WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

Norway Privacy & Data Protection Laws

Every regime below can apply to a business handling Norway residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Norway is not an EU member but is in the EEA, and the GDPR applies there in full as Norwegian law through the Personal Data Act, which incorporates Regulation (EU) 2016/679 by reference and adds national provisions on areas the GDPR leaves to member states (employment processing, age of consent — 13 in Norway, freedom of expression). The territorial test is GDPR Article 3, unchanged: established presence in Norway, or offering goods/services to or monitoring the behavior of people in Norway. Enforced by Datatilsynet, not by an EU authority — so a business with EU-only compliance still owes a separate Norwegian supervisory relationship if Norway is its main establishment.

LOV-2018-06-15-38; GDPR incorporated via EEA Joint Committee Decision No. 154/2018Read regulation →

Cross-Border Data Transfer · 1

Norway is inside the EEA, so transfers between Norway and the EU are not restricted transfers at all — the restriction applies to moving data out of the EEA, on the same Chapter V terms as for an EU controller: adequacy, then appropriate safeguards plus a transfer impact assessment, then the narrow Art. 49 derogations. Datatilsynet is the authority that supervises this. Marked 'check' because the entry rests on the EEA incorporation mechanism rather than on a Norwegian-language reading of the Act's own provisions on transfers.

LOV-2018-06-15-38, incorporating Regulation (EU) 2016/679, Arts. 44-49 (EEA Joint Committee Decision No. 154/2018)Read regulation →

Data Security & Breach Notification · 1

Norway applies GDPR Arts. 33-34 as national law through the Personal Data Act, so the substantive test and the 72-hour deadline are identical to the EU's. What differs is who you notify: the Norwegian supervisory authority is Datatilsynet, and a business whose main establishment is in Norway deals with Datatilsynet rather than an EU authority. Marked 'check' because this entry rests on the incorporation mechanism rather than on a Norwegian-language reading of the Act's own breach provisions — confirm the national procedural detail (reporting channel, any sector-specific overlays) with Datatilsynet directly.

LOV-2018-06-15-38, incorporating Regulation (EU) 2016/679, Arts. 33-34 (EEA Joint Committee Decision No. 154/2018)Read regulation →

Other Europe jurisdictions