Data
protection
The GDPR in practice, DPIAs, data processing agreements and transfers to third countries. Written for businesses that build, buy or sell technology.
Articles on this topic
SaaS data processing agreement: what must it contain, and what should you require?
When a SaaS supplier processes personal data on your behalf, GDPR Art. 28 requires a written SaaS data processing agreement. It must cover instructions, confidentiality, security, sub-processors, assistance, deletion and audits, among others. The supplier's standard terms often meet the minimum, but rarely the customer's needs on breach notification, insight, transfers outside the EEA and exit.
Anonymisation under the EDPB guidelines: is your data really anonymous?
Anonymisation under the GDPR requires the likelihood of identifying anyone to be insignificant, assessed from the perspective of whoever will use the data. The draft EDPB guidelines 02/2026 build on the SRB judgment and apply three criteria, singling out, linkability and inference. A processor inherits its customer's perspective, and the assessment must be repeated over time.
Duty to cooperate with the Data Protection Authority: what does it require?
The duty to cooperate under GDPR Art. 31 means a business must answer the Norwegian Data Protection Authority within the deadline and produce the documents it asks for, including contracts with a confidentiality clause. The business may disagree and appeal the order. Threats against case officers and repeated stalling are a breach, and cost Lab Pharma AS a NOK 205,000 fine in August 2026.
Location data: when does tracking become high-risk processing under the GDPR?
Location data becomes high-risk processing when a person's position is tracked systematically over time, particularly employees or app users. Datatilsynet will then usually require a DPIA. The business needs a clear purpose and legal basis, must inform plainly and delete early. Apps reading the phone's position normally also need consent under the Electronic Communications Act § 3-15.
Marketing consent for ‘partners’: what does the Canal+ case mean?
Marketing consent given to ‘our partners’ only covers businesses whose identity the data subject knew when consenting. That is the view of the Advocate General in Canal+ (C-317/25). Any other sender must obtain fresh consent before marketing, and an unsubscribe link in the first email does not cure the defect. The judgment is still to come.
Nordlo judgment: why did the customer get only NOK 8,280 after a cyber attack?
In the Nordlo judgment of 30 June 2026, Gulating Court of Appeal held that Btec AS, which lost its production data in a ransomware attack on its IT supplier and claimed over NOK 57 million, was bound by the supplier's unsigned standard terms. The attack was not force majeure, the supplier was not grossly negligent, and a cap of three months' fees gave NOK 8,280.
Norway's AI agreement: what must employers discuss before introducing AI?
Norway's AI agreement of 2 October 2026 is a letter of intent between the government and the social partners. It places no new obligations on individual employers, whose duties come from the Working Environment Act and collective agreements. If AI changes how work is organised, or can be used to monitor staff, it must be discussed with employee representatives before the decision is made.
Personal data in test environments: can we test with real customer data?
Personal data in test environments may only be used where testing is compatible with the purpose for which the data was collected, under GDPR Art. 6(4), and where synthetic or pseudonymised data will not do. Private businesses have no special rule. Copies of production data used for testing need the same security, access control and deletion as production.
AI policy for employees: what can an employer require and monitor?
Under Norwegian law, an employer can set an AI policy for employees under its managerial prerogative, including bans on certain tools and requirements to check the output. Monitoring how employees actually use AI is a control measure that requires objective grounds, discussion with employee representatives and prior information. Continuous monitoring of individual use is generally prohibited.
Cloud exit: how do you secure your data when the contract ends?
A cloud exit must be secured in the contract before it is signed. The contract should give a right to all data in a machine-readable format, assistance from the provider, a transition period and documented deletion. In the EU the Data Act requires at most two months' notice, a 30-day transition and at least 30 days' access to the data. In Norway the regulation does not yet apply.
Cookies and newsletters: when do you need consent in Norway?
Cookies and consent go hand in hand under the Norwegian Electronic Communications Act § 3-15. From 1 January 2025 cookie consent must meet the GDPR requirements, and browser settings are no longer enough. Only strictly necessary cookies are exempt. Email newsletters to private individuals require consent under the Marketing Control Act § 15, with a narrow exception for existing customers.
Transferring personal data to the US: how safe is the Data Privacy Framework?
The Data Privacy Framework makes it lawful to transfer personal data to US companies certified under it. The adequacy decision applies in Norway and was upheld by the EU General Court in 2025, but the case has been appealed and US oversight bodies have been weakened. Businesses should use the framework, but keep standard contractual clauses and an exit plan in reserve.
DPIA for AI tools: when is it required, and what must it contain?
A DPIA for AI tools is required when their use is likely to result in a high risk to data subjects, under GDPR Art. 35. AI tools with access to email, documents, customer data or employee data often meet the threshold. If two or more of the nine criteria in the Article 29 Working Party guidelines are met, you should assume that a DPIA is required.
When can an employer access an employee's email in Norway?
Under Norwegian law, employers may only access an employee's email when access is necessary for day-to-day operations or other legitimate interests, or where there is a well-founded suspicion of serious misconduct. As a rule the employee must be notified in advance and be able to attend. Automatic forwarding counts as unlawful monitoring and has led to administrative fines.
Personal data breach: what must you do within 72 hours?
A personal data breach must be notified to the Norwegian Data Protection Authority without undue delay and, where feasible, within 72 hours of the business becoming aware of it, unless the breach is unlikely to result in a risk. Where the risk is high, the affected individuals must also be informed. All breaches must be documented, including those that are not notified.
Subject access requests from staff and customers: deadlines, exemptions and disputes
A subject access request under GDPR Art. 15 must be answered without undue delay and within one month at the latest. The deadline can be extended by two months for complex requests. The requester need not give reasons, and the request cannot be refused because it is used in an employment dispute or litigation. Only exceptionally can a request be refused as manifestly unfounded or excessive.
The legal framework
- General Data Protection Regulation (EU) 2016/679EU
- General Data Protection Regulation (GDPR), Norwegian textEU
- Norwegian Personal Data Act (personopplysningsloven)lov
- Norwegian Public Administration Act (forvaltningsloven)lov
- Norwegian Penal Code (straffeloven)lov
- New Norwegian Public Administration Act (Act of 20 June 2025 No. 81), not yet in forcelov
- Norwegian Working Environment Act (arbeidsmiljøloven)lov
- Norwegian Electronic Communications Act (ekomloven, 2024)lov
- Directive on privacy and electronic communications 2002/58/ECEU
- Norwegian Marketing Control Act (markedsføringsloven)lov
- Norwegian Dispute Act (tvisteloven)lov
- Regulation on employer access to email accounts and other electronically stored material (e-postforskriften)forskrift
- Artificial Intelligence Act, Regulation (EU) 2024/1689EU
- Norwegian Financial Supervision Act (finanstilsynsloven)lov
- Data Act, Regulation (EU) 2023/2854EU
- Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy FrameworkEU
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countriesEU
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)EU
- Norwegian Digital Security Act (digitalsikkerhetsloven)lov
- Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processorsEU