Skip to the content
Global Data RulesData governance rules, country by country

Norway

Part of the EEA, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Norway — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Norway follows Europe's privacy rulebook, so personal data can leave once you have the right paperwork. Norway is in the European Economic Area, which is how the European rules apply here. No general rule forces data to stay in Norway. There are two catches. Your accounting records must sit in Europe, Britain or Switzerland unless the tax office agrees otherwise. Public sector archives need the National Archivist's permission to leave.

Data governance in Norway

The eight things that decide how you handle data about people in Norway. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach you even if you have no office here. That is true if you offer goods or services to people in Norway, or track what they do online. There is no size or revenue level you can stay under. A company based outside the European Economic Area must name a representative inside that area. That representative is the person the regulator writes to.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes. Personal data can leave Norway and even leave Europe once you have the right paperwork. Nothing in Norwegian privacy law says personal data must be stored here. Two rules that apply to almost everyone are the real limits. Your accounting records must stay in a short list of European countries. And a public body's archives cannot leave Norway without permission.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

First check the destination. A short list of countries and territories is pre-approved by the European Commission, and data can go there with no extra paperwork. Everywhere else you sign the European Commission's standard contract or use approved group-wide rules, and you write down why the destination is safe enough. Norway adds no separate national permission step for personal data.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Norwegian Data Protection Authority enforces the rules, and it is really working. It had 69 staff at the end of 2024. That year it registered 4,736 new cases, issued 384 decisions and five fines, and received 3,191 breach reports. In June 2026 it fined the electronics retailer Elkjøp 20 million Norwegian kroner, roughly 2 million US dollars, over its customer club. Appeals go to a separate board, which does overturn decisions.

How long you must keep it — and when to delete it

There is a floor and a ceiling. The floor: company accounting records must be kept for five years. Ten years applies to construction project accounts, bank customer records and some others. Fifteen years applies in oil and pipeline businesses. The ceiling: personal data must go once the purpose is finished. Phone and internet providers must delete traffic data once it is no longer needed for billing. When a keeping duty and a deleting duty clash, the keeping duty wins for as long as it lasts. Then you delete.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three clocks, because they run at once and have different lengths. Providers of essential services have 24 hours to tell the National Security Authority about a serious digital incident. They then have 72 hours for an update and one month for a full report. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Financial firms have four hours from classifying an incident as serious, and never later than 24 hours after they found it.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. A child can consent from age 13 in Norway, lower than in several neighbours. You may only use a person's national identity number where there is a real need for secure identification. Reading an employee's work mailbox has its own rulebook, and getting it wrong is a breach even if you had a good reason. Moving your accounting records abroad needs a notification to the tax office and only works inside Europe, Britain and Switzerland. Aerial photographs and drone sensor readings are controlled before you may release them.

What you have to do here:
Get a parent's consent for children

What's changing next

The biggest thing about Norway right now is what has not arrived. Three European laws that apply in the European Union are not yet Norwegian law. They are the Data Act, the newer cybersecurity law known as NIS2, and the Artificial Intelligence Act. A new Norwegian data sharing act was passed on 19 June 2026. Parliament has told the government to map Norway's digital dependence on other countries, with a first report due by the end of 2026.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data rules

Official name: Lov om arkiv (arkivlova) § 9 bokstav b · LOV-1992-12-04-126 · Act of parliament

In forceNo — it stays put

A public body's archive material may not be taken out of Norway without the National Archivist's consent. This is a real location rule for the public sector. It applies even where privacy law would allow the data to move.

In force since 1 January 1999

Enforced by National Archives of Norway

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Finance

Payment data rules

Official name: Lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) og DORA-forskriften · LOV-2025-05-27-18; FOR-2025-06-24-1296, amended by FOR-2026-01-26-87 · Act of parliament

In forceYes, with paperwork

Since 1 July 2025 Norwegian banks, insurers, payment firms and investment firms follow Europe's digital resilience rules, through a dedicated Norwegian act. There is no rule about where data must be stored. But contracts must disclose where data sits, and give audit and exit rights. Incidents must be reported on a very short clock.

In force since 1 July 2025

Enforced by Financial Supervisory Authority of Norway

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules

Official name: Lov om digital sikkerhet (digitalsikkerhetsloven) og digitalsikkerhetsforskriften · Digitalsikkerhetsloven; FOR-2025-06-20-1131 · Act of parliament

In forceYes — store it anywhere

Norway's cybersecurity law for essential and digital service providers started on 1 October 2025 and implements Europe's older network security directive, not the newer NIS2. It requires a 24-hour incident notification but says nothing about where data must be stored.

In force since 1 October 2025

Enforced by Norwegian National Security Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Lov om behandling av personopplysninger (personopplysningsloven) · LOV-2018-06-15-38 · Act of parliament

In forceYes, with paperwork

The national privacy statute. It makes the European rulebook Norwegian law and adds local detail. It sets the age of a child's own consent at 13. It restricts use of the national identity number. It reaches foreign companies that target or monitor people in Norway. It says nothing about where data must be stored.

In force since 20 July 2018

Enforced by Norwegian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data must stay in the country

Official name: Bokføringsforskriften § 7-5, jf. bokføringsloven § 13 (endring om oppbevaring av elektronisk regnskapsmateriale i utlandet) · Amendment announced by Skatteetaten 29 January 2025, in force 27 January 2025 · Directly binding regulation

In forceYes, with paperwork

Every Norwegian company's accounting records may only be stored electronically in the European Economic Area, the United Kingdom or Switzerland. You must tell the tax office where they are. Storage anywhere else needs approval. Records must stay reachable electronically from Norway for the whole keeping period.

In force since 27 January 2025

Enforced by Norwegian Tax Administration

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Applies across the EEA2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Forordning (EU) 2016/679 (personvernforordningen), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 154/2018 of 6 July 2018 · Directly binding regulation

In forceYes, with paperwork

Europe's General Data Protection Regulation applies in Norway through the European Economic Area Agreement, not through European Union membership. It does not require personal data to stay in Norway or in Europe. It sets the conditions for sending it out.

In force since 20 July 2018

Enforced by Norwegian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cyber security rules (Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689)

Official name: Dataforordningen (Data Act), NIS2-direktivet og KI-forordningen (AI Act) — ikke innlemmet i EØS-avtalen · Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689 · Directly binding regulation

ProposedNot yet established

Three European digital laws that people assume apply in Norway do not. The Data Act is still being assessed by the European Economic Area states. The newer cybersecurity law known as NIS2 has not been brought in. The Artificial Intelligence Act is still being prepared for Norwegian law. None of them creates rights or duties in Norway today.

Enforced by Norwegian Communications Authority

How this country controls where data goes: No restriction

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Datatilsynet

    General privacy law, breach notification, international transfers

    Fully staffed and issuing decisions. 69 employees at the end of 2024, 4,736 new cases, 384 decisions, five fines totalling about 20.7 million kroner and 3,191 breach notifications that year. In June 2026 it fined Elkjøp 20 million kroner.

  • Personvernnemnda

    Appeals against Datatilsynet's decisions

    Active. Datatilsynet referred 48 cases to it in 2024, and it overturned a 20 million kroner fine against the labour and welfare administration.

  • Finanstilsynet

    Banking, insurance, securities, payments; digital operational resilience

    Active. Issued its circular on incident reporting under the Digital Operational Resilience Act on 30 June 2025. Keeps a live question and answer page on the new rules.

  • Nasjonal sikkerhetsmyndighet

    Security Act approvals, digital security incident notification, airborne sensor control

    Active. Runs the 24-hour incident notification channel under the Digital Security Act and the notification scheme for airborne sensor systems.

  • Nasjonal kommunikasjonsmyndighet

    Telecoms, electronic communications confidentiality; preparing for the Artificial Intelligence Act

    Active. Supervises the Electronic Communications Act that started on 1 January 2025 and publishes guidance on the coming artificial intelligence rules.

  • Arkivverket / Riksarkivaren

    Public sector archives, including consent to take archive material out of Norway

    Active. Publishes a standing guide and consent process for taking archives abroad.

  • Skatteetaten

    Accounting records: retention periods, storage location and approvals

    Active. Announced the January 2025 change permitting storage in the European Economic Area, the United Kingdom and Switzerland.

  • Helsedirektoratet

    Health sector guidance on cloud use and information security

    Active. Cloud guidance last updated 4 November 2025.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the 2021 amendment requiring providers to store internet protocol addresses for police use is in force today

    We could not confirm whether Norway has a duty on telecoms companies to keep data. Parliament passed the amendment on 18 June 2021. We could not confirm from a government source whether it ever started. We also could not confirm how it carried over into the Electronic Communications Act that began on 1 January 2025. The communications regulator's own page describes only a duty to delete traffic data. Treat any claim that Norway has telecoms data retention with suspicion until you find the commencement notice.

  • Whether any Norwegian gambling rule requires gaming systems or player data to be located in Norway

    We found no rule requiring gambling data to stay in Norway, checked 18 August 2026, medium confidence. We found the Gambling Act and the Gambling Regulation, but we could not confirm the regulator's own text of the technical requirements. Norway's monopoly model means the question is rarely tested. If you work in gambling, check before you rely on this.

  • The exact current status of the Data Act, NIS2 and the Artificial Intelligence Act in the European Economic Area process

    We could not confirm that these three European laws are still outside Norwegian law today. The government's own European Economic Area notes are the best source, but they are out of date. The Data Act note was last revised in October 2024, and the NIS2 note in August 2023. The communications regulator confirmed in June 2026 that the artificial intelligence rules are still to be taken in. A Joint Committee decision could have been taken since those notes were updated, so check before you rely on this.

  • Whether breaching the bookkeeping rules is a criminal offence in Norway as well as an administrative matter

    We could not confirm whether Norway has criminal penalties for accounting offences. Norwegian criminal law does contain accounting offences, but we could not confirm the wording or the penalties from a government source. So no criminal penalty is recorded on the accounting rule.

  • The full operative text and section numbers of bokføringsforskriften § 7-5 as amended

    We could not confirm the wording against the consolidated regulation text, because the official law database blocks automated access. We used the tax administration's own announcement of the change, which quotes the wording.

  • Whether Datatilsynet issued further fines between 1 and 18 August 2026

    We could not confirm whether the regulator issued decisions after June 2026. Its website blocks automated access. We confirmed decisions up to June 2026 through search listings of its own decision pages, and a media report of the Elkjøp fine. Check the regulator's site for anything newer.

  • Whether any Norwegian health rule requires patient records to be hosted inside Norway

    We found no rule requiring patient records to stay in Norway, checked 18 August 2026. The Directorate of Health's guidance treats this as a transfer assessment under the European rulebook rather than a location ban. We did not review every registry-specific regulation. The health sector's information security norm also adds contract requirements that we did not read in full. If you work in health, check before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.