Norway
Part of the EEA, so bloc-wide rules apply here too. Checked yesterday.
The answer
Norway follows Europe's privacy rulebook through the European Economic Area, so personal data may leave once the right paperwork is in place. No general rule forces data to stay in Norway. The catches are accounting records, which must sit in Europe, Britain or Switzerland unless the tax office agrees otherwise, and public sector archives, which need the National Archivist's permission to leave.
Data governance in Norway
The eight things that decide how you handle data about people in Norway. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. If you offer goods or services to people in Norway, or track what they do online, the rules reach you even if you have no office here. There is no size or revenue level you can stay under. A company based outside the European Economic Area must name a representative inside that area, and that representative is the person the regulator writes to.
Norway applies the European Union's General Data Protection Regulation through the European Economic Area Agreement, not through European Union membership. The national statute, personopplysningsloven of 15 June 2018, makes the Regulation Norwegian law and adds national detail. Its section 2 covers processing carried out in connection with the activities of a controller or processor in Norway regardless of where the processing happens, and also covers processing about people who are in Norway by controllers outside the European Economic Area where it relates to offering goods or services to them or monitoring their behaviour in Norway. The representative duty is the Regulation's Article 27 duty; Norway adds no separate registration or licence.
Sources
- Official sourceStortinget (Norwegian Parliament)Vedtak til lov om behandling av personopplysninger (personopplysningsloven), sections 2, 5 and 12 as adopted
stortinget.no
Link checked 18 August 2026
- Official sourceLovdata (official Norwegian law database)Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38
lovdata.no
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
In general, yes. Personal data can leave Norway and even leave Europe once you have the right legal instrument in place. Nothing in Norwegian privacy law says personal data must be stored here. Two rules that apply to almost everyone are the real limits: your accounting records must stay in a short list of European countries, and a public body's archives cannot leave Norway without permission.
Sector by sector, checked on 18 August 2026. GENERAL PERSONAL DATA — conditional. The European rulebook governs, and it sets conditions for export rather than banning it. Regulation (EU) 2018/1807 also forbids localisation rules for non-personal data except on public-security grounds. ACCOUNTING AND TAX RECORDS, ALL INDUSTRIES — conditional but geographically capped. Since 27 January 2025 electronic accounting material may be kept in the European Economic Area, the United Kingdom and Switzerland without asking anyone, provided you notify your tax office and the records stay reachable electronically from Norway. Storage anywhere else needs the tax authority's approval. This replaced the older, narrower Nordic-only permission and the rule that cash register journals had to physically stay in Norway. PUBLIC SECTOR ARCHIVES — closed unless permission is given. Archive material held by a public body may not be taken out of the country except under regulations or with the National Archivist's specific consent. The National Archivist tells applicants to prefer suppliers inside the European Union or European Economic Area. BANKING, PAYMENTS, INSURANCE, SECURITIES — conditional, no localisation. Since 1 July 2025 the European digital resilience rules for finance apply in Norway through a dedicated Norwegian act. They demand contracts, registers of suppliers, exit plans and notification of contracts supporting critical functions, but they do not say where data must sit. HEALTH — conditional, no localisation. The Directorate of Health's own guidance accepts cloud processing of patient data, including outside Norway, subject to a documented transfer assessment and the health sector's information security norm. No Norwegian rule requires patient records to be hosted in Norway. TELECOMS — no localisation found. The Electronic Communications Act that started on 1 January 2025 requires providers to delete traffic data once it is no longer needed for billing or carrying the communication, and imposes strict confidentiality. It does not require networks or data to sit in Norway. GOVERNMENT CLOUD AND CLASSIFIED SYSTEMS — conditional in law, restrictive in practice. The National Security Authority states there is no explicit ban on outsourcing systems covered by the Security Act to a cloud provider, but says it can be hard to meet the Act's requirements and obtain security approval when the service is delivered from abroad. MAPPING AND AERIAL IMAGERY — conditional. Photography, filming and other sensor use from the air is restricted around sensitive installations, notification to the National Security Authority is required for some sensor types, and foreign aircraft using sensors over Norway must notify. GAMBLING, EDUCATION, E-COMMERCE, DEFENCE PROCUREMENT — no data localisation rule found, checked 18 August 2026, medium confidence. Norwegian gambling law works by keeping the market closed to all but two licensed operators rather than by regulating where data sits.
Sources
- Official sourceSkatteetaten (Norwegian Tax Administration)Oppbevaring av elektronisk regnskapsmateriale i utlandet — endringer i bokføringsforskriften og skattebetalingsforskriften, 29 January 2025
skatteetaten.no
“Elektronisk regnskapsmateriale kan oppbevares i EØS-området, Storbritannia og Sveits”
Link checked 18 August 2026
- Official sourceArkivverket (National Archives of Norway)Veileder for midlertidig utførsel av arkiv til utlandet
arkivverket.no
“kan ikkje arkivmateriale førast ut or landet”
Link checked 18 August 2026
- Official sourceHelsedirektoratet (Norwegian Directorate of Health)Helseopplysninger i skyen — guidance updated 4 November 2025
helsedirektoratet.no
Link checked 18 August 2026
- Official sourceNasjonal sikkerhetsmyndighet (Norwegian National Security Authority)Spørsmål særskilt relatert til sikkerhetsloven — cloud services and the Security Act
nsm.no
“Det er heller ikke et eksplisitt forbud i loven mot å tjenesteutsette informasjonssystemer underlagt sikkerhetsloven til en skytjenesteleverandør.”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighet (Norwegian Communications Authority)Personvern og tilbyders taushetsplikt — traffic data deletion under the Electronic Communications Act
nkom.no
Link checked 18 August 2026
Sending data out of the country
First check the destination. A short list of countries and territories is pre-approved by the European Commission, and data can go there with no extra paperwork. Everywhere else you sign the European Commission's standard contract or use approved group-wide rules, and you write down why the destination is safe enough. Norway adds no separate national permission step for personal data.
The model is an allowlist and the list is populated. Approved destinations as verified on 18 August 2026: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial bodies, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States but only for organisations self-certified under the European Union to United States Data Privacy Framework, plus the European Patent Organisation. No decision has been withdrawn or suspended. The 2021 standard contractual clauses remain the operative set and are unamended; the promised extra clauses for importers already directly caught by the Regulation are still not adopted. Binding corporate rules remain available. The narrow one-off exceptions are not a basis for routine or bulk transfers, and a transfer impact assessment is still expected. On 31 July 2026 the European Data Protection Board formally asked the European Commission to examine whether changes in the United States affect the validity of the Data Privacy Framework; the framework has not been suspended or revoked, but it should not be your only mechanism. A separate point that catches people: an order from a foreign authority is not by itself a lawful reason to hand data over. For non-personal accounting records the model is different — the European Economic Area, the United Kingdom and Switzerland are free, and anything beyond that needs the tax authority's approval.
Sources
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
- Official sourceSkatteetaten (Norwegian Tax Administration)Storage of electronic accounting material abroad — approval needed outside the European Economic Area, United Kingdom and Switzerland
skatteetaten.no
Link checked 18 August 2026
The regulator, and whether it actually acts
The Norwegian Data Protection Authority, and it is genuinely working, not a name on paper. It had 69 staff at the end of 2024, registered 4,736 new cases that year, issued 384 decisions and five fines, and received 3,191 breach reports. In June 2026 it fined the electronics retailer Elkjøp 20 million Norwegian kroner, roughly 2 million US dollars, over its customer club. Appeals go to a separate board, which does overturn decisions.
The authority is Datatilsynet. Its decisions can be appealed to Personvernnemnda, an independent appeals board that is also active — it overturned a 20 million kroner fine against the labour and welfare administration in 2024, which is useful evidence that appeal is a real remedy rather than a formality. Other regulators enforce in their own lanes and are all operational: Finanstilsynet supervises the finance sector including the digital resilience rules, Nasjonal sikkerhetsmyndighet handles the security act, critical-service incident reporting and airborne sensor control, Nasjonal kommunikasjonsmyndighet supervises telecoms, Arkivverket controls public archives, and Skatteetaten controls accounting records. Rated active rather than aggressive: the fine count is steady and mid-sized rather than headline-grabbing, and the Elkjøp decision itself notes the fine was set low relative to group revenue. Note for automated link checkers: datatilsynet.no serves a broken robots file, so its pages record as robots-blocked rather than unreachable.
Sources
- Official sourceDigitaliserings- og forvaltningsdepartementet / DatatilsynetDatatilsynets årsrapport 2024 — staffing, 4,736 new cases, 384 decisions, five fines, 3,191 breach notifications
regjeringen.no
“I 2024 mottok vi totalt 3 191 slike meldinger”
Link checked 18 August 2026
- Official sourceDatatilsynetOvertredelsesgebyr til Elkjøp — 20 million kroner, 4 June 2026
datatilsynet.no
Link checked 18 August 2026
- Official sourceDatatilsynetAvgjørelser fra Datatilsynet — running list of decisions including 2026 penalties
datatilsynet.no
Link checked 18 August 2026
- Secondary sourceVGDatatilsynet gir Elkjøp gebyr på 20 millioner, 4 June 2026
vg.no
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling. The floor: company accounting records must be kept for five years, with ten years for construction project accounts, bank customer records and some others, and fifteen years in oil and pipeline businesses. The ceiling: personal data must go once the purpose is finished, and phone and internet providers must delete traffic data once it is no longer needed for billing. When a keeping duty and a deleting duty clash, the keeping duty wins for as long as it lasts, and then you delete.
The general accounting retention period dropped from ten years to five with effect from 1 January 2015 under bokføringsloven section 13. The exceptions that stayed at ten years include project accounting in the building and construction trades, documentation for capital assets under value added tax rules where input tax is 100,000 kroner or more, customer and supplier specifications for banks and financial undertakings, and foreign undertakings on the Norwegian continental shelf. Petroleum extraction and pipeline transport keep fifteen years. Records must remain readable and reachable from Norway for the whole period, which is why moving them to a foreign cloud is a notification event rather than a free choice. On the deletion side, the European rulebook's storage limitation principle applies unchanged, and the Electronic Communications Act requires providers to delete traffic data when it is no longer needed for billing or for carrying the communication unless the user consents to longer storage. Norway has no general telecoms data retention mandate in force.
Sources
- Official sourceSkatteetaten (Norwegian Tax Administration)Redusert oppbevaringstid for regnskapsmateriale — five-year rule and the ten- and fifteen-year exceptions
skatteetaten.no
“Oppbevaringstiden for regnskapsmateriale er fra 1. januar 2015 redusert fra ti år til fem år.”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetPersonvern og tilbyders taushetsplikt — duty to delete traffic data, ekomloven sections 3-10 and 3-11
nkom.no
“slette trafikkdata når disse ikke lenger trengs for enten å fakturere kunder eller å iverksette en kommunikasjon”
Link checked 18 August 2026
If something goes wrong
Count three clocks, because they run at once and have different lengths. Providers of essential services have 24 hours to tell the National Security Authority about a serious digital incident, then 72 hours for an update and one month for a full report. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Financial firms have four hours from classifying an incident as serious, and never later than 24 hours after they found it.
Clock one, cybersecurity: the Digital Security Act started on 1 October 2025 and implements the older European network security directive, not the newer one. Its notification form and guidance state that the provider must notify within 24 hours of becoming aware of the incident, with a status report within 72 hours of that notification and a final report within one month. Clock two, privacy: the European rulebook's 72-hour deadline to Datatilsynet, plus notification to the people affected where the risk to them is high. Clock three, finance: the Norwegian digital resilience act applies the European reporting scheme, so an initial notification goes to Finanstilsynet within four hours of classifying an incident as major and at the latest 24 hours after becoming aware of it, an intermediate report within 72 hours of that notification, and a final report within one month of the last intermediate report. A single incident at a bank can therefore trigger all three. A fourth clock exists for organisations covered by the Security Act, which must notify the National Security Authority of security-threatening activity.
Sources
- Official sourceNasjonal sikkerhetsmyndighetVarsle om hendelser etter digitalsikkerhetsloven — 24-hour notification
nsm.no
“Tilbyder skal varsle innen 24 timer etter at tilbyder fikk kjennskap til hendelsen.”
Link checked 18 August 2026
- Official sourceFinanstilsynet (Financial Supervisory Authority of Norway)Hendelsesrapportering etter DORA, circular of 30 June 2025 — four-hour, 72-hour and one-month reports
finanstilsynet.no
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
What catches people out
Five things that are not in the summary. A child can consent from age 13 in Norway, lower than in several neighbours. You may only use a person's national identity number where there is a real need for secure identification. Reading an employee's work mailbox has its own rulebook, and getting it wrong is a breach even if you had a good reason. Moving your accounting records abroad needs a notification to the tax office and only works inside Europe, Britain and Switzerland. Aerial photographs and drone sensor readings are controlled before you may release them.
One: personopplysningsloven section 5 sets the age for a child's own consent to online services at 13. Two: section 12 says the national identity number and other unique identifiers may only be processed where there is an objective need for secure identification and the method is necessary to achieve it, so using it as a customer reference is unlawful. Three: employer access to an employee's mailbox and other stored material is governed by a separate 2018 regulation, which sets out when access is allowed, requires the employee to be told and given the chance to be present, and requires deletion at the end of employment; this sits on top of, not instead of, the privacy rules. Four: electronic accounting material may sit in the European Economic Area, the United Kingdom or Switzerland, but you must notify your tax office and keep the records reachable from Norway; anything outside that group needs approval. Five: photography, filming and other sensor use from the air is restricted around military and sensitive sites, other sensor types outside restricted areas must be notified to the National Security Authority, and foreign aircraft using sensors over Norway must notify. Six, for public bodies: taking archive material out of Norway needs the National Archivist's consent, which quietly makes some offshore hosting arrangements unlawful for the public sector even where privacy law would allow them.
Sources
- Official sourceStortingetPersonopplysningsloven as adopted — section 5 (age 13) and section 12 (national identity number)
stortinget.no
“Fødselsnummer og andre entydige identifikasjonsmidler kan bare behandles når det er saklig behov for sikker identifisering”
Link checked 18 August 2026
- Official sourceLovdataForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materiale, FOR-2018-07-02-1108
lovdata.no
- Official sourceNasjonal sikkerhetsmyndighetLuftbårne sensorsystemer — control of airborne sensor information
nsm.no
“Det er varslingsplikt til NSM for bruk av andre sensorer enn foto/video utenfor forbudsområdene”
Link checked 18 August 2026
- Official sourceArkivverketVeileder for midlertidig utførsel av arkiv til utlandet — National Archivist's consent
arkivverket.no
Link checked 18 August 2026
What's changing next
The biggest thing about Norway right now is what has not arrived. Three European laws that apply in the European Union are not yet Norwegian law: the Data Act, the newer cybersecurity law known as NIS2, and the Artificial Intelligence Act. A new Norwegian data sharing act was passed on 19 June 2026. Parliament has told the government to map Norway's digital dependence on other countries, with a first report due by the end of 2026.
Not yet in force in Norway, verified 18 August 2026. The Data Act is still under assessment by the European Economic Area states and has not been incorporated; its January 2027 ban on cloud switching charges therefore does not bind Norwegian providers today, and incorporation needs Parliament's consent. NIS2 has not been incorporated either — Norway's Digital Security Act, in force since 1 October 2025, implements the older 2016 directive, so Norway is running one generation behind the European Union on cybersecurity duties. The Artificial Intelligence Act is to be taken in through the European Economic Area Agreement and adapted to Norwegian law, with no confirmed date; the transparency duties that started in the European Union on 2 August 2026 do not yet apply here. Recently landed: the Digital Operational Resilience Act for finance started on 1 July 2025 and its Norwegian regulation was amended on 26 January 2026; the data sharing and data governance act was sanctioned on 19 June 2026, bringing in the European data governance regulation, the open data directive and high-value datasets. Dormant switches worth watching: the tax authority can refuse or condition approval for accounting records held outside Europe; the National Archivist can refuse consent to move public archives; the National Security Authority's approval regime can effectively close off foreign hosting for security-relevant systems; and a 2021 amendment on storing internet protocol addresses for police use was adopted by Parliament but we could not confirm that it is in force under the 2024 Electronic Communications Act. On the European side, the pressure on the European Union to United States Data Privacy Framework is the single most time-sensitive item: the appeal in the Latombe case is pending before the Court of Justice, and on 31 July 2026 the European Data Protection Board asked the Commission to examine the decision's validity.
Sources
- Official sourceRegjeringen.no (Norwegian Government)EØS-notat: Dataforordningen (Data Act) — under assessment by the EEA EFTA states, not incorporated
regjeringen.no
“Forordningen er til vurdering i EØS-EFTA-statene”
Link checked 18 August 2026
- Official sourceRegjeringen.noEØS-notat: NIS2-direktivet — not yet incorporated into the EEA Agreement
regjeringen.no
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetKI-loven i et nøtteskall, 10 June 2026 — the AI Act is to be taken into Norwegian law through the EEA Agreement
nkom.no
“I Norge skal regelverket tas inn gjennom EØS-avtalen og tilpasses norsk rett og forvaltning”
Link checked 18 August 2026
- Official sourceStortingetInnst. 225 S (2025–2026) — digital sovereignty; government to map digital dependencies, first report by end of 2026
stortinget.no
Link checked 18 August 2026
- Official sourceStortingetLov om datadeling og dataforvaltning (dataforvaltningsloven) — passed 15 June 2026, sanctioned 19 June 2026
stortinget.no
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Lov om arkiv (arkivlova) § 9 bokstav b
Act of parliament · LOV-1992-12-04-126
A public body's archive material may not be taken out of Norway without the National Archivist's consent. This is a genuine location rule for the public sector, and it applies even where privacy law would allow the data to move.
Enforced by National Archives of Norway
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryArchive material may not be taken out of Norway except under regulations or with the National Archivist's specific consent.
- Secure the dataThe National Archivist expects binding safeguards for transport, storage and prevention of unauthorised access, and recommends suppliers inside the European Union or European Economic Area.
Sources
- Official sourceArkivverketVeileder for midlertidig utførsel av arkiv til utlandet
arkivverket.no
“Utan i samsvar med føresegner gjevne i medhald av § 12 [...] eller etter særskilt samtykke frå Riksarkivaren, kan ikkje arkivmateriale førast ut or landet”
Link checked 18 August 2026
Lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) og DORA-forskriften
Act of parliament · LOV-2025-05-27-18; FOR-2025-06-24-1296, amended by FOR-2026-01-26-87
Since 1 July 2025 Norwegian banks, insurers, payment firms and investment firms follow Europe's digital resilience rules through a dedicated Norwegian act. There is no storage location requirement, but contracts must disclose where data sits and give audit and exit rights, and incidents must be reported on a very short clock.
Enforced by Financial Supervisory Authority of Norway
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractTechnology contracts must state where data is processed and stored, and give audit and exit rights.
- Keep records of processingA register of all technology service arrangements must be maintained and reported.
- Register or notifyPlanned contracts supporting critical or important functions must be notified to the supervisor. This replaced the older Norwegian outsourcing notification duty for firms inside the scope.
- Report cyber incidents — within 4 hoursWithin four hours of classifying an incident as major, and at the latest 24 hours after becoming aware of it. Intermediate report within 72 hours, final report within one month.
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory orders, including on technology arrangements
- Loss of your licenceSerious or repeated breach by a licensed firm
Sources
- Official sourceFinanstilsynetQ&A DORA — entry into force 1 July 2025 and the replacement of the earlier outsourcing notification duty
finanstilsynet.no
Link checked 18 August 2026
- Official sourceFinanstilsynetNy lov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven) trer i kraft 1. juli 2025
finanstilsynet.no
- Official sourceLovdataLov om digital operasjonell motstandsdyktighet i finanssektoren (DORA-loven)
lovdata.no
- Official sourceFinanstilsynetHendelsesrapportering etter DORA, 30 June 2025
finanstilsynet.no
Link checked 18 August 2026
Lov om digital sikkerhet (digitalsikkerhetsloven) og digitalsikkerhetsforskriften
Act of parliament · Digitalsikkerhetsloven; FOR-2025-06-20-1131
Norway's cybersecurity law for essential and digital service providers started on 1 October 2025 and implements Europe's older network security directive, not the newer NIS2. It requires a 24-hour incident notification but says nothing about where data must be stored.
Enforced by Norwegian National Security Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataRisk-based security requirements for providers of essential and digital services in energy, transport, health, water, banking, financial market infrastructure, digital infrastructure and digital services.
- Report cyber incidents — within 24 hoursNotify within 24 hours of becoming aware. Status report within 72 hours of the notification, full report within one month.
What it costs if you get it wrong
- Fixed maximum fineAdministrative fines for failure to secure services or to notify
Sources
- Official sourceRegjeringen.noNy lov om digital sikkerhet trer i kraft i dag — 1 October 2025, implementing the NIS1 directive
regjeringen.no
“Loven gjennomfører EUs NIS1-direktiv som ble vedtatt i 2016”
Link checked 18 August 2026
- Official sourceNasjonal sikkerhetsmyndighetVarsle om hendelser etter digitalsikkerhetsloven
nsm.no
“Tilbyder skal varsle innen 24 timer etter at tilbyder fikk kjennskap til hendelsen.”
Link checked 18 August 2026
Forskrift om kontroll med informasjon innhentet med luftbårne sensorsystemer
Directly binding regulation · FOR-2018-06-22-951
Pictures and sensor readings collected from aircraft and drones over Norway are controlled. Some areas are off limits, some sensor types must be notified to the National Security Authority, and foreign aircraft using sensors must notify before flying.
Enforced by Norwegian National Security Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyNotification to the National Security Authority for sensor types other than photo and video outside restricted areas, and for any sensor use by foreign aircraft over Norway.
- Secure the dataPhotography and filming from the air is banned in and around designated military and sensitive installations.
What it costs if you get it wrong
- Fixed maximum fineBreach of the restrictions on airborne sensor use
Sources
- Official sourceNasjonal sikkerhetsmyndighetLuftbårne sensorsystemer
nsm.no
“Det er varslingsplikt til NSM for bruk av andre sensorer enn foto/video utenfor forbudsområdene”
Link checked 18 August 2026
- Official sourceLovdataForskrift om kontroll med informasjon innhentet med luftbårne sensorsystemer
lovdata.no
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Lov om behandling av personopplysninger (personopplysningsloven)
Act of parliament · LOV-2018-06-15-38
The national privacy statute that makes the European rulebook Norwegian law and adds local detail. It sets the age of a child's own consent at 13, restricts use of the national identity number, and reaches foreign companies that target or monitor people in Norway. It imposes no storage location requirement.
Enforced by Norwegian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for childrenA child may consent to online services from age 13; below that a parent must consent.
- Allowed because the law requires itThe national identity number may only be used where there is an objective need for secure identification.
- Appoint a data protection officerSame trigger as the European rulebook. No requirement that the officer be resident in Norway.
- Put a transfer safeguard in place
What it costs if you get it wrong
- Percentage of global turnover: 4 % of worldwide group turnover, applied in Norwegian kronerBreach of the privacy rules
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceStortingetVedtak til lov om behandling av personopplysninger, sections 2, 5 and 12
stortinget.no
“Fødselsnummer og andre entydige identifikasjonsmidler kan bare behandles når det er saklig behov for sikker identifisering”
Link checked 18 August 2026
- Official sourceLovdataPersonopplysningsloven, consolidated text
lovdata.no
Link checked 18 August 2026
Bokføringsforskriften § 7-5, jf. bokføringsloven § 13 (endring om oppbevaring av elektronisk regnskapsmateriale i utlandet)
Directly binding regulation · Amendment announced by Skatteetaten 29 January 2025, in force 27 January 2025
Every Norwegian company's accounting records may only be stored electronically in the European Economic Area, the United Kingdom or Switzerland, and you must tell the tax office where they are. Storage anywhere else needs approval. Records must stay reachable electronically from Norway for the whole retention period.
Enforced by Norwegian Tax Administration
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryElectronic accounting records may be kept in the European Economic Area, the United Kingdom and Switzerland. Anywhere else needs the tax authority's approval.
- Keep data for a minimum period — 5 yearsFive years for primary documentation. Ten years for construction project accounts, bank customer and supplier specifications and some other categories; fifteen years for petroleum extraction and pipeline transport.
- Register or notifyYou must notify your local tax office that the records are held abroad.
What it costs if you get it wrong
- Fixed maximum fineEnforcement fines and orders by the tax authority for bookkeeping failures
Sources
- Official sourceSkatteetatenOppbevaring av elektronisk regnskapsmateriale i utlandet — endringer i bokføringsforskriften og skattebetalingsforskriften
skatteetaten.no
“Elektronisk regnskapsmateriale kan oppbevares i EØS-området, Storbritannia og Sveits”
Link checked 18 August 2026
- Official sourceSkatteetatenRedusert oppbevaringstid for regnskapsmateriale
skatteetaten.no
“Oppbevaringstiden for regnskapsmateriale er fra 1. januar 2015 redusert fra ti år til fem år.”
Link checked 18 August 2026
Applies across the EEA2 rules
Written once for the whole bloc, and in force in every member country.
Forordning (EU) 2016/679 (personvernforordningen), incorporated into the EEA Agreement
Directly binding regulation · EEA Joint Committee Decision No. 154/2018 of 6 July 2018
Europe's General Data Protection Regulation applies in Norway through the European Economic Area Agreement, not through European Union membership. It does not require personal data to stay in Norway or in Europe; it sets the conditions for sending it out.
Enforced by Norwegian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Put a transfer safeguard in place
- Written vendor contract
- Appoint a local representativeOnly where the organisation has no establishment in the European Economic Area.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWhere the breach is likely to result in a high risk to the people affected.
What it costs if you get it wrong
- Percentage of global turnover: 4 % of worldwide group turnoverBreach of basic principles, individual rights or the transfer rules
- Fixed maximum fine: €20 million — about $22 millionAlternative ceiling where higher than the turnover figure
- Order to stopOrder to stop processing or suspend flows to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEFTA SecretariatEEA-Lex: GDPR incorporated by Joint Committee Decision 154/2018, in force in the EEA 20 July 2018
efta.int
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Dataforordningen (Data Act), NIS2-direktivet og KI-forordningen (AI Act) — ikke innlemmet i EØS-avtalen
Directly binding regulation · Regulation (EU) 2023/2854; Directive (EU) 2022/2555; Regulation (EU) 2024/1689
Three European digital laws that people assume apply in Norway do not. The Data Act is still under assessment by the European Economic Area states, the newer cybersecurity law known as NIS2 has not been incorporated, and the Artificial Intelligence Act is still being prepared for Norwegian law. None of them creates rights or duties in Norway today.
Enforced by Norwegian Communications Authority
Transfer model: No restriction
What it makes you do
- Make switching cloud provider possibleThe Data Act duty to remove cloud switching charges by 12 January 2027 does NOT yet bind in Norway, because the regulation has not been incorporated into the European Economic Area Agreement.
Sources
- Official sourceRegjeringen.noEØS-notat: Dataforordningen
regjeringen.no
“Forordningen er til vurdering i EØS-EFTA-statene”
Link checked 18 August 2026
- Official sourceNasjonal kommunikasjonsmyndighetKI-loven i et nøtteskall, 10 June 2026
nkom.no
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the 2021 amendment requiring providers to store internet protocol addresses for police use is in force today
Parliament passed the amendment on 18 June 2021, but we could not verify from a government source whether it was ever commenced or how it was carried over into the Electronic Communications Act that started on 1 January 2025. The communications regulator's own page describes only a duty to delete traffic data. Treat any claim that Norway has telecoms data retention with suspicion until the commencement notice is found.
Whether any Norwegian gambling rule requires gaming systems or player data to be located in Norway
No rule found, checked 18 August 2026, medium confidence. We located the Gambling Act and the Gambling Regulation but could not open the regulator's own text of the technical requirements, and Norway's monopoly model means the question is rarely tested. Absence of a finding is not proof of absence.
The exact current status of the Data Act, NIS2 and the Artificial Intelligence Act in the European Economic Area process
The government's own European Economic Area notes are the authoritative source but are themselves stale: the Data Act note was last revised in October 2024 and the NIS2 note in August 2023. The direction is clear and the communications regulator confirmed in June 2026 that the artificial intelligence rules are still to be taken in, but a Joint Committee decision could have been taken since the notes were updated.
Whether breaching the bookkeeping rules is a criminal offence in Norway as well as an administrative matter
Norwegian criminal law contains accounting offences, but we did not verify the provision or its penalties from a government source during this run, so no criminal penalty is recorded on the accounting rule.
The full operative text and section numbers of bokføringsforskriften § 7-5 as amended
We relied on the tax administration's own announcement of the amendment, which quotes the operative wording, rather than the consolidated regulation text, because the official law database blocks automated fetching.
Whether Datatilsynet issued further fines between 1 and 18 August 2026
The regulator's site serves a broken robots file and could not be fetched. Decisions up to June 2026 were confirmed through search listings of its own decision pages and a media report of the Elkjøp fine. We cannot prove the absence of later decisions.
Whether any Norwegian health rule requires patient records to be hosted inside Norway
No rule found, checked 18 August 2026. The Directorate of Health's guidance treats the question as a transfer assessment under the European rulebook rather than a location ban, but we did not review every registry-specific regulation, and the health sector's information security norm imposes additional contractual requirements we did not read in full.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Norway versus
Compare