Cookies and consent go hand in hand under the Norwegian Electronic Communications Act § 3-15. From 1 January 2025 cookie consent must meet the GDPR requirements, and browser settings are no longer enough. Only strictly necessary cookies are exempt. Email newsletters to private individuals require consent under the Marketing Control Act § 15, with a narrow exception for existing customers.
Most Norwegian websites use cookies, and most businesses send newsletters. Both are governed by special rules that apply in addition to the GDPR. The cookie rules became considerably stricter from 1 January 2025, and many consent banners still do not meet the requirements.
What does the Electronic Communications Act say about cookie consent?
Cookies and any other storage of, or access to, information on the user’s device require consent under Electronic Communications Act § 3-15. The provision is found in the new Norwegian Electronic Communications Act (ekomloven), which entered into force on 1 January 2025. The user must be informed of, among other things, what information is processed, the purpose and who is processing it, and the user must have consented.
The rule applies whether or not personal data is processed. It covers not only cookies in the narrow sense, but any technology that stores or reads information on a mobile phone, tablet or computer. This includes local storage in the browser, fingerprinting techniques and tracking pixels. The European Data Protection Board (EDPB) takes the view in its Guidelines 2/2023 that tracking pixels in emails are also covered by the corresponding EU rule.
What is new from 2025?
What is new is that consent must meet the GDPR requirements. Under Electronic Communications Act 2003 § 2-7b of the old Act, the preparatory works accepted that users could consent through their browser settings. That approach no longer applies. The Norwegian Data Protection Authority (Datatilsynet) has stated that consent via browser settings is not valid under the new rules.
Section 3-15 implements Article 5(3) of the EU ePrivacy Directive. Norway has thereby aligned itself with the position EU member states have had since the GDPR took effect.
Which cookies are exempt from consent?
Only two types of storage are exempt. These are technical storage carried out solely to transmit a communication over an electronic network, and storage that is strictly necessary to provide a service the user has explicitly requested.
The exemptions are narrow. A cookie that keeps the contents of the shopping basket, remembers the login or stores the user’s choice in the consent banner will normally be strictly necessary. Analytics, ad measurement, retargeting, A/B testing and embedded third-party services normally are not. The fact that the business itself considers the statistics necessary to run the website is not decisive. The assessment starts from what the user has asked for.
| Purpose | Consent? |
|---|---|
| Shopping basket and login | No, normally strictly necessary |
| Storing the consent choice | No |
| Security and load balancing | No, where linked to the service |
| Visitor statistics and analytics | Yes |
| Advertising pixels and retargeting | Yes |
| Tracking pixel in newsletters | Yes, in the EDPB’s view |
| Embedded video and social media | Yes, where the third party sets cookies |
What is required for consent to be valid?
Consent must be a freely given, specific, informed and unambiguous indication of wishes given by a clear affirmative act. This follows from the definition in GDPR Art. 4(11). Under GDPR Art. 7 the business must be able to demonstrate consent, and it must be as easy to withdraw consent as to give it.
In Planet49 (C-673/17) the Court of Justice of the EU held that pre-ticked boxes do not constitute valid consent. The same applies to continued use of the website or the user closing the banner.
In April 2025 Datatilsynet published guidance with specific requirements for consent banners. The key points are these.
- The reject button must be as visible and as easy to access as the accept button.
- Saying no must not take more clicks than saying yes.
- No boxes may be pre-ticked.
- Information on purposes and on who receives the data must appear in the banner.
- Users must be able to withdraw consent easily, for example via a permanent link at the bottom of the page.
A consent banner that makes it easier to say yes than no does not produce valid consent, and then there is no basis for any of the tracking that follows.
Who supervises the rules?
Datatilsynet and the Norwegian Communications Authority (Nkom) share supervisory responsibility for Electronic Communications Act § 3-15. According to the authorities themselves, Nkom focuses on the technical side, including whether a cookie falls within the exemptions. Datatilsynet assesses whether the consent and information meet the GDPR. Shared supervision raises questions about who sanctions what, and practice is so far limited.
What is the risk of getting cookies wrong?
The biggest risk often lies in the GDPR, not in the Electronic Communications Act. Where valid consent under § 3-15 is lacking, there is normally also no legal basis for the further use of the personal data, such as sharing with advertising platforms. That can lead to an administrative fine under the GDPR and an order to stop the processing. Tracking tools from US providers also involve transfers of personal data outside the EEA. Read more in the article on transfers to the US and the Data Privacy Framework.
The provider of the consent solution or analytics tool is often a processor for the business. A data processing agreement with the SaaS provider that meets GDPR Art. 28 is then required.
When do newsletters need consent under the Marketing Control Act?
Marketing by email and SMS to natural persons requires prior consent under Marketing Control Act § 15(1) of the Norwegian Marketing Control Act (markedsføringsloven). This is a separate rule alongside the GDPR and the Electronic Communications Act, and it is enforced by the Norwegian Consumer Authority (Forbrukertilsynet).
The prohibition also covers email to employees of other businesses where the address is personal, for example ola.nordmann@firma.no. This follows from Forbrukertilsynet’s guidance on marketing by email and SMS, last updated on 8 May 2026. Generic addresses such as post@firma.no are not covered. Many businesses selling to other businesses believe they are exempt because the recipient is a company. That is not correct when the email goes to a named individual.
Consent must be freely given, express and informed. Customers cannot be required to consent in order to buy. It is the business that must prove that consent was given, and Forbrukertilsynet recommends double opt-in, where the recipient confirms the sign-up via a link in the email.
The exception for existing customers
Consent is not required for email within an existing customer relationship under Marketing Control Act § 15(3). The exception has three conditions, and all must be met.
- The business must have obtained the customer’s email address in connection with a sale.
- The marketing must concern the business’s own goods or services corresponding to those on which the customer relationship is based.
- The customer must be able to opt out easily and free of charge, both when the address is collected and in every subsequent communication.
Forbrukertilsynet interprets the customer relationship on a case-by-case basis. An ongoing subscription or membership creates a customer relationship. A one-off purchase of a cheap consumer item normally does not. The customer relationship only lasts for a reasonable time after the sale. Signing up for an event, downloading a free document or entering a competition is not a sale, and does not allow the business to rely on the exception.
| Situation | Consent required? |
|---|---|
| Newsletter to people who have signed up | Consent has been given |
| Offer of a similar service to a subscriber | No, with an opt-out option |
| Offer of entirely different products to an existing customer | Yes |
| Email to a named employee at a prospective customer | Yes |
| Email to post@firma.no | No |
| Purchased email list | Yes, and the buyer must verify the consents itself |
Breaches can be met with prohibitions, coercive fines and administrative fines under Marketing Control Act §§ 40–42. Forbrukertilsynet has acted against unlawful email and SMS campaigns in several cases.
What should the business do?
- Map all cookies and tracking pixels on the website, in apps and in newsletters, and group them by purpose.
- Replace the consent banner if it lacks an equally visible reject button on the first layer, or if tracking starts before the user has responded.
- Test that the choices actually work. Third-party tools commonly load before consent has been given.
- Document consents, both for cookies and for newsletters, and keep a record of the time and the text the user saw.
- Review your email lists. Distinguish between people who have consented, existing customers and others, and stop sending to those without a valid basis.
- Include an unsubscribe link in every mailing, and make sure unsubscribing takes effect immediately.
- Enter into data processing agreements with the providers of the consent solution, analytics tools and mailing tools.
The rules on cookies and consent are now the same in Norway as in the rest of the EEA. That makes it easier to use common solutions, but it also means Norwegian authorities can be expected to follow European practice. See more articles on the topic page on data protection.
Questions and answers
Do we need consent for Google Analytics and similar analytics tools?
Yes, as a general rule. Analytics is not strictly necessary to provide the service the user has requested, and therefore falls outside the exemption in the Electronic Communications Act § 3-15. The analytics tool may only be activated once the user has consented.
Does the consent requirement for newsletters also apply when we send to employees of other businesses?
Yes, when the email goes to a named individual, for example ola.nordmann@firma.no. The Marketing Control Act § 15 protects natural persons, including at their work address. Generic addresses such as post@firma.no are not covered by the prohibition.
Can we still rely on cookie consents obtained before 2025?
Only if they meet the GDPR requirements. Consent based on browser settings, pre-ticked boxes or continued use of the website is not valid under the new Act. Such solutions must be replaced with an active consent mechanism.
- Norwegian Electronic Communications Act (ekomloven, 2024) § 3-15
- Norwegian Marketing Control Act (markedsføringsloven) §§ 15, 40–42
- General Data Protection Regulation (EU) 2016/679 Art. 4(11) and Art. 7
- Norwegian Communications Authority (Nkom), Cookies
- Norwegian Data Protection Authority (Datatilsynet), New cookie rules from 1 January
- Norwegian Data Protection Authority (Datatilsynet), Consent to the use of cookies and other tracking technologies
- Norwegian Consumer Authority (Forbrukertilsynet), Guidance on marketing by email, SMS and similar
- EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive
Next legal review: 1 April 2027