recorded. Searched: Datatilsynet data portability decision.
Deadlines And Response WindowsGreen
Standard GDPR one-month response deadline (extendable to three months for complex requests) applies as directly incorporated EEA law; SATS case turned partly on documentation of timely responses.
Claims: CLM-NO-f2a3b4c5
Category narrative32 words
GDPR Arts 12-22 apply directly in Norway. Enforcement decisions (SATS, Meta) demonstrate active supervision of access, erasure, and objection rights, with the right to object to profiling for marketing treated as unconditional.
Sources and claims (4)
ConfirmedDatatilsynet — Datatilsynet's decision in SATS ASA relied on EDPB Guidelines 01/2022 on the right of access to assess whether the controller adequately facilitated data subjects' exercise of their access rights under Article 12(2) and 15 GDPR.
ConfirmedDatatilsynet — Datatilsynet found that retaining personal data of a fitness-centre member for longer than necessary, or beyond the purpose of the retention, violates the storage limitation principle in Article 5(1)(e) GDPR and engages the right of erasure.
ConfirmedDatatilsynet — Datatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.
ProbableDatatilsynet — Norway is bound by the GDPR's statutory response deadlines for controller responses to data subject requests in the same manner as EU Member States.
Traffic-light rationale — GreenStrong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.
Sub-modules (7)
Accountability And DpiaGreen
Datatilsynet maintains a published list of processing activities that always require a DPIA, based on Art 29 WP/EDPB guidelines.
Claims: CLM-NO-a3b4c5d6
Dpo RequirementsGreen
In its Telenor ASA decision, Datatilsynet examined DPO designation obligations under Art 37 GDPR, including establishment and cross-border processing analysis.
Claims: CLM-NO-b4c5d6e7
Ropa RequirementsGreen
Datatilsynet ordered Telenor ASA to revise its record of processing activities under Art 30 GDPR and implement organisational measures to keep it current.
Claims: CLM-NO-c5d6e7f8
Joint Controller ArrangementsAmber
Datatilsynet's Disqus decision analysed controllership criteria under Art 4(7) for third-party widget/tracking arrangements, relevant to joint/separate controller determinations.
Claims: CLM-NO-d6e7f8a9
Security MeasuresGreen
Datatilsynet fined the Norwegian Parliament (Storting) EUR 200,000 for failing to implement suitable technical and organisational security measures, including lack of two-factor authentication.
Claims: CLM-NO-e7f8a9b0
Breach NotificationGreen
The Storting case arose from a 2020 data breach involving unauthorised logins to email accounts, triggering Datatilsynet's security-of-processing enforcement under Art 32.
Claims: CLM-NO-f8a9b0c1
Retention And DisposalGreen
SATS was found to have retained personal data (e.g. training logs, correspondence) beyond the necessary retention period, in breach of the storage limitation principle.
Claims: CLM-NO-a9b0c1d2
Category narrative37 words
Datatilsynet actively enforces accountability obligations: it maintains a mandatory DPIA trigger-list, has issued binding decisions on DPO independence/designation (Telenor), on ROPA completeness (Telenor), and has fined controllers heavily for inadequate security measures (Storting) and unlawful retention (SATS).
Sources and claims (7)
ConfirmedDatatilsynet — Datatilsynet has made a list of processing activities considered likely to result in high risk to data subjects, which always require a Data Protection Impact Assessment before processing begins.
ConfirmedDatatilsynet — Datatilsynet's decision on Telenor ASA analysed whether the company's establishment and cross-border processing triggered the obligation to designate a data protection officer under Article 37 GDPR.
ConfirmedDatatilsynet — Datatilsynet ordered Telenor ASA to revise its record of processing activities under Article 30 GDPR and implement organisational measures ensuring the record remains continuously updated.
ConfirmedDatatilsynet — Datatilsynet found that a third-party widget provider (Disqus) can qualify as a data controller under Article 4(7) GDPR for processing occurring through its presence on client websites, when it determines the means and purposes of such processing.
ConfirmedEDPB — Datatilsynet imposed a EUR 200,000 (NOK 2 million) fine on the Norwegian Parliament for failing to implement suitable technical and organisational security measures, including two-factor authentication, following a 2020 data breach.
ConfirmedEDPB — The Storting breach involved unauthorised logins to email accounts of parliamentary representatives and staff, with Datatilsynet emphasising the failure to implement effective security measures as the core violation.
ConfirmedDatatilsynet — Datatilsynet found that retaining personal data such as training logs and correspondence for longer than the duration of a membership ban violates the storage limitation principle set out in Article 5(1)(e) GDPR.
Traffic-light rationale — GreenEEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.
Sub-modules (6)
Transfer MechanismsGreen
Norway relies on the GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) as extended by the EEA Agreement.
Claims: CLM-NO-b0c1d2e3
Adequacy ReceivedAmber
No specific evidence located of a third-country adequacy decision naming Norway as recipient distinct from the EU; Norway follows Commission adequacy decisions directly.
Absence provenance: not recorded. Searched: Norway adequacy decision received third country.
Adequacy GrantedGreen
Norway does not independently grant adequacy; it applies EU Commission adequacy decisions (e.g. to the US under the EU-US DPF) by virtue of EEA incorporation.
Claims: CLM-NO-c1d2e3f4
Sccs And BcrsGreen
The European Commission's 2021 SCC modules (Implementing Decision 2021/914) extend to the EEA, including Norway, and intra-EEA disclosures are not treated as onward transfers under the Clauses.
Claims: CLM-NO-d2e3f4a5
Transfer Impact AssessmentAmber
No Norway-specific TIA methodology beyond the EDPB/Schrems II-derived approach applied across the EEA was identified.
Absence provenance: not recorded. Searched: Datatilsynet transfer impact assessment guidance.
Data LocalisationGreen
No general data localisation mandate under the Personal Data Act/GDPR was identified for Norway.
Absence provenance: not recorded. Searched: Norway data localisation requirement personal data.
Category narrative50 words
As an EEA state, Norway relies on the same transfer toolkit as EU Member States: EU adequacy decisions (e.g. the EU-US Data Privacy Framework) extend automatically to Norway via the EEA Agreement, and the European Commission's SCC modules (Implementing Decision 2021/914) apply equally. No Norway-specific data localisation mandate was identified.
Sources and claims (3)
ConfirmedEuropean Commission — Norway, as an EEA state, applies the same GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) as EU Member States by virtue of GDPR's incorporation into the EEA Agreement.
ConfirmedEuropean Commission — The EU-US Data Privacy Framework adequacy decision explicitly extends to the EEA/EFTA states, including Norway, on the basis that GDPR is covered by the EEA Agreement and references to the EU/EU Member States are understood to include the EEA states.
ConfirmedEuropean Commission — Because Union data protection legislation, including the GDPR, is covered by the EEA Agreement, disclosures by a data importer to a third party located in the EEA (including Norway) do not qualify as an onward transfer under the European Commission's 2021 Standard Contractual Clauses.
Traffic-light rationale — AmberGeneral GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.
Sub-modules (7)
Financial Sector OverlayAmber
No Norway-specific financial-sector DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway Finanstilsynet data protection overlay GDPR banking.
Health Sector OverlayAmber
No Norway-specific health-sector DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway health data protection helseregisterloven GDPR.
Telecoms And EprivacyAmber
Datatilsynet's Telenor ASA decision engaged with a telecom-sector controller's GDPR compliance (DPO/ROPA), though a distinct ePrivacy-specific Norwegian instrument (Electronic Communications Act) was not independently sourced in this pass.
Claims: CLM-NO-e3f4a5b6
Employment DataAmber
No Norway-specific employment-data DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway employment data protection GDPR overlay.
Credit And ScoringAmber
No Norway-specific credit-scoring DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway credit scoring data protection GDPR.
EducationAmber
No Norway-specific education-sector DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway education sector data protection GDPR.
InsuranceAmber
No Norway-specific insurance-sector DP overlay was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway insurance sector data protection GDPR.
Category narrative63 words
The research pass located limited Norway-specific sectoral overlay evidence beyond the general GDPR framework. Datatilsynet acts as the cross-sectoral regulator; case evidence (Telenor - telecoms; Elkjøp/SATS - retail/consumer) shows GDPR applied without a distinct sectoral carve-out regime being surfaced in this pass. Sector-specific instruments (e.g. Norwegian Electronic Communications Act for ePrivacy, financial-sector AML data-sharing rules) were not independently verified in this research cycle.
Sources and claims (1)
ProbableDatatilsynet — Datatilsynet's inspection of Telenor ASA, a telecom-sector controller, examined cross-border processing, establishment, and DPO/ROPA obligations under general GDPR provisions rather than a telecom-specific instrument.
Traffic-light rationale — GreenMultiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.
Sub-modules (6)
Cookies And TrackersGreen
Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations (Arts 6, 12, 13) relating to tracking pixels sharing personal data, including children's data, with third parties without legal basis or notice, as part of a broader six-website investigation.
Claims: CLM-NO-f4a5b6c7, CLM-NO-a5b6c7d8
Dark PatternsGreen
Norwegian guidance (Forbrukerrådet/Consumer Authority material referenced in Datatilsynet consent guidance) treats bundled, non-granular, and pre-checked consent mechanisms as non-compliant, consistent with dark-pattern prohibitions.
Claims: CLM-NO-a7b8c9d0
Opt Out SignalsAmber
No Norway-specific Global Privacy Control/DAA opt-out-signal enforcement was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Datatilsynet Global Privacy Control opt-out signal enforcement.
Clean Rooms And DcrAmber
No Norway-specific clean-room/data-collaboration-room guidance was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Datatilsynet data clean room guidance.
Cross Context AdvertisingGreen
Datatilsynet imposed a temporary ban on Meta's processing of personal data in Norway for targeting ads on the basis of observed behaviour where Meta relied on Art 6(1)(b) or 6(1)(f) GDPR.
Claims: CLM-NO-b6c7d8e9
Direct MarketingGreen
Direct marketing consent and suppression rules sit in the Marketing Control Act, enforced by the Consumer Authority, which can prohibit practices, issue orders, and impose administrative fines; decisions are appealable to the Market Council.
Claims: CLM-NO-c7d8e9f0
Category narrative61 words
Datatilsynet is a highly active regulator of adtech practices: it has fined multiple websites over unlawful tracking-pixel data sharing, imposed a temporary ban on Meta's behavioural advertising processing, and co-led (with the Dutch and Hamburg DPAs) a formal EDPB Article 64(2) request on 'consent or pay' models. The Marketing Control Act (enforced by the Consumer Authority) separately governs direct marketing consent.
Sources and claims (4)
ConfirmedDataGuidance — Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on a website that collected children's personal data and sent it to third parties without a valid legal basis or user notification.
ConfirmedEDPB — Following an inspection of six websites using tracking pixels, Datatilsynet imposed one administrative fine of approximately EUR 22,000 and issued reprimands to the remaining five websites for unlawful sharing of personal data without legal basis and breaches of the duty to inform.
ConfirmedDatatilsynet — Datatilsynet imposed a temporary ban on Meta's processing of personal data of data subjects in Norway for targeting ads on the basis of observed behaviour where Meta relied on Article 6(1)(b) or 6(1)(f) GDPR.
ConfirmedDatatilsynet — The Marketing Control Act empowers the Consumer Authority to prohibit direct-marketing practices, issue orders, impose suspended penalties, and in some cases administrative fines, with decisions appealable to the Market Council.
Profiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.
Primary frameworkGDPR Arts 9, 21, 22 (EEA-incorporated); EU AI Act EEA-incorporation status unconfirmed
Traffic-light rationale — AmberProfiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.
Sub-modules (6)
Profiling RestrictionsGreen
Datatilsynet's Meta decision confirms that the Article 21 right to object to profiling for direct marketing purposes is unconditional and irrespective of legal basis.
Claims: CLM-NO-e1f2a3b4
Automated Decision Making TransparencyAmber
No Norway-specific ADM transparency enforcement decision (distinct from general Art 22 GDPR application) was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Datatilsynet automated decision making transparency enforcement.
Ai Risk AssessmentsAmber
Nordic DPAs, including Datatilsynet, jointly discussed AI governance and affirmed that the GDPR will continue to apply alongside the EU AI Act; whether/when the AI Act itself is incorporated into the EEA Agreement for Norway was not confirmed in this pass.
Claims: CLM-NO-d8e9f0a1
Biometric RegimeAmber
Biometric data is treated as special category data under Art 9 GDPR when used for unique identification; no Norway-specific biometric statute distinct from GDPR was identified in this pass.
Absence provenance: not recorded. Searched: Datatilsynet biometric data facial recognition guidance.
Genetic DataAmber
No Norway-specific genetic data regime distinct from GDPR Art 9 was identified in this pass.
Absence provenance: not recorded. Searched: Datatilsynet genetic data regime.
State Surveillance CarveoutsAmber
No Norway-specific state-surveillance/national-security carve-out analysis was identified in this pass.
Absence provenance: not recorded. Searched: Norway national security data protection carve-out GDPR.
Category narrative65 words
Norway applies GDPR's profiling/objection framework (Art 21, treated as unconditional in the Meta decision) and Art 9 special-category rules to biometric data. Nordic DPAs (including Datatilsynet) have discussed AI governance jointly, noting that the GDPR continues to apply alongside the incoming EU AI Act; however, formal EEA incorporation of the AI Act into the EEA Agreement was not confirmed as complete in this research pass.
Sources and claims (1)
ProbableDatatilsynet — At the 2024 Nordic DPA meeting, which Datatilsynet participated in, the Nordic authorities discussed AI governance and noted that while the EU AI Act will address certain aspects of AI, the GDPR will continue to apply.
Active enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.
Traffic-light rationale — AmberActive enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.
Sub-modules (5)
Age VerificationAmber
The Norwegian Government has announced work toward imposing an age limit for social media/digital services, reported by trade press, but enactment status is unconfirmed in this pass.
Claims: CLM-NO-e9f0a1b2
Parental ConsentAmber
A specific Norwegian statutory age-of-consent threshold under GDPR Art 8 (the EU default range is 13-16) could not be independently confirmed from primary Datatilsynet sources in this pass.
Absence provenance: not recorded. Searched: Norway personal data act age 13 information society services consent, Norway GDPR article 8 age consent 13 years digital services children.
Minor Profiling BansAmber
No standalone Norwegian minor-profiling ban distinct from GDPR Art 21/22 protections was identified in this pass.
Absence provenance: not recorded. Searched: Norway minor profiling ban data protection.
Education SettingsAmber
No Norway-specific education-settings children's data rule distinct from GDPR was identified in this pass.
Absence provenance: not recorded. Searched: Norway education settings children data protection.
Dependent AdultsAmber
No Norway-specific dependent-adults data protection provision was identified in this pass.
Absence provenance: not recorded. Searched: Norway dependent adults data protection vulnerable groups.
Category narrative76 words
Norway participates in Nordic-level joint DPA principles on children's data in online gaming, and Datatilsynet enforcement has specifically flagged unlawful collection/sharing of children's personal data via tracking pixels. Separately, the Norwegian Government has publicly signalled intent to move forward with statutory social-media age limits, though this reform was not confirmed as enacted at the time of this research pass. A Norway-specific numeric age-of-consent threshold under GDPR Art 8 could not be independently confirmed in this pass.
Sources and claims (2)
UncertainDataGuidance — The Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.
ConfirmedDatatilsynet — The Nordic Data Protection Authorities, including Datatilsynet, adopted joint principles on children and online gaming during their 2024 Nordic Meeting.
Traffic-light rationale — GreenSustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Datatilsynet exercises GDPR Art 58 investigative/corrective powers, including compliance orders, reprimands and administrative fines, applying the GDPR's effective/proportionate/dissuasive standard.
Claims: CLM-NO-a1b2c3e4, CLM-NO-b2c3d4f5
Enforcement Activity IndexGreen
A clear escalation in fine sizes is observable: from NOK 2m (Storting, 2022) and NOK 10m (SATS, 2023) to NOK 20m (Elkjøp, 2026), alongside multiple smaller tracking-pixel fines in 2025.
No Norway-specific collective-redress/class-action mechanism for data protection claims was independently confirmed in this pass.
Absence provenance: not recorded. Searched: Norway collective redress class action data protection.
Private Right Of ActionGreen
Datatilsynet decisions (e.g. Elkjøp) are appealable before the Oslo District Court, evidencing judicial recourse against regulatory decisions.
Claims: CLM-NO-f6g7h8i9
Recent Developments 180DGreen
Within the last 180 days, Datatilsynet imposed a NOK 20 million fine on Elkjøp (2026) for customer-club consent violations, handled as a cross-border case under the one-stop-shop mechanism with Sweden, Iceland, Finland and Denmark as concerned authorities; the Norwegian Government's social-media age-limit initiative also remains an active recent development.
Claims: CLM-NO-c3d4e5g6, CLM-NO-e9f0a1b2
Category narrative52 words
Datatilsynet is a demonstrably active enforcer, with a track record of significant fines (Storting EUR 200k/2022, SATS NOK 10m/2023, Kristiansand NOK 250k/2025, six-website tracking-pixel case ~EUR22k/2025, Elkjøp NOK 20m/2026) and use of the GDPR one-stop-shop cross-border cooperation mechanism. Decisions are appealable to ordinary courts (e.g. Oslo District Court for the Elkjøp decision).
Sources and claims (7)
ConfirmedDatatilsynet — Datatilsynet applies the GDPR principle that administrative fines must be effective, proportionate and dissuasive, as articulated in its SATS decision.
ConfirmedDatatilsynet — Datatilsynet's fine calculations take into account the turnover of the undertaking to which the controller belongs, as demonstrated in the Elkjøp decision.
ConfirmedDatatilsynet — Datatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.
ConfirmedDatatilsynet — Datatilsynet upheld a notified fine of NOK 10 million against SATS ASA for multiple GDPR violations concerning the right to information, access and erasure, and lack of legal basis for certain processing.
ConfirmedEDPB — Datatilsynet fined the Norwegian Parliament EUR 200,000 (NOK 2 million) for inadequate security measures following a 2020 data breach.
ConfirmedDatatilsynet — Datatilsynet's administrative fine decision against Elkjøp may be appealed before the Oslo District Court.
ConfirmedDatatilsynet — The Elkjøp case was handled as a cross-border matter with the data protection authorities of Sweden, Iceland, Finland and Denmark acting as concerned supervisory authorities under the GDPR's cooperation and consistency mechanism.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Norway
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s), 19 source(s) in the cumulative register.