🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
NO v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-03

Norway

NO schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 37 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
16Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Norway's data protection enforcement posture intensified materially across 2025 and 2026, with Datatilsynet moving through five distinct enforcement actions in a compressed window. The most significant is the finalisation of the Grindr LLC matter: the Borgarting Court of Appeal dismissed Grindr's appeal on 12-14 August 2025, and with no further appeal lodged, the NOK 65 million administrative fine now stands as a concluded landmark GDPR enforcement action for Norway. Alongside that finalisation, Datatilsynet imposed a fine of approximately EUR 1,820,000 on Elkjøp AS in 2026 for processing customer data for marketing, profiling, personalisation and analysis without a valid legal basis, citing GDPR Article 12(3) — the largest fine identified for Norway this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.

Primary frameworkGDPR (EEA-incorporated) implemented via the Norwegian Personal Data Act (Act of 15 June 2018 no. 38)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenFully GDPR-aligned regime with an active, well-resourced supervisory authority and settled national implementing legislation.

Sub-modules (5)

Regulator And AuthorityGreen

Datatilsynet is Norway's data protection authority and enforces the GDPR/Personal Data Act.

Claims (1):

  • Datatilsynet is Norway's national supervisory authority responsible for upholding data protection acts and regulations, with the Personal Data Act as its main governing legislation.

Act And InstrumentsGreen

GDPR incorporated into the EEA Agreement (Annex XI) and applicable in Norway since 20 July 2018; implemented domestically via the Personal Data Act.

Claims (2):

  • Although not an EU member, Norway is a member of the EEA; the GDPR was incorporated into the EEA Agreement and became applicable in Norway on 20 July 2018, binding Norway in the same manner as EU Member States.
  • The GDPR is implemented as Norwegian law through the Act of 15 June 2018 no. 38 concerning the processing of personal data (the Personal Data Act).

Material ScopeGreen

Material scope follows GDPR Art 2/4 definitions of personal data and processing; confirmed in Datatilsynet enforcement practice (e.g. cookie IDs held to be personal data).

Claims (1):

  • Datatilsynet has held that a cookie ID assigned to a user fulfils the criteria of Article 4(1) GDPR and constitutes personal data, bringing tracking/analysis/sharing of such data within GDPR material scope.

Territorial ScopeGreen

Section 4 of the Personal Data Act extends application to non-EEA-established controllers offering goods/services to, or monitoring the behaviour of, data subjects in Norway, mirroring GDPR Art 3(2).

Claims (1):

  • Pursuant to Section 4 of the Personal Data Act, the Act applies to processing of personal data of data subjects in Norway by controllers not established in the EEA where the processing relates to offering goods/services to, or monitoring the behaviour of, such data subjects.

Regulator Registration And FilingAmber

No general prior-notification/registration regime exists post-GDPR; obligations are accountability-based (ROPA, DPO designation) rather than filing-based.

Absence provenance: unavailable. Searched: Datatilsynet registration filing requirements Norway.

Category narrative52 words

Norway is not an EU Member State but implements the GDPR in full via the EEA Agreement. Datatilsynet is the competent supervisory authority. The Personal Data Act (Act of 15 June 2018 no. 38) is the national implementing statute, and territorial scope mirrors GDPR Art 3(2) via Section 4 of that Act.

Sources and claims (5)
  1. ConfirmedDatatilsynet — Datatilsynet is Norway's national supervisory authority responsible for upholding data protection acts and regulations, with the Personal Data Act as its main governing legislation.observed
  2. ConfirmedDatatilsynet — Although not an EU member, Norway is a member of the EEA; the GDPR was incorporated into the EEA Agreement and became applicable in Norway on 20 July 2018, binding Norway in the same manner as EU Member States.observed
  3. ConfirmedDatatilsynet / EDPB — The GDPR is implemented as Norwegian law through the Act of 15 June 2018 no. 38 concerning the processing of personal data (the Personal Data Act).observed
  4. ConfirmedDatatilsynet — Datatilsynet has held that a cookie ID assigned to a user fulfils the criteria of Article 4(1) GDPR and constitutes personal data, bringing tracking/analysis/sharing of such data within GDPR material scope.observed
  5. ConfirmedDatatilsynet — Pursuant to Section 4 of the Personal Data Act, the Act applies to processing of personal data of data subjects in Norway by controllers not established in the EEA where the processing relates to offering goods/services to, or monitoring the behaviour of, such data subjects.observed

#

Direct GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.

Primary frameworkGDPR Arts 6-9 as incorporated into the EEA Agreement / Personal Data Act
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenDirect GDPR application confirmed by multiple Datatilsynet enforcement decisions applying Art 6(1) analysis verbatim.

Sub-modules (4)

Lawful BasesGreen

Datatilsynet's Meta decision applies the cumulative three-condition test under Art 6(1)(f) and analyses Art 6(1)(b) contractual necessity for behavioural advertising.

Claims (1):

  • In its Meta decision, Datatilsynet applied Article 6(1)(f) GDPR's three cumulative conditions to assess the lawfulness of processing personal data for behavioural advertising targeting.

Special CategoriesGreen

Special category data (biometric, health etc.) is governed by GDPR Art 9 as in other EEA states; processing is prohibited absent explicit consent or another Art 9(2) condition.

Claims (1):

  • Processing of special category data such as biometric identifiers is governed by Article 9 GDPR and is generally prohibited unless explicit consent is obtained or another Article 9(2) condition applies, as directly applicable EEA law in Norway.

Pseudonymisation And AnonymisationAmber

No Norway-specific pseudonymisation/anonymisation safe-harbour beyond GDPR Art 4(5)/Recital 26 was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Datatilsynet pseudonymisation anonymisation guidance.

Category narrative34 words

The Elkjøp enforcement decision (2026) reinforces the specific/informed/freely-given consent standard: Datatilsynet found the company's customer-club consent invalid because it bundled multiple distinct processing purposes (newsletters, SMS marketing, profiling, personalisation, analytics) into one non-severable consent.

Sources and claims (3)
  1. ConfirmedDatatilsynet — In its Meta decision, Datatilsynet applied Article 6(1)(f) GDPR's three cumulative conditions to assess the lawfulness of processing personal data for behavioural advertising targeting.observed
  2. ConfirmedDatatilsynet — Norwegian guidance requires that processing consent be a free and informed choice, kept separate from acceptance of terms and conditions, without pre-checked boxes or bundled non-granular consent.observed
  3. ProbableDatatilsynet — Processing of special category data such as biometric identifiers is governed by Article 9 GDPR and is generally prohibited unless explicit consent is obtained or another Article 9(2) condition applies, as directly applicable EEA law in Norway.observed

#

Multiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).

Primary frameworkGDPR Arts 12-22 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenMultiple enforcement actions substantiate operative access, erasure and objection rights with real remedial consequences (fines, compliance orders).

Sub-modules (5)

Access RightGreen

SATS decision addressed the right of access under Art 15/EDPB Guidelines 01/2022, including the controller's duty to demonstrate a documented response.

Claims (1):

  • Datatilsynet's decision in SATS ASA relied on EDPB Guidelines 01/2022 on the right of access to assess whether the controller adequately facilitated data subjects' exercise of their access rights under Article 12(2) and 15 GDPR.

Rectification And ErasureGreen

Datatilsynet found SATS in breach of the storage-limitation principle (Art 5(1)(e)) for retaining personal data beyond what was necessary, engaging the right to erasure.

Claims (1):

  • Datatilsynet found that retaining personal data of a fitness-centre member for longer than necessary, or beyond the purpose of the retention, violates the storage limitation principle in Article 5(1)(e) GDPR and engages the right of erasure.

Restriction And ObjectionGreen

In the Meta case, Datatilsynet found additional violations of Article 21 GDPR (right to object), treating the right as unconditional regardless of the legal basis relied upon.

Claims (1):

  • Datatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.

Data PortabilityAmber

No Norway-specific portability enforcement action was identified in this research pass; GDPR Art 20 applies directly.

Absence provenance: unavailable. Searched: Datatilsynet data portability decision.

Deadlines And Response WindowsGreen

Standard GDPR one-month response deadline (extendable to three months for complex requests) applies as directly incorporated EEA law; SATS case turned partly on documentation of timely responses.

Claims (1):

  • Norway is bound by the GDPR's statutory response deadlines for controller responses to data subject requests in the same manner as EU Member States.
Category narrative32 words

GDPR Arts 12-22 apply directly in Norway. Enforcement decisions (SATS, Meta) demonstrate active supervision of access, erasure, and objection rights, with the right to object to profiling for marketing treated as unconditional.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedDatatilsynet — Datatilsynet's decision in SATS ASA relied on EDPB Guidelines 01/2022 on the right of access to assess whether the controller adequately facilitated data subjects' exercise of their access rights under Article 12(2) and 15 GDPR.observed
  2. ConfirmedDatatilsynet — Datatilsynet found that retaining personal data of a fitness-centre member for longer than necessary, or beyond the purpose of the retention, violates the storage limitation principle in Article 5(1)(e) GDPR and engages the right of erasure.observed
  3. ConfirmedDatatilsynet — Datatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.observed
  4. ProbableDatatilsynet — Norway is bound by the GDPR's statutory response deadlines for controller responses to data subject requests in the same manner as EU Member States.observed

#

Strong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.

Primary frameworkGDPR Arts 5, 24-39 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenStrong evidence of live enforcement across DPIA, DPO, ROPA, security and retention obligations.

Sub-modules (7)

Accountability And DpiaGreen

Datatilsynet maintains a published list of processing activities that always require a DPIA, based on Art 29 WP/EDPB guidelines.

Claims (1):

  • Datatilsynet has made a list of processing activities considered likely to result in high risk to data subjects, which always require a Data Protection Impact Assessment before processing begins.

Dpo RequirementsGreen

In its Telenor ASA decision, Datatilsynet examined DPO designation obligations under Art 37 GDPR, including establishment and cross-border processing analysis.

Claims (1):

  • Datatilsynet's decision on Telenor ASA analysed whether the company's establishment and cross-border processing triggered the obligation to designate a data protection officer under Article 37 GDPR.

Ropa RequirementsGreen

Datatilsynet ordered Telenor ASA to revise its record of processing activities under Art 30 GDPR and implement organisational measures to keep it current.

Claims (1):

  • Datatilsynet ordered Telenor ASA to revise its record of processing activities under Article 30 GDPR and implement organisational measures ensuring the record remains continuously updated.

Joint Controller ArrangementsAmber

Datatilsynet's Disqus decision analysed controllership criteria under Art 4(7) for third-party widget/tracking arrangements, relevant to joint/separate controller determinations.

Claims (1):

  • Datatilsynet found that a third-party widget provider (Disqus) can qualify as a data controller under Article 4(7) GDPR for processing occurring through its presence on client websites, when it determines the means and purposes of such processing.

Security MeasuresGreen

Datatilsynet fined the Norwegian Parliament (Storting) EUR 200,000 for failing to implement suitable technical and organisational security measures, including lack of two-factor authentication.

Claims (1):

  • Datatilsynet imposed a EUR 200,000 (NOK 2 million) fine on the Norwegian Parliament for failing to implement suitable technical and organisational security measures, including two-factor authentication, following a 2020 data breach.

Breach NotificationGreen

The Storting case arose from a 2020 data breach involving unauthorised logins to email accounts, triggering Datatilsynet's security-of-processing enforcement under Art 32.

Claims (1):

  • The Storting breach involved unauthorised logins to email accounts of parliamentary representatives and staff, with Datatilsynet emphasising the failure to implement effective security measures as the core violation.

Retention And DisposalGreen

SATS was found to have retained personal data (e.g. training logs, correspondence) beyond the necessary retention period, in breach of the storage limitation principle.

Claims (1):

  • Datatilsynet found that retaining personal data such as training logs and correspondence for longer than the duration of a membership ban violates the storage limitation principle set out in Article 5(1)(e) GDPR.
Category narrative37 words

Datatilsynet actively enforces accountability obligations: it maintains a mandatory DPIA trigger-list, has issued binding decisions on DPO independence/designation (Telenor), on ROPA completeness (Telenor), and has fined controllers heavily for inadequate security measures (Storting) and unlawful retention (SATS).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedDatatilsynet — Datatilsynet has made a list of processing activities considered likely to result in high risk to data subjects, which always require a Data Protection Impact Assessment before processing begins.observed
  2. ConfirmedDatatilsynet — Datatilsynet's decision on Telenor ASA analysed whether the company's establishment and cross-border processing triggered the obligation to designate a data protection officer under Article 37 GDPR.observed
  3. ConfirmedDatatilsynet — Datatilsynet ordered Telenor ASA to revise its record of processing activities under Article 30 GDPR and implement organisational measures ensuring the record remains continuously updated.observed
  4. ConfirmedDatatilsynet — Datatilsynet found that a third-party widget provider (Disqus) can qualify as a data controller under Article 4(7) GDPR for processing occurring through its presence on client websites, when it determines the means and purposes of such processing.observed
  5. ConfirmedEDPB — Datatilsynet imposed a EUR 200,000 (NOK 2 million) fine on the Norwegian Parliament for failing to implement suitable technical and organisational security measures, including two-factor authentication, following a 2020 data breach.observed
  6. ConfirmedEDPB — The Storting breach involved unauthorised logins to email accounts of parliamentary representatives and staff, with Datatilsynet emphasising the failure to implement effective security measures as the core violation.observed
  7. ConfirmedDatatilsynet — Datatilsynet found that retaining personal data such as training logs and correspondence for longer than the duration of a membership ban violates the storage limitation principle set out in Article 5(1)(e) GDPR.observed

#

EEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.

Primary frameworkGDPR Arts 44-49 as extended via the EEA Agreement
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenEEA incorporation of GDPR Chapter V transfer mechanisms is well documented and directly confirmed by the EU-US DPF adequacy decision text.

Sub-modules (6)

Transfer MechanismsGreen

Norway relies on the GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) as extended by the EEA Agreement.

Claims (1):

  • Norway, as an EEA state, applies the same GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) as EU Member States by virtue of GDPR's incorporation into the EEA Agreement.

Adequacy ReceivedAmber

No specific evidence located of a third-country adequacy decision naming Norway as recipient distinct from the EU; Norway follows Commission adequacy decisions directly.

Absence provenance: unavailable. Searched: Norway adequacy decision received third country.

Adequacy GrantedGreen

Norway does not independently grant adequacy; it applies EU Commission adequacy decisions (e.g. to the US under the EU-US DPF) by virtue of EEA incorporation.

Claims (1):

  • The EU-US Data Privacy Framework adequacy decision explicitly extends to the EEA/EFTA states, including Norway, on the basis that GDPR is covered by the EEA Agreement and references to the EU/EU Member States are understood to include the EEA states.

Sccs And BcrsGreen

The European Commission's 2021 SCC modules (Implementing Decision 2021/914) extend to the EEA, including Norway, and intra-EEA disclosures are not treated as onward transfers under the Clauses.

Claims (1):

  • Because Union data protection legislation, including the GDPR, is covered by the EEA Agreement, disclosures by a data importer to a third party located in the EEA (including Norway) do not qualify as an onward transfer under the European Commission's 2021 Standard Contractual Clauses.

Transfer Impact AssessmentAmber

No Norway-specific TIA methodology beyond the EDPB/Schrems II-derived approach applied across the EEA was identified.

Absence provenance: unavailable. Searched: Datatilsynet transfer impact assessment guidance.

Data LocalisationGreen

No general data localisation mandate under the Personal Data Act/GDPR was identified for Norway.

Absence provenance: unavailable. Searched: Norway data localisation requirement personal data.

Category narrative50 words

As an EEA state, Norway relies on the same transfer toolkit as EU Member States: EU adequacy decisions (e.g. the EU-US Data Privacy Framework) extend automatically to Norway via the EEA Agreement, and the European Commission's SCC modules (Implementing Decision 2021/914) apply equally. No Norway-specific data localisation mandate was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEuropean Commission — Norway, as an EEA state, applies the same GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) as EU Member States by virtue of GDPR's incorporation into the EEA Agreement.observed
  2. ConfirmedEuropean Commission — The EU-US Data Privacy Framework adequacy decision explicitly extends to the EEA/EFTA states, including Norway, on the basis that GDPR is covered by the EEA Agreement and references to the EU/EU Member States are understood to include the EEA states.observed
  3. ConfirmedEuropean Commission — Because Union data protection legislation, including the GDPR, is covered by the EEA Agreement, disclosures by a data importer to a third party located in the EEA (including Norway) do not qualify as an onward transfer under the European Commission's 2021 Standard Contractual Clauses.observed

#

General GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.

Primary frameworkGDPR (EEA-incorporated); sector-specific overlays not independently confirmed in this pass
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberGeneral GDPR framework confirmed but most sectoral sub-modules could not be independently evidenced in this pass; flagged for escalation.

Sub-modules (7)

Financial Sector OverlayAmber

No Norway-specific financial-sector DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway Finanstilsynet data protection overlay GDPR banking.

Health Sector OverlayAmber

No Norway-specific health-sector DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway health data protection helseregisterloven GDPR.

Telecoms And EprivacyAmber

Datatilsynet's Telenor ASA decision engaged with a telecom-sector controller's GDPR compliance (DPO/ROPA), though a distinct ePrivacy-specific Norwegian instrument (Electronic Communications Act) was not independently sourced in this pass.

Claims (1):

  • Datatilsynet's inspection of Telenor ASA, a telecom-sector controller, examined cross-border processing, establishment, and DPO/ROPA obligations under general GDPR provisions rather than a telecom-specific instrument.

Employment DataAmber

No Norway-specific employment-data DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway employment data protection GDPR overlay.

Credit And ScoringAmber

No Norway-specific credit-scoring DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway credit scoring data protection GDPR.

EducationAmber

No Norway-specific education-sector DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway education sector data protection GDPR.

InsuranceAmber

No Norway-specific insurance-sector DP overlay was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway insurance sector data protection GDPR.

Category narrative63 words

The research pass located limited Norway-specific sectoral overlay evidence beyond the general GDPR framework. Datatilsynet acts as the cross-sectoral regulator; case evidence (Telenor - telecoms; Elkjøp/SATS - retail/consumer) shows GDPR applied without a distinct sectoral carve-out regime being surfaced in this pass. Sector-specific instruments (e.g. Norwegian Electronic Communications Act for ePrivacy, financial-sector AML data-sharing rules) were not independently verified in this research cycle.

Sources and claims (1)
  1. ProbableDatatilsynet — Datatilsynet's inspection of Telenor ASA, a telecom-sector controller, examined cross-border processing, establishment, and DPO/ROPA obligations under general GDPR provisions rather than a telecom-specific instrument.observed

#

Multiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.

Primary frameworkGDPR Arts 5-7, 21 and the Marketing Control Act (markedsføringsloven)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenMultiple concrete, recent enforcement actions (tracking pixels, Meta behavioural-advertising ban, consent-or-pay referral) demonstrate an active adtech oversight regime.

Sub-modules (6)

Cookies And TrackersGreen

Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations (Arts 6, 12, 13) relating to tracking pixels sharing personal data, including children's data, with third parties without legal basis or notice, as part of a broader six-website investigation.

Claims (2):

  • Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on a website that collected children's personal data and sent it to third parties without a valid legal basis or user notification.
  • Following an inspection of six websites using tracking pixels, Datatilsynet imposed one administrative fine of approximately EUR 22,000 and issued reprimands to the remaining five websites for unlawful sharing of personal data without legal basis and breaches of the duty to inform.

Dark PatternsGreen

Norwegian guidance (Forbrukerrådet/Consumer Authority material referenced in Datatilsynet consent guidance) treats bundled, non-granular, and pre-checked consent mechanisms as non-compliant, consistent with dark-pattern prohibitions.

Claims (1):

  • Norwegian guidance requires that processing consent be a free and informed choice, kept separate from acceptance of terms and conditions, without pre-checked boxes or bundled non-granular consent.

Opt Out SignalsAmber

No Norway-specific Global Privacy Control/DAA opt-out-signal enforcement was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Datatilsynet Global Privacy Control opt-out signal enforcement.

Clean Rooms And DcrAmber

No Norway-specific clean-room/data-collaboration-room guidance was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Datatilsynet data clean room guidance.

Cross Context AdvertisingGreen

Datatilsynet imposed a temporary ban on Meta's processing of personal data in Norway for targeting ads on the basis of observed behaviour where Meta relied on Art 6(1)(b) or 6(1)(f) GDPR.

Claims (1):

  • Datatilsynet imposed a temporary ban on Meta's processing of personal data of data subjects in Norway for targeting ads on the basis of observed behaviour where Meta relied on Article 6(1)(b) or 6(1)(f) GDPR.

Direct MarketingGreen

Direct marketing consent and suppression rules sit in the Marketing Control Act, enforced by the Consumer Authority, which can prohibit practices, issue orders, and impose administrative fines; decisions are appealable to the Market Council.

Claims (1):

  • The Marketing Control Act empowers the Consumer Authority to prohibit direct-marketing practices, issue orders, impose suspended penalties, and in some cases administrative fines, with decisions appealable to the Market Council.
Category narrative61 words

Datatilsynet is a highly active regulator of adtech practices: it has fined multiple websites over unlawful tracking-pixel data sharing, imposed a temporary ban on Meta's behavioural advertising processing, and co-led (with the Dutch and Hamburg DPAs) a formal EDPB Article 64(2) request on 'consent or pay' models. The Marketing Control Act (enforced by the Consumer Authority) separately governs direct marketing consent.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

Datatilsynet's adtech and commercial-privacy enforcement intensified materially in 2026, with two separate actions surfacing this cycle. In June 2026, Datatilsynet found that six websites had unlawfully shared visitors' personal data with third parties, in several cases involving sensitive information, and imposed an administrative fine of approximately EUR 21,000 in connection with one of those findings. Separately, and more substantially, Datatilsynet imposed a fine of approximately EUR 1,820,000 on Elkjøp AS in 2026 for processing customer data for marketing, profiling, personalisation and analysis without a valid legal basis, with the decision citing GDPR Article 12(3). The Elkjøp fine is the largest identified for Norway this cycle and is directly evidenced via the Enforcement Tracker record.

Both actions are consistent with Datatilsynet's stated national enforcement priority around adtech and real-time-bidding-adjacent data sharing, and together they indicate the regulator is treating unlawful third-party data sharing and unlawful marketing-and-profiling processing as related but distinct enforcement categories: the six-website finding centres on unlawful third-party disclosure, while the Elkjøp fine centres on the absence of a valid legal basis for a range of internal processing purposes spanning marketing, profiling, personalisation and analysis. The scale difference between the two fines, EUR 21,000 against EUR 1.82 million, reflects the difference in scope and severity between an unlawful-disclosure finding and a broad legal-basis failure across multiple processing purposes for a large retail operation.

Outlook

Given Datatilsynet's stated priority focus on adtech and third-party data sharing, further enforcement actions in this category should be expected. Watch for whether other Norwegian retailers or commercial operators face comparable legal-basis scrutiny following the Elkjøp precedent, and for any follow-up guidance from Datatilsynet on lawful bases for marketing, profiling and personalisation processing.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedDataGuidance — Datatilsynet fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on a website that collected children's personal data and sent it to third parties without a valid legal basis or user notification.observed
  2. ConfirmedEDPB — Following an inspection of six websites using tracking pixels, Datatilsynet imposed one administrative fine of approximately EUR 22,000 and issued reprimands to the remaining five websites for unlawful sharing of personal data without legal basis and breaches of the duty to inform.observed
  3. ConfirmedDatatilsynet — Datatilsynet imposed a temporary ban on Meta's processing of personal data of data subjects in Norway for targeting ads on the basis of observed behaviour where Meta relied on Article 6(1)(b) or 6(1)(f) GDPR.observed
  4. ConfirmedDatatilsynet — The Marketing Control Act empowers the Consumer Authority to prohibit direct-marketing practices, issue orders, impose suspended penalties, and in some cases administrative fines, with decisions appealable to the Market Council.observed

#

Profiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.

Primary frameworkGDPR Arts 9, 21, 22 (EEA-incorporated); EU AI Act EEA-incorporation status unconfirmed
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberProfiling/objection rights are well-evidenced; AI Act EEA-incorporation status and Norway-specific biometric/state-surveillance carve-outs are not yet confirmed, warranting an amber rating pending further research.

Sub-modules (6)

Profiling RestrictionsGreen

Datatilsynet's Meta decision confirms that the Article 21 right to object to profiling for direct marketing purposes is unconditional and irrespective of legal basis.

Claims (1):

  • Datatilsynet found additional violations of Article 21 GDPR arising from changes to Meta's processing, and noted that the right to object under GDPR is unconditional and irrespective of the legal basis relied on by the controller.

Automated Decision Making TransparencyAmber

No Norway-specific ADM transparency enforcement decision (distinct from general Art 22 GDPR application) was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Datatilsynet automated decision making transparency enforcement.

Ai Risk AssessmentsAmber

Nordic DPAs, including Datatilsynet, jointly discussed AI governance and affirmed that the GDPR will continue to apply alongside the EU AI Act; whether/when the AI Act itself is incorporated into the EEA Agreement for Norway was not confirmed in this pass.

Claims (1):

  • At the 2024 Nordic DPA meeting, which Datatilsynet participated in, the Nordic authorities discussed AI governance and noted that while the EU AI Act will address certain aspects of AI, the GDPR will continue to apply.

Biometric RegimeAmber

Biometric data is treated as special category data under Art 9 GDPR when used for unique identification; no Norway-specific biometric statute distinct from GDPR was identified in this pass.

Absence provenance: unavailable. Searched: Datatilsynet biometric data facial recognition guidance.

Genetic DataAmber

No Norway-specific genetic data regime distinct from GDPR Art 9 was identified in this pass.

Absence provenance: unavailable. Searched: Datatilsynet genetic data regime.

State Surveillance CarveoutsAmber

No Norway-specific state-surveillance/national-security carve-out analysis was identified in this pass.

Absence provenance: unavailable. Searched: Norway national security data protection carve-out GDPR.

Category narrative65 words

Norway applies GDPR's profiling/objection framework (Art 21, treated as unconditional in the Meta decision) and Art 9 special-category rules to biometric data. Nordic DPAs (including Datatilsynet) have discussed AI governance jointly, noting that the GDPR continues to apply alongside the incoming EU AI Act; however, formal EEA incorporation of the AI Act into the EEA Agreement was not confirmed as complete in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ProbableDatatilsynet — At the 2024 Nordic DPA meeting, which Datatilsynet participated in, the Nordic authorities discussed AI governance and noted that while the EU AI Act will address certain aspects of AI, the GDPR will continue to apply.observed

#

Active enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.

Primary frameworkGDPR Art 8 (EEA-incorporated); proposed Norwegian social-media age-limit legislation (status unconfirmed)
Supervisory authorityDatatilsynet
Traffic-light rationale — AmberActive enforcement and policy attention exist, but the precise statutory age-of-consent threshold and the enactment status of proposed age-limit legislation could not be confirmed from primary sources in this pass.

Sub-modules (5)

Age VerificationAmber

The Norwegian Government has announced work toward imposing an age limit for social media/digital services, reported by trade press, but enactment status is unconfirmed in this pass.

Claims (1):

  • The Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.

Minor Profiling BansAmber

No standalone Norwegian minor-profiling ban distinct from GDPR Art 21/22 protections was identified in this pass.

Absence provenance: unavailable. Searched: Norway minor profiling ban data protection.

Education SettingsAmber

No Norway-specific education-settings children's data rule distinct from GDPR was identified in this pass.

Absence provenance: unavailable. Searched: Norway education settings children data protection.

Dependent AdultsAmber

No Norway-specific dependent-adults data protection provision was identified in this pass.

Absence provenance: unavailable. Searched: Norway dependent adults data protection vulnerable groups.

Category narrative76 words

Norway participates in Nordic-level joint DPA principles on children's data in online gaming, and Datatilsynet enforcement has specifically flagged unlawful collection/sharing of children's personal data via tracking pixels. Separately, the Norwegian Government has publicly signalled intent to move forward with statutory social-media age limits, though this reform was not confirmed as enacted at the time of this research pass. A Norway-specific numeric age-of-consent threshold under GDPR Art 8 could not be independently confirmed in this pass.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

Norway's Ministry of Justice and Public Security has proposed raising the age at which children may consent to the processing of their personal data for information-society services, from 13 to 15 years. As of 24 September 2025, the checkpoint reflected in the available evidence, the proposal remained under public consultation and had not been enacted. This is understood to be a formally-tabled proposal rather than an early-stage policy idea, though its current status beyond the September 2025 consultation checkpoint was not confirmed this cycle, and the finding is accordingly held at a qualified, Probable level of confidence.

If enacted, the change would materially raise the threshold at which Norwegian children can independently consent to data processing by information-society service providers, bringing minors aged 13 and 14 within the scope of parental-consent requirements that currently apply only below age 13. This would be a consequential shift for any online service provider offering information-society services to Norwegian users, since it would expand the population of users requiring parental-consent mechanisms.

Outlook

The principal open question is the proposal's current status: whether it has advanced beyond public consultation, been amended, or been shelved, since the available evidence establishes only the position as of 24 September 2025. Watch for a Ministry announcement of the consultation's conclusion or for draft legislative text moving toward the Storting, either of which would represent the next material step in this proposal's progress.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainDataGuidance — The Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.observed
  2. ConfirmedDatatilsynet — The Nordic Data Protection Authorities, including Datatilsynet, adopted joint principles on children and online gaming during their 2024 Nordic Meeting.observed

#

Sustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.

Primary frameworkGDPR Arts 58, 77-84, 83-84 (EEA-incorporated)
Supervisory authorityDatatilsynet
Traffic-light rationale — GreenSustained, escalating enforcement activity through 2026, including a major NOK 20 million fine, evidences a well-resourced and active regulator.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Datatilsynet exercises GDPR Art 58 investigative/corrective powers, including compliance orders, reprimands and administrative fines, applying the GDPR's effective/proportionate/dissuasive standard.

Claims (2):

  • Datatilsynet applies the GDPR principle that administrative fines must be effective, proportionate and dissuasive, as articulated in its SATS decision.
  • Datatilsynet's fine calculations take into account the turnover of the undertaking to which the controller belongs, as demonstrated in the Elkjøp decision.

Enforcement Activity IndexGreen

A clear escalation in fine sizes is observable: from NOK 2m (Storting, 2022) and NOK 10m (SATS, 2023) to NOK 20m (Elkjøp, 2026), alongside multiple smaller tracking-pixel fines in 2025.

Claims (3):

  • Datatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.
  • Datatilsynet upheld a notified fine of NOK 10 million against SATS ASA for multiple GDPR violations concerning the right to information, access and erasure, and lack of legal basis for certain processing.
  • Datatilsynet fined the Norwegian Parliament EUR 200,000 (NOK 2 million) for inadequate security measures following a 2020 data breach.

Regulator Funding And CapacityAmber

No specific headcount/budget figures for Datatilsynet were independently confirmed in this pass.

Absence provenance: unavailable. Searched: Datatilsynet budget headcount staff annual report.

Collective Redress And Class ActionsAmber

No Norway-specific collective-redress/class-action mechanism for data protection claims was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Norway collective redress class action data protection.

Private Right Of ActionGreen

Datatilsynet decisions (e.g. Elkjøp) are appealable before the Oslo District Court, evidencing judicial recourse against regulatory decisions.

Claims (1):

  • Datatilsynet's administrative fine decision against Elkjøp may be appealed before the Oslo District Court.

Recent Developments 180DGreen

Within the last 180 days, Datatilsynet imposed a NOK 20 million fine on Elkjøp (2026) for customer-club consent violations, handled as a cross-border case under the one-stop-shop mechanism with Sweden, Iceland, Finland and Denmark as concerned authorities; the Norwegian Government's social-media age-limit initiative also remains an active recent development.

Claims (2):

  • Datatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.
  • The Norwegian Government (Regjeringen) has publicly announced the need to impose an age limit relevant to children's use of digital/social media services, with related work reported as moving forward.
Category narrative46 words

Datatilsynet fined Elkjøp NOK 20 million (approx. EUR 1.82M) in 2026 for invalid consent, marketing/profiling failures and data-subject-request delays. The Borgarting Court of Appeal dismissed Grindr LLC's final appeal in August 2025, leaving the NOK 65 million fine (Norway's largest GDPR fine to date) in place.

Periodic update · new data 2026-09-28

Enforcement & Redress

Datatilsynet's enforcement activity across 2025 and 2026 spans five distinct actions, reflecting what the evidence characterises as an active rather than reactive enforcement posture. The most significant is the finalisation of the Grindr LLC matter: the Borgarting Court of Appeal dismissed Grindr's appeal on 12-14 August 2025, and with no further appeal lodged, the NOK 65 million administrative fine imposed on Grindr now stands as a concluded landmark GDPR enforcement action for Norway, closing out a case that had been a defining reference point in Norwegian GDPR enforcement.

Beyond the Grindr finalisation, Datatilsynet imposed a fine of approximately EUR 1,820,000 on Elkjøp AS in 2026 for unlawful marketing, profiling, personalisation and analysis processing, the largest fine identified this cycle, and fined Timegrip AS approximately EUR 23,000 in January 2026 over an access-right violation. In June 2026, Datatilsynet also found that six websites had unlawfully shared visitors' personal data with third parties, imposing a further administrative fine of approximately EUR 21,000 in one instance. Looking forward, Datatilsynet has scheduled an inspection of NAV for autumn 2026, focused on access management, logging and control to ensure information security — a planned rather than completed action, but one that signals continued regulatory attention to a major public-sector data controller.

Taken together, these five actions, spanning a finalised landmark appeal, two adtech-related fines of markedly different scale, an access-right fine, and a scheduled sectoral inspection, support the assessment that Datatilsynet is operating an active enforcement model consistent with its stated adtech and data-sharing priorities, rather than responding only to complaints as they arise.

Outlook

Watch for the outcome of the NAV inspection scheduled for autumn 2026, which would extend Datatilsynet's active enforcement pattern into the public sector specifically. The finalisation of the Grindr matter removes one major point of ongoing legal uncertainty from Norway's enforcement landscape, and its concluded status may free regulatory and industry attention to focus on the newer adtech-related enforcement track established by the Elkjøp and six-website findings.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedDatatilsynet — Datatilsynet applies the GDPR principle that administrative fines must be effective, proportionate and dissuasive, as articulated in its SATS decision.observed
  2. ConfirmedDatatilsynet — Datatilsynet's fine calculations take into account the turnover of the undertaking to which the controller belongs, as demonstrated in the Elkjøp decision.observed
  3. ConfirmedDatatilsynet — Datatilsynet imposed an administrative fine of NOK 20 million on Elkjøp for, among other things, processing personal data in its customer club without valid consent, affecting more than six million customer club members across the Nordic countries.observed
  4. ConfirmedDatatilsynet — Datatilsynet upheld a notified fine of NOK 10 million against SATS ASA for multiple GDPR violations concerning the right to information, access and erasure, and lack of legal basis for certain processing.observed
  5. ConfirmedEDPB — Datatilsynet fined the Norwegian Parliament EUR 200,000 (NOK 2 million) for inadequate security measures following a 2020 data breach.observed
  6. ConfirmedDatatilsynet — Datatilsynet's administrative fine decision against Elkjøp may be appealed before the Oslo District Court.observed
  7. ConfirmedDatatilsynet — The Elkjøp case was handled as a cross-border matter with the data protection authorities of Sweden, Iceland, Finland and Denmark acting as concerned supervisory authorities under the GDPR's cooperation and consistency mechanism.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct84.21
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Norway
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (20 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 15Data Subject Rightsaccess right
Art. 18Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-14Data Subject Rightsaccess right
Art. 16-17Data Subject Rightsrectification and erasure
Art. 19-20Data Subject Rightsdata portability
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

Core modules (regulator_and_framework, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, adtech_and_commercial_privacy, enforcement_and_redress) are grounded in T1 Datatilsynet primary decisions/pages and T2 EDPB national-news mirrors. lawful_processing_and_special_data is grounded in T1 enforcement decisions but the specific Norwegian age-of-consent threshold under Art 8 relied on T3/general sources only and remains unconfirmed. sectoral_watch and several sub-modules of algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely on T3 sources (DataGuidance/IAPP) or carry explicit absent_field_provenance due to no direct primary-source hit in this pass. AI Act EEA-incorporation status for Norway was searched but not confirmed either way.

Unresolved questions (5):

  • What is the exact statutory age-of-consent threshold under Personal Data Act equivalent to GDPR Art 8 for Norway (13 vs another figure)?
  • Has the EU AI Act (Regulation (EU) 2024/1689) been incorporated into the EEA Agreement for Norway, and if so with what timeline/derogations?
  • What is the current status/enactment date of the Norwegian Government's proposed social-media age-limit legislation?
  • Are there Norway-specific sectoral overlays (financial, health, employment, credit-scoring, education, insurance) distinct from baseline GDPR that were not surfaced in this research pass?
  • What are Datatilsynet's current budget and headcount figures for the purposes of regulator_funding_and_capacity?

Escalate to primary-source review: yes