🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
NO · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 19 sources retrieved model claude-sonnet-5 ·

Norway

NO schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 37 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.

Primary frameworkGDPR (EEA-incorporated) implemented via the Norwegian Personal Data Act (Act of 15 June 2018 no. 38)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenFully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.

Sub-modules (5)

Regulator And AuthorityGreen

Datatilsynet is Norway's data protection authority and enforces the GDPR/Personal Data Act.

Claims: CLM-NO-a1b2c3d4

Act And InstrumentsGreen

GDPR incorporated into the EEA Agreement (Annex XI) and applicable in Norway since 20 July 2018; implemented domestically via the Personal Data Act.

Claims: CLM-NO-b2c3d4e5, CLM-NO-c3d4e5f6

Material ScopeGreen

Material scope follows GDPR Art 2/4 definitions of personal data and processing; confirmed in Datatilsynet enforcement practice (e.g. cookie IDs held to be personal data).

Claims: CLM-NO-d4e5f6a7

Territorial ScopeGreen

Section 4 of the Personal Data Act extends application to non-EEA-established controllers offering goods/services to, or monitoring the behaviour of, data subjects in Norway, mirroring GDPR Art 3(2).

Claims: CLM-NO-e5f6a7b8

Regulator Registration And FilingAmber

No general prior-notification/registration regime exists post-GDPR; obligations are accountability-based (ROPA, DPO designation) rather than filing-based.

Absence provenance: not recorded. Searched: Datatilsynet registration filing requirements Norway.

Category narrative52 words

Norway is not an EU Member State but implements the GDPR in full via the EEA Agreement. Datatilsynet is the competent supervisory authority. The Personal Data Act (Act of 15 June 2018 no. 38) is the national implementing statute, and territorial scope mirrors GDPR Art 3(2) via Section 4 of that Act.

Sources and claims (5)
  1. ConfirmedDatatilsynetDatatilsynet is Norway's national supervisory authority responsible for upholding data protection acts and regulations, with the Personal Data Act as its main governing legislation.
  2. ConfirmedDatatilsynetAlthough not an EU member, Norway is a member of the EEA; the GDPR was incorporated into the EEA Agreement and became applicable in Norway on 20 July 2018, binding Norway in the same manner as EU Member States.
  3. ConfirmedDatatilsynet / EDPBThe GDPR is implemented as Norwegian law through the Act of 15 June 2018 no. 38 concerning the processing of personal data (the Personal Data Act).
  4. ConfirmedDatatilsynetDatatilsynet has held that a cookie ID assigned to a user fulfils the criteria of Article 4(1) GDPR and constitutes personal data, bringing tracking/analysis/sharing of such data within GDPR material scope.
  5. ConfirmedDatatilsynetPursuant to Section 4 of the Personal Data Act, the Act applies to processing of personal data of data subjects in Norway by controllers not established in the EEA where the processing relates to offering goods/services to, or monitoring the behaviour of, such data subjects.

#

Direct GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.

Primary frameworkGDPR Arts 6-9 as incorporated into the EEA Agreement / Personal Data Act
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenDirect GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.

Sub-modules (4)

Lawful BasesGreen

Datatilsynet's Meta decision applies the cumulative three-condition test under Art 6(1)(f) and analyses Art 6(1)(b) contractual necessity for behavioural advertising.

Claims: CLM-NO-f6a7b8c9

Special CategoriesGreen

Special category data (biometric, health etc.) is governed by GDPR Art 9 as in other EEA states; processing is prohibited absent explicit consent or another Art 9(2) condition.

Claims: CLM-NO-b8c9d0e1

Pseudonymisation And AnonymisationAmber

No Norway-specific pseudonymisation/anonymisation safe-harbour beyond GDPR Art 4(5)/Recital 26 was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Datatilsynet pseudonymisation anonymisation guidance.

Category narrative43 words

Norway applies GDPR Arts 6-9 directly (via EEA incorporation) with no material derogation identified in the sources reviewed. Datatilsynet enforcement (Meta, SATS) confirms orthodox application of the Art 6(1) lawful-basis test, and Norwegian Consumer Authority guidance separately governs consent quality for digital-service contracts.

Sources and claims (3)
  1. ConfirmedDatatilsynetIn its Meta decision, Datatilsynet applied Article 6(1)(f) GDPR's three cumulative conditions to assess the lawfulness of processing personal data for behavioural advertising targeting.
  2. ConfirmedDatatilsynetNorwegian guidance requires that processing consent be a free and informed choice, kept separate from acceptance of terms and conditions, without pre-checked boxes or bundled non-granular consent.
  3. ProbableDatatilsynetProcessing of special category data such as biometric identifiers is governed by Article 9 GDPR and is generally prohibited unless explicit consent is obtained or another Article 9(2) condition applies, as directly applicable EEA law in Norway.

#

Multiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).

Primary frameworkGDPR Arts 12-22 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenMultiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).

Sub-modules (5)

Access RightGreen

SATS decision addressed the right of access under Art 15/EDPB Guidelines 01/2022, including the controller's duty to demonstrate a documented response.

Claims: CLM-NO-c9d0e1f2

Rectification And ErasureGreen

Datatilsynet found SATS in breach of the storage-limitation principle (Art 5(1)(e)) for retaining personal data beyond what was necessary, engaging the right to erasure.

Claims: CLM-NO-d0e1f2a3

Restriction And ObjectionGreen

In the Meta case, Datatilsynet found additional violations of Article 21 GDPR (right to object), treating the right as unconditional regardless of the legal basis relied upon.

Claims: CLM-NO-e1f2a3b4

Data PortabilityAmber

No Norway-specific portability enforcement action was identified in this research pass; GDPR Art 20 applies directly.

Absence provenance: not recorded. Searched: Datatilsynet data portability decision.

Deadlines And Response WindowsGreen

Standard GDPR one-month response deadline (extendable to three months for complex requests) applies as directly incorporated EEA law; SATS case turned partly on documentation of timely responses.

Claims: CLM-NO-f2a3b4c5

Category narrative32 words

GDPR Arts 12-22 apply directly in Norway. Enforcement decisions (SATS, Meta) demonstrate active supervision of access, erasure, and objection rights, with the right to object to profiling for marketing treated as unconditional.

Sources and claims (4)
  1. ConfirmedDatatilsynetDatatilsynet's decision in SATS ASA relied on EDPB Guidelines 01/2022 on the right of access to assess whether the controller adequately facilitated data subjects' exercise of their access rights under Article 12(2) and 15 GDPR.
  2. ConfirmedDatatilsynetDatatilsynet found that retaining personal data of a fitness-centre member for longer than necessary, or beyond the purpose of the retention, violates the storage limitation principle in Article 5(1)(e) GDPR and engages the right of erasure.
  3. ConfirmedDatatilsynetDatatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.
  4. ProbableDatatilsynetNorway is bound by the GDPR's statutory response deadlines for controller responses to data subject requests in the same manner as EU Member States.

#

Strong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.

Primary frameworkGDPR Arts 5, 24-39 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenStrong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.

Sub-modules (7)

Accountability And DpiaGreen

Datatilsynet maintains a published list of processing activities that always require a DPIA, based on Art 29 WP/EDPB guidelines.

Claims: CLM-NO-a3b4c5d6

Dpo RequirementsGreen

In its Telenor ASA decision, Datatilsynet examined DPO designation obligations under Art 37 GDPR, including establishment and cross-border processing analysis.

Claims: CLM-NO-b4c5d6e7

Ropa RequirementsGreen

Datatilsynet ordered Telenor ASA to revise its record of processing activities under Art 30 GDPR and implement organisational measures to keep it current.

Claims: CLM-NO-c5d6e7f8

Joint Controller ArrangementsAmber

Datatilsynet's Disqus decision analysed controllership criteria under Art 4(7) for third-party widget/tracking arrangements, relevant to joint/separate controller determinations.

Claims: CLM-NO-d6e7f8a9

Security MeasuresGreen

Datatilsynet fined the Norwegian Parliament (Storting) EUR 200,000 for failing to implement suitable technical and organisational security measures, including lack of two-factor authentication.

Claims: CLM-NO-e7f8a9b0

Breach NotificationGreen

The Storting case arose from a 2020 data breach involving unauthorised logins to email accounts, triggering Datatilsynet's security-of-processing enforcement under Art 32.

Claims: CLM-NO-f8a9b0c1

Retention And DisposalGreen

SATS was found to have retained personal data (e.g. training logs, correspondence) beyond the necessary retention period, in breach of the storage limitation principle.

Claims: CLM-NO-a9b0c1d2

Category narrative37 words

Datatilsynet actively enforces accountability obligations: it maintains a mandatory DPIA trigger-list, has issued binding decisions on DPO independence/designation (Telenor), on ROPA completeness (Telenor), and has fined controllers heavily for inadequate security measures (Storting) and unlawful retention (SATS).

Sources and claims (7)
  1. ConfirmedDatatilsynetDatatilsynet has made a list of processing activities considered likely to result in high risk to data subjects, which always require a Data Protection Impact Assessment before processing begins.
  2. ConfirmedDatatilsynetDatatilsynet's decision on Telenor ASA analysed whether the company's establishment and cross-border processing triggered the obligation to designate a data protection officer under Article 37 GDPR.
  3. ConfirmedDatatilsynetDatatilsynet ordered Telenor ASA to revise its record of processing activities under Article 30 GDPR and implement organisational measures ensuring the record remains continuously updated.
  4. ConfirmedDatatilsynetDatatilsynet found that a third-party widget provider (Disqus) can qualify as a data controller under Article 4(7) GDPR for processing occurring through its presence on client websites, when it determines the means and purposes of such processing.
  5. ConfirmedEDPBDatatilsynet imposed a EUR 200,000 (NOK 2 million) fine on the Norwegian Parliament for failing to implement suitable technical and organisational security measures, including two-factor authentication, following a 2020 data breach.
  6. ConfirmedEDPBThe Storting breach involved unauthorised logins to email accounts of parliamentary representatives and staff, with Datatilsynet emphasising the failure to implement effective security measures as the core violation.
  7. ConfirmedDatatilsynetDatatilsynet found that retaining personal data such as training logs and correspondence for longer than the duration of a membership ban violates the storage limitation principle set out in Article 5(1)(e) GDPR.

#

EEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.

Primary frameworkGDPR Arts 44-49 as extended via the EEA Agreement
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenEEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.

Sub-modules (6)

Transfer MechanismsGreen

Norway relies on the GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) as extended by the EEA Agreement.

Claims: CLM-NO-b0c1d2e3

Adequacy ReceivedAmber

No specific evidence located of a third-country adequacy decision naming Norway as recipient distinct from the EU; Norway follows Commission adequacy decisions directly.

Absence provenance: not recorded. Searched: Norway adequacy decision received third country.

Adequacy GrantedGreen

Norway does not independently grant adequacy; it applies EU Commission adequacy decisions (e.g. to the US under the EU-US DPF) by virtue of EEA incorporation.

Claims: CLM-NO-c1d2e3f4

Sccs And BcrsGreen

The European Commission's 2021 SCC modules (Implementing Decision 2021/914) extend to the EEA, including Norway, and intra-EEA disclosures are not treated as onward transfers under the Clauses.

Claims: CLM-NO-d2e3f4a5

Transfer Impact AssessmentAmber

No Norway-specific TIA methodology beyond the EDPB/Schrems II-derived approach applied across the EEA was identified.

Absence provenance: not recorded. Searched: Datatilsynet transfer impact assessment guidance.

Data LocalisationGreen

No general data localisation mandate under the Personal Data Act/GDPR was identified for Norway.

Absence provenance: not recorded. Searched: Norway data localisation requirement personal data.

Category narrative50 words

As an EEA state, Norway relies on the same transfer toolkit as EU Member States: EU adequacy decisions (e.g. the EU-US Data Privacy Framework) extend automatically to Norway via the EEA Agreement, and the European Commission's SCC modules (Implementing Decision 2021/914) apply equally. No Norway-specific data localisation mandate was identified.

Sources and claims (3)
  1. ConfirmedEuropean CommissionNorway, as an EEA state, applies the same GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) as EU Member States by virtue of GDPR's incorporation into the EEA Agreement.
  2. ConfirmedEuropean CommissionThe EU-US Data Privacy Framework adequacy decision explicitly extends to the EEA/EFTA states, including Norway, on the basis that GDPR is covered by the EEA Agreement and references to the EU/EU Member States are understood to include the EEA states.
  3. ConfirmedEuropean CommissionBecause Union data protection legislation, including the GDPR, is covered by the EEA Agreement, disclosures by a data importer to a third party located in the EEA (including Norway) do not qualify as an onward transfer under the European Commission's 2021 Standard Contractual Clauses.

#

General GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.

Primary frameworkGDPR (EEA-incorporated); sector-specific overlays not independently confirmed in this pass
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberGeneral GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.

Sub-modules (7)

Financial Sector OverlayAmber

No Norway-specific financial-sector DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway Finanstilsynet data protection overlay GDPR banking.

Health Sector OverlayAmber

No Norway-specific health-sector DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway health data protection helseregisterloven GDPR.

Telecoms And EprivacyAmber

Datatilsynet's Telenor ASA decision engaged with a telecom-sector controller's GDPR compliance (DPO/ROPA), though a distinct ePrivacy-specific Norwegian instrument (Electronic Communications Act) was not independently sourced in this pass.

Claims: CLM-NO-e3f4a5b6

Employment DataAmber

No Norway-specific employment-data DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway employment data protection GDPR overlay.

Credit And ScoringAmber

No Norway-specific credit-scoring DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway credit scoring data protection GDPR.

EducationAmber

No Norway-specific education-sector DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway education sector data protection GDPR.

InsuranceAmber

No Norway-specific insurance-sector DP overlay was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway insurance sector data protection GDPR.

Category narrative63 words

The research pass located limited Norway-specific sectoral overlay evidence beyond the general GDPR framework. Datatilsynet acts as the cross-sectoral regulator; case evidence (Telenor - telecoms; Elkjøp/SATS - retail/consumer) shows GDPR applied without a distinct sectoral carve-out regime being surfaced in this pass. Sector-specific instruments (e.g. Norwegian Electronic Communications Act for ePrivacy, financial-sector AML data-sharing rules) were not independently verified in this research cycle.

Sources and claims (1)
  1. ProbableDatatilsynetDatatilsynet's inspection of Telenor ASA, a telecom-sector controller, examined cross-border processing, establishment, and DPO/ROPA obligations under general GDPR provisions rather than a telecom-specific instrument.

#

Multiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.

Primary frameworkGDPR Arts 5-7, 21 and the Marketing Control Act (markedsføringsloven)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenMultiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.

Sub-modules (6)

Cookies And TrackersGreen

Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations (Arts 6, 12, 13) relating to tracking pixels sharing personal data, including children's data, with third parties without legal basis or notice, as part of a broader six-website investigation.

Claims: CLM-NO-f4a5b6c7, CLM-NO-a5b6c7d8

Dark PatternsGreen

Norwegian guidance (Forbrukerrådet/Consumer Authority material referenced in Datatilsynet consent guidance) treats bundled, non-granular, and pre-checked consent mechanisms as non-compliant, consistent with dark-pattern prohibitions.

Claims: CLM-NO-a7b8c9d0

Opt Out SignalsAmber

No Norway-specific Global Privacy Control/DAA opt-out-signal enforcement was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Datatilsynet Global Privacy Control opt-out signal enforcement.

Clean Rooms And DcrAmber

No Norway-specific clean-room/data-collaboration-room guidance was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Datatilsynet data clean room guidance.

Cross Context AdvertisingGreen

Datatilsynet imposed a temporary ban on Meta's processing of personal data in Norway for targeting ads on the basis of observed behaviour where Meta relied on Art 6(1)(b) or 6(1)(f) GDPR.

Claims: CLM-NO-b6c7d8e9

Direct MarketingGreen

Direct marketing consent and suppression rules sit in the Marketing Control Act, enforced by the Consumer Authority, which can prohibit practices, issue orders, and impose administrative fines; decisions are appealable to the Market Council.

Claims: CLM-NO-c7d8e9f0

Category narrative61 words

Datatilsynet is a highly active regulator of adtech practices: it has fined multiple websites over unlawful tracking-pixel data sharing, imposed a temporary ban on Meta's behavioural advertising processing, and co-led (with the Dutch and Hamburg DPAs) a formal EDPB Article 64(2) request on 'consent or pay' models. The Marketing Control Act (enforced by the Consumer Authority) separately governs direct marketing consent.

Sources and claims (4)
  1. ConfirmedDataGuidanceDatatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on a website that collected children's personal data and sent it to third parties without a valid legal basis or user notification.
  2. ConfirmedEDPBFollowing an inspection of six websites using tracking pixels, Datatilsynet imposed one administrative fine of approximately EUR 22,000 and issued reprimands to the remaining five websites for unlawful sharing of personal data without legal basis and breaches of the duty to inform.
  3. ConfirmedDatatilsynetDatatilsynet imposed a temporary ban on Meta's processing of personal data of data subjects in Norway for targeting ads on the basis of observed behaviour where Meta relied on Article 6(1)(b) or 6(1)(f) GDPR.
  4. ConfirmedDatatilsynetThe Marketing Control Act empowers the Consumer Authority to prohibit direct-marketing practices, issue orders, impose suspended penalties, and in some cases administrative fines, with decisions appealable to the Market Council.

#

Profiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.

Primary frameworkGDPR Arts 9, 21, 22 (EEA-incorporated); EU AI Act EEA-incorporation status unconfirmed
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberProfiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.

Sub-modules (6)

Profiling RestrictionsGreen

Datatilsynet's Meta decision confirms that the Article 21 right to object to profiling for direct marketing purposes is unconditional and irrespective of legal basis.

Claims: CLM-NO-e1f2a3b4

Automated Decision Making TransparencyAmber

No Norway-specific ADM transparency enforcement decision (distinct from general Art 22 GDPR application) was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Datatilsynet automated decision making transparency enforcement.

Ai Risk AssessmentsAmber

Nordic DPAs, including Datatilsynet, jointly discussed AI governance and affirmed that the GDPR will continue to apply alongside the EU AI Act; whether/when the AI Act itself is incorporated into the EEA Agreement for Norway was not confirmed in this pass.

Claims: CLM-NO-d8e9f0a1

Biometric RegimeAmber

Biometric data is treated as special category data under Art 9 GDPR when used for unique identification; no Norway-specific biometric statute distinct from GDPR was identified in this pass.

Absence provenance: not recorded. Searched: Datatilsynet biometric data facial recognition guidance.

Genetic DataAmber

No Norway-specific genetic data regime distinct from GDPR Art 9 was identified in this pass.

Absence provenance: not recorded. Searched: Datatilsynet genetic data regime.

State Surveillance CarveoutsAmber

No Norway-specific state-surveillance/national-security carve-out analysis was identified in this pass.

Absence provenance: not recorded. Searched: Norway national security data protection carve-out GDPR.

Category narrative65 words

Norway applies GDPR's profiling/objection framework (Art 21, treated as unconditional in the Meta decision) and Art 9 special-category rules to biometric data. Nordic DPAs (including Datatilsynet) have discussed AI governance jointly, noting that the GDPR continues to apply alongside the incoming EU AI Act; however, formal EEA incorporation of the AI Act into the EEA Agreement was not confirmed as complete in this research pass.

Sources and claims (1)
  1. ProbableDatatilsynetAt the 2024 Nordic DPA meeting, which Datatilsynet participated in, the Nordic authorities discussed AI governance and noted that while the EU AI Act will address certain aspects of AI, the GDPR will continue to apply.

#

Active enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.

Primary frameworkGDPR Art 8 (EEA-incorporated); proposed Norwegian social-media age-limit legislation (status unconfirmed)
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.

Sub-modules (5)

Age VerificationAmber

The Norwegian Government has announced work toward imposing an age limit for social media/digital services, reported by trade press, but enactment status is unconfirmed in this pass.

Claims: CLM-NO-e9f0a1b2

Minor Profiling BansAmber

No standalone Norwegian minor-profiling ban distinct from GDPR Art 21/22 protections was identified in this pass.

Absence provenance: not recorded. Searched: Norway minor profiling ban data protection.

Education SettingsAmber

No Norway-specific education-settings children's data rule distinct from GDPR was identified in this pass.

Absence provenance: not recorded. Searched: Norway education settings children data protection.

Dependent AdultsAmber

No Norway-specific dependent-adults data protection provision was identified in this pass.

Absence provenance: not recorded. Searched: Norway dependent adults data protection vulnerable groups.

Category narrative76 words

Norway participates in Nordic-level joint DPA principles on children's data in online gaming, and Datatilsynet enforcement has specifically flagged unlawful collection/sharing of children's personal data via tracking pixels. Separately, the Norwegian Government has publicly signalled intent to move forward with statutory social-media age limits, though this reform was not confirmed as enacted at the time of this research pass. A Norway-specific numeric age-of-consent threshold under GDPR Art 8 could not be independently confirmed in this pass.

Sources and claims (2)
  1. UncertainDataGuidanceThe Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.
  2. ConfirmedDatatilsynetThe Nordic Data Protection Authorities, including Datatilsynet, adopted joint principles on children and online gaming during their 2024 Nordic Meeting.

#

Sustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.

Primary frameworkGDPR Arts 58, 77-84, 83-84 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenSustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Datatilsynet exercises GDPR Art 58 investigative/corrective powers, including compliance orders, reprimands and administrative fines, applying the GDPR's effective/proportionate/dissuasive standard.

Claims: CLM-NO-a1b2c3e4, CLM-NO-b2c3d4f5

Enforcement Activity IndexGreen

A clear escalation in fine sizes is observable: from NOK 2m (Storting, 2022) and NOK 10m (SATS, 2023) to NOK 20m (Elkjøp, 2026), alongside multiple smaller tracking-pixel fines in 2025.

Claims: CLM-NO-c3d4e5g6, CLM-NO-d4e5f6g7, CLM-NO-e5f6g7h8

Regulator Funding And CapacityAmber

No specific headcount/budget figures for Datatilsynet were independently confirmed in this pass.

Absence provenance: not recorded. Searched: Datatilsynet budget headcount staff annual report.

Collective Redress And Class ActionsAmber

No Norway-specific collective-redress/class-action mechanism for data protection claims was independently confirmed in this pass.

Absence provenance: not recorded. Searched: Norway collective redress class action data protection.

Private Right Of ActionGreen

Datatilsynet decisions (e.g. Elkjøp) are appealable before the Oslo District Court, evidencing judicial recourse against regulatory decisions.

Claims: CLM-NO-f6g7h8i9

Recent Developments 180DGreen

Within the last 180 days, Datatilsynet imposed a NOK 20 million fine on Elkjøp (2026) for customer-club consent violations, handled as a cross-border case under the one-stop-shop mechanism with Sweden, Iceland, Finland and Denmark as concerned authorities; the Norwegian Government's social-media age-limit initiative also remains an active recent development.

Claims: CLM-NO-c3d4e5g6, CLM-NO-e9f0a1b2

Category narrative52 words

Datatilsynet is a demonstrably active enforcer, with a track record of significant fines (Storting EUR 200k/2022, SATS NOK 10m/2023, Kristiansand NOK 250k/2025, six-website tracking-pixel case ~EUR22k/2025, Elkjøp NOK 20m/2026) and use of the GDPR one-stop-shop cross-border cooperation mechanism. Decisions are appealable to ordinary courts (e.g. Oslo District Court for the Elkjøp decision).

Sources and claims (7)
  1. ConfirmedDatatilsynetDatatilsynet applies the GDPR principle that administrative fines must be effective, proportionate and dissuasive, as articulated in its SATS decision.
  2. ConfirmedDatatilsynetDatatilsynet's fine calculations take into account the turnover of the undertaking to which the controller belongs, as demonstrated in the Elkjøp decision.
  3. ConfirmedDatatilsynetDatatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.
  4. ConfirmedDatatilsynetDatatilsynet upheld a notified fine of NOK 10 million against SATS ASA for multiple GDPR violations concerning the right to information, access and erasure, and lack of legal basis for certain processing.
  5. ConfirmedEDPBDatatilsynet fined the Norwegian Parliament EUR 200,000 (NOK 2 million) for inadequate security measures following a 2020 data breach.
  6. ConfirmedDatatilsynetDatatilsynet's administrative fine decision against Elkjøp may be appealed before the Oslo District Court.
  7. ConfirmedDatatilsynetThe Elkjøp case was handled as a cross-border matter with the data protection authorities of Sweden, Iceland, Finland and Denmark acting as concerned supervisory authorities under the GDPR's cooperation and consistency mechanism.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Norway
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s), 19 source(s) in the cumulative register.