Law / Norway

Norway

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 9 in force and 1 proposed. As of 12 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (95 words)

Norway has no AI-specific statute in force. The proposed Norwegian Artificial Intelligence Act (KI-loven), which would implement Regulation (EU) 2024/1689, remains at the pre-enactment stage: as of 29 May 2026 the Ministry of Digitalisation and Public Governance was preparing a legislative proposition for the Storting, and had not yet sent it.

Because Norway is an EEA member and not an EU member, Regulation (EU) 2024/1689 does not apply as Norwegian law on the strength of its EU status, and no confirmation that the Regulation has since been incorporated into the EEA Agreement has been located.

AI risk obligations

Norwegian Artificial Intelligence Act (KI-loven)

Proposed Act on Artificial Intelligence (KI-loven), not yet enacted; Stortinget EU/EØS-nytt briefing of 29 May 2026Stortinget (the Storting), EU/EEA news briefing quoting the Ministry of Digitalisation and Public Governance's 26 May 2026 press release

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

The Ministry of Digitalisation and Public Governance is preparing a legislative proposition to the Storting for a Norwegian Act implementing Regulation (EU) 2024/1689 (the EU AI Act). As of 29 May 2026, the ministry stated that the high-risk rules will apply in Norway only once the Norwegian AI Act is adopted by the Storting.

It also stated that Norwegian rules are intended to take effect as soon as possible after Regulation (EU) 2024/1689, with the amendments agreed under the EU's Digital Omnibus package, is incorporated into the EEA Agreement. This measure is proposed and binds nobody yet.

What it requires

Privacy law6 instruments, 6 in force

Research summary (93 words)

Norway is not an EU member; General Data Protection Regulation (GDPR) reaches Norway through the EEA Agreement, incorporated by Norway's own Personal Data Act (personopplysningsloven, LOV-15 June 2018-38), which is the controlling instrument recorded here rather than the EU Regulation directly.

Drawn from lovdata.no, the Act incorporates the GDPR text in full and adds Chapter 3 supplementary provisions (digital consent age of 13, national identity number processing) and Chapter 7 sanctions provisions under which Datatilsynet imposes administrative fines directly, unlike Denmark's criminal-court route. As at 24 August 2026; later amendment to the Act is not independently confirmed.

Breach notification

Personal Data Act, Breach Notification in Norway

personopplysningsloven LOV-2018-06-15-38, breach notification provisionsLovdata.no official consolidated-law database

In force since 20 July 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 33-34, incorporated as Norwegian law through the Personal Data Act: a controller must notify Datatilsynet within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to natural persons, and must notify affected individuals without undue delay for a breach likely to result in a high risk. Chapter 3 adds no Norway-specific narrowing.

What it requires

Comprehensive regime

Personal Data Act (personopplysningsloven)

Lov om behandling av personopplysninger (personopplysningsloven), LOV-2018-06-15-38, in force 20 July 2018Lovdata.no official consolidated-law database

In force since 20 July 2018. Binds public and private bodies.

What this law does

Norway is not an EU member; General Data Protection Regulation (GDPR) reaches Norway through the EEA Agreement, incorporated by Norway's own Personal Data Act (personopplysningsloven), not as directly applicable EU law. Drawn from lovdata.no, the Act's introductory text states the Regulation is thus part of the Personal Data Act and applies as Norwegian law, and the GDPR text is incorporated in full as part of the Act's own published text.

Chapter 3 sets the digital age of consent for information society services at 13 (Section 5), governs national identity number (fodselsnummer) processing (Section 12), and permits limited public-authority data sharing to combat workplace crime while preserving GDPR Article 9 protection for sensitive data (Section 12a). Datatilsynet is the supervisory authority, institutionally distinct from Denmark's identically named authority.

What it requires

Cross border transfer

Personal Data Act and GDPR Chapter V, Cross-Border Transfer from Norway

personopplysningsloven LOV-2018-06-15-38, transfer provisionsLovdata.no official consolidated-law database

In force since 20 July 2018. Binds public and private bodies.

What this law does

Transfers within the EEA, including to EU member states, are unrestricted; the restriction applies to transfers to third countries outside the EEA. General Data Protection Regulation (GDPR) Chapter V, incorporated as Norwegian law through the Act, permits such a transfer only on an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Chapter 3 contains no Norway-specific provision narrowing or broadening this beyond the incorporated GDPR text.

What it requires

Data subject rights

Personal Data Act, Data Subject Rights in Norway

personopplysningsloven LOV-2018-06-15-38, data subject rights provisionsLovdata.no official consolidated-law database

In force since 20 July 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21, incorporated as Norwegian law through the Personal Data Act: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect. Chapter 3 adds no Norway-specific narrowing of these rights.

What it requires

Enforcement supervision

Personal Data Act Chapter 7, Datatilsynet Enforcement in Norway

personopplysningsloven, enforcement chapter (Chapter 7)Lovdata.no official consolidated-law database, Chapter 7

In force since 20 July 2018. Binds public and private bodies.

What this law does

Unlike Denmark, Norway's Datatilsynet imposes administrative fines directly rather than routing them through the criminal courts.

Chapter 7 of the Act: Section 26 lets Datatilsynet impose administrative fines under General Data Protection Regulation (GDPR) Article 83; Section 27 gives a four-week compliance deadline from a final fine decision, with court review available; Section 28 sets a five-year limitation period from when the violation ceased; Section 29 lets Datatilsynet impose a daily coercive fine for continued non-compliance; and Section 30 cross-references GDPR Article 82, letting a liable party also be ordered to pay compensation for non-economic harm.

Section 26's fining power is stated in terms of public authorities; whether the same or a separate mechanism reaches private controllers is not confirmed against Section 26's exact Norwegian text.

What it requires

Sensitive categories

Personal Data Act Chapter 3 and GDPR Article 9, Special Categories in Norway

personopplysningsloven, special categories chapter (Chapter 3)Lovdata.no official consolidated-law database, Chapter 3

In force since 20 July 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1), incorporated as Norwegian law through the Personal Data Act, classifies biometric data processed for unique identification as a special category. Chapter 3 of the Act contains no biometric-specific provision and no enumeration of biometric examples, so the special category here is the incorporated GDPR one without Norwegian elaboration.

What it requires

Scraping law2 instruments, 2 in force

Research summary (287 words)

Norway has no scraping-specific statute, so general law governs each dimension separately.

The Penal Code (straffeloven, LOV-20 May 2005-28) section 204 criminalises gaining access to a computer system by breaching a protection measure or by another unauthorised method; because the offence's trigger is breaching a protection measure, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, and no reported Norwegian case addressing the point has been located.

Section 205 of the same Penal Code chapter is not an aggravated form of the section 204 offence; it addresses violation of the right to private communication (unlawful interception of correspondence), a different offence entirely, correcting an earlier record that had described section 205 as an aggravated unauthorised-access offence.

The Copyright Act (åndsverkloven, LOV-15 June 2018-40) section 24 confers a sui generis right on the producer of a database resulting from a substantial investment in collecting, checking or presenting its contents; the Act's own list of the EU/EEA directives it implements does not include a text-and-data-mining exception.

No account of the enforceability of a browsewrap or clickwrap terms-of-service against a scraper under the Contracts Act (avtaleloven, 1918) has been located; that Act does not appear in the WIPO Lex database, and lovdata.no, the consolidated statute publisher, disallows automated access under its robots.txt. Norway's data-protection law (the Personal Data Act, incorporating the General Data Protection Regulation (GDPR) through the EEA Agreement) is documented as this jurisdiction's privacy-topic instrument rather than repeated here, and whether it carries a carve-out for publicly available personal data specific to scraping has not been confirmed.

No Norwegian statute or reported case establishing a scraping-specific unfair-competition or misappropriation doctrine, or assigning legal weight to a robots.txt directive, has been located.

Computer misuse

Penal Code, Unauthorised Access to a Computer System

Straffeloven (Penal Code), LOV-2005-05-20-28, kapittel 21 (Vern av informasjon og informasjonsutveksling), § 204Norwegian-language consolidated text of the Penal Code (straffeloven), WIPO Lex

In force. Binds public and private bodies.

What this law does

Section 204 punishes, with a fine or imprisonment of up to two years, a person who gains access to a computer system or part of it by breaching a protection measure or by another unauthorised method. The provision sits in Chapter 21 (Protection of Information and the Exchange of Information), added to the Penal Code by the Act of 19 June 2009 No. 74.

Because the offence's trigger is breaching a protection measure, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

What it requires

Database right

Copyright Act, Sui Generis Database Right

Act relating to Copyright in Intellectual Works, etc. (Copyright Act), LOV-2018-06-15-40, as amended to 1 September 2021, s. 24Official English translation of the Copyright Act (åndsverkloven), as amended to 1 September 2021, WIPO Lex

In force since 1 July 2018. Binds public and private bodies.

What this law does

Section 24 gives the producer of a database, such as a form, catalogue, table, program or similar work resulting from a substantial investment in collecting, checking or presenting its contents, an exclusive right to control extraction from or reuse of all or a substantial part of the database's contents, and this right applies correspondingly to repeated or systematic extraction or reuse of immaterial parts of the database that is harmful to its normal use or that unreasonably sets aside the producer's legitimate interests.

The right subsists for 15 years after expiry of the year the database was produced, or, if the database is published within that period, for 15 years after expiry of the year of first publication. The Act's own list of the EU/EEA directives it implements includes Directive 96/9/EC on the legal protection of databases, as amended, but does not include a text-and-data-mining exception.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (187 words)

Norway has no press-publisher neighbouring right along the lines of Directive (EU) 2019/790 article 15, no compelled platform-to-publisher bargaining code, and no hot-news or misappropriation doctrine distinct from ordinary copyright law.

None of these appear in the current text of the Copyright Act (åndsverkloven, LOV-15 June 2018-40, as amended to 1 September 2021), and that Act's own list of the EU/EEA instruments it implements does not include Directive (EU) 2019/790's press-publisher article.

The Act's general quotation exception and its exception for reproducing a work that forms part of a current event in media coverage of that event are the provisions an aggregator's own reproduction of headlines and snippets would fall under; neither carries a headline-length or short-extract cap distinct from a fair-practice, purpose-justified test, and no reported Norwegian decision applies either provision to a systematic news aggregator rather than an individual reproduction.

Norway has not enacted a text-and-data-mining opt-out mechanism of the kind Directive (EU) 2019/790 article 4 contemplates. No statute or case law addressing whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, has been located.

Snippet reproduction

Copyright Act, Quotation and Current-Event Reproduction Exceptions

Act relating to Copyright in Intellectual Works, etc. (Copyright Act), LOV-2018-06-15-40, as amended to 1 September 2021, ss. 29, 36Official English translation of the Copyright Act (åndsverkloven), as amended to 1 September 2021, WIPO Lex

In force since 1 July 2018. Binds public and private bodies.

What this law does

Section 29 permits quotation from a published work in accordance with proper usage and to the extent required for the purpose, with no headline-length or short-extract cap distinct from that fair-practice test. Section 36 permits a work that forms part of a current event to be reproduced in media coverage of that event on the same fair-practice, purpose-justified terms.

It also permits a published work of art, photograph or film connected to but not part of the event to be reproduced on the same terms against remuneration, except where the work was created in the course of trade for the purpose of reproduction in the media.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.