Jurisdictions Surveyed:
The Americas: Argentina | Brazil | Mexico
East Asia, South Asia and Pacific: Australia | China | India | Japan | South Korea | Taiwan
Europe and Central Asia: European Union | England | France | Iceland | Italy | Norway | Portugal | Russia | Spain | Turkey
Middle East and Africa: Iran | Israel | South Africa | United Arab Emirates


Norway protects the right to privacy in its Constitution and, following a European Economic Area (EEA) Joint Committee Decision in 2018, is bound by the European Union General Data Protection Regulation. Personal data may typically be stored for purposes of a public need and may specifically be used and shared to prevent the spread of contagious diseases.

Norway has launched a physical location tracking app, Smittestopp, to locate and prevent the spread of COVID-19. The app, which is available for download to Android, Google, and Huawei smartphones, uses both Bluetooth technology and GPS to track users who are in close proximity, defined as within two meters (about six feet) of each other for at least fifteen minutes. Downloading the app is voluntary, and once downloaded the app requires consent in order for the Norwegian Institute of Public Health to track the location of the person. The information is deleted after thirty days.

The Norwegian Data Protection Authority, Datatilsynet, is currently investigating whether the app complies with Norwegian and international data protection rules. An expert committee has recommended that changes be made to the app to enable further anonymization and prevent individual identification.

I. Introduction

A. COVID-19 Infections

Norway has a low rate of infection and deaths related to COVID-19 and a high rate of testing.[1] As of May 22, 2020, it had 8,309 confirmed cases and 235 fatalities from COVID-19,[2] the equivalent of 43 deaths per million residents.[3] Norway reported its first confirmed case of COVID-19 on February 24, 2020.[4] On March 12, 2020, it reported its first fatality.[5] On May 22, 2020, it reported no new deaths from COVID-19.[6] During the prior week a total of 15 persons were reported to have died from COVID-19.[7]

B. Smartphone Use

The use of smartphones is widespread in Norway. In 2019, Statistics Norway (Statistisk Sentralbyrå, SSB) reported that close to 100% of Norwegians age 9 to 79 have a cellular phone, and 95% have a smartphone,[8] not counting any smartphone access persons may have via their work.[9] Most users use either Telenor or Telia; Telenor has the largest market share of account subscribers with almost half of the market (48.9%), with Telia at 37.2%.[10]  

II. Legal Framework

A. Privacy and Data Protection

The Norwegian Constitution guarantees the right to privacy in article 102, which states that “[e]veryone has a right to respect for his or her personal life and family life, as well as his or her home and communication. House searches may not be conducted, except during criminal investigations. State authorities shall ensure the protection of personal integrity.”[11] In addition, Norway is a signatory to the European Convention on Human Rights, which guarantees the right to privacy in article 8.[12]

Norway regulates privacy rights and data protection in its Personal Information Act.[13] Though not a European Union (EU) Member State, it is bound by the EU legislation on personal data, namely the General Data Protection Regulation (GDPR),[14] because of its obligations as a member of the European Economic Area (EEA) and European Free Trade Agreement (EFTA). In 2018 the EEA Joint Committee signed on to the GDPR legislation in order to ensure harmonized rules on data protection within the EEA.[15] The Personal Information Act incorporates the EU GDPR.[16] Thus, the same rules for the collection of data apply in Norway as in the EU Member States.[17]

In accordance with the GDPR as implemented in the Personal Information Act, “personal data” is defined as

any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.[18]

 Data may only be collected in the following situations:

a.      the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b.      processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c.      processing is necessary for compliance with a legal obligation to which the controller is subject;

d.      processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e.      processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f.        processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.[19]

Thus, the general basis for the collection of information is informed, adequate, and voluntary consent.[20] Specifically, consent is defined in article 4  of the GDPR as “any  freely  given, specific,  informed  and  unambiguous indication of  the  data subject's wishes by  which  he  or  she,  by  a  statement or  by  a  clear  affirmative action, signifies  agreement to  the processing of personal data relating to him or her.”[21] Moreover, as specified in article 7, such consent must “be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.”[22] A person’s consent remains revocable at all times.[23] In addition, a person must be at least 13 years old to provide consent under Norwegian law.[24] As implemented in Norwegian law, consent can also be given for the collection and processing of all sensitive data, as Norway has not provided additional provisions to further limit the sharing of sensitive information.[25] Thus, there is no data that cannot be shared provided that prior adequate and voluntary consent has been given during the collection phase.[26]

Legally, information may be stored without the consent of the data subject, if needed for a public purpose.[27] However, in such cases the public interest in processing the data must clearly exceed the disadvantages to the person whom the data is about (the data subject) and must be approved by the Norwegian Data Protection Agency.[28] The storage and sharing of data typically requires anonymization and pseudonymization.[29] In accordance with the Personal Information Act the Personal Data Authority may allow the handling of personal data in individual cases, if in the public interest.[30] Similarly, the government may issue specific regulations pertaining to data retention.[31]  The collection of personal data, allowing use also without consent, is regulated in a number of legal acts, including the Criminal Procedures Act and the Health Registry Act.[32] The lawfulness of measures that may be used to contain contagious diseases is regulated in the Control of Communicable Diseases Act.[33] The law allows for the collection and sharing of personal data in order to prevent disease.[34] The permissibility of using personal data to trace contagious disease is specifically mentioned in the GDPR, and was also mentioned in the bill implementing the GDPR into Norwegian law.[35] The GDPR allows for the use and sharing of personal information when needed for disease tracing.[36]

B. Data Retention and Location Tracking

The telecommunications sector is regulated by the Electronic Communication Act.[37] However, location tracking is primarily regulated through the Personal Information Act as, per the GDPR, the definition of personal data includes location data.[38] As mentioned above, the Personal Information Act authorizes the Personal Data Authority to handle and retain personal data in individual cases, if in the public interest.[39] Similarly, the government may issue specific regulations pertaining to data retention.[40] Telecommunication service providers may store data, including location data, but only for as long as needed; they must delete or anonymize the data when no longer needed.[41]

C. Enforcement

Datatilsynet, the Norwegian Data Protection Authority, is the supervisory authority for the collection and use of personal data in Norway.[42]  Violations are subject to monetary fines, including compulsory fulfillment fines that run until the violation has been corrected.[43] Violations are also subject to damages for nonmonetary losses caused by the breach of the data protection rules.[44]

D. COVID-19 Tracing Legislation

On March 27, 2020, the Norwegian Ministry of Health and Care Services issued a regulation on tracing and epidemic contagion related to COVID-19.[45] The regulation was adopted with the purpose of making it easier to track COVID-19 cases and prevent community spread[46] based on authorization provided by temporary emergency legislation pertaining to COVID-19, known as the Corona Act.[47] The regulation gives the FHI power to establish an electronic system for tracking COVID-19 infections.[48] Participation in the system must be voluntary and must include “comprehensive, understandable, and easily accessible information, including on the processing of personal data.”[49]

III. Electronic Measures to Fight COVID-19 Spread

A. Smittestopp Voluntary COVID-19 Tracing App

On April 16, 2020, Norway introduced a mobile app, called Smittestopp (which means infection stop), to trace persons infected with COVID-19.[50] Interest in the app was initially high, but usage has since waned. On April 17, 2020, close to a million users were reported as having downloaded the app.[51] As of April 30, 2020, the Norwegian Public Health Agency (Folkehelseinstituttet, FHI) reported that about 900,000 Norwegians were actively using the app (about 20.5% of the population age 16 and above).[52] On May 7, the FHI reported that they needed more users to use the app for it to work properly.[53] As of May 19, 2020, the FHI reported that 641,824 users actively used the app.[54] Most of the users are located in the Norwegian capital, Oslo, with about 100,000 users.[55] Oslo has a population of about 680,000. As of May 20, 2020, no municipality had more than 20% of active Smittestopp app users.[56]

Smittestopp[57] traces the movements of users with the explicit purpose of determining whether a user has been in close contact with another user who later developed COVID-19.[58] “Close contact” is defined as within two meters (about six feet) for a minimum of fifteen minutes.[59] Initial reporting suggests that it is possible that locations on separate sides of a wall may erroneously be recorded as within close contact, because they are registered as within two meters.[60]

The app records the movements of users, provided that the user actively chooses to share its location data with FHI.[61] The data obtained and stored is reportedly pseudonymized but the location of a user may nevertheless be identifiable, which is why, according to the developer, no analysts may look directly at the data.[62] According to Helse Norge, the Norwegian Health Network that services all e-health resources for Norwegians, the data is stored on the smartphone and uploaded to the app once every hour, provided that there is an internet connection.[63] The app also has a number of privacy protection features.[64] For example, stored data is automatically deleted after 30 days.[65] Smittestopp has a 16-year-old age requirement for use.[66]

Persons who have been in close proximity to another user who develops the disease will get a text message instructing them to take additional measures to determine if they have contracted COVID-19.[67] However, users who are notified are not required to self-isolate.

B. Supervisory Authority Investigation of the App

On April 27, 2020, Datatilsynet announced that it was about to launch an investigation into the use of the Smittestopp app because the central registration and collection of users’ location data may be an infringement of privacy.[68] Datatilsynet, is the supervisory authority for the collection and use of personal data in Norway.[69]  It explained that the purpose of the investigation is to ensure that the app complies with the Norwegian regulation on tracing and epidemic contagion related to COVID-19.[70] As noted above, the regulation requires that the system be voluntary and include “comprehensive, understandable and easily accessible information, including on the processing of personal data.”[71]

On May 12, 2020, Datatilsynet initiated the investigation.[72] On May 20, 2020, it asked the FHI to provide additional information no later than June 1, 2020,[73] on how the FHI has balanced the need for the app (presumably the public need for contact tracing during a pandemic) with the protection of users’ personal data.[74] Datatilsynet noted in its press release that, “[i]f you do not have an overview of which personal data is used for what purpose, one cannot determine if it necessary to use that personal data to achieve each of these goals.”[75]

Following the announcement of the investigation, an expert group suggested improvements to the Smittestopp app, particularly the use of non-static Bluetooth IDs.[76] The expert group also suggested using privacy differentiation for analytical purposes.[77]

C. Privacy & and Other Critiques of the App

In addition to the supervisory authority investigation mentioned above, concerns have also been raised internationally that the current design of the app is problematic in relation to the international framework for collecting personal data, even though using the app is voluntary. Specifically, the European Data Protection Board, which oversees compliance with the GDPR and the Data Protection Law Enforcement Directive, has voiced concerns that apps that collect and store information in the way the Norwegian app does violate those privacy protections.[78]

Another critique of the app is that it was launched too soon, before municipalities were ready to use it.[79] As of May 10, 2020, only three municipalities had the technology available to send notification texts to their residents, Drammen, Tromsø, and Trondheim.[80]  Reportedly, as of May 16, no case had been discovered with the help of the app, as notifications of potential exposure was limited to users in these areas.[81]

On the other hand, the app has also been criticized by IT experts for not collecting and sharing enough data—specifically the app’s establishment of a 15-minute contact requirement for information sharing—on the ground that contact for shorter intervals of time may also result in the spread of COVID-19, and that such information must be recorded in order to better develop the app.[82]

D. Use of Telecommunication Data for Determining Travel Restriction Compliance

Norway implemented travel restrictions, both to and from the country as well as domestically within Norway, during the month of March 2020.[83] The travel restrictions were coupled with monetary fines or prison of up to six months, including for persons breaching the domestic travel restrictions.[84] Telecommunications data was used to measure compliance with these restrictions.[85] Initial reports on how many Norwegians were present outside their home municipality were based on numerical data from the telecommunications systems,[86] reporting the number of mobile users in a given area compared to the number of permanent residents, but there were no reports of people being individually targeted by that approach.[87] Instead, as described by the telecommunications company Telenor, the data only provides information on how many mobile users are present in a given area (connected to a given cellular tower), not who or how close from each other they are.[88]

Update: June 16, 2020

On June 16, 2020, the Norwegian Data Protection Authority determined that the Norwegian COVID-19 tracing app was not a proportional invasion in the individual user's privacy rights based on the current situation in Norway, with low community spread, and because few persons had  downloaded the app.

Additional information on this topic is available.

Back to Top

Prepared by Elin Hofverberg
Foreign Law Specialist
June 2020

