Norway
Part of the EEA, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Norway — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Norway follows Europe's privacy rulebook, so personal data can leave once you have the right paperwork. Norway is in the European Economic Area, which is how the European rules apply here. No general rule forces data to stay in Norway. There are two catches. Your accounting records must sit in Europe, Britain or Switzerland unless the tax office agrees otherwise. Public sector archives need the National Archivist's permission to leave.
Data governance in Norway
The eight things that decide how you handle data about people in Norway. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules reach you even if you have no office here. That is true if you offer goods or services to people in Norway, or track what they do online. There is no size or revenue level you can stay under. A company based outside the European Economic Area must name a representative inside that area. That representative is the person the regulator writes to.
- What you have to do here:
- Appoint a representative
Norway applies the European Union's General Data Protection Regulation through the European Economic Area Agreement, not through European Union membership. The national statute is personopplysningsloven of 15 June 2018. It makes the Regulation Norwegian law and adds national detail. Its section 2 covers organisations in Norway that decide how data is used, or that handle data for someone else. It covers their activities wherever the data is actually used. Section 2 also covers data about people who are in Norway, held by organisations outside the European Economic Area. That applies where the data relates to offering them goods or services, or to tracking their behaviour in Norway. The duty to appoint a representative is the Regulation's Article 27 duty. Norway adds no separate registration or licence.
Sources
- Official sourceStortinget (Norwegian Parliament)Vedtak til lov om behandling av personopplysninger (personopplysningsloven), sections 2, 5 and 12 as adopted
stortinget.no
Link checked 18 August 2026
- Official sourceLovdata (official Norwegian law database)Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38
lovdata.no
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
In general, yes. Personal data can leave Norway and even leave Europe once you have the right paperwork. Nothing in Norwegian privacy law says personal data must be stored here. Two rules that apply to almost everyone are the real limits. Your accounting records must stay in a short list of European countries. And a public body's archives cannot leave Norway without permission.
Sector by sector, checked on 18 August 2026. GENERAL PERSONAL DATA. Conditional. The European rulebook applies. It sets conditions for sending data out rather than banning it. Regulation (EU) 2018/1807 also bans rules that force non-personal data to stay in one country, except on public-security grounds. ACCOUNTING AND TAX RECORDS, ALL INDUSTRIES. Conditional, but limited by geography. Since 27 January 2025 you may keep electronic accounting material in the European Economic Area, the United Kingdom and Switzerland without asking anyone. You must notify your tax office, and the records must stay reachable electronically from Norway. Storage anywhere else needs the tax authority's approval. This replaced the older, narrower Nordic-only permission. It also replaced the rule that cash register journals had to physically stay in Norway. PUBLIC SECTOR ARCHIVES. Closed unless permission is given. Archive material held by a public body may not be taken out of the country. The exceptions are where regulations allow it, or where the National Archivist gives specific consent. The National Archivist tells applicants to prefer suppliers inside the European Union or European Economic Area. BANKING, PAYMENTS, INSURANCE, SECURITIES. Conditional. No rule says where data must sit. Since 1 July 2025 the European digital resilience rules for finance apply in Norway through a dedicated Norwegian act. They demand contracts, registers of suppliers, exit plans, and notification of contracts supporting critical functions. They do not say where data must sit. HEALTH. Conditional. No rule says where data must sit. The Directorate of Health's own guidance accepts using cloud services for patient data, including outside Norway. You need a written transfer assessment and you must follow the health sector's information security norm. No Norwegian rule requires patient records to be hosted in Norway. TELECOMS. We found no rule about where data must sit. The Electronic Communications Act started on 1 January 2025. It requires providers to delete traffic data once it is no longer needed for billing or for carrying the communication, and it imposes strict confidentiality. It does not require networks or data to sit in Norway. GOVERNMENT CLOUD AND CLASSIFIED SYSTEMS. Conditional in law, restrictive in real life. The National Security Authority states there is no explicit ban on outsourcing systems covered by the Security Act to a cloud provider. But it says it can be hard to meet the Act's requirements and get security approval when the service is delivered from abroad. MAPPING AND AERIAL IMAGERY. Conditional. Photography, filming and other sensor use from the air is restricted around sensitive installations. Some sensor types must be notified to the National Security Authority. Foreign aircraft using sensors over Norway must notify. GAMBLING, EDUCATION, E-COMMERCE, DEFENCE PROCUREMENT. We found no rule about where data must sit, checked 18 August 2026, medium confidence. Norwegian gambling law works by keeping the market closed to all but two licensed operators, rather than by regulating where data sits.
Sources
- Official sourceSkatteetaten (Norwegian Tax Administration)Oppbevaring av elektronisk regnskapsmateriale i utlandet — endringer i bokføringsforskriften og skattebetalingsforskriften, 29 January 2025
skatteetaten.no
“Elektronisk regnskapsmateriale kan oppbevares i EØS-området, Storbritannia og Sveits”
Link checked 18 August 2026
- Official sourceArkivverket (National Archives of Norway)Veileder for midlertidig utførsel av arkiv til utlandet
arkivverket.no
“kan ikkje arkivmateriale førast ut or landet”
Link checked 18 August 2026
- Official sourceHelsedirektoratet (Norwegian Directorate of Health)Helseopplysninger i skyen — guidance updated 4 November 2025
helsedirektoratet.no
Link checked 18 August 2026
- Official sourceNasjonal sikkerhetsmyndighet (Norwegian National Security Authority)Spørsmål særskilt relatert til sikkerhetsloven — cloud services and the Security Act
nsm.no
“Det er heller ikke et eksplisitt forbud i loven mot å tjenesteutsette informasjonssystemer underlagt sikkerhetsloven til en skytjenesteleverandør.”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighet (Norwegian Communications Authority)Personvern og tilbyders taushetsplikt — traffic data deletion under the Electronic Communications Act
nkom.no
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
First check the destination. A short list of countries and territories is pre-approved by the European Commission, and data can go there with no extra paperwork. Everywhere else you sign the European Commission's standard contract or use approved group-wide rules, and you write down why the destination is safe enough. Norway adds no separate national permission step for personal data.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed
The model is a list of approved countries, and the list is populated. Approved destinations as verified on 18 August 2026: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial bodies, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, and the European Patent Organisation. The United States counts only for organisations self-certified under the European Union to United States Data Privacy Framework. No decision has been withdrawn or suspended. The 2021 standard contractual clauses are still the set to use and have not been amended. Europe promised extra clauses for receivers already covered directly by the Regulation. Those are still not adopted. Binding corporate rules are still available. The narrow one-off exceptions are not a basis for routine or bulk transfers, and you are still expected to write a transfer risk assessment. On 31 July 2026 the European Data Protection Board formally asked the European Commission to examine whether changes in the United States affect the EU-US Data Privacy Framework. It has not been suspended or revoked, but it should not be your only route. One point catches people out. An order from a foreign authority is not by itself a lawful reason to hand data over. For non-personal accounting records the model is different. The European Economic Area, the United Kingdom and Switzerland are free. Anything beyond that needs the tax authority's approval.
Sources
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
- Official sourceSkatteetaten (Norwegian Tax Administration)Storage of electronic accounting material abroad — approval needed outside the European Economic Area, United Kingdom and Switzerland
skatteetaten.no
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Norwegian Data Protection Authority enforces the rules, and it is really working. It had 69 staff at the end of 2024. That year it registered 4,736 new cases, issued 384 decisions and five fines, and received 3,191 breach reports. In June 2026 it fined the electronics retailer Elkjøp 20 million Norwegian kroner, roughly 2 million US dollars, over its customer club. Appeals go to a separate board, which does overturn decisions.
The authority is Datatilsynet. Its decisions can be appealed to Personvernnemnda, an independent appeals board. That board is also active. It overturned a 20 million kroner fine against the labour and welfare administration in 2024. So appealing is a real remedy, not a formality. Other regulators enforce in their own areas, and all are working. Finanstilsynet supervises the finance sector, including the digital resilience rules. Nasjonal sikkerhetsmyndighet handles the security act, incident reporting for critical services, and airborne sensor control. Nasjonal kommunikasjonsmyndighet supervises telecoms. Arkivverket controls public archives. Skatteetaten controls accounting records. We rate the privacy regulator active rather than aggressive. The fine count is steady and mid-sized rather than attention-grabbing, and the Elkjøp decision itself notes the fine was set low against group revenue. Note for automated link checkers: datatilsynet.no serves a broken robots file, so its pages record as robots-blocked rather than unreachable.
Sources
- Official sourceDigitaliserings- og forvaltningsdepartementet / DatatilsynetDatatilsynets årsrapport 2024 — staffing, 4,736 new cases, 384 decisions, five fines, 3,191 breach notifications
regjeringen.no
“I 2024 mottok vi totalt 3 191 slike meldinger”
Link checked 18 August 2026
- Official sourceDatatilsynetOvertredelsesgebyr til Elkjøp — 20 million kroner, 4 June 2026
datatilsynet.no
Link checked 18 August 2026
- Official sourceDatatilsynetAvgjørelser fra Datatilsynet — running list of decisions including 2026 penalties
datatilsynet.no
Link checked 18 August 2026
- Secondary sourceVGDatatilsynet gir Elkjøp gebyr på 20 millioner, 4 June 2026
vg.no
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling. The floor: company accounting records must be kept for five years. Ten years applies to construction project accounts, bank customer records and some others. Fifteen years applies in oil and pipeline businesses. The ceiling: personal data must go once the purpose is finished. Phone and internet providers must delete traffic data once it is no longer needed for billing. When a keeping duty and a deleting duty clash, the keeping duty wins for as long as it lasts. Then you delete.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
The general accounting retention period dropped from ten years to five with effect from 1 January 2015, under bokføringsloven section 13. Some categories stayed at ten years. Those are project accounting in the building and construction trades. Also records for capital assets under value added tax rules, where input tax is 100,000 kroner or more. Also customer and supplier specifications for banks and financial undertakings. And also foreign undertakings on the Norwegian continental shelf. Petroleum extraction and pipeline transport keep fifteen years. Records must stay readable and reachable from Norway for the whole period. That is why moving them to a foreign cloud means telling the tax office rather than making a free choice. On the deletion side, the European rule that you keep data no longer than you need it applies unchanged. The Electronic Communications Act requires providers to delete traffic data when it is no longer needed for billing or for carrying the communication. The exception is where the user agrees to longer storage. Norway has no general duty on telecoms companies to keep data.
Sources
- Official sourceSkatteetaten (Norwegian Tax Administration)Redusert oppbevaringstid for regnskapsmateriale — five-year rule and the ten- and fifteen-year exceptions
skatteetaten.no
“Oppbevaringstiden for regnskapsmateriale er fra 1. januar 2015 redusert fra ti år til fem år.”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetPersonvern og tilbyders taushetsplikt — duty to delete traffic data, ekomloven sections 3-10 and 3-11
nkom.no
“slette trafikkdata når disse ikke lenger trengs for enten å fakturere kunder eller å iverksette en kommunikasjon”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three clocks, because they run at once and have different lengths. Providers of essential services have 24 hours to tell the National Security Authority about a serious digital incident. They then have 72 hours for an update and one month for a full report. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Financial firms have four hours from classifying an incident as serious, and never later than 24 hours after they found it.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one, cybersecurity. The Digital Security Act started on 1 October 2025. It puts the older European network security directive into Norwegian law, not the newer one. Its notification form and guidance say the provider must notify within 24 hours of becoming aware of the incident. A status report follows within 72 hours of that notification, and a final report within one month. Clock two, privacy. The European rulebook gives you 72 hours to tell Datatilsynet. You must also tell the people affected where the risk to them is high. Clock three, finance. The Norwegian digital resilience act applies the European reporting scheme. So a first notification goes to Finanstilsynet within four hours of classifying an incident as major. It must never be later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours of that notification. A final report follows within one month of the last intermediate report. A single incident at a bank can therefore trigger all three. A fourth clock exists for organisations covered by the Security Act. They must tell the National Security Authority about activity that threatens security.
Sources
- Official sourceNasjonal sikkerhetsmyndighetVarsle om hendelser etter digitalsikkerhetsloven — 24-hour notification
nsm.no
“Tilbyder skal varsle innen 24 timer etter at tilbyder fikk kjennskap til hendelsen.”
Link checked 18 August 2026
- Official sourceFinanstilsynet (Financial Supervisory Authority of Norway)Hendelsesrapportering etter DORA, circular of 30 June 2025 — four-hour, 72-hour and one-month reports
finanstilsynet.no
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. A child can consent from age 13 in Norway, lower than in several neighbours. You may only use a person's national identity number where there is a real need for secure identification. Reading an employee's work mailbox has its own rulebook, and getting it wrong is a breach even if you had a good reason. Moving your accounting records abroad needs a notification to the tax office and only works inside Europe, Britain and Switzerland. Aerial photographs and drone sensor readings are controlled before you may release them.
- What you have to do here:
- Get a parent's consent for children
One: personopplysningsloven section 5 sets the age for a child's own consent to online services at 13. Two: section 12 covers the national identity number and other unique identifiers. You may only use them where there is an objective need for secure identification, and where the method is necessary to achieve it. So using it as a customer reference is unlawful. Three: employer access to an employee's mailbox and other stored material is governed by a separate 2018 regulation. It sets out when access is allowed. It requires the employee to be told and given the chance to be present. It requires deletion at the end of employment. It sits on top of the privacy rules, not instead of them. Four: electronic accounting material may sit in the European Economic Area, the United Kingdom or Switzerland. You must notify your tax office and keep the records reachable from Norway. Anything outside that group needs approval. Five: photography, filming and other sensor use from the air is restricted around military and sensitive sites. Other sensor types outside restricted areas must be notified to the National Security Authority. Foreign aircraft using sensors over Norway must notify. Six, for public bodies: taking archive material out of Norway needs the National Archivist's consent. That quietly makes some offshore hosting arrangements unlawful for the public sector, even where privacy law would allow them.
Sources
- Official sourceStortingetPersonopplysningsloven as adopted — section 5 (age 13) and section 12 (national identity number)
stortinget.no
“Fødselsnummer og andre entydige identifikasjonsmidler kan bare behandles når det er saklig behov for sikker identifisering”
Link checked 18 August 2026
- Official sourceLovdataForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materiale, FOR-2018-07-02-1108
lovdata.no
- Official sourceNasjonal sikkerhetsmyndighetLuftbårne sensorsystemer — control of airborne sensor information
nsm.no
“Det er varslingsplikt til NSM for bruk av andre sensorer enn foto/video utenfor forbudsområdene”
Link checked 18 August 2026
- Official sourceArkivverketVeileder for midlertidig utførsel av arkiv til utlandet — National Archivist's consent
arkivverket.no
Link checked 18 August 2026
What's changing next
The biggest thing about Norway right now is what has not arrived. Three European laws that apply in the European Union are not yet Norwegian law. They are the Data Act, the newer cybersecurity law known as NIS2, and the Artificial Intelligence Act. A new Norwegian data sharing act was passed on 19 June 2026. Parliament has told the government to map Norway's digital dependence on other countries, with a first report due by the end of 2026.
Not yet in force in Norway, verified 18 August 2026. The Data Act is still being assessed by the European Economic Area states and has not been brought in. Its January 2027 ban on cloud switching charges therefore does not bind Norwegian providers today, and bringing it in needs Parliament's consent. NIS2 has not been brought in either. Norway's Digital Security Act, in force since 1 October 2025, puts the older 2016 directive into Norwegian law. So Norway is one generation behind the European Union on cybersecurity duties. The Artificial Intelligence Act is to be taken in through the European Economic Area Agreement and adapted to Norwegian law. There is no confirmed date. The transparency duties that started in the European Union on 2 August 2026 do not yet apply here. Recently landed: the Digital Operational Resilience Act for finance started on 1 July 2025, and its Norwegian regulation was amended on 26 January 2026. The data sharing and data governance act was sanctioned on 19 June 2026. It brings in the European data governance regulation, the open data directive and high-value datasets. Some powers can be used without warning, and are worth watching. The tax authority can refuse approval for accounting records held outside Europe, or attach conditions to it. The National Archivist can refuse consent to move public archives. The National Security Authority's approval process can close off foreign hosting for security-relevant systems. And a 2021 amendment on storing internet protocol addresses for police use was adopted by Parliament. We could not confirm it is in force under the 2024 Electronic Communications Act. On the European side, the pressure on the European Union to United States Data Privacy Framework is the most time-sensitive item. The appeal in the Latombe case is pending before the Court of Justice. On 31 July 2026 the European Data Protection Board asked the Commission to examine whether the decision is still valid.
Sources
- Official sourceRegjeringen.no (Norwegian Government)EØS-notat: Dataforordningen (Data Act) — under assessment by the EEA EFTA states, not incorporated
regjeringen.no
“Forordningen er til vurdering i EØS-EFTA-statene”
Link checked 18 August 2026
- Official sourceRegjeringen.noEØS-notat: NIS2-direktivet — not yet incorporated into the EEA Agreement
regjeringen.no
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetKI-loven i et nøtteskall, 10 June 2026 — the AI Act is to be taken into Norwegian law through the EEA Agreement
nkom.no
“I Norge skal regelverket tas inn gjennom EØS-avtalen og tilpasses norsk rett og forvaltning”
Link checked 18 August 2026
- Official sourceStortingetInnst. 225 S (2025–2026) — digital sovereignty; government to map digital dependencies, first report by end of 2026
stortinget.no
Link checked 18 August 2026
- Official sourceStortingetLov om datadeling og dataforvaltning (dataforvaltningsloven) — passed 15 June 2026, sanctioned 19 June 2026
stortinget.no
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data rules
Official name: Lov om arkiv (arkivlova) § 9 bokstav b · LOV-1992-12-04-126 · Act of parliament
A public body's archive material may not be taken out of Norway without the National Archivist's consent. This is a real location rule for the public sector. It applies even where privacy law would allow the data to move.
Enforced by National Archives of Norway
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryArchive material may not be taken out of Norway except under regulations or with the National Archivist's specific consent.
- Secure the dataThe National Archivist expects binding safeguards for transport, storage and prevention of unauthorised access, and recommends suppliers inside the European Union or European Economic Area.
Sources
- Official sourceArkivverketVeileder for midlertidig utførsel av arkiv til utlandet
arkivverket.no
“Utan i samsvar med føresegner gjevne i medhald av § 12 [...] eller etter særskilt samtykke frå Riksarkivaren, kan ikkje arkivmateriale førast ut or landet”
Link checked 18 August 2026
Payment data rules
Official name: Lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) og DORA-forskriften · LOV-2025-05-27-18; FOR-2025-06-24-1296, amended by FOR-2026-01-26-87 · Act of parliament
Since 1 July 2025 Norwegian banks, insurers, payment firms and investment firms follow Europe's digital resilience rules, through a dedicated Norwegian act. There is no rule about where data must be stored. But contracts must disclose where data sits, and give audit and exit rights. Incidents must be reported on a very short clock.
Enforced by Financial Supervisory Authority of Norway
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractTechnology contracts must state where data is processed and stored, and give audit and exit rights.
- Keep records of how you use dataA register of all technology service arrangements must be maintained and reported.
- Register or notifyPlanned contracts supporting critical or important functions must be notified to the supervisor. This replaced the older Norwegian outsourcing notification duty for firms inside the scope.
- Report cyber incidents — within 4 hoursWithin four hours of classifying an incident as major, and at the latest 24 hours after becoming aware of it. Intermediate report within 72 hours, final report within one month.
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory orders, including on technology arrangements
- Loss of your licenceSerious or repeated breach by a licensed firm
Sources
- Official sourceFinanstilsynetQ&A DORA — entry into force 1 July 2025 and the replacement of the earlier outsourcing notification duty
finanstilsynet.no
Link checked 18 August 2026
- Official sourceFinanstilsynetNy lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) trer i kraft 1. juli 2025
finanstilsynet.no
- Official sourceLovdataLov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven)
lovdata.no
- Official sourceFinanstilsynetHendelsesrapportering etter DORA, 30 June 2025
finanstilsynet.no
Link checked 18 August 2026
Cyber security rules
Official name: Lov om digital sikkerhet (digitalsikkerhetsloven) og digitalsikkerhetsforskriften · Digitalsikkerhetsloven; FOR-2025-06-20-1131 · Act of parliament
Norway's cybersecurity law for essential and digital service providers started on 1 October 2025 and implements Europe's older network security directive, not the newer NIS2. It requires a 24-hour incident notification but says nothing about where data must be stored.
Enforced by Norwegian National Security Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataRisk-based security requirements for providers of essential and digital services in energy, transport, health, water, banking, financial market infrastructure, digital infrastructure and digital services.
- Report cyber incidents — within 24 hoursNotify within 24 hours of becoming aware. Status report within 72 hours of the notification, full report within one month.
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines for failure to secure services or to notify
Sources
- Official sourceRegjeringen.noNy lov om digital sikkerhet trer i kraft i dag — 1 October 2025, implementing the NIS1 directive
regjeringen.no
“Loven gjennomfører EUs NIS1-direktiv som ble vedtatt i 2016”
Link checked 18 August 2026
- Official sourceNasjonal sikkerhetsmyndighetVarsle om hendelser etter digitalsikkerhetsloven
nsm.no
“Tilbyder skal varsle innen 24 timer etter at tilbyder fikk kjennskap til hendelsen.”
Link checked 18 August 2026
State and security data rules
Official name: Forskrift om kontroll med informasjon innhentet med luftbårne sensorsystemer · FOR-2018-06-22-951 · Directly binding regulation
Pictures and sensor readings collected from aircraft and drones over Norway are controlled. Some areas are off limits, some sensor types must be notified to the National Security Authority, and foreign aircraft using sensors must notify before flying.
Enforced by Norwegian National Security Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyNotify the National Security Authority for sensor types other than photo and video, outside restricted areas. Also notify for any sensor use by foreign aircraft over Norway.
- Secure the dataPhotography and filming from the air is banned in and around designated military and sensitive installations.
What it costs if you get it wrong
- Fixed maximum fineBreach of the restrictions on airborne sensor use
Sources
- Official sourceNasjonal sikkerhetsmyndighetLuftbårne sensorsystemer
nsm.no
“Det er varslingsplikt til NSM for bruk av andre sensorer enn foto/video utenfor forbudsområdene”
Link checked 18 August 2026
- Official sourceLovdataForskrift om kontroll med informasjon innhentet med luftbårne sensorsystemer
lovdata.no
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Lov om behandling av personopplysninger (personopplysningsloven) · LOV-2018-06-15-38 · Act of parliament
The national privacy statute. It makes the European rulebook Norwegian law and adds local detail. It sets the age of a child's own consent at 13. It restricts use of the national identity number. It reaches foreign companies that target or monitor people in Norway. It says nothing about where data must be stored.
Enforced by Norwegian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for childrenA child may consent to online services from age 13; below that a parent must consent.
- Allowed because the law requires itThe national identity number may only be used where there is an objective need for secure identification.
- Appoint a data protection officerSame trigger as the European rulebook. No requirement that the officer be resident in Norway.
- Put a transfer safeguard in place
What it costs if you get it wrong
- Percentage of global turnover: 4 % of worldwide group turnover, applied in Norwegian kronerBreach of the privacy rules
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceStortingetVedtak til lov om behandling av personopplysninger, sections 2, 5 and 12
stortinget.no
“Fødselsnummer og andre entydige identifikasjonsmidler kan bare behandles når det er saklig behov for sikker identifisering”
Link checked 18 August 2026
- Official sourceLovdataPersonopplysningsloven, consolidated text
lovdata.no
Link checked 18 August 2026
Personal data must stay in the country
Official name: Bokføringsforskriften § 7-5, jf. bokføringsloven § 13 (endring om oppbevaring av elektronisk regnskapsmateriale i utlandet) · Amendment announced by Skatteetaten 29 January 2025, in force 27 January 2025 · Directly binding regulation
Every Norwegian company's accounting records may only be stored electronically in the European Economic Area, the United Kingdom or Switzerland. You must tell the tax office where they are. Storage anywhere else needs approval. Records must stay reachable electronically from Norway for the whole keeping period.
Enforced by Norwegian Tax Administration
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryElectronic accounting records may be kept in the European Economic Area, the United Kingdom and Switzerland. Anywhere else needs the tax authority's approval.
- Keep data for a minimum period — 5 yearsFive years for primary documentation. Ten years for construction project accounts, bank customer and supplier specifications and some other categories; fifteen years for petroleum extraction and pipeline transport.
- Register or notifyYou must notify your local tax office that the records are held abroad.
What it costs if you get it wrong
- Fixed maximum fineEnforcement fines and orders by the tax authority for bookkeeping failures
Sources
- Official sourceSkatteetatenOppbevaring av elektronisk regnskapsmateriale i utlandet — endringer i bokføringsforskriften og skattebetalingsforskriften
skatteetaten.no
“Elektronisk regnskapsmateriale kan oppbevares i EØS-området, Storbritannia og Sveits”
Link checked 18 August 2026
- Official sourceSkatteetatenRedusert oppbevaringstid for regnskapsmateriale
skatteetaten.no
“Oppbevaringstiden for regnskapsmateriale er fra 1. januar 2015 redusert fra ti år til fem år.”
Link checked 18 August 2026
Applies across the EEA2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Forordning (EU) 2016/679 (personvernforordningen), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 154/2018 of 6 July 2018 · Directly binding regulation
Europe's General Data Protection Regulation applies in Norway through the European Economic Area Agreement, not through European Union membership. It does not require personal data to stay in Norway or in Europe. It sets the conditions for sending it out.
Enforced by Norwegian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Put a transfer safeguard in place
- Written vendor contract
- Appoint a representativeOnly where the organisation has no establishment in the European Economic Area.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWhere the breach is likely to result in a high risk to the people affected.
What it costs if you get it wrong
- Percentage of global turnover: 4 % of worldwide group turnoverBreach of basic principles, individual rights or the transfer rules
- Fixed maximum fine: €20 million — about $22 millionAlternative ceiling where higher than the turnover figure
- Order to stopOrder to stop processing or suspend flows to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEFTA SecretariatEEA-Lex: GDPR incorporated by Joint Committee Decision 154/2018, in force in the EEA 20 July 2018
efta.int
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Cyber security rules (Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689)
Official name: Dataforordningen (Data Act), NIS2-direktivet og KI-forordningen (AI Act) — ikke innlemmet i EØS-avtalen · Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689 · Directly binding regulation
Three European digital laws that people assume apply in Norway do not. The Data Act is still being assessed by the European Economic Area states. The newer cybersecurity law known as NIS2 has not been brought in. The Artificial Intelligence Act is still being prepared for Norwegian law. None of them creates rights or duties in Norway today.
Enforced by Norwegian Communications Authority
How this country controls where data goes: No restriction
What you have to do
- Make switching cloud provider possibleThe Data Act duty to remove cloud switching charges by 12 January 2027 does NOT yet apply in Norway. The regulation has not been brought into the European Economic Area Agreement.
Sources
- Official sourceRegjeringen.noEØS-notat: Dataforordningen
regjeringen.no
“Forordningen er til vurdering i EØS-EFTA-statene”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetKI-loven i et nøtteskall, 10 June 2026
nkom.no
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the 2021 amendment requiring providers to store internet protocol addresses for police use is in force today
We could not confirm whether Norway has a duty on telecoms companies to keep data. Parliament passed the amendment on 18 June 2021. We could not confirm from a government source whether it ever started. We also could not confirm how it carried over into the Electronic Communications Act that began on 1 January 2025. The communications regulator's own page describes only a duty to delete traffic data. Treat any claim that Norway has telecoms data retention with suspicion until you find the commencement notice.
Whether any Norwegian gambling rule requires gaming systems or player data to be located in Norway
We found no rule requiring gambling data to stay in Norway, checked 18 August 2026, medium confidence. We found the Gambling Act and the Gambling Regulation, but we could not confirm the regulator's own text of the technical requirements. Norway's monopoly model means the question is rarely tested. If you work in gambling, check before you rely on this.
The exact current status of the Data Act, NIS2 and the Artificial Intelligence Act in the European Economic Area process
We could not confirm that these three European laws are still outside Norwegian law today. The government's own European Economic Area notes are the best source, but they are out of date. The Data Act note was last revised in October 2024, and the NIS2 note in August 2023. The communications regulator confirmed in June 2026 that the artificial intelligence rules are still to be taken in. A Joint Committee decision could have been taken since those notes were updated, so check before you rely on this.
Whether breaching the bookkeeping rules is a criminal offence in Norway as well as an administrative matter
We could not confirm whether Norway has criminal penalties for accounting offences. Norwegian criminal law does contain accounting offences, but we could not confirm the wording or the penalties from a government source. So no criminal penalty is recorded on the accounting rule.
The full operative text and section numbers of bokføringsforskriften § 7-5 as amended
We could not confirm the wording against the consolidated regulation text, because the official law database blocks automated access. We used the tax administration's own announcement of the change, which quotes the wording.
Whether Datatilsynet issued further fines between 1 and 18 August 2026
We could not confirm whether the regulator issued decisions after June 2026. Its website blocks automated access. We confirmed decisions up to June 2026 through search listings of its own decision pages, and a media report of the Elkjøp fine. Check the regulator's site for anything newer.
Whether any Norwegian health rule requires patient records to be hosted inside Norway
We found no rule requiring patient records to stay in Norway, checked 18 August 2026. The Directorate of Health's guidance treats this as a transfer assessment under the European rulebook rather than a location ban. We did not review every registry-specific regulation. The health sector's information security norm also adds contract requirements that we did not read in full. If you work in health, check before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.