EnglishNO
Norway flag

Norway

Norway Data Privacy Laws: GDPR via the EEA, Personal Data Act, and Datatilsynet (2026)

By Recording Law Editorial TeamReviewed May 20, 202625 min read
Norway Data Privacy Laws: GDPR via the EEA, Personal Data Act, and Datatilsynet (2026)

Frequently Asked Questions

Does the GDPR apply in Norway even though Norway is not an EU member?

Yes. Norway is a member of the European Economic Area, and the GDPR was incorporated into the EEA Agreement by a Joint Committee Decision on 6 July 2018. The Norwegian Personal Data Act of 2018 formally implements the GDPR in national law. The result is a framework substantively identical to that of EU member states, enforced by Datatilsynet.

What is the largest GDPR fine in Norwegian history?

The largest fine is NOK 65 million (approximately EUR 5.8 million), imposed on Grindr LLC in December 2021 for sharing users' personal data -- including location data and sexual orientation -- with advertising partners without valid consent. Borgarting Court of Appeal upheld the fine in October 2025, confirming Datatilsynet's authority to impose substantial penalties against international technology companies.

What is the age of digital consent for children in Norway?

The current age is 13 years, set by Section 5 of the Personal Data Act -- the lowest threshold permitted under the GDPR. Children aged 13 and above can provide valid consent for the processing of their personal data for information society services. For younger children, parental or guardian authorization is required. The Norwegian government proposed raising this to 15 in October 2024; that proposal is under public consultation.

Can personal data be transferred freely between Norway and EU countries?

Yes. Norway is part of the EEA, so personal data flows freely between Norway and all EU and EEA member states without additional transfer mechanisms. Transfers outside the EEA require an adequacy decision, standard contractual clauses, binding corporate rules, or another Article 46 safeguard -- the same rules that apply to EU member states.

Do I need a Data Protection Officer in Norway?

A DPO is mandatory if your organization is a public authority, conducts large-scale systematic monitoring of individuals, or processes special categories of personal data on a large scale. Datatilsynet fined Telenor ASA NOK 4 million in March 2025 for DPO governance failures, including lack of documentation, absence of a direct reporting line to management, and conflict of interest concerns.

What is Datatilsynet's AI sandbox?

Datatilsynet operates a regulatory sandbox for artificial intelligence, in which a small group of selected organizations receive free expert guidance on privacy-by-design in AI development. The sandbox has run since 2020 and is in its fifth round as of 2024, focusing on generative AI and large language models. Participating organizations agree to full transparency about their systems; findings are published and inform broader regulatory guidance.

When will the EU AI Act apply in Norway?

Norway is working to incorporate the EU AI Act into the EEA Agreement. The Norwegian government published a consultation package for a national AI Act (KI-loven) in June 2025, with a target entry into force in summer 2026, aligned with the EU's own compliance timeline. Datatilsynet is expected to be the competent authority for AI systems involving personal data processing.

How does Norway handle data breaches?

Controllers must notify Datatilsynet without undue delay and, where feasible, within 72 hours of becoming aware of a breach. Where the breach is likely to cause high risk to individuals, the affected data subjects must also be notified without delay. Processors must notify their controller immediately. All breaches must be documented internally, whether or not they are reported to the authority.

Updates

Expanded to cover 2024-2025 Datatilsynet enforcement, Grindr Court of Appeal ruling, Telenor DPO fine, tracking pixel sweep, NAV NOK 20m fine, proposed age-of-consent increase to 15, Norway AI Act consultation (summer 2026 timeline), Datatilsynet AI sandbox Round 5 generative AI projects, and U.S. transfer guidance.

Sources and References

  1. Datatilsynet - Norwegian Data Protection Authority(datatilsynet.no).gov
  2. Norwegian Personal Data Act (LOV-2018-06-15-38) - Lovdata(lovdata.no).gov
  3. Datatilsynet Regulatory Sandbox for AI(datatilsynet.no).gov
  4. Datatilsynet: Decision on infringement penalty - NAV (2024)(datatilsynet.no).gov
  5. Datatilsynet: Sanctions imposed on Telenor ASA (2025)(datatilsynet.no).gov
  6. Datatilsynet: Court of Appeal upholds fine against Grindr (2025)(datatilsynet.no).gov
  7. Datatilsynet: Tracking pixel enforcement (2025)(datatilsynet.no).gov
  8. European Data Protection Board(edpb.europa.eu).gov
  9. DLA Piper: Data Protection Laws of the World - Norway(dlapiperdataprotection.com)
  10. CMS Expert Guide: Data Protection and Cybersecurity Laws in Norway(cms.law)
  11. CMS GDPR Enforcement Tracker - Norway(cms.law)
  12. DataGuidance: Norway Data Protection Overview(dataguidance.com)
Share: