Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Automated Processing
| Code | Title |
|---|---|
| NOPDA-18 | Automated Decision Making |
Breach Management
| Code | Title |
|---|---|
| NOPDA-2 | Notification of Personal Data Breaches |
Cross Border Transfer
| Code | Title |
|---|---|
| NOPDA-6 | International Transfers |
Data Lifecycle
| Code | Title |
|---|---|
| NOPDA-15 | Retention and Erasure |
Data Subject Rights
| Code | Title |
|---|---|
| NOPDA-4 | Data Subject Rights |
Design
| Code | Title |
|---|---|
| NOPDA-10 | Privacy by Design and Default |
Documentation
| Code | Title |
|---|---|
| NOPDA-7 | Records of Processing Activities |
Governance
| Code | Title |
|---|---|
| NOPDA-19 | Internal Compliance Programme |
| NOPDA-3 | Data Protection Officer |
Lawfulness
| Code | Title |
|---|---|
| NOPDA-1 | GDPR Implementation Compliance |
Marketing
| Code | Title |
|---|---|
| NOPDA-14 | Direct Marketing and ePrivacy |
Norway PDPA: Accountability & Compliance
Demonstration of compliance and accountability (Norway PDPA)
| Code | Title |
|---|---|
| NO-PDPA-25 | Compliance monitoring and auditing |
| NO-PDPA-26 | Training and awareness programs |
| NO-PDPA-27 | Regulatory reporting and cooperation |
| NO-PDPA-28 | Complaints handling and resolution |
| NO-PDPA-29 | Enforcement and penalties awareness |
Norway PDPA: Data Collection & Consent
Requirements for lawful collection and consent management (Norway PDPA)
| Code | Title |
|---|---|
| NO-PDPA-01 | Notice and transparency requirements |
| NO-PDPA-02 | Consent management and withdrawal |
| NO-PDPA-03 | Lawful basis for processing |
| NO-PDPA-04 | Purpose limitation and specification |
| NO-PDPA-05 | Data minimization requirements |
Norway PDPA: Data Governance
Organizational governance of personal data processing (Norway PDPA)
| Code | Title |
|---|---|
| NO-PDPA-19 | Data protection officer designation |
| NO-PDPA-20 | Records of processing activities |
| NO-PDPA-21 | Data protection impact assessments |
| NO-PDPA-22 | Privacy by design and default |
| NO-PDPA-23 | Data processing agreements |
| NO-PDPA-24 | Cross-border transfer safeguards |
Norway PDPA: Data Security
Technical and organizational security measures (Norway PDPA)
| Code | Title |
|---|---|
| NO-PDPA-13 | Encryption of personal data |
| NO-PDPA-14 | Pseudonymization techniques |
| NO-PDPA-15 | Access control for personal data |
| NO-PDPA-16 | Data breach notification requirements |
| NO-PDPA-17 | Security incident response procedures |
| NO-PDPA-18 | Regular security testing and assessment |
Norway PDPA: Data Subject Rights
Individual rights regarding their personal data (Norway PDPA)
| Code | Title |
|---|---|
| NO-PDPA-06 | Right of access to personal data |
| NO-PDPA-07 | Right to rectification of inaccurate data |
| NO-PDPA-08 | Right to erasure and deletion |
| NO-PDPA-09 | Right to data portability |
| NO-PDPA-10 | Right to restrict processing |
| NO-PDPA-11 | Right to object to processing |
| NO-PDPA-12 | Automated decision-making protections |
Regulator Relations
| Code | Title |
|---|---|
| NOPDA-17 | Cooperation With Datatilsynet |
Risk Assessment
| Code | Title |
|---|---|
| NOPDA-5 | Data Protection Impact Assessment |
Sector Specific
| Code | Title |
|---|---|
| NOPDA-11 | Employment Context Processing |
Security
| Code | Title |
|---|---|
| NOPDA-9 | Security of Processing |
Sensitive Categories
| Code | Title |
|---|---|
| NOPDA-12 | Children's Data |
Sensitive Data
| Code | Title |
|---|---|
| NOPDA-13 | Special Categories of Data |
Third Party
| Code | Title |
|---|---|
| NOPDA-8 | Processor Agreements |
Transparency
| Code | Title |
|---|---|
| NOPDA-16 | Transparency |
Your Compliance Coverage
If you comply with Norway PDPA, you already cover:
Chile DPL
23%
11 controls mapped
Compare →Montana Consumer Data Privacy Act
23%
11 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
23%
11 controls mapped
Compare →+ 606 more: New Jersey Data Privacy Act (23%), Nebraska Data Privacy Act (23%)
See all 609 mapped frameworks ↓Maps to 609 other frameworks
Frequently Asked Questions
What is Norway PDPA?
Norway PDPA is a compliance framework from Norway with 23 domains and 48 controls. Norwegian Personal Data Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Norway PDPA have?
Norway PDPA has 48 controls organised across 23 domains. The largest domains are Norway PDPA: Data Subject Rights (7 controls), Norway PDPA: Data Governance (6 controls), Norway PDPA: Data Security (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Norway PDPA map to?
Norway PDPA maps to 609 other compliance frameworks. The top mapping partners are Chile DPL (23% coverage), Montana Consumer Data Privacy Act (23% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Norway PDPA compliance?
Start your Norway PDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Norway PDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required