PrivacyChecker
🇳🇴

GDPR Compliance in Norway

Norge · Norwegian Personal Data Act

TL;DR

Websites targeting users in Norway must comply with GDPR as implemented locally through the Norwegian Personal Data Act. The supervisory authority is the Datatilsynet. Notable enforcement: Grindr fined for consent violations (€6.5 million). Use our free scanner below to check your website instantly.

Check your website's Norway compliance now

Free audit — 25+ automated checks in 60 seconds

Scan My Website Free →

Data Protection Authority

Authority

Datatilsynet

Local Law

Norwegian Personal Data Act

Language

Norwegian

Largest Fine

€6.5 million

Population

5.5 million

Key Requirements for Norway

GDPR applies via EEA agreement

Strict consent requirements for tracking and analytics

DPO mandatory for public bodies

Data breach notification within 72 hours

Special provisions for research data

Employee data processing has additional safeguards

What Makes Norway Different?

Norway (via EEA) applies GDPR directly. The Norwegian Datatilsynet made international headlines by fining Grindr €6.5M for sharing user data with advertisers without valid consent. They are also active on AI regulation.

Norway Website Compliance Checklist

Cookie consent banner that requires opt-in before non-essential cookies

Privacy policy available in Norwegian

Clear identification of data controller and contact details

Data Processing Agreement (DPA) with all third-party processors

Lawful basis documented for each processing activity

Data Subject Access Request (DSAR) process in place

Data breach notification procedure compliant with 72-hour rule

Data Protection Impact Assessment for high-risk processing

International data transfer mechanisms documented (SCCs, adequacy decisions)

Records of processing activities (ROPA) maintained

Frequently Asked Questions

What are the GDPR requirements for websites in Norway?

In Norway, websites must comply with GDPR as implemented by the Norwegian Personal Data Act. Key requirements include obtaining explicit consent before setting non-essential cookies, providing a clear privacy policy, appointing a DPO when required, and notifying data breaches within 72 hours to the Datatilsynet.

Who enforces GDPR in Norway?

The Datatilsynet is the supervisory authority responsible for enforcing data protection laws in Norway. They can investigate complaints, conduct audits, and issue fines up to €20 million or 4% of annual global turnover.

How can I check if my website complies with Norway data protection laws?

Use PrivacyChecker's free scanner to perform an instant audit of your website. Our tool checks 25+ compliance points including cookie consent, privacy policy presence, security headers, tracker detection, and more — all relevant to Norway's GDPR requirements.

Is your website compliant in Norway?

Find out in 60 seconds with our free GDPR scanner

Run Free Audit →

GDPR Compliance in Other Countries

🇩🇪Germany🇫🇷France🇳🇱Netherlands🇪🇸Spain🇮🇹Italy🇧🇪Belgium🇦🇹Austria🇵🇱Poland