Law / Norway

Personal Data Act Chapter 7, Datatilsynet Enforcement in Norway

personopplysningsloven, enforcement chapter (Chapter 7)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 20 July 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect Datatilsynet to have direct administrative-fine authority over your processing of personal data of a person in Norway, under Personal Data Act Section 26.
  • Expect any person who suffered damage from an infringement, including non-economic harm, to have a right to compensation from you as controller or processor, under Personal Data Act Section 30.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Section 26 extends GDPR Article 83 into Norwegian law and additionally lets Datatilsynet fine public authorities and bodies, a choice GDPR Article 83(7) leaves to member-state discretion. This is the top tier (Article 83(5)-(6)) for breaches of the core principles, consent, data-subject rights, international transfers, and non-compliance with a supervisory order. A separate lower tier of EUR 10,000,000 or 2% of global turnover (Article 83(4)) applies to controller and processor obligations under Articles 8, 11, 25 to 39, 42 and 43, and Section 26 extends that lower tier to Articles 10 and 24 as well. Where a controller breaches several connected provisions, the total fine is capped at the amount for the gravest infringement rather than summed.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Datatilsynet (the Norwegian Data Protection Authority)

Enforcement record

Figures cover calendar year 2025, from Datatilsynet's 2025 annual report (Arsrapport for 2025). In 2025 Datatilsynet made 36 total corrective-measure and sanction decisions under GDPR Article 58(2) and (6), of which 4 were specific to this chapter's own overtredelsesgebyr and tvangsmulkt powers: 2 administrative fines (overtredelsesgebyr, Section 26), Kristiansand kommune (NOK 250,000) and Telenor ASA (NOK 4,000,000, under appeal to Personvernnemnda as of the report date), and 2 conditional coercive daily fines (tvangsmulkt, Section 29). The broader 36-decision count also includes reprimands and orders that fall outside this chapter's own fine and coercive-fine mechanism. The yearly count of corrective-and-sanction decisions was 54 in 2022, 42 in 2023 and 44 in 2024, a declining trend the report attributes partly to its own stated intent to increase use of overtredelsesgebyr going forward.

As of
2 September 2026
Trend
Falling
Currency
NOK
Source link
https://www.datatilsynet.no/link/88940761a1414b2ca479ecd16db8b3bb.aspx/download
Fines per year
4,250,000
Actions per year
4

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Unlike Denmark, Norway's Datatilsynet imposes administrative fines directly rather than routing them through the criminal courts.

Chapter 7 of the Act: Section 26 lets Datatilsynet impose administrative fines under General Data Protection Regulation (GDPR) Article 83; Section 27 gives a four-week compliance deadline from a final fine decision, with court review available; Section 28 sets a five-year limitation period from when the violation ceased; Section 29 lets Datatilsynet impose a daily coercive fine for continued non-compliance; and Section 30 cross-references GDPR Article 82, letting a liable party also be ordered to pay compensation for non-economic harm.

Section 26's fining power is stated in terms of public authorities; whether the same or a separate mechanism reaches private controllers is not confirmed against Section 26's exact Norwegian text.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • processes_biometrics
  • processes_voice

Read the law

Lovdata.no official consolidated-law database, Chapter 7

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app