Skip to the content
Global Data RulesData governance rules, country by country

Norway

Part of the EEA, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Active

Norway follows Europe's privacy rulebook through the European Economic Area, so personal data may leave once the right paperwork is in place. No general rule forces data to stay in Norway. The catches are accounting records, which must sit in Europe, Britain or Switzerland unless the tax office agrees otherwise, and public sector archives, which need the National Archivist's permission to leave.

Data governance in Norway

The eight things that decide how you handle data about people in Norway. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. If you offer goods or services to people in Norway, or track what they do online, the rules reach you even if you have no office here. There is no size or revenue level you can stay under. A company based outside the European Economic Area must name a representative inside that area, and that representative is the person the regulator writes to.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

In general, yes. Personal data can leave Norway and even leave Europe once you have the right legal instrument in place. Nothing in Norwegian privacy law says personal data must be stored here. Two rules that apply to almost everyone are the real limits: your accounting records must stay in a short list of European countries, and a public body's archives cannot leave Norway without permission.

High confidenceDepends on your industryYes, with paperworkAllowlist

Sending data out of the country

First check the destination. A short list of countries and territories is pre-approved by the European Commission, and data can go there with no extra paperwork. Everywhere else you sign the European Commission's standard contract or use approved group-wide rules, and you write down why the destination is safe enough. Norway adds no separate national permission step for personal data.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesGovernment sign-off needed

The regulator, and whether it actually acts

The Norwegian Data Protection Authority, and it is genuinely working, not a name on paper. It had 69 staff at the end of 2024, registered 4,736 new cases that year, issued 384 decisions and five fines, and received 3,191 breach reports. In June 2026 it fined the electronics retailer Elkjøp 20 million Norwegian kroner, roughly 2 million US dollars, over its customer club. Appeals go to a separate board, which does overturn decisions.

High confidenceActive

How long you must keep it — and when to delete it

There is a floor and a ceiling. The floor: company accounting records must be kept for five years, with ten years for construction project accounts, bank customer records and some others, and fifteen years in oil and pipeline businesses. The ceiling: personal data must go once the purpose is finished, and phone and internet providers must delete traffic data once it is no longer needed for billing. When a keeping duty and a deleting duty clash, the keeping duty wins for as long as it lasts, and then you delete.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count three clocks, because they run at once and have different lengths. Providers of essential services have 24 hours to tell the National Security Authority about a serious digital incident, then 72 hours for an update and one month for a full report. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Financial firms have four hours from classifying an incident as serious, and never later than 24 hours after they found it.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. A child can consent from age 13 in Norway, lower than in several neighbours. You may only use a person's national identity number where there is a real need for secure identification. Reading an employee's work mailbox has its own rulebook, and getting it wrong is a breach even if you had a good reason. Moving your accounting records abroad needs a notification to the tax office and only works inside Europe, Britain and Switzerland. Aerial photographs and drone sensor readings are controlled before you may release them.

High confidenceGet a parent's consent for childrenKeep the data in the countryEmployee dataMapping and survey data

What's changing next

The biggest thing about Norway right now is what has not arrived. Three European laws that apply in the European Union are not yet Norwegian law: the Data Act, the newer cybersecurity law known as NIS2, and the Artificial Intelligence Act. A new Norwegian data sharing act was passed on 19 June 2026. Parliament has told the government to map Norway's digital dependence on other countries, with a first report due by the end of 2026.

Medium confidenceProposedIn force

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Lov om arkiv (arkivlova) § 9 bokstav b

Act of parliament · LOV-1992-12-04-126

In forceNo — it stays put

A public body's archive material may not be taken out of Norway without the National Archivist's consent. This is a genuine location rule for the public sector, and it applies even where privacy law would allow the data to move.

In force since 1 January 1999

Enforced by National Archives of Norway

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Finance

Lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) og DORA-forskriften

Act of parliament · LOV-2025-05-27-18; FOR-2025-06-24-1296, amended by FOR-2026-01-26-87

In forceYes, with paperwork

Since 1 July 2025 Norwegian banks, insurers, payment firms and investment firms follow Europe's digital resilience rules through a dedicated Norwegian act. There is no storage location requirement, but contracts must disclose where data sits and give audit and exit rights, and incidents must be reported on a very short clock.

In force since 1 July 2025

Enforced by Financial Supervisory Authority of Norway

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Lov om digital sikkerhet (digitalsikkerhetsloven) og digitalsikkerhetsforskriften

Act of parliament · Digitalsikkerhetsloven; FOR-2025-06-20-1131

In forceYes — store it anywhere

Norway's cybersecurity law for essential and digital service providers started on 1 October 2025 and implements Europe's older network security directive, not the newer NIS2. It requires a 24-hour incident notification but says nothing about where data must be stored.

In force since 1 October 2025

Enforced by Norwegian National Security Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Lov om behandling av personopplysninger (personopplysningsloven)

Act of parliament · LOV-2018-06-15-38

In forceYes, with paperwork

The national privacy statute that makes the European rulebook Norwegian law and adds local detail. It sets the age of a child's own consent at 13, restricts use of the national identity number, and reaches foreign companies that target or monitor people in Norway. It imposes no storage location requirement.

In force since 20 July 2018

Enforced by Norwegian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Bokføringsforskriften § 7-5, jf. bokføringsloven § 13 (endring om oppbevaring av elektronisk regnskapsmateriale i utlandet)

Directly binding regulation · Amendment announced by Skatteetaten 29 January 2025, in force 27 January 2025

In forceYes, with paperwork

Every Norwegian company's accounting records may only be stored electronically in the European Economic Area, the United Kingdom or Switzerland, and you must tell the tax office where they are. Storage anywhere else needs approval. Records must stay reachable electronically from Norway for the whole retention period.

In force since 27 January 2025

Enforced by Norwegian Tax Administration

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Applies across the EEA2 rules

Written once for the whole bloc, and in force in every member country.

Forordning (EU) 2016/679 (personvernforordningen), incorporated into the EEA Agreement

Directly binding regulation · EEA Joint Committee Decision No. 154/2018 of 6 July 2018

In forceYes, with paperwork

Europe's General Data Protection Regulation applies in Norway through the European Economic Area Agreement, not through European Union membership. It does not require personal data to stay in Norway or in Europe; it sets the conditions for sending it out.

In force since 20 July 2018

Enforced by Norwegian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Dataforordningen (Data Act), NIS2-direktivet og KI-forordningen (AI Act) — ikke innlemmet i EØS-avtalen

Directly binding regulation · Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689

ProposedNot yet established

Three European digital laws that people assume apply in Norway do not. The Data Act is still under assessment by the European Economic Area states, the newer cybersecurity law known as NIS2 has not been incorporated, and the Artificial Intelligence Act is still being prepared for Norwegian law. None of them creates rights or duties in Norway today.

Enforced by Norwegian Communications Authority

Transfer model: No restriction

Medium confidence

Who you would hear from

  • Datatilsynet

    General privacy law, breach notification, international transfers

    Fully staffed and issuing decisions. 69 employees at the end of 2024, 4,736 new cases, 384 decisions, five fines totalling about 20.7 million kroner and 3,191 breach notifications that year. In June 2026 it fined Elkjøp 20 million kroner. Its website serves a broken robots file, so automated link checks report robots-blocked.

  • Personvernnemnda

    Appeals against Datatilsynet's decisions

    Active. Datatilsynet referred 48 cases to it in 2024, and it overturned a 20 million kroner fine against the labour and welfare administration.

  • Finanstilsynet

    Banking, insurance, securities, payments; digital operational resilience

    Active. Issued the DORA incident reporting circular on 30 June 2025 and maintains a live question and answer page on the new regime.

  • Nasjonal sikkerhetsmyndighet

    Security Act approvals, digital security incident notification, airborne sensor control

    Active. Runs the 24-hour incident notification channel under the Digital Security Act and the notification scheme for airborne sensor systems.

  • Nasjonal kommunikasjonsmyndighet

    Telecoms, electronic communications confidentiality; preparing for the Artificial Intelligence Act

    Active. Supervises the Electronic Communications Act that started on 1 January 2025 and publishes guidance on the coming artificial intelligence rules.

  • Arkivverket / Riksarkivaren

    Public sector archives, including consent to take archive material out of Norway

    Active. Publishes a standing guide and consent process for taking archives abroad.

  • Skatteetaten

    Accounting records: retention periods, storage location and approvals

    Active. Announced the January 2025 change permitting storage in the European Economic Area, the United Kingdom and Switzerland.

  • Helsedirektoratet

    Health sector guidance on cloud use and information security

    Active. Cloud guidance last updated 4 November 2025.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the 2021 amendment requiring providers to store internet protocol addresses for police use is in force today

    Parliament passed the amendment on 18 June 2021, but we could not verify from a government source whether it was ever commenced or how it was carried over into the Electronic Communications Act that started on 1 January 2025. The communications regulator's own page describes only a duty to delete traffic data. Treat any claim that Norway has telecoms data retention with suspicion until the commencement notice is found.

  • Whether any Norwegian gambling rule requires gaming systems or player data to be located in Norway

    No rule found, checked 18 August 2026, medium confidence. We located the Gambling Act and the Gambling Regulation but could not open the regulator's own text of the technical requirements, and Norway's monopoly model means the question is rarely tested. Absence of a finding is not proof of absence.

  • The exact current status of the Data Act, NIS2 and the Artificial Intelligence Act in the European Economic Area process

    The government's own European Economic Area notes are the authoritative source but are themselves stale: the Data Act note was last revised in October 2024 and the NIS2 note in August 2023. The direction is clear and the communications regulator confirmed in June 2026 that the artificial intelligence rules are still to be taken in, but a Joint Committee decision could have been taken since the notes were updated.

  • Whether breaching the bookkeeping rules is a criminal offence in Norway as well as an administrative matter

    Norwegian criminal law contains accounting offences, but we did not verify the provision or its penalties from a government source during this run, so no criminal penalty is recorded on the accounting rule.

  • The full operative text and section numbers of bokføringsforskriften § 7-5 as amended

    We relied on the tax administration's own announcement of the amendment, which quotes the operative wording, rather than the consolidated regulation text, because the official law database blocks automated fetching.

  • Whether Datatilsynet issued further fines between 1 and 18 August 2026

    The regulator's site serves a broken robots file and could not be fetched. Decisions up to June 2026 were confirmed through search listings of its own decision pages and a media report of the Elkjøp fine. We cannot prove the absence of later decisions.

  • Whether any Norwegian health rule requires patient records to be hosted inside Norway

    No rule found, checked 18 August 2026. The Directorate of Health's guidance treats the question as a transfer assessment under the European rulebook rather than a location ban, but we did not review every registry-specific regulation, and the health sector's information security norm imposes additional contractual requirements we did not read in full.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Norway versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.