WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Personal Data Act (personopplysningsloven) — GDPR breach notification as incorporated into Norwegian law

GDPR Arts. 33-34 (Norway)

Norway · July 20, 2018

Verify details

Norway applies GDPR Arts. 33-34 as national law through the Personal Data Act, so the substantive test and the 72-hour deadline are identical to the EU's. What differs is who you notify: the Norwegian supervisory authority is Datatilsynet, and a business whose main establishment is in Norway deals with Datatilsynet rather than an EU authority. Marked 'check' because this entry rests on the incorporation mechanism rather than on a Norwegian-language reading of the Act's own breach provisions — confirm the national procedural detail (reporting channel, any sector-specific overlays) with Datatilsynet directly.

LOV-2018-06-15-38, incorporating Regulation (EU) 2016/679, Arts. 33-34 (EEA Joint Committee Decision No. 154/2018)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.