Brækhus strengthens its position within gaming and entertainment law through a contribution to the international publication Panoramic – Gaming 2026. Alexander Mollan and Brede A. Haglund have authored the Norwegian chapter on gambling regulation in Norway.
Alexander Mollan and Brede A. Haglund have recently authored the Norwegian chapter on gaming for the latest edition of the renowned publication ” Panoramic – Gaming 2026″ published by Law Business Research Ltd.
Panoramic is a globally recognised, Q&A-based reference guide that covers legislation and key issues in 150 jurisdictions. The guide is relied upon by more than 150,000 in-house counsel, private practitioners, and executives in both the private and public sectors, providing comprehensive insights into current legal frameworks and significant developments within each jurisdiction.
Brækhus is among the select few law firms in Norway with a dedicated team of specialists in gaming and entertainment law. Our lawyers have extensive experience in establishing international service offerings, managing sales processes, navigating national and EU/EEA legal matters, meeting financial requirements, advising on marketing law, and handling a wide range of legal and commercial matters in Norway. We also assist clients with applications for the establishment of gaming operations in Norway, including lotteries, poker, bingo, and skill-based offerings.
In this guide you can get a brief overview of data protection law in Norway, including how the GDPR applies under the EEA Agreement, Norwegian-specific rules on national identity numbers and employee monitoring, and the role of the Norwegian Data Protection Authority.
This guide provides a practical introduction to Norwegian data protection law for foreign businesses operating in Norway or considering a Norwegian presence, whether through a Norwegian branch office or a Norwegian subsidiary. The guide focuses on the rules most relevant to day-to-day operations and highlights where Norwegian law goes beyond the GDPR framework that many foreign businesses will already be familiar with.
GDPR applies in full
While Norway is not a member of the European Union, it is a contracting party to the Agreement on the European Economic Area (the “EEA Agreement”), on which basis it incorporates the significant portion of the EU regulatory framework (incl. the GDPR into Norwegian law.
The GDPR therefore applies in Norway in the same way as in EU member states, with the same scope, obligations and sanctions. The GDPR was implemented into Norwegian law through the Personal Data Act of 2018, which both gives the GDPR force of law and adds several Norwegian-specific rules on top of it.
The Norwegian Data Protection Authority is the competent supervisory authority. It is an active regulator that publishes detailed guidance, conducts inspections and has issued substantial administrative fines against both Norwegian and foreign companies.
For a foreign business with a Norwegian subsidiary or branch, the GDPR’s establishment-based territorial scope will typically apply. Processing activities carried out in the context of the Norwegian establishment must comply with the GDPR, regardless of where the actual processing takes place. Even without a formal establishment, a foreign company targeting Norwegian consumers or monitoring individuals in Norway may fall within the GDPR’s extraterritorial reach under Article 3(2).
Norwegian-Specific Rules: What Foreign Businesses Need to Know
The Personal Data Act supplements the GDPR in several respects that are particularly relevant to foreign businesses with a Norwegian footprint.
National Identity Numbers
Section 12 of the Personal Data Act imposes restrictions on the processing of Norwegian national identity numbers and D-numbers that go beyond the ordinary GDPR framework. Such numbers may only be processed where there is a clear and legitimate need for certain identification of the data subject, or where processing is required by law. It is not sufficient that a valid GDPR legal basis exists; the specific necessity condition under Section 12 must be satisfied independently. This requirement is practically relevant for payroll and HR systems, customer onboarding, identity verification, and any operational context in which Norwegian identity numbers would routinely be collected or stored.
Employer Monitoring and Control Measures
Chapter 9 of the Working Environment Act regulates the use of control measures and employee monitoring in the workplace. This covers monitoring of employees’ use of electronic communications, e-mail, internet access, GPS tracking, and video surveillance, among other measures. An employer may only implement a control measure if it has an objective justification in the company’s operational needs and the burden placed on employees is not disproportionate to that purpose.
These requirements apply in addition to, and independently of, the GDPR. Even where a valid legal basis exists under the GDPR for processing employee data, the control measure must separately satisfy the Chapter 9 conditions. Employees must be informed in advance, and the measure should ordinarily be discussed with employee representatives before it is introduced. For foreign businesses accustomed to treating the GDPR as the sole compliance framework for employee monitoring, this additional layer of Norwegian employment law is a significant practical consideration when deploying group-wide HR monitoring solutions or surveillance tools in Norway.
Camera Surveillance
The Regulation on camera surveillance in undertakings contains specific rules on the use of camera surveillance, including requirements regarding signage and the rights of individuals in areas subject to monitoring. Where a Norwegian business premises includes areas accessible to employees or the public, these rules apply alongside the GDPR’s general accountability requirements and may impose obligations that are not obvious from the GDPR text alone.
Accountability and Enforcement
Foreign businesses with a Norwegian establishment should ensure that their group-level GDPR compliance framework accounts for the Norwegian-specific rules described above. This includes appointing a data protection officer where required, maintaining records of processing activities and conducting data protection impact assessments for high-risk processing activities.
Where the Norwegian entity participates in cross-border processing activities within the EEA, the GDPR’s one-stop-shop mechanism may apply. It is worth clarifying at an early stage which supervisory authority will act as lead authority, as this affects where enforcement proceedings may be initiated and where complaints about the company’s processing can be lodged.
The Norwegian Data Protection Authority is generally regarded as an engaged and accessible authority. It publishes sector-specific guidance and provides informal opinions, which can be a valuable resource for businesses seeking to understand their obligations in novel or uncertain situations.
Next Steps
We regularly assist foreign businesses with GDPR and Norwegian data protection compliance, including structuring compliance programmes for Norwegian entities, advising on employee monitoring frameworks, reviewing HR documentation, and providing guidance on dealings with the Norwegian Data Protection Authority.
Contact us today for an informal discussion on how we can assist you.
Brækhus contributes cybersecurity expertise to this year’s edition of “Cybersecurity 2026”
Alexander Mollan has authored the Norwegian chapter on cybersecurity in this year’s edition of “Cybersecurity 2026”, published by The International Comparative Legal Guides (ICLG).
Alexander Mollan has written the Norwegian chapter on cybersecurity in the 2026 edition of “Cybersecurity 2026”, published by The International Comparative Legal Guides (ICLG). His contribution, titled “Cybersecurity Laws and Regulations Report 2026 – Norway”, addresses key aspects of the Norwegian cybersecurity framework.
The chapter provides an overview of the Norwegian legal framework for cybersecurity, including international compliance requirements, litigation, investigations, and the powers of the police and other authorities.
Alexander Mollan and Brede A. Haglund have recently authored the Norwegian chapter on gaming for the latest edition of the renowned publication “Panoramic – Gaming 2025” published by Law Business Research Ltd.
Panoramic is a globally recognised, Q&A-based reference guide that covers legislation and key issues in 150 jurisdictions. The guide is relied upon by more than 150,000 in-house counsel, private practitioners, and executives in both the private and public sectors, providing comprehensive insights into current legal frameworks and significant developments within each jurisdiction.
Brækhus is among the select few law firms in Norway with a dedicated team of specialists in gaming and entertainment law. Our lawyers have extensive experience in establishing international service offerings, managing sales processes, navigating national and EU/EEA legal matters, meeting financial requirements, advising on marketing law, and handling a wide range of legal and commercial matters in Norway. We also assist clients with applications for the establishment of gaming operations in Norway, including lotteries, poker, bingo, and skill-based offerings.
NIS2 and Norwegian Law: What Your Business Needs to Know in 2025
The NIS2 Directive, adopted by the EU in December 2022, represents a significant update to the original NIS Directive from 2016. Its primary goal is to strengthen cybersecurity across critical sectors and improve protection against increasingly sophisticated cyber threats.
While EU member states were required to implement NIS2 by October 2024, the directive has not yet been incorporated into Norwegian law as of May 2025. However, Norwegian businesses should start preparing now to meet the upcoming requirements.
For an overview of the implementation of NIS2 in other european countries, please click here.
What Is NIS2, and Who Does It Apply To?
Once implemented in Norway, NIS2 will introduce stricter cybersecurity requirements for businesses in sectors such as energy, healthcare, transport, financial services, and digital infrastructure. The directive will apply to medium-sized and large organisations in these sectors, with stricter obligations for entities classified as “essential.” Key obligations under NIS2 include:
Risk Management: Businesses must implement technical and organisational measures to manage cybersecurity risks effectively.
Incident Reporting: Significant cybersecurity incidents must be reported to relevant authorities within tight deadlines, likely within 24 hours.
Supply Chain Security: Organisations must ensure that their suppliers and service providers meet cybersecurity standards.
Governance and Accountability: Clear responsibilities for cybersecurity must be established at the management level, with boards and executives held accountable for compliance.
Regular Audits: Businesses will need to conduct periodic risk assessments and audits to ensure ongoing compliance.
How Can Businesses Operating in Norway Prepare?
Although NIS2 has not yet been implemented in Norway, businesses can take proactive steps to prepare for its eventual adoption:
Stay Informed About Legislative Developments Keep track of updates regarding NIS2’s implementation in Norway. Consult with legal experts to understand how the directive will impact your business.
Conduct a Cybersecurity Gap Analysis Evaluate your current cybersecurity measures against the anticipated requirements of NIS2. Identify gaps and create a plan to address them before the directive becomes law.
Develop an Incident Response Plan Prepare for the directive’s likely incident reporting requirements by creating and testing a robust incident response plan. Ensure your team is equipped to detect, respond to, and report cyber incidents effectively.
Collaborate with Your Supply Chain Work closely with suppliers and service providers to verify their cybersecurity practices. Update contracts to include specific security obligations that align with NIS2 standards.
Raise Awareness Across Your Organisation Provide training to employees and management about the importance of cybersecurity and the anticipated requirements of NIS2. Building a culture of security awareness will help your organisation adapt smoothly to the new regulations.
Why Act Now?
Although the timeline for NIS2 implementation in Norway remains uncertain, waiting until the last minute to prepare could expose your business to unnecessary risks. Non-compliance with the directive, once it becomes law, could result in significant penalties, including fines and reputational damage. Early preparation not only ensures compliance but also strengthens your organization’s resilience against cyber threats, giving you a competitive edge in an increasingly digital economy.
How Brækhus Can Support Your Business in adapting to NIS2
At Brækhus, we specialise in helping businesses navigate complex regulatory landscapes. Our team of legal and cybersecurity experts is closely monitoring the progress of NIS2 implementation in Norway and is ready to assist your business in preparing for the changes ahead.
We offer tailored advice and practical solutions, including:
Conducting compliance assessments
Developing incident response plans
Strengthening supply chain security
Providing training and awareness programs
Contact us today to learn how we can support your business in adapting to NIS2 and enhancing its cybersecurity posture. By acting now, your organisation can stay ahead of regulatory developments and position itself for long-term success in a rapidly evolving threat landscape.
CSRD and CSDDD – What’s the difference and what do they mean for your business? Join us for a breakfast seminar where we take a practical approach to the CSRD and CSDDD and share insights on how to navigate compliance requirements and turn sustainability obligations into opportunities.
kl. 07:30 – 09:00
Venue: Brækhus, Roald Amundsens vei 6, Oslo
06
Mar
Key Topics:
✅ CSRD & CSDDD: What you need to know
✅ Basic principles of the OECD Guidelines
✅ Practical strategies for effective due diligence
✅ Contract and audit management
✅ Best practice examples for compliance with due diligence and disclosure legislation
Speakers:
☕ Breakfast will be served
Take advantage of this opportunity to gain valuable insights, ask questions, and network with industry professionals over breakfast.
Cost:
This is a free in-person event open to eligible professionals. Places are limited. To secure your place, please use this form
Brækhus has contributed to Gambling 2025, published in The International Comparative Legal Guides
Alexander Mollan and Brede A. Haglund have recently contributed to the Norwegian chapter on gambling in this year’s edition of the prestigious publication “The International Comparative Legal Guides”. The article is published in The International Comparative Legal Guides – Gambling 2025 by Global Legal Group Ltd.
The International Comparative Legal Guides is a Q&A-based worldwide reference guide covering 140 jurisdictions. The guide is used as an information resource by in-house lawyers, private practitioners and heads of companies and governmental institutions, and provides an overview of current legislation and important issues within a given jurisdiction.
The article is reproduced with permission from Global Legal Group Ltd. and can be read here.
Brækhus is one of the few law firms in Norway with a dedicated group of experts in gaming and entertainment activities. Our lawyers have experience related to the establishment of international service offerings, sales processes, national and EU/EEA legal issues, financial requirements, marketing law, and general legal and commercial relationships in Norway. We have also assisted with applications for the establishment of gambling in Norway, including poker and gaming machines.