Personal Data Act, Breach Notification in Norway
personopplysningsloven LOV-2018-06-15-38, breach notification provisions
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 20 July 2018.
A breach notification rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms.
- Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
General Data Protection Regulation (GDPR) Articles 33-34, incorporated as Norwegian law through the Personal Data Act: a controller must notify Datatilsynet within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to natural persons, and must notify affected individuals without undue delay for a breach likely to result in a high risk. Chapter 3 adds no Norway-specific narrowing.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
Lovdata.no official consolidated-law database
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.