GDPR in Norway: What UK Tech and AI Companies Must Know
Last updated 27 July 2026 · by attorney-at-law Kjell Steffner
|
In brief
|
A UK SaaS or AI company that is already compliant at home often assumes Norway is covered by the same programme. That assumption is half right, and the half that is wrong is expensive. GDPR in Norway follows the EEA rulebook rather than the UK one, the two regimes are actively diverging, and the AI rules arriving in Norway look nothing like the UK’s approach. This guide sets out what a UK technology supplier needs to have in order before a Norwegian enterprise customer, or its data protection officer, starts asking questions.
How is GDPR in Norway implemented and enforced?
Norway is not an EU member, but the GDPR applies in full through the EEA Agreement and has been part of Norwegian law since July 2018, implemented by the Personal Data Act (personopplysningsloven). The supervisory authority is Datatilsynet, an active regulator with a track record of enforcement against both Norwegian and foreign companies. For practical purposes a UK supplier should treat a Norwegian customer exactly as it would treat a customer in Germany or France.
The typical commercial setup places the UK supplier as a processor for its Norwegian customer. That triggers the full Article 28 apparatus — a data processing agreement, documented technical and organisational measures, a maintained subprocessor list with a change-notification mechanism, assistance obligations, and audit rights. Norwegian enterprise customers ask for these documents during procurement, not after signature, and an incomplete package slows deals down more often than price does.
Can personal data flow freely between the UK and Norway?
Yes, in both directions, and this is worth stating precisely because the position changed recently. The European Commission renewed the UK adequacy decisions on 19 December 2025, shortly before the previous extension expired, with effect until 27 December 2031. The renewal is binding for the EEA EFTA states, so transfers from Norway to the UK require no additional safeguards. In the other direction, the UK continues to treat the EEA states as adequate under its own rules.
Two qualifications belong in every UK supplier’s risk register. First, the renewed decisions carry a sunset clause and ongoing monitoring — the EDPB flagged specific developments in UK law it expects the Commission to watch, which means adequacy is a standing arrangement, not a permanent right. Second, adequacy can be suspended or amended faster than a supplier can renegotiate its contracts. The pragmatic response is not alarm but documentation — keep standard contractual clauses ready as a fallback in the DPA architecture, so a change in adequacy status becomes an administrative exercise rather than a renegotiation.
What about onward transfers to the US and other third countries?
Adequacy between the UK and the EEA does not solve the rest of the supply chain. A UK SaaS product typically rests on US cloud infrastructure, follow-the-sun support, and analytics or AI subprocessors outside the EEA. For data originating in Norway, each of those onward transfers needs a valid mechanism — an adequacy decision where one exists, otherwise standard contractual clauses combined with a documented transfer impact assessment in line with the EDPB’s recommendations following Schrems II.
The work here is mostly cartography. Map where personal data actually goes — hosting, support access, logging, telemetry, backup, model inference — and be able to show the map. Norwegian customers and their advisers increasingly ask for the subprocessor list with locations and transfer mechanisms as a single document, and suppliers that can produce it immediately have a visibly easier procurement path.
Is UK data protection law drifting away from the EEA?
Yes, deliberately and by statute. The Data (Use and Access) Act 2025 amends UK GDPR in stages, and the most significant change for technology suppliers took effect on 5 February 2026 — section 80 replaces Article 22 on automated decision-making with new Articles 22A to 22D, which permit solely automated significant decisions on a broader range of legal bases, subject to safeguards, except where special category data is involved. The Act also reformulates how the UK assesses other countries for its own transfers, replacing essential equivalence with a test of whether protection is “not materially lower” than the UK standard (gov.uk factsheet).
For a supplier serving both markets the consequence is concrete rather than theoretical. An automated decision flow that is lawful under the new UK regime may still be restricted under Article 22 of the EEA GDPR that applies to Norwegian data subjects, so product features built to the UK rulebook need a separate EEA assessment. The divergence is also exactly what the EDPB’s monitoring of UK adequacy is watching, which ties this section back to the contingency planning above.
Does the EU AI Act apply in Norway yet?
No — and the gap is closing, so the dates matter. The EU AI Act (Regulation 2024/1689) entered into force in the EU on 1 August 2024, with the prohibitions and AI-literacy duties applying in the EU from 2 February 2025. Norway is a different story. The regulation must be incorporated into the EEA Agreement and implemented by a Norwegian act — the draft “KI-loven” — before it binds in Norway, and as at July 2026 that has not happened. Entry into force is expected during 2026, with Nkom designated as the coordinating supervisory authority, but the timetable has slipped before and should be verified at the time of reading.
The gap is narrower than it looks for a UK vendor, for two reasons. First, the AI Act reaches beyond the EU’s borders — a UK provider placing an AI system on the EU market, or whose system’s output is used in the EU, is already within scope regardless of where the provider sits. Second, Norwegian enterprise and public-sector customers are contracting as if the Act were already in force, writing AI governance, transparency and risk-classification requirements into procurement documents today. The UK’s own approach — no comprehensive AI statute, principles applied through existing sector regulators — offers no preparation for this, so a UK vendor’s first exposure to EU-style AI regulation is often a Norwegian customer’s questionnaire.
What do Norwegian enterprise customers require in practice?
Beyond the statutes, there is a recognisable checklist in Norwegian enterprise deals. Expect requirements on data residency or at least hosting transparency, a complete subprocessor list with locations, documented technical and organisational measures, breach-notification commitments tighter than the statutory baseline, exit and deletion terms with verification, and — increasingly the first question asked — whether customer data, prompts or outputs are used to train the supplier’s models. A supplier that cannot answer the training question in one clear sentence, with the contract language to match, should resolve that before entering the Norwegian market rather than during its first negotiation.
UK vs Norway — data and AI rules at a glance
| Topic | United Kingdom | Norway | What it means for a UK supplier |
|---|---|---|---|
| Core data law | UK GDPR and DPA 2018, as amended by the DUAA 2025 | EEA GDPR implemented by the Personal Data Act; enforced by Datatilsynet | Run an EEA-grade programme for Norwegian customers |
| UK–Norway transfers | EEA states treated as adequate | UK covered by EU adequacy until 27 Dec 2031, with sunset clause | No extra safeguards now; keep SCCs ready as fallback |
| Onward transfers | UK IDTA / Addendum regime; new “not materially lower” test | EEA SCCs plus transfer impact assessment | Map subprocessors, support and telemetry; document mechanisms |
| Automated decisions | Articles 22A–22D from 5 Feb 2026 — broader permissions with safeguards | EEA GDPR Article 22 baseline | Assess ADM features separately per market |
| AI regulation | No comprehensive statute; principles-based, sector regulators | EU AI Act expected via the EEA during 2026 (KI-loven); Nkom coordinating | Build AI Act-style governance before the customer asks |
| AI extraterritorial reach | Not applicable | EU AI Act already covers providers on the EU market or outputs used in the EU | You may be in scope today, before Norwegian entry into force |
Which mistakes do UK suppliers make most often?
Four patterns recur when we review UK suppliers’ data and AI documentation for the Norwegian market.
- Presenting a UK GDPR programme as sufficient for EEA customers without mapping the differences, particularly around automated decision-making.
- Having no single, current document showing subprocessors, locations and transfer mechanisms.
- Leaving the model-training question — whether customer data, prompts or outputs train the supplier’s AI — unanswered in the contract.
- Assuming the UK’s light-touch AI approach travels, and meeting EU-style AI governance requirements for the first time in a live tender.
When should a UK tech company involve Norwegian counsel?
The reliable triggers are the first Norwegian enterprise customer that sends a data protection questionnaire, the appointment of subprocessors outside the EEA, any use of AI on customer data, a public-sector tender with security and data requirements, and the preparation of the core document set — DPA, technical and organisational measures, subprocessor list, transfer assessments and exit terms. Getting that set right once carries every subsequent Norwegian deal.
The commercial contract that sits around these obligations — liability, standard terms, IP in deliverables — is covered in the first article in this series about Norwegian contract law. If your route to market runs through the public sector, the procurement rules add a further layer.
Nordia Law helps UK technology companies enter and operate in the Norwegian market. As part of a Nordic firm with a presence in Norway, Sweden, Denmark and Finland — and through close cooperation with DAC Beachcroft and Laworld — we also coordinate cross-border legal questions across the Nordics and beyond.
Preparing your data protection and AI documentation for Norwegian customers? Book a short Teams call with Kjell Steffner to pressure-test your setup against EEA requirements. Book a meeting.
Sources: GDPR (Regulation 2016/679), EUR-Lex · Personal Data Act (personopplysningsloven), Lovdata · Datatilsynet — regulations · EDPB opinions on the UK adequacy decisions · Renewal of the UK adequacy decisions, eucrim · Data (Use and Access) Act 2025 s. 80, legislation.gov.uk · DUAA factsheet, gov.uk · EU AI Act (Regulation 2024/1689), EUR-Lex · Nkom on the AI Act in Norway
|
About the author Kjell Steffner · attorney-at-law Partner, Nordia Law (Oslo) Kjell Steffner advises technology companies on data protection, privacy, AI compliance, commercial contracts and intellectual property, and assists international businesses entering the Norwegian and Nordic markets. |