Skip to main content

GDPR for Norwegian businesses — what has to be in place on the website?

What does a Norwegian business actually need for data protection on its website? A practical walkthrough of cookies, consent, agreements and storage.

By Lars Henrik Netland

Produced with AI tools, edited and fact-checked by the author

Last updated: 15 June 2026

Data protection is often experienced as something large companies have to deal with, while small businesses can look the other way. That is not correct. If you collect personal data through your website — and most do, often without thinking about it — you are covered by the rules. The good news is that it is not as complicated as it sounds, as long as you take a few basic things deliberately.

What GDPR is really about

GDPR is not bureaucracy for its own sake. The core is simple: personal data belongs to the person it concerns, not to whoever collects it. As a business you are borrowing it for a clear purpose, and you have a responsibility to process it safely and openly. Think of it that way and most of the concrete requirements become logical.

The most common things on a website

You are probably collecting more than you think:

  • Contact form — name, email, phone number, and whatever people write in the message field
  • Analytics tools — IP address and behavioural data about visitors
  • Cookies — which remember settings or track visits
  • Newsletter — email addresses and consent to be contacted

Each of these is personal data in some form, and each requires that you have thought through why you are collecting it and what happens to it.

Consent and cookies

The main rule is that non-essential cookies and tracking — typically analytics and marketing — require active consent before they load. Not a pre-ticked box, not "by using the site you accept", but a real choice made by the visitor.

In practice that means analytics tools should not run at all before someone has said yes. A site that loads tracking before consent is not in line with the rules, however neat the consent banner is.

Data processing agreement

The moment you use a third party to process data on your behalf — hosting provider, email service, analytics tool — you need a data processing agreement with them. It is an agreement that governs what they are allowed to do with the data. Many forget this because the services "just work", but responsibility for the data stays with you.

Where the data is stored

This is the point most people overlook, and it is a real choice. Is the data stored within the EU/EEA, or is it sent to servers in other countries with weaker data protection? Transfer out of the EEA is not prohibited, but it comes with its own requirements. For many businesses the simplest and safest thing is to make sure data stays within the EEA from the start — that removes a whole category of questions you would otherwise have to be able to answer.

It is about trust, not just the law

It is easy to see data protection as a box to tick. But the way you handle people's data is a visible signal of trust. A business that is tidy about data protection tells its customers that it is tidy about the things they cannot see either. That is cheap marketing for something you have to do anyway.

One clarification at the end: this is a general overview, not legal advice. If you are in doubt about your specific situation, you should check with someone who knows the rules in detail. But if you have the five things above in place — a deliberate purpose, proper consent, data processing agreements, control of where data is stored, and openness about all of it — you are well ahead of most.

Related