Editorial composition: a Norwegian constitutional press-freedom scene — a bound Grunnloven volume on a granite plinth at Eidsvoll, the Oslo fjord silhouette in cold winter light, the NordBastion polar-bear mascot standing watch on a wharf
Jurisdiction · Norway · Constitutional deep-dive

Norway.
Section 100 expression. EEA inside, EU outside. The hedge that is real.

A deep read of the regime that reaches a server in Oslo: Section 100 of the Grunnloven (1814 / reformed 2004), Personopplysningsloven, Datatilsynet — and the structural advantage of being inside the EEA but outside the European Court of Justice.

TL;DR
  • 01

    Section 100 of the 1814 Grunnloven, reformed 2004, codifies expression, prohibits prior restraint, and imposes a positive state duty to facilitate discourse.

  • 02

    GDPR applies via EEA incorporation (Personopplysningsloven 2018) — but Norway is OUTSIDE EU e-Evidence and direct CJEU jurisdiction.

  • 03

    Honest limits: NATO since 1949, PST + E-tjenesten signals powers (2020 + 2023 amendments), recurring data-retention proposals.

The regime

A 1814 constitution, a 2004 expression reform. Inside the EEA. Outside the EU.

The Norwegian Grunnloven was signed at Eidsvoll on 17 May 1814 and is the second-oldest single-document constitution still in force in the world (after the United States). It has been amended substantially over the two centuries since, but never replaced. The amendment that matters most to a hosting provider is the 2004 reform of Section 100, drafted by the parliamentary Ytringsfrihetskommisjonen and adopted unanimously by the Storting. It produced one of the more expansive press-freedom clauses in Europe.

Section 100 now opens with the flat statement "There shall be freedom of expression." Paragraph 2 forbids prior restraint and post-publication liability except in narrow, statutorily defined cases that must themselves be justifiable in a free society — a structure that imports proportionality review directly into the constitutional text. Paragraph 4 codifies the right of public access to documents of the state and municipalities. Paragraph 6 is the unusual one: it imposes a positive obligation on state authorities to create conditions that facilitate open and informed public discourse. Norwegian constitutional commentators (Eggen, Kierulf, Bing) read § 100(6) as a constitutional duty on the state not merely to tolerate but to support the infrastructure of free expression.

On data protection, Norway sits in an unusual jurisdictional position: it is a member of the European Economic Area (EEA) but not of the European Union. GDPR (Regulation (EU) 2016/679) applies in Norway by virtue of Decision 154/2018 of the EEA Joint Committee, which incorporated it into Annex XI of the EEA Agreement; it is implemented domestically by Personopplysningsloven (LOV-2018-06-15-38). The substantive obligations are identical to those facing an EU-based provider. The structural difference is jurisdictional: Norwegian courts interpret GDPR through the EFTA Court (under the EEA homogeneity principle) rather than via direct preliminary references to the CJEU. In practice the EFTA Court tracks CJEU rulings closely; in theory there is one additional layer of interpretive flexibility.

The structural advantage is on cross-border legal process. The EU e-Evidence package — Regulation (EU) 2023/1543 and the accompanying directive — creates direct European Production Orders and European Preservation Orders that one Member State can serve on a provider in another, with comparatively short response windows. Norway is not an EU Member State and is not party to e-Evidence. Cross-border requests aimed at a server in Oslo therefore run through the older, slower channels: the 2000 EU MLA Convention (Norway is associated via Schengen), Council of Europe instruments, bilateral MLATs. It is not invisibility — it is meaningful procedural friction.

Three readings

Regulator, hedge, limits. All three matter.

Norway is not a copy-paste of Sweden or Finland. It is a different jurisdictional shape — and that shape is the point.

The regulator · Datatilsynet

Among Europe's most assertive DPAs

Documented enforcement: Grindr (NOK 65M, 2021); the 2023 Meta behavioural-advertising decision that triggered the EDPB urgency procedure and a Europe-wide suspension of consent-less behavioural ads on Facebook and Instagram; continuing biometric narrowings through 2024–2025.

Effect for a customer: GDPR rights are not just incorporated by EEA treaty — they are enforced by a regulator whose published actions have shaped European data-protection law beyond Norway's borders.

The hedge · EEA without EU

Same data law, different process pipe

GDPR substance applies (Personopplysningsloven 2018). EU e-Evidence does not. Cross-border requests must run through MLAT, Council of Europe instruments, or the 2000 EU MLA Convention via Schengen — slower, judicially-supervised, with dual-criminality requirements.

This is the workload-shape question: if your model treats EU cross-border production as the threat, Norway gives you the same data-protection floor without the e-Evidence ceiling.

The limits · honestly

NATO, PST, retention debates

Founding NATO member (1949). The 2020 Intelligence Service Act gave E-tjenesten bulk-collection powers on cross-border flows; the 2021 ECtHR ruling found procedural deficiencies; the 2023 Storting amendments addressed them. Recurring Justice Ministry proposals for targeted IP-address retention since 2022.

Section 100 still constrains all of this constitutionally, and parliamentary EOS Committee oversight is real — but the shape of the limits is structurally different from Sweden or Finland, and worth knowing.

Verdict

Pick Norway when the workload needs GDPR-grade data protection without EU cross-border production orders.

Norway is the right answer when your model treats EU jurisdiction itself as the threat — when Article 5 minimisation, Article 17 erasure and the rest of the GDPR rights regime are the floor you want, but EU e-Evidence direct cross-border orders are the ceiling you want out from under. EEA membership gives you the same substantive data law. Non-membership of the EU keeps you outside the fastest legal-process pipes.

It is not the right answer for every workload. If your priority is the oldest constitutional press-freedom act with the deepest case law, Sweden is still the canonical pick. If your priority is the strongest source-refusal statute in the Union, Finland is. If your priority is full geographic distance from continental Europe, Iceland is.

What Norway gives you that nowhere else does: GDPR substance plus EEA-shaped procedure, a constitution with a positive state duty to facilitate discourse, and one of the most assertive data-protection regulators on the continent — without sitting inside the EU's direct cross-border production-order regime.

FAQ · Norwegian law

Constitution, EEA, case law.

Specific questions about Section 100, the EEA-not-EU posture, Datatilsynet, and the recurring data-retention proposals.

What does Section 100 of the Norwegian Constitution actually say?

Section 100 of the Grunnloven (Norwegian Constitution, dated 17 May 1814) was substantially reformed by the 2004 amendments and now reads as one of the more expansive press-freedom clauses in Europe. Paragraph 1 states "There shall be freedom of expression." Paragraph 2 forbids prior restraint and post-publication liability except in narrow, statutorily defined cases that must themselves be justifiable in a free society. Paragraph 4 codifies the right of access to documents of the state and municipalities. Paragraph 6 imposes a positive obligation on state authorities to create conditions that facilitate open and informed public discourse. The 2004 reform was drafted by a parliamentary commission (the Ytringsfrihetskommisjonen) and is generally read as constitutionalising a positive duty on the state to support, not merely tolerate, free expression.

Norway is outside the EU. What does that mean for GDPR?

Norway is a member of the European Economic Area (EEA) but not of the European Union. GDPR (Regulation (EU) 2016/679) applies in Norway through Decision 154/2018 of the EEA Joint Committee, which incorporated it into Annex XI to the EEA Agreement; it is implemented domestically by Personopplysningsloven (LOV-2018-06-15-38). The substantive obligations are identical to those facing an EU-based provider: Article 5 minimisation, Article 17 erasure, the full GDPR rights regime. The structural difference is jurisdictional: Norwegian courts interpret GDPR through the EFTA Court (homogeneity principle) rather than direct preliminary references to the Court of Justice of the European Union (CJEU). In practice the EFTA Court tracks CJEU rulings closely, but it is institutionally distinct and the Norwegian Supreme Court (Høyesterett) retains final interpretive authority.

Why does EEA-not-EU matter for cross-border legal process?

This is the structural advantage worth being precise about. The EU e-Evidence package (Regulation (EU) 2023/1543 and the accompanying directive) creates European Production Orders and European Preservation Orders that one Member State can serve directly on a service provider in another Member State, with comparatively short response windows. Norway is not an EU Member State and is not party to e-Evidence. Cross-border requests aimed at a server in Oslo therefore go through the older, slower, judicially-supervised channels: the 2000 EU MLA Convention (Norway is associated via Schengen), Council of Europe instruments, or bilateral MLATs. None of these are as fast or as direct as e-Evidence. It is not invisibility; it is procedural friction.

Who is Datatilsynet and what is its enforcement record?

Datatilsynet is the Norwegian Data Protection Authority, headquartered in Oslo. It is consistently ranked among the more assertive European DPAs in published surveys (notably the EDRi annual enforcement reports). Recent high-profile actions include the Grindr fine (2021, NOK 65M for unlawful consent handling), the Meta behavioural-advertising decision (2023, leading to the temporary suspension of behavioural advertising on Facebook and Instagram across the EU/EEA via the EDPB urgency procedure), and continuing enforcement on biometric overreach. For a customer this means GDPR rights are not just incorporated by treaty — they are actively enforced by a regulator with a published willingness to act.

What about PST and the Norwegian intelligence services?

Politiets sikkerhetstjeneste (PST) is the Norwegian Police Security Service, the domestic security and counter-intelligence agency. Etterretningstjenesten (E-tjenesten) is the foreign military intelligence service. PST operates under the Police Act and the 2016 Civil Intelligence Service Act with parliamentary oversight by the EOS Committee. The 2020 Intelligence Service Act (etterretningstjenesteloven) gave E-tjenesten new powers for bulk collection of cross-border traffic — these were the subject of a 2021 European Court of Human Rights challenge that found procedural deficiencies; the Norwegian Parliament passed amendments in 2023 to address them. The current regime targets counter-terrorism and counter-intelligence on cross-border flows, not ordinary hosting customers; as elsewhere, no jurisdiction substitutes for application-layer encryption against a state-actor adversary.

Did Norway reintroduce data retention?

This is an active debate worth being honest about. Norway implemented the EU Data Retention Directive (2006/24/EC) in 2011, but suspended it before it took effect after the CJEU's Digital Rights Ireland ruling (2014) struck the directive down. Since 2022 there have been periodic Justice Ministry proposals to reintroduce targeted IP-address retention for serious-crime investigations. As of the date of this article no general retention obligation applies to hosting providers in Norway. NordBastion is not subject to bulk retention; we retain only what is operationally necessary, on the schedules published in the transparency report. If the legal landscape changes materially, the warrant canary will reflect it.

Norway is a NATO member — does that compromise the jurisdiction?

Norway has been a founding NATO member since 1949 and hosts substantial allied infrastructure. NATO membership does not, by itself, create cross-border legal-process obligations against hosting customers; it operates at the military and intelligence layers, not in the ordinary legal-process pipeline that reaches an Oslo data centre. The honest framing is the same as for SÄPO in Sweden or Supo in Finland: signals-intelligence cooperation exists, it is constrained by domestic statute and parliamentary oversight, and it is not the day-to-day risk facing an ordinary hosting workload — but it is a real part of the picture if the workload genuinely attracts state-actor adversaries.

Can a Norwegian court compel NordBastion to identify a customer?

Only through a Norwegian court order, on a named subject, for data we actually hold — and that intersection is narrow by design. The Norwegian Criminal Procedure Act (Straffeprosessloven) requires judicial supervision for production orders. The Norwegian Media Liability Act (Lov om redaksjonell uavhengighet og ansvar i redaktørstyrte journalistiske medier, 2020) and Criminal Procedure Act § 125 create a strong source-protection privilege for journalists and editorial collaborators. For ordinary hosting customers, the binding limit is what does not exist: we do not collect identity at signup, we do not retain payment-card data, and infrastructure logs are kept on the published rotation. What does not exist cannot be compelled.

How does the EFTA Court interact with CJEU case law on data?

Under the EEA homogeneity principle (Article 6 EEA, Article 3 ESA-Court Agreement), the EFTA Court is obliged to interpret EEA-incorporated EU law consistently with CJEU rulings — both those handed down before the EEA Agreement and, in practice, those handed down after. The post-Schrems II environment is the live test case: CJEU rulings on data-transfer adequacy (Schrems II, C-311/18, 2020; Meta v. Bundeskartellamt, C-252/21, 2023) flow into Norwegian law via EFTA Court interpretation, but Norwegian courts have one additional procedural step where the executive can, in principle, exercise EEA reservations. In practice this is rarely used for data-protection law; it is mentioned for completeness.

Private hosting, built in the North.