What Is Personal Data Act, LOV-2018-06-15-38?
Norway is an EEA/EFTA country, not an EU Member State. GDPR applies in Norway through its incorporation into the EEA Agreement and through the Norwegian Personal Data Act; section 1 gives GDPR force as Norwegian law with EEA adaptations. The specific incorporation instrument is EEA Joint Committee Decision No. 154/2018 of 6 July 2018, and EFTA supervisory authorities participate in the EDPB consistency mechanism without voting rights. The current consolidated statute is the Personal Data Act, LOV-2018-06-15-38, enacted on 15 June 2018 and in force from 20 July 2018. Lovdata identifies LOV-2021-06-18-124 as the latest statutory amendment, effective 1 January 2022, plus a later non-substantive correction. GDPR Chapter III rights apply through EEA incorporation, subject to targeted Norwegian rules on expression, research, criminal-offence data, special-category processing, information-society-service consent age, and fødselsnummer. Datatilsynet is Norway's ordinary supervisory and enforcement authority. It recommends contacting the controller first; its digital complaint form requires Norwegian electronic ID and is available only in Norwegian, while a written postal route exists. No fixed statutory resolution deadline was located; the approximately one-year handling time is a practical average. Decisions may generally be appealed to Personvernnemnda, except certain cross-border Article 56 and Chapter VII decisions handled through the EDPB consistency mechanism. No Norway-specific general consumer data-broker opt-out registry or standalone public-record deletion portal was located in this bounded review. The ordinary GDPR rights-request route remains available, while the 2022 Credit Information Act and statutory tax-list disclosure regime create adjacent sector-specific rules that must not be conflated with a universal broker opt-out.
At a glance
- Full name
- Personal Data Act, LOV-2018-06-15-38
- Short code
- Personal Data Act
- Jurisdiction
- Norway
- Enacted
- 2018
- Last major update
- Latest located statutory amendment is LOV-2021-06-18-124, effective 1 January 2022, plus a later non-substantive correction
- Regulator
- Norwegian Data Protection Authority (Datatilsynet)
- Private right of action
- Limited
- Statutory citation
- Personal Data Act, LOV-2018-06-15-38
Scope, who Personal Data Act covers
Protected data
Data subject rights
Right to transparent information and assistance in exercising rights
Right to collection-time information under GDPR Articles 13-14
Right of access under Article 15
Right to rectification under Article 16
Right to erasure under Article 17, subject to exceptions
Right to restriction of processing under Article 18
Right to data portability under Article 20
Right to object under Article 21, including an absolute objection to direct marketing
Safeguards concerning automated decision-making under Article 22
Right to complain to Datatilsynet after contacting the controller
Right to appeal eligible Datatilsynet decisions to Personvernnemnda, subject to cross-border exceptions
Notable features
Norway’s GDPR framework is based on EEA incorporation rather than direct EU Member State applicability. EEA/EFTA supervisory authorities participate in the EDPB consistency mechanism without voting rights, while the EFTA Surveillance Authority does not replace Datatilsynet as first-instance enforcer. Norwegian-specific features include the fødselsnummer necessity rule, a qualified freedom-of-expression exception, and a Svalbard rule excluding GDPR Article 56 and Chapter VII. The current credit-information regime is not a licensing regime: the previous licence system ended when the Credit Information Act took effect on 1 July 2022.
Enforcement & penalties
Regulator: Norwegian Data Protection Authority (Datatilsynet)
Penalties: GDPR Article 83, incorporated into Norwegian law, permits fines up to €10 million or 2% of worldwide turnover for Article 83(4) infringements and up to €20 million or 4% of worldwide turnover for Articles 83(5)-(6), assessed against factors including gravity, duration, intent, mitigation, prior infringements, cooperation, data categories, and notification. Norwegian §26 extends Article 83(4) to breaches of GDPR Articles 10 and 24 and permits public authorities and bodies to be fined under the Article 83(7) national option. Section 29 permits coercive daily fines, but no universal fixed amount was located. The EFTA Surveillance Authority does not replace Datatilsynet as the first-instance complaint or sanctioning authority.
Private right of action: Datatilsynet complaints, Personvernnemnda appeals, and the Article 78(2) judicial-remedy context are the identified mechanisms. Certain cross-border Article 56 and Chapter VII decisions are excluded from the ordinary Board route. A separate general private damages action was not identified in the reviewed report, so these administrative and judicial-remedy routes should not be presented as a blanket private right of action.
Relevance to data brokers
No Norway-specific general consumer data-broker opt-out registry or standalone public-record deletion portal was located in this bounded review — a "not located" finding, not confirmed nonexistence. The general route is an ordinary GDPR rights request against the relevant controller, followed by a Datatilsynet complaint if necessary. The Credit Information Act provides sector-specific rules on access, prior notification, correction, credit freezes, disclosure records, retention, and deletion or correction, but Norway no longer operates the former credit-reporting licensing regime. Tax Administration Act §9-7 authorizes specified public tax lists, while search-engine index removal is a separate and qualified process rather than deletion at source.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does GDPR apply to Norway as an EU Member State?+
No. Norway is an EEA/EFTA country, not an EU Member State. GDPR applies through its incorporation into the EEA Agreement and section 1 of the Norwegian Personal Data Act. EEA Joint Committee Decision No. 154/2018 is the specific incorporation instrument identified in the reviewed materials.
How do I complain to Datatilsynet?+
Contact the controller first, then complain to Datatilsynet. The digital complaint form requires Norwegian electronic ID such as BankID or ID-porten and is available only in Norwegian; a written postal route exists as an alternative. No fixed statutory resolution deadline was located, and the approximately one-year handling time is a practical average rather than a statutory deadline.
Does Norway have a dedicated data-broker deletion route?+
No Norway-specific general consumer data-broker opt-out registry or standalone public-record deletion portal was located in this bounded review. The ordinary GDPR rights-request route remains available. Credit-reporting and tax-list rules are sector-specific and do not establish a universal broker opt-out.
Official sources & citations
Other international privacy regimes
Personal Data Act sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
