Per Norwegian Personal Data Act (personopplysningsloven, Lov av 15. juni 2018 nr. 38) implementing GDPR: scope + transparency + lawful basis. Requirements include (a) implement GDPR through national law per Lov om behandling av personopplysninger including direct GDPR application + Norwegian supplements (employment context + criminal records + similar) + (b) determine scope including extraterritorial application per GDPR Article 3 + (c) provide Transparency through privacy notices covering identity of controller + purposes + categories + recipients + retention + rights + transfer + (d) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + (e) document applicability + lawful basis + (f) align with EEA and EU developments including evolving guidance from EDPB + Datatilsynet.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.