Professional expertise in privacy
We can help you navigate the regulations, find solutions for digitizing the business and at the same time safeguard privacy and business-critical data.
Bull is among the law firms in Norway with the largest number of specialized privacy lawyers.
Our services include, among other things:
Systematic assessment of discrepancies between your current practices (current situation) and the requirements of the GDPR.
Including processing protocols (RoPA), deletion procedures (retention periods) and bespoke guidelines.
Drafting and review, tailored to your supplier and product portfolio.
In relevant languages and tailored to your organisation’s processing activities.
Including mapping, risk assessment and documentation for management approval.
Including transfer impact assessments (TIA), selection of transfer mechanisms and risk assessment of the recipient country.
Including procedures and templates for access, erasure, rectification and data portability.
Including procedures, standard templates and a contingency plan for data breaches.
Emergency assistance in the event of data breaches and cyber attacks through our response team. Read more.
Ongoing professional support with full independence, for organisations that are required or wish to have an external Data Protection Officer (DPO). Read more.
Assessment of the obligation to appoint and the setup of an internal or external Data Protection Officer.
HR data, employee monitoring, background checks and the processing of personal data in employment relationships.
Profiling, cookies, consent mechanisms and the use of personal data in marketing.
Privacy assessments during the development and procurement of software (IT systems).
Risk assessment, DPIA and compliance when using artificial intelligence (AI) in business.
Privacy review and risk assessment as part of the due diligence process (corporate transactions).
Basic training, role-based training and organisation of data protection work.
Workshop for the management team covering requirements, personal responsibilities, strategic importance and recommendations for further work.
Great rankings and satisfied clients
We are ranked among the best in the field, both in Finansavisen, The Legal 500, Who'sWho Legal and Chambers and partners.
Useful insight
The use of cookies is regulated in Norway by the Electronic Communications Act as well as the GDPR. The general rule is that non-essential cookies require the user’s active consent before they are set.
In practice, this means:
- Technically necessary cookies – for example, for logging in and the shopping basket – may be set without consent
- All other cookies, including analytics and marketing tools such as Google Analytics and Meta Pixel, require prior consent
- The cookie banner must give the user a genuine choice: it should be just as easy to opt out as to opt in
- Pre-ticked boxes do not constitute valid consent
- Users must be able to easily withdraw their consent at any time
It is not sufficient to provide information about cookies after they have already been set. Many Norwegian websites still do not comply with these requirements, and in recent years the Norwegian Data Protection Authority has shown increased interest in enforcement in this area.
All processing of personal data must have a legal basis (basis for processing). Without a valid basis, the processing is unlawful. The GDPR sets out six possible bases: consent, necessity for a contract or request, legal obligation, vital interests, public interest and legitimate interest. The basis must be identified and documented before processing begins; it is not possible to choose a basis retrospectively.
Consent is the basis many people turn to first, but it is also the most challenging to apply correctly. Consent is only valid if it is:
- Voluntary: the data subject must have a genuine choice to say no without facing any negative consequences
- Specific: given for a specific and clearly defined purpose
- Informed: the data subject must understand what they are consenting to and who is processing the data
- Unambiguous: consent must be actively given, for example by the user ticking a box themselves. Pre-ticked boxes result in invalid consent.
Consent may be withdrawn at any time. It must be just as easy to withdraw consent as it is to give it. In employment relationships, consent is rarely a suitable legal basis, because the unequal balance of power between employer and employee makes it difficult to say that the consent is genuinely voluntary.
Legitimate interest is perhaps the most commonly used legal basis for processing. The data controller’s interest must be genuine and legitimate. The impact on privacy must be minimal. This balancing test must be documented.
The GDPR requires organisations to be able to demonstrate that they comply with the regulations, not merely that they are aware of them. A good place to start is a gap analysis: a systematic review of what you are currently doing compared with what the regulations require. The gap analysis identifies shortcomings and provides a concrete basis for prioritising further work.
At the heart of the documentation is the processing record (also known as RoPA – Records of Processing Activities). This is an overview of all the ways in which the organisation processes personal data, and is a legal requirement for the vast majority of organisations under Article 30 of the GDPR. It must include the purposes, categories of data and data subjects, recipients, retention periods and security measures. The processing register is the first thing the Data Protection Authority requests during an inspection.
A comprehensive internal control system should also include:
- Privacy notices (internal, for staff etc.) and external (typically on the website)
- Guidelines and procedures for the most common processing situations
- Deletion procedures and plans
- Procedures for data breaches and incident management
- Procedures for handling data subjects’ rights
- Training plan for staff
You must also have:
- Privacy notices (internal, for staff etc.) and external (typically on the website)
- Data processing agreements (with your subcontractors who process data on your behalf)
Good internal controls are the best protection against fines for breaches and liability for damages.
A data processing agreement is required whenever your organisation allows another organisation to process personal data on your behalf. Typical examples include outsourcing IT operations, using cloud-based payroll or invoicing systems, purchasing HR services, or using marketing tools that handle customer data. Without a data processing agreement, the processing is, in principle, unlawful, regardless of whether it is carried out responsibly in practice.
Article 28 of the GDPR sets out specific requirements regarding the content of the agreement. As a minimum, the agreement must regulate:
- What kind of personal data is processed and for what purposes
- That the data processor acts solely in accordance with documented instructions from you
- Requirements for adequate information security
- Rules on the use of sub-processors
- The obligation to assist with data subjects’ rights
- Notification in the event of a data breach
- What happens to the data when the agreement ends, deletion or return
- Right to audit and inspection
Many organisations have far more data processing arrangements than they realise. A review of the supplier portfolio is therefore a useful first step.
A DPIA (Data Protection Impact Assessment) is required by law if it is likely that planned processing will pose a high risk to individuals’ privacy. The assessment must be carried out before processing begins, not afterwards.
The Norwegian Data Protection Authority has published a list of types of processing that always trigger the requirement for a DPIA. In addition, a DPIA is typically necessary if the processing involves:
- Systematic and comprehensive profiling that forms the basis for automated decisions
- Large-scale processing of special categories of personal data, such as health data
- Systematic monitoring of publicly accessible areas
- Use of new technology where the privacy implications are uncertain
- Processing of personal data relating to vulnerable groups, such as children or employees
A DPIA involves a systematic description of the processing, an assessment of necessity, proportionality and risk, and a concrete plan for measures to mitigate the risk. Finally, management must approve the assessment. If the risk cannot be reduced to an acceptable level, the Norwegian Data Protection Authority must be consulted before processing commences.
A data breach is any incident resulting in unauthorised or unlawful access to, loss of, or disclosure of personal data. This includes everything from cyber-attacks and ransomware to misdirected emails and lost devices.
If a data breach is likely to pose a risk to the rights of data subjects, the breach must be reported to the Norwegian Data Protection Authority within 72 hours of its discovery. This deadline is absolute. If you are unable to gather all the information within the deadline, report what you know and provide the remaining details later. If the breach is likely to result in a high risk, the individuals concerned must also be notified directly without undue delay.
To manage data breaches appropriately, the organisation should have:
- Clear procedures for who does what when a breach is detected
- An internal incident log documenting all incidents, regardless of whether they are reported to the Data Protection Authority
- Standard templates for notifications to the Data Protection Authority and to data subjects
- Training for staff on how to recognise and report potential breaches internally
Many of the most serious cases handled by the Data Protection Authority do not concern the breach itself, but rather a lack of procedures and delayed notification.
A Data Protection Officer is mandatory for three categories of organisations:
- Public authorities and public bodies, with some exceptions for courts
- Organisations whose core activity involves the regular and systematic monitoring of data subjects on a large scale, such as platforms that track user behaviour, telecoms companies or companies engaged in profiling
- Organisations whose core activities involve the large-scale processing of special categories of personal data, such as healthcare providers, insurance companies and HR firms
Private organisations that do not fall into these categories are not obliged to do so, but many choose to appoint a data protection officer on a voluntary basis, particularly if they process large amounts of personal data or operate in regulated sectors. An alternative may be to appoint a data protection officer, as the appointment of a data protection officer imposes stricter obligations.
A data protection officer must have in-depth expertise, be professionally independent and cannot be instructed in their supervisory work. The DPO may be an in-house employee or an external service provider. An external DPO service provides access to in-depth specialist expertise without the costs associated with permanent employment, and is a flexible option for many organisations.
A privacy policy is a document setting out how an organisation processes personal data. It must provide data subjects (customers, users, employees or others) with sufficient information to understand what happens to their data. The policy is a statutory duty to provide information, not an optional document.
A privacy policy must contain at least the following:
- Who the data controller is and how they can be contacted
- What personal data is processed and for what purposes
- The legal basis for each processing activity
- Who the data may be shared with
- Whether data is transferred to countries outside the EEA and on what basis
- How long the data is stored
- The data subjects’ rights: access, rectification, erasure, data portability and the right to lodge a complaint
The privacy notice must be written in clear and understandable language (not in legal jargon) and must be easily accessible, typically via a link in the footer of the website (for external privacy notices). Internal privacy notices must be easily accessible to employees and contractors. The policies must be updated in the event of changes to processing practices.
The GDPR operates with two levels of administrative fines:
- Up to 10 million euros, or 2 per cent of global annual turnover, for breaches of requirements relating to internal controls, data processing agreements and the obligation to report data breaches
- Up to 20 million euros, or 4 per cent of global annual turnover, for the most serious infringements, such as processing without a valid legal basis, failure to provide information (privacy notice), refusal of access and rectification, unlawful profiling, breaches of other fundamental principles of data protection, and unlawful transfers to third countries
The higher of the two amounts is taken as the basis. In Norway, the Norwegian Data Protection Authority has, amongst other things, imposed a fine of 65 million kroner on Grindr. The Norwegian Data Protection Authority may also issue orders for rectification and prohibit processing.
In addition, you may be liable to data subjects for financial and non-financial losses. If the data breach affects a large number of people, the sums involved may be substantial. In the worst-case scenario, your organisation may face a class action.
Responsibility for compliance lies with the organisation as a legal entity, but the board and senior management have a clear overarching responsibility. The board should maintain an overview of the organisation’s most significant processing activities and risks, approve the data protection strategy, ensure adequate resources for compliance, and be kept informed of serious non-compliance incidents and supervisory cases. A lack of management commitment is an aggravating factor in the Data Protection Authority’s determination of fines and may give rise to personal liability for damages on the part of board members in the event of negligence (under the Companies Acts – board liability).
Under the GDPR, all natural persons whose personal data you process have a number of rights:
- Right of access: they have the right to know what information you hold about them and what it is used for
- Right to rectification: inaccurate or incomplete data must be corrected
- Right to erasure: in certain cases, the data subject has the right to request that the data be erased
- Right to restriction of processing: in some situations, processing may be temporarily suspended or restricted
- Right to data portability: information provided with consent or for the performance of a contract must be provided in a machine-readable format
- Right to object: the data subject may object to processing based on legitimate interests, and may always object to direct marketing
In the event of a data access request, you are obliged to respond within one month. The deadline may be extended by a further two months in the case of complex requests, but the data subject must then be notified within the first month. The response must, as a rule, be provided free of charge. The organisation should have clear procedures for receiving and handling such requests. This is one of the areas in which the Norwegian Data Protection Authority receives the most complaints.

Bull strengthens position in Chambers Europe 2026
Bull once again stands out in Chambers Europe, with rankings in three practice areas and as many as eleven individual recognitions.
Read more
NIS2: Personal liability for management and employees
The NIS2 directive is a new EU regulation that tightens cybersecurity requirements and introduces personal liability ...
Read more
Expertise
- Auditing and accounting
- Climate, environment, waste and sustainability
- Commercial Contracts
- Company law and transactions
- Competition law, state aid and EU/EEA
- Construction
- Employment law
- Familiy law, guardianship and divorce
- Industry
- Inheritance, probate and succession planning
- Insurance and liability
- Intellectual property and marketing law
- Investigation, compliance and financial crime
