Data Protection in Norway

Online privacy in Norway

Traffic data

A new law on electronic communications was adopted 1st of January 2025, the Electronic Communications Act (LOV-2024-12-13-76, Nw. Ekomloven).

Traffic data is defined in the Electronic Communications Act section 1-5 as data which is necessary to transfer communication in an electronic communications network or for billing of such transfer services.

Processing of traffic data held by a Communications Services Provider ('CSP') (Nw: Tilbyder) may,  according to the Regulation relating to Electronic Communications Networks and Electronic Communications Services (FOR-2024-12-20-3410, Nw: Ekomforskriften),  only be performed by individuals tasked with invoicing, traffic management, customer enquiries, marketing of electronic communications networks or the prevention or detection of fraud.

Traffic Data held by a CSP must be erased or anonymized when it is no longer necessary for the purpose of the transmission of a communication and related billing or for the purpose of complying with a legal obligation (Electronic Communications Act (LOV-2003-07-04-83) section 3-11 (Nw: Ekomloven). However, Traffic Data can be retained if it is being used to provide a value-added service and consent has been given for the retention of the Traffic Data.

Location data

Location data may only be processed for purpose of the transmission of a communication and related billing or for the purpose of complying with a legal obligation. Other processing requires explicit consent and the users must be given understandable information on which data is processed and how the data is used. The user shall have the opportunity to withdraw their consent. See Norwegian Regulation relating to Electronic Communications Networks and Electronic Communications Services section 3-1.

Cookie compliance

The Electronic Communications Act has been changed in accordance with directive 2009/136/EC regarding the use of cookies. According to section 3-15, the user must give their consent before cookies, or any other form of data is stored in their browser. The users must receive clear and comprehensive information about the use of cookies and the purpose of the storage or access. However, obtaining user consent is not required if the cookie solely has the purpose of transferring communication in an electronic network, or if it is deemed to be strictly necessary for the delivery of a service requested by the user. The consent must fulfill the requirements of the  GDPR (i.e. freely given, specific, informed and unambiguous) according to the Electronic Communications Act section 3-15.

Continue reading

  • no results

Previous topic
Back to top