NORWAY Law and Practice Contributed by: Kari Gimmingsrud, Stian Hultin Oddbjørnsen and Andreas Bernt, Haavind
Transport When it comes to AI in transport, Norway has adopted specific regulations on the testing of autonomous vehicles. The Norwegian Public Roads Administration is authorised to grant permits for testing of autonomous vehicles in restricted areas. Aviation regulations regulate the use of drones. An entity must register and acquire a licence to operate drones on both a personal and commercial level. 4. Internet of Things 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection There is not yet any specific Norwegian leg - islation regarding the internet of things (IoT), although there has been a manifest proliferation of sensor technology across industries and for personal use in Norway in the last decade. EU Data Act In November 2023, the EU Data Act (Regula - tion (EU) 2023/2854)) (Data Act) was adopted by the EU, with the stated purpose of enhancing innovation within the EU by providing increased access to, as well as greater opportunities for the re-use of, data originating from connected prod - ucts and related services. As Norway is not part of the EU (but part of the EEA) the Act will not apply directly in Norway until implemented. The process of evaluating whether the text should be included in the EEA Agreement, and subse - quently implemented into Norwegian law, often takes significantly longer than the time it takes for the legal act to take effect in EU countries. At the time of writing, no date for implementation of the Data Act in Norway has been announced. Nevertheless, the Data Act will also have impli -
cations for Norwegian businesses operating in the EU before any implementation in Norway. Data-Dependent Requirements Legal regulation applicable to the processing of data within IoT devices will apply, depending on the type of data processed in the devices. All processing of personal data (in IoT devices or otherwise) must comply with data protection regulation, including the general principles of the GDPR, such as not collecting more data than is necessary for the purpose of processing (data minimisation) and not processing data in a man - ner that is incompatible with the initial purposes of processing (purpose limitation). Accordingly, legal requirements for data protection will limit the scope of IoT projects when it comes to per - sonal data, as these devices usually collect a large amount of data. If IoT devices are used in a workplace environ - ment, specific attention should be given to Nor - wegian employee monitoring regulation, which limits allowed processing purposes and sets out procedural requirements. In addition, some entities may be subject to Nor - wegian mandatory security requirements due to the sector in which they operate – eg, entities in the health, utilities and financial sectors. Such security requirements may apply to the use of IoT devices. General Requirements for Products General product safety requirements applicable to electronic products and requirements applica - ble to products communicating through publicly available communication networks may apply to IoT devices. The European Telecommunications Standards Institute has issued a consumer IoT security standard (ETSI EN 303 645), setting a
347 CHAMBERS.COM
Powered by FlippingBook