A personal data breach must be notified to the Norwegian Data Protection Authority without undue delay and, where feasible, within 72 hours of the business becoming aware of it, unless the breach is unlikely to result in a risk. Where the risk is high, the affected individuals must also be informed. All breaches must be documented, including those that are not notified.
A security breach starts a clock. From the moment the business becomes aware of the breach, it has, as a rule, 72 hours to notify the Norwegian Data Protection Authority (Datatilsynet). Most mistakes happen not because the business is unaware of the deadline, but because it waits for the full picture before notifying.
What is a personal data breach?
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, as defined in GDPR Art. 4(12). The rules apply in Norway through Personal Data Act § 1 in the Personal Data Act (personopplysningsloven) and the GDPR.
The definition covers three types of breach. A confidentiality breach means that unauthorised persons gain access. An integrity breach means that data is altered. An availability breach means that data is lost or becomes inaccessible, for example in a ransomware attack. It is not necessary for anyone to have misused the data.
Typical examples are cyber attacks, phishing that gives access to email accounts, flawed access control, stolen unencrypted laptops, and emails or letters sent to the wrong recipient.
When does the 72-hour deadline start to run?
The deadline runs from when the business became aware of the breach, under GDPR Art. 33(1). In Guidelines 9/2022, the EDPB takes the view that the business is aware when it has a reasonable degree of certainty that a security incident has compromised personal data. A short initial investigation to establish this is accepted, but it must be carried out quickly.
This means that the deadline does not wait until the cause has been found or the scope mapped. Datatilsynet has stressed exactly this, pointing out that the business cannot wait until all the circumstances have been clarified. If the breach is notified after 72 hours, the notification must give reasons for the delay.
If the breach occurs at a supplier, the supplier as processor must inform you without undue delay, under GDPR Art. 33(2). The law sets no deadline in hours for the supplier, which is why the deadline should be agreed. See data processing agreements for SaaS.
Which personal data breaches must be notified to Datatilsynet?
The main rule is that all breaches must be notified. The exception is breaches that are unlikely to result in a risk to the rights and freedoms of natural persons. In its guidance on which breaches must be notified, Datatilsynet states that the business must be close to certain that there is no risk before it decides not to notify.
Datatilsynet revised its guidance in 2025. The earlier encouragement to notify in case of doubt has been removed, and misdirected mail has been moved down the list because it often involves little risk. The threshold in the GDPR is nevertheless the same. The risk is assessed on the basis of the type of data concerned, how many people are affected, whether the data can be linked to individuals and what consequences the breach may have. The EDPB has given many concrete examples in Guidelines 01/2021.
| Situation | Notify Datatilsynet? | Inform the affected individuals? |
|---|---|---|
| Ransomware, data encrypted and probably exfiltrated | Yes | Usually yes |
| Ransomware, up-to-date backups and no sign of exfiltration | Often yes, after a risk assessment | Normally no |
| Encrypted laptop stolen, key not compromised | Normally no | No |
| Payroll list sent to the wrong internal department | Yes, as a rule | Depends on the risk |
| Phishing gives access to an email account with customer data | Yes | Depends on the content |
| Email with name and work address sent to the wrong recipient, deleted | Often no | No |
The table is a simplification. The assessment must always be made on the specific facts and documented.
What must the notification contain, and how is it submitted?
The notification must at least describe the nature of the breach, the categories and approximate number of individuals and records concerned, a contact point at the business, the likely consequences and the measures taken or proposed, under GDPR Art. 33(3). If not everything is known, the information may be provided in phases under GDPR Art. 33(4).
In Norway, breaches are notified to Datatilsynet through a form in Altinn, the government’s digital reporting portal. The person notifying must have authorisation in Altinn to report on behalf of the business. It is wise to clarify who holds that authorisation before anything happens, not in the middle of an incident on a Friday evening. Datatilsynet accepts a preliminary notification stating that further information will follow, and a supplementary notification is later submitted through the same system.
If the business carries out processing in several EEA countries, the breach must be notified to the lead supervisory authority. If the business is subject to the Digital Security Act (digitalsikkerhetsloven), separate reporting obligations with shorter deadlines towards the sector authority may also apply. These are two separate processes that must be coordinated.
When must the affected individuals be informed?
Data subjects must be informed without undue delay when the breach is likely to result in a high risk to their rights and freedoms, under GDPR Art. 34(1). The threshold is therefore higher than for notifying Datatilsynet. The communication must be in clear and plain language and explain what has happened, the likely consequences and what they can do themselves, for example change passwords or watch out for fraud.
Under GDPR Art. 34(3), communication is not required if the data was protected, for example by encryption, if subsequent measures ensure that the high risk is no longer likely to materialise, or if communication would involve disproportionate effort. In the last case, a public communication must be made instead. Datatilsynet can order the business to inform the individuals.
It is rarely the breach itself that leads to a fine. It is the delay and the lack of documentation.
What must be documented?
All breaches must be documented, including those that are not notified, under GDPR Art. 33(5). The documentation must cover the facts, the effects and the remedial action taken. A decision not to notify should be reasoned in writing, because that is what Datatilsynet will ask for if the matter comes up later.
Documentation also matters in compensation claims. In Case C-340/21, the Court of Justice of the EU held that a security breach does not in itself mean that the measures were inadequate, but that it is the controller that must prove that the measures were appropriate under GDPR Art. 32. The Court also held that fear of misuse may constitute non-material damage under GDPR Art. 82. Without documentation, the business is in a weak position.
What does late notification cost?
Breach of the notification duty can lead to an administrative fine of up to EUR 10 million or 2 per cent of global annual turnover, under GDPR Art. 83(4). Failures in the security measures behind the breach come on top of that.
In 2023, Datatilsynet imposed an administrative fine of NOK 2.5 million on the US company Argon Medical Devices for notifying too late. The breach concerned data about employees in Europe that could be used for fraud and identity theft. It occurred in July 2021 but was not notified until September of the same year. The decision shows that Datatilsynet reacts to late notification even where the breach itself has been dealt with.
The largest cost, however, often lies in reputational damage, claims from affected individuals and the time spent on follow-up. Breach handling is also an internal control matter for the board, see the article on the board’s responsibility for AI.
Are changes coming to the 72-hour deadline?
In November 2025, the European Commission proposed a package of simplifications known as the Digital Omnibus. Among other things, the proposal means that only breaches likely to result in a high risk must be notified, that the deadline is extended to 96 hours, and that a single reporting point is established for several regulatory frameworks. The proposal has not been adopted as of October 2026, and it must also be incorporated into the EEA Agreement before it applies in Norway. Until then, the 72-hour deadline and the current threshold apply.
What should the business do?
- Put in place a breach procedure stating who assesses, who decides and who notifies, with names and deputies.
- Make sure at least two people have authorisation in Altinn to notify breaches on behalf of the business.
- Prepare a risk assessment template that can be completed within the first few hours.
- Notify provisionally rather than late, and send a supplementary notification when more is known.
- Agree specific notification deadlines with suppliers in the data processing agreements.
- Keep a breach log of all breaches, including those not notified, with reasons.
- Rehearse a realistic scenario with the clock running at least once a year.
A breach may also trigger access requests from affected individuals who want to know what has happened to their data, see subject access requests under the GDPR. If the breach concerns an AI tool, the DPIA for the AI tool should also be updated. More articles are available on the data protection topic page.
Questions and answers
Must we notify an email sent to the wrong recipient?
It depends on the risk. If the email contains information that deserves protection, such as health data, salary details or national identity numbers, it should normally be notified. If it only concerns names and work email addresses and the recipient has confirmed deletion, the risk may be so low that notification is not required. The incident must be documented in any event.
Who must notify when the breach occurs at the supplier?
You, as the controller, must notify the Norwegian Data Protection Authority. The supplier, as processor, must inform you without undue delay. The agreement can authorise the supplier to notify on your behalf, but the responsibility remains with you.
Can data subjects claim compensation after a security breach?
Yes. Under GDPR Art. 82 they can claim compensation for material and non-material damage. In Case C-340/21, the Court of Justice of the EU held that fear of misuse of the data may in itself constitute non-material damage, and that it is the business that must prove that its security measures were appropriate.
- General Data Protection Regulation (EU) 2016/679 Arts. 4(12), 33 and 34
- Norwegian Personal Data Act (personopplysningsloven) § 1
- Norwegian Digital Security Act (digitalsikkerhetsloven)
- EDPB, Guidelines 9/2022 on personal data breach notification under GDPR (version 2.0)
- EDPB, Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
- Norwegian Data Protection Authority (Datatilsynet), Which breaches must be notified to Datatilsynet?
- Norwegian Data Protection Authority (Datatilsynet), Notify a breach to Datatilsynet
- Norwegian Data Protection Authority (Datatilsynet), Administrative fine to Argon Medical Devices (2023)
- Court of Justice of the EU, Case C-340/21 Natsionalna agentsia za prihodite
Next legal review: 31 January 2027