Other Developments
Datatilsynet fined Timegrip AS approximately EUR 23,000 in January 2026 after employees at a retail chain were denied access to their own working-time records, a violation of the GDPR Article 15 access right. In June 2026, Datatilsynet found that six websites had unlawfully shared visitors' personal data with third parties, in several cases involving sensitive information, and imposed an administrative fine of approximately EUR 21,000 in connection with one of those findings. A proposal to raise the age at which children may consent to processing of their personal data for information-society services, from 13 to 15, remained under public consultation as of 24 September 2025, per the Ministry of Justice and Public Security; current status beyond that checkpoint was not confirmed this cycle. Datatilsynet has scheduled an inspection of NAV for autumn 2026, focusing on access management, logging and control to ensure information security.
Cross-Monitor Connections
The adtech-related findings against Elkjøp AS and the six unnamed websites are relevant to the financial-integrity monitor only insofar as they concern data-driven commercial profiling rather than money-laundering typologies, and no direct nexus was identified this cycle. The children's-consent-age proposal may be of interest to the advennt gambling monitor given the interaction between age-verification standards and data protection consent thresholds, though no direct cross-reference was established in the interpreter output this cycle. No world-payments or crypto nexus was identified.
Outlook
Watch for the outcome of Datatilsynet's planned autumn 2026 inspection of NAV, and for confirmation of the children's-consent-age proposal's status beyond the 24 September 2025 consultation checkpoint. The pattern of five enforcement actions across 2025-2026, spanning a finalised landmark appeal, two adtech-related fines, an access-right fine, and a scheduled sectoral inspection, indicates Datatilsynet is applying an active enforcement model, and further actions in this vein should be expected in the near term, particularly given the regulator's stated priority focus on adtech and real-time-bidding-adjacent data sharing.
Standing brief · as of 14 September 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Norway's Datatilsynet has shown an active and escalating enforcement posture over 2025-2026, anchored by the finalisation of the country's landmark GDPR fine: the Borgarting Court of Appeal dismissed Grindr's appeal after an August 2025 hearing, leaving the NOK 65 million administrative fine in place and unappealed further. This finalisation, together with a March 2025 fine of approximately EUR 338,000 against Telenor ASA for inadequate organisation of its data protection officer function and lack of internal control, and a June 2026 sweep in which Datatilsynet found six websites had unlawfully shared visitors' personal data with third parties (resulting in a fine of approximately EUR 21,000 in at least one case), together indicate that GDPR enforcement risk in Norway is comparable to or exceeding that of larger EU member states this cycle. Datatilsynet can impose administrative fines of up to EUR 20 million or four percent of global annual turnover for GDPR violations, and this cycle's enforcement record shows the regulator is prepared to use decisions across a range of magnitudes, from six-figure sums against a major national telecom operator to smaller sums against a cluster of website operators for tracking-related breaches. Datatilsynet's 2026 enforcement record now spans several distinct fact patterns within a twelve-month window: a finalised landmark fine against a global dating platform for consent and data-sharing violations, an organisational-governance fine against a major domestic telecommunications provider, and a sweep-based enforcement action against a cluster of website operators for unlawful third-party data sharing. This breadth, rather than any single decision, is what supports reading Norway's enforcement posture as structurally active rather than reliant on one high-profile case.
Other Developments
Cross-border enforcement architecture is due to tighten further: the EU has adopted Regulation (EU) 2025/2518, laying down additional procedural rules for enforcement of the GDPR in cross-border cases, applicable from April 2027 once incorporated into the EEA framework applicable to Norway. This procedural-harmonisation measure is aimed at addressing known friction points in the EU's existing one-stop-shop mechanism for cross-border GDPR enforcement, under which a lead supervisory authority coordinates enforcement across member states for controllers or processors with cross-border processing activity; once incorporated, it would apply to Datatilsynet's own cross-border cooperation obligations.
Algorithmic and AI governance is advancing toward a concrete domestic instrument: the Norwegian government published a consultation package for a national AI Act (KI-loven) in June 2025, targeting entry into force in summer 2026 aligned with the EU AI Act compliance timeline, with Datatilsynet expected to be the competent authority for AI systems that process personal data. If confirmed, this would represent a significant expansion of Datatilsynet's institutional remit beyond data protection into a broader algorithmic-governance role, mirroring similar competent-authority debates playing out in EU member states.
Children's data protection is also under active reform consideration: the Ministry of Justice and Public Security proposed raising the age at which children may independently consent to processing of personal data for information-society services from 13 to 15 years, with the proposal under public consultation as of 24 September 2025.
Cross-Monitor Connections
Norway's pending national AI Act (KI-loven) is directly relevant to the artificial-intelligence monitor, given its stated alignment with the EU AI Act compliance timeline and Datatilsynet's expected role as competent authority for personal-data-processing AI systems; that monitor is better placed to track the substantive AI-governance content once available. The enforcement and cross-border developments described here have no evidenced connection to the world-payments, financial-integrity, or crypto monitors' coverage of Norway this cycle.
Outlook
The clearest items to watch next cycle are whether Norway's Personal Data Act amendment raising the children's consent age from 13 to 15 has been adopted since the September 2025 consultation closed, and whether the national AI Act (KI-loven) enters into force on its targeted summer-2026 timeline. Continued Datatilsynet enforcement activity, following the pattern established by the Grindr, Telenor and website-tracking-sweep decisions, is a reasonable baseline expectation given the regulator's demonstrated willingness to act across firm sizes and violation types. The Telenor fine's organisational-governance focus -- deficiencies in DPO role structuring and internal control, rather than a specific data breach -- is also worth tracking as a template for how Datatilsynet may approach other large regulated entities' internal compliance architecture in future cycles.