Skip to content

Evidence request lists

Personal Data Act (personopplysningsloven)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability

NORWAY-4
DPIA, Privacy by Design, Records of Processing

Per Norwegian PDPA + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + Datatilsynet lists + (b) implement Privacy by Design and Default across systems + processes + products + procurement per GDPR Article 25 + (c) maintain Records of Processing Activities per GDPR Article 30 including purposes + categories + recipients + retention + safeguards + (d) maintain Internal Compliance Programme including governance + roles + monitoring + improvement + (e) integrate with broader privacy + risk + IT governance + (f) maintain documented accountability framework.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-4
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Breach and Enforcement

NORWAY-8
Breach Notification, Complaints, Compliance, Enforcement

Per Norwegian PDPA + GDPR Articles 33-34 + 77-84: breach notification + enforcement. Requirements include (a) implement Notification of Personal Data Breaches to Datatilsynet within 72 hours of becoming aware unless unlikely to result in risk + notify affected data subjects where high risk per GDPR Article 34 + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) operate Complaints Handling and Resolution mechanism enabling complaints to controller + Datatilsynet + (d) maintain Compliance Monitoring and Auditing + Regulatory Reporting and Cooperation + (e) maintain Enforcement and Penalties awareness including administrative fines (up to higher of EUR 20m or 4% global annual turnover) + corrective powers + (f) maintain breach log + incident response + tabletop exercises.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-8
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Governance and Lifecycle

NORWAY-7
DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Per Norwegian PDPA: governance + lifecycle. Requirements include (a) appoint Data Protection Officer where required per GDPR Article 37 with defined responsibilities + reporting to highest management + (b) maintain Cooperation With Datatilsynet (Norwegian Data Protection Authority) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing and ePrivacy safeguards per Norwegian + EU ePrivacy including consent + opt-out + suppression lists + (e) deliver Training and Awareness programmes including role-based content + GDPR + Norwegian specifics + (f) maintain documented governance + accountability framework.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-7
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

High-Risk Processing

NORWAY-3
Special Categories, Children's Data, Employment Context

Per Norwegian PDPA + GDPR Article 9 + Norwegian supplements: heightened safeguards for high-risk processing. Requirements include (a) implement Special Categories of Data protections including health + biometric + genetic + religious + political + sexual orientation + criminal records with strict lawful basis per GDPR Article 9 + (b) implement Children's Data protections per GDPR Article 8 + Norwegian age of consent (13 years per Section 5 of personopplysningsloven) + (c) implement Employment Context Processing including Norwegian-specific employment privacy protections including monitoring + email access + (d) maintain DPIA for high-risk processing + (e) integrate with Privacy by Design and Default + (f) maintain documented safeguards + risk assessments.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-3
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Individual Rights

NORWAY-2
Data Subject Rights and Automated Decision-Making

Per Norwegian PDPA + GDPR Articles 12-22: data subject rights. Requirements include (a) implement Data Subject Rights including Access + Rectification + Erasure + Restriction + Object + Data Portability per GDPR + (b) implement Right to Object specifically for direct marketing + (c) implement Automated Decision Making protections including human review + meaningful information about logic + explanation + (d) maintain mechanism for receiving + verifying + responding within statutory timelines (typically 30 days extendable) + (e) maintain records of requests + responses + decisions + (f) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-2
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Scope and Lawful Basis

NORWAY-1
GDPR Implementation, Scope, Transparency, Lawful Basis

Per Norwegian Personal Data Act (personopplysningsloven, Lov av 15. juni 2018 nr. 38) implementing GDPR: scope + transparency + lawful basis. Requirements include (a) implement GDPR through national law per Lov om behandling av personopplysninger including direct GDPR application + Norwegian supplements (employment context + criminal records + similar) + (b) determine scope including extraterritorial application per GDPR Article 3 + (c) provide Transparency through privacy notices covering identity of controller + purposes + categories + recipients + retention + rights + transfer + (d) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + (e) document applicability + lawful basis + (f) align with EEA and EU developments including evolving guidance from EDPB + Datatilsynet.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-1
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Security

NORWAY-5
Security of Processing, Encryption, Pseudonymization, Access Control

Per Norwegian PDPA + GDPR Article 32: security of processing. Requirements include (a) implement appropriate technical + organisational security measures appropriate to risk per GDPR Article 32 + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) align with NSM (Norwegian National Security Authority) guidance + Datatilsynet expectations.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-5
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial

Transfer and Processor Management

NORWAY-6
International Transfers and Processor Agreements

Per Norwegian PDPA + GDPR Chapter V + Article 28: transfer + processor management. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with Datatilsynet on transfer matters.

Artefacts an auditor will ask for
  • Norway PDPA evidence for NORWAY-6
Where this commonly fails
  • DPO + DPIA + TIA + breach notification + Datatilsynet cooperation partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Personal Data Act (personopplysningsloven) framework page.