Insights
All analysis, sorted by date.
AI agent liability: who pays when an AI agent causes harm?
Under Norwegian law, AI agent liability rests primarily with the business that puts the agent to work. An agent is neither a legal person nor an employee, so the harm is treated as the business's own. Towards customers, ordinary contractual liability applies. The vendor is liable only as far as the contract allows, and the new EU Product Liability Directive does not yet apply in Norway.
Anonymisation under the EDPB guidelines: is your data really anonymous?
Anonymisation under the GDPR requires the likelihood of identifying anyone to be insignificant, assessed from the perspective of whoever will use the data. The draft EDPB guidelines 02/2026 build on the SRB judgment and apply three criteria, singling out, linkability and inference. A processor inherits its customer's perspective, and the assessment must be repeated over time.
Checking AI-generated text: what can businesses learn from a ruling set aside?
Checking AI-generated text means checking it against the source, not against how plausible it sounds. In September 2026 a Norwegian court of appeal set aside a ruling that set out nine paragraphs of submissions no party had made, and the court has confirmed AI was used. The same error in contracts, board papers or replies to regulators binds the business or misleads the board.
Duty to cooperate with the Data Protection Authority: what does it require?
The duty to cooperate under GDPR Art. 31 means a business must answer the Norwegian Data Protection Authority within the deadline and produce the documents it asks for, including contracts with a confidentiality clause. The business may disagree and appeal the order. Threats against case officers and repeated stalling are a breach, and cost Lab Pharma AS a NOK 205,000 fine in August 2026.
Location data: when does tracking become high-risk processing under the GDPR?
Location data becomes high-risk processing when a person's position is tracked systematically over time, particularly employees or app users. Datatilsynet will then usually require a DPIA. The business needs a clear purpose and legal basis, must inform plainly and delete early. Apps reading the phone's position normally also need consent under the Electronic Communications Act § 3-15.
Marketing consent for ‘partners’: what does the Canal+ case mean?
Marketing consent given to ‘our partners’ only covers businesses whose identity the data subject knew when consenting. That is the view of the Advocate General in Canal+ (C-317/25). Any other sender must obtain fresh consent before marketing, and an unsubscribe link in the first email does not cure the defect. The judgment is still to come.
Nordlo judgment: why did the customer get only NOK 8,280 after a cyber attack?
In the Nordlo judgment of 30 June 2026, Gulating Court of Appeal held that Btec AS, which lost its production data in a ransomware attack on its IT supplier and claimed over NOK 57 million, was bound by the supplier's unsigned standard terms. The attack was not force majeure, the supplier was not grossly negligent, and a cap of three months' fees gave NOK 8,280.
Norway's AI agreement: what must employers discuss before introducing AI?
Norway's AI agreement of 2 October 2026 is a letter of intent between the government and the social partners. It places no new obligations on individual employers, whose duties come from the Working Environment Act and collective agreements. If AI changes how work is organised, or can be used to monitor staff, it must be discussed with employee representatives before the decision is made.
Personal data in test environments: can we test with real customer data?
Personal data in test environments may only be used where testing is compatible with the purpose for which the data was collected, under GDPR Art. 6(4), and where synthetic or pseudonymised data will not do. Private businesses have no special rule. Copies of production data used for testing need the same security, access control and deletion as production.
AI hallucinations: who is liable when your chatbot promises a customer too much?
A business is liable for AI hallucinations in its own customer service. The chatbot is not a separate legal person, and what it says counts as the business's own statements. Towards consumers, wrong answers can give rise to claims for non-conformity, and misleading answers can breach Norwegian marketing law. A disclaimer in the chat window helps little.
AI literacy is now a requirement: what Article 4 of the AI Act means for your business
AI literacy is a requirement under Article 4 of the AI Act. Businesses that use AI at work must take measures to build literacy among staff and others who use the systems on their behalf. The requirement has applied in the EU since 2 February 2025 and was softened in July 2026. It does not yet apply in Norway, but should be prepared for now.
AI policy for employees: what can an employer require and monitor?
Under Norwegian law, an employer can set an AI policy for employees under its managerial prerogative, including bans on certain tools and requirements to check the output. Monitoring how employees actually use AI is a control measure that requires objective grounds, discussion with employee representatives and prior information. Continuous monitoring of individual use is generally prohibited.
Board responsibility for AI: what should the board ask before its next meeting?
Board responsibility for AI follows from the general rules of the Norwegian Companies Act. The board must ensure the business is properly organised, subject to adequate control and that the chief executive is supervised, and this also covers the use of artificial intelligence. The board does not need technical expertise, but it must know where AI is used, what the risk is and who is responsible.
Choice of law and jurisdiction: which country's law governs your contract?
Choice of law and jurisdiction clauses decide which country's law governs the contract and where a dispute is resolved. As a rule, the parties can agree both. If the contract is silent, Norwegian law applies the law of the country with the closest connection, while jurisdiction follows the Dispute Act and the Lugano Convention. Choose deliberately, especially under US standard terms.
Cloud exit: how do you secure your data when the contract ends?
A cloud exit must be secured in the contract before it is signed. The contract should give a right to all data in a machine-readable format, assistance from the provider, a transition period and documented deletion. In the EU the Data Act requires at most two months' notice, a 30-day transition and at least 30 days' access to the data. In Norway the regulation does not yet apply.
Cookies and newsletters: when do you need consent in Norway?
Cookies and consent go hand in hand under the Norwegian Electronic Communications Act § 3-15. From 1 January 2025 cookie consent must meet the GDPR requirements, and browser settings are no longer enough. Only strictly necessary cookies are exempt. Email newsletters to private individuals require consent under the Marketing Control Act § 15, with a narrow exception for existing customers.
Copyright and AI: who owns the text, code and images that AI creates?
Content that AI creates entirely on its own probably has no copyright under Norwegian law, because the Copyright Act requires original and individual creative effort by a human. If a human reworks the output creatively, the human contribution may be protected. A vendor's promise that you own the output gives no more protection than the law itself provides.
Transferring personal data to the US: how safe is the Data Privacy Framework?
The Data Privacy Framework makes it lawful to transfer personal data to US companies certified under it. The adequacy decision applies in Norway and was upheld by the EU General Court in 2025, but the case has been appealed and US oversight bodies have been weakened. Businesses should use the framework, but keep standard contractual clauses and an exit plan in reserve.
DPIA for AI tools: when is it required, and what must it contain?
A DPIA for AI tools is required when their use is likely to result in a high risk to data subjects, under GDPR Art. 35. AI tools with access to email, documents, customer data or employee data often meet the threshold. If two or more of the nine criteria in the Article 29 Working Party guidelines are met, you should assume that a DPIA is required.
When can an employer access an employee's email in Norway?
Under Norwegian law, employers may only access an employee's email when access is necessary for day-to-day operations or other legitimate interests, or where there is a well-founded suspicion of serious misconduct. As a rule the employee must be notified in advance and be able to attend. Automatic forwarding counts as unlawful monitoring and has led to administrative fines.
NDA: what should it contain, and what does it not protect?
A non-disclosure agreement (NDA) is a contract under which confidential information may only be used for a specific purpose and must not be passed on. It should define what is confidential, set out exceptions, duration and remedies, and regulate the use of AI tools. It binds only the parties, and it cannot prevent whistleblowing or protect information that is already known.
Personal data breach: what must you do within 72 hours?
A personal data breach must be notified to the Norwegian Data Protection Authority without undue delay and, where feasible, within 72 hours of the business becoming aware of it, unless the breach is unlikely to result in a risk. Where the risk is high, the affected individuals must also be informed. All breaches must be documented, including those that are not notified.
SaaS data processing agreement: what must it contain, and what should you require?
When a SaaS supplier processes personal data on your behalf, GDPR Art. 28 requires a written SaaS data processing agreement. It must cover instructions, confidentiality, security, sub-processors, assistance, deletion and audits, among others. The supplier's standard terms often meet the minimum, but rarely the customer's needs on breach notification, insight, transfers outside the EEA and exit.
SaaS limitation of liability: what holds up under Norwegian law?
A SaaS limitation of liability is, as a rule, valid between businesses under Norwegian law. A liability cap and an exclusion of indirect loss normally hold, but as a starting point they do not protect the supplier against wilful misconduct or gross negligence. Unusual and onerous terms may also fall away as not accepted, be read restrictively or be adjusted under the Contracts Act § 36.
SaaS price increase from your provider: what can you do?
A SaaS price increase requires a basis in the contract. Without a change clause, the agreed price is binding for the contract term. Where the provider has reserved the right to change prices, the clause is generally valid between businesses, but it may be read narrowly or adjusted under section 36 of the Norwegian Contracts Act. The customer's key tools are a right to terminate and an agreed cap.
Subject access requests from staff and customers: deadlines, exemptions and disputes
A subject access request under GDPR Art. 15 must be answered without undue delay and within one month at the latest. The deadline can be extended by two months for complex requests. The requester need not give reasons, and the request cannot be refused because it is used in an employment dispute or litigation. Only exceptionally can a request be refused as manifestly unfounded or excessive.
Your secrets in ChatGPT: can you lose protection for trade secrets?
Trade secrets are only protected if the business has taken reasonable steps to keep them secret. One employee pasting a confidential document into ChatGPT does not normally remove that protection. But if the business lets employees use AI tools freely, without rules and without an enterprise agreement, it becomes hard to show reasonable steps when the secret later has to be enforced.
Vibe lawyering: what is the risk when management drafts contracts with AI?
Vibe lawyering means managers and specialists producing contracts with AI without legal review. The contract binds the company in full, even when it rests on foreign concepts, hallucinated references or liability rules that do not work under Norwegian law. AI can be used for simple agreements, but not without review when a lot is at stake.