NORWAY Law and Practice Contributed by: Harald Sætermo, LexOslo
means that it does not have the same voting position as EU supervisory authorities. Other rules may also be relevant. Electronic marketing is regulated by the Marketing Control Act, and cookies and similar technologies are regulated through elec - tronic communications rules. Sector-specific confi - dentiality, security and record-keeping rules may also apply, for example in financial services, healthcare, telecoms and employment. In practice, businesses operating in Norway should treat GDPR compliance as the core data protection requirement, supplemented by Norwegian national rules and Datatilsynet guidance. 8.2 Geographical Scope The geographical scope of Norwegian data protection law follows the GDPR. The rules apply to controllers and processors established in Norway where personal data is processed in the context of that establish - ment’s activities, regardless of whether the processing itself takes place in Norway. The rules may also apply to a foreign company with no establishment in Norway or the EEA if it offers goods or services to individuals in Norway or monitors their behaviour in Norway. Relevant indicators may include use of Norwegian language, pricing in Norwegian kro - ner, delivery to Norway, marketing directed at Norwe - gian customers, or tracking and profiling of users in Norway. A non-EEA controller or processor subject to the GDPR under these rules may need to appoint an EU/ EEA representative, unless an exemption applies. The representative may be contacted by supervisory authorities and data subjects on GDPR matters. International transfers of personal data from Norway to countries outside the EEA are subject to Chapter V of the GDPR. Transfers may take place on the basis of an adequacy decision, or, in the absence of such a decision, where appropriate safeguards are provid - ed, such as the EU Standard Contractual Clauses or Binding Corporate Rules, unless a specific derogation applies. For transfers to the United States, the EU–US Data Privacy Framework currently permits transfers
to US organisations certified under the framework, while transfers to non-certified US recipients require another valid transfer mechanism. Businesses using non-EEA service providers should map relevant data flows, including remote access, cloud services, sub- processors and onward transfers, and assess whether the chosen transfer mechanism is effective in practice. Where necessary, supplementary technical, contrac - tual or organisational safeguards must be implement - ed. For practical purposes, a foreign business actively targeting Norwegian customers should assume that GDPR compliance may be required even without a Norwegian subsidiary or branch. 8.3 Role and Authority of the Data Protection Agency The Norwegian Data Protection Authority, Datatilsynet, is the supervisory authority responsible for enforcing data protection rules in Norway. It is an independent administrative authority and supervises compliance with the GDPR and the Norwegian Personal Data Act. Datatilsynet’s role includes providing guidance, han - dling complaints from individuals, conducting investi - gations and inspections, assessing data breach notifi - cations, and supervising controllers and processors. It may also issue opinions and guidance on new legisla - tion, technology and processing practices. Datatilsynet has the enforcement powers provided by the GDPR. It may order a controller or processor to bring processing into compliance, require infor - mation, impose temporary or permanent processing bans, order rectification or deletion of personal data, issue reprimands and impose administrative fines. The maximum GDPR fines are the same as in the EU: up to EUR 20 million or 4% of worldwide annual turnover, depending on the nature of the infringement. Datatilsynet also co-operates with other European supervisory authorities through the GDPR co-opera - tion and consistency mechanisms. As Norway is part of the EEA, Datatilsynet participates in the European Data Protection Board system, although Norway is not an EU member state.
801 CHAMBERS.COM
Powered by FlippingBook