Is Google Analytics Legal in Norway? Cookie Consent, the New Law, and What Changed

Until January 2025, Norway had the weakest cookie consent standard in the entire EEA. Browser settings counted as valid consent. In plain English: doing nothing counted as saying yes. While Austria, France, and Italy were ruling Google Analytics illegal, Norwegian websites could technically claim their visitors had "consented" by not changing their default Chrome preferences. That loophole is closed. The new ekomloven took effect on New Year's Day 2025, and Datatilsynet is already sanctioning sites that haven't caught up. Here's the full picture as I read it in July 2026.
- Norway had the weakest cookie consent standard in the EEA until January 1, 2025. The old ekomloven allowed browser settings as consent. The new § 3-15 requires explicit, GDPR-grade opt-in for all analytics cookies, with no exemptions.
- Datatilsynet found Google Analytics unlawful in the Telenor case (GDPR Article 44), with the final reprimand landing 16 days after the Data Privacy Framework restored legal cover. In February 2025 guidance, Datatilsynet advised businesses to 'have an exit strategy' for US transfers.
- Only 11% of Norwegian cookie banners are minimally compliant (CHI 2025, 254,148 websites). 86% of Norwegian websites have compliance issues, and 81% fire non-essential cookies before consent. Norway has the lowest compliance of all Nordic countries.
- Datatilsynet issued Norway's largest GDPR fine: NOK 65 million against Grindr, upheld by the appeals board and two courts (most recently October 2025). In June 2025, six websites were sanctioned for tracking pixels on sensitive content, with a warning that 'future sanctions may be much stricter.'
- The EU Digital Omnibus (proposed November 2025) would create an analytics consent exemption, but won't reach Norway until 2028+ due to the EEA adoption pipeline. Google Analytics wouldn't qualify anyway. Cookieless, first-party analytics already operate without consent under current Norwegian law.
From Europe's weakest cookie law to active enforcement
Cookie consent in Norway is governed by the ekomloven (Electronic Communications Act), Norway's implementation of the ePrivacy Directive. Before January 2025, the operative provision was § 2-7 b. It had a loophole that existed nowhere else in Europe: consent could be satisfied through pre-configured browser settings. Enabling cookies in your browser preferences technically counted as consent.
Datatilsynet itself called this "the decidedly worst solution," noting it enabled "extensive collection of personal information with very limited user control."
The new § 3-15, in force since January 1, 2025, eliminates that loophole entirely. Consent must now meet all seven GDPR requirements: voluntary, specific, informed, unambiguous, based on active user action, documented, and easily revocable. That means 7 boxes to tick before a single analytics cookie fires.
Only two exemptions exist. A cookie is exempt if its sole purpose is transmitting a communication over a network, or if it's strictly necessary to deliver a service the user explicitly requested. Session cookies, login state, shopping carts. That's it.
Analytics cookies aren't exempt. If your tool sets a cookie, you need consent. Full stop. Norway has no first-party analytics exemption. Unlike France, where CNIL long maintained a list of exempted audience-measurement tools (retired in January 2026 in favor of self-assessment), Norway has no exemption framework, no approved list, and no carve-out for first-party analytics. This is the same position as Sweden and Denmark.
There's a critical legal nuance here. Under ekomloven, consent is the only valid legal basis for non-essential cookies. GDPR technically permits other bases like legitimate interest for data processing, but for device storage and access, § 3-15 requires consent. Period. Datatilsynet's own guidance states that the E-Com Act "imposes practically stricter requirements than the privacy regulation."
Enforcement is split between two authorities. Nkom (Norwegian Communications Authority) determines whether a technology falls under § 3-15 and whether exemptions apply. Datatilsynet evaluates whether consent is valid and whether data processing complies with GDPR. Both can sanction. Nkom can impose infringement fines sized by gravity, duration, fault, and the company's turnover. Datatilsynet can impose standard GDPR fines up to EUR 20 million or 4% of global turnover.
In April 2025, Datatilsynet published comprehensive guidance on the new rules: reject must be as prominent as accept, no pre-ticked boxes, no blocking site access for non-essential cookies, granular choice by purpose, and documented consent records. In March 2026, they held a public webinar because website owners were struggling with compliance.
Datatilsynet: 69 employees, NOK 65 million in fines
Datatilsynet has 69 employees and a budget of approximately EUR 7.5 million (NOK 84 million). For comparison, France's CNIL has over 300 staff. Norway's regulator is small, but it hits hard. Put another way: 1 employee for every 81,000 Norwegians.
Director General Line Coll has led the authority since August 2022 and frames privacy as an enabler rather than an obstacle.
In 2024, Datatilsynet registered 4,736 new cases, a record. Complaints from individuals hit 902, a 53% increase over 2023. They conducted 18 inspections, including 6 focused specifically on digital tracking. That means 1 in 3 of its inspections went after tracking. The authority received 3,191 data breach notifications, with intentional attacks up 39%.
Norway is an EEA member, not an EU member. GDPR applies through the EEA Agreement, implemented via the Norwegian Personal Data Act of 2018. Datatilsynet sits on the European Data Protection Board (EDPB) but without voting rights and without the right to be elected chair. Norway is bound by GDPR, enforces GDPR, but has no vote in shaping it. In plain English: rule-taker, not rule-maker.
My favorite detail: Datatilsynet doesn't use analytics cookies on its own website. When the privacy regulator won't use cookie-based analytics, that tells you where the legal standard is heading.
Google Analytics: ruled illegal, then saved by sixteen days
On August 17, 2020, noyb filed 101 complaints across 30 EU/EEA countries. Three targeted Norwegian companies. One of them targeted Telenor for using Google Analytics.
On March 1, 2023, Datatilsynet announced a preliminary decision finding that Telenor's use of Google Analytics violated GDPR Article 44. The technical problem: IP anonymization happened on Google's US servers, meaning IP addresses were transferred to the US before being truncated. Standard Contractual Clauses plus Telenor's supplementary measures were found insufficient against US surveillance under FISA Section 702.
Tobias Judin, Datatilsynet's Section Chief for International Affairs, stated: "Regarding Google Analytics use, a clear European consensus has emerged." He told Norwegian media: "The likelihood that Datatilsynet would reach a different conclusion is not very large. Therefore, there is no reason to wait for a final ruling."
Datatilsynet also noted that GA4 "will not necessarily correct those problems we have so far identified," citing the Danish DPA's parallel conclusion.
The final decision came on July 26, 2023. Because Telenor had already stopped using Google Analytics in January 2021, Datatilsynet issued a reprimand, not a fine. No Norwegian company has been fined for GA use. In plain English: Norway wrote the legal reasoning but never sent a bill. Sweden remains the only country that put a price tag on it.
The timing was remarkable. The EU-US Data Privacy Framework was adopted on July 10, 2023. Datatilsynet's final ruling came sixteen days later. In the same announcement, they declared that "what has been a major problem with Google Analytics appears to be resolved" under the DPF, while adding the caveat: "we do not rule out that there may be other privacy challenges with the tool."
There's an EEA quirk worth knowing. Norway is EEA, not EU, so the DPF wasn't formally incorporated into the EEA Agreement (Decision 169/2024) until July 2024, a full twelve months after the EU decision. In practice, nothing was missing during that year: under the GDPR's EEA adaptation, Norway applies Commission adequacy decisions from the same day as EU member states, and Datatilsynet told Norwegian businesses on 10 July 2023 that the new rules applied immediately. The paperwork lagged. The legal cover didn't.
The Grindr precedent and the tracking pixel crackdown
Datatilsynet's largest fine has nothing to do with analytics. It has everything to do with consent.
In January 2020, the Norwegian Consumer Council (Forbrukerrådet) and noyb filed a complaint against Grindr for sharing user data, including GPS location, IP addresses, age, gender, and the fact someone used a gay dating app, with advertising partners without valid consent. The critical legal finding: simply being identifiable as a Grindr user constitutes disclosure of sexual orientation, which is Article 9 special category data.
Datatilsynet fined Grindr NOK 65 million (about EUR 6.5 million) in December 2021. Grindr appealed. Three times. Lost every time. The Privacy Appeals Board upheld it in September 2023. Oslo District Court upheld it in July 2024. The Borgarting Court of Appeal upheld it in October 2025, and no Supreme Court appeal has been reported since. That means 4 years of appeals bought Grindr nothing.
Line Coll stated: "Consent is a tool for giving users control over their own personal data. If users are not made able to understand what they are consented to, or if they are not granted real freedom of choice, the consents are illusory."
Then there's Disqus, the comment platform. Datatilsynet proposed a NOK 25 million fine in 2021 for tracking visitors to major Norwegian news sites (NRK, TV2) via its comment widget and sharing their data with parent company Zeta Global for ad profiling. Disqus didn't even know GDPR applied to Norway. They assumed it was EU-only. Norway is EEA, and GDPR is Norwegian law. The case closed in November 2024 with a reprimand, not the proposed fine. In other words: not knowing the map put a NOK 25 million threat over Disqus for three years.
In June 2025, Datatilsynet sanctioned six websites for transmitting sensitive visitor data through tracking pixels without legal basis. The targets: a children's crisis helpline, an online pharmacy, a health information portal, a Bible distribution site, a medical booking service, and a support service for children with incarcerated parents. All six were sharing visitor data revealing health conditions, religious beliefs, or children's identities with third-party advertising platforms.
The children's helpline 116111.no received a NOK 250,000 fine. In plain English: the first targets weren't ad-tech giants, they were a children's helpline and a pharmacy. Its privacy policy had falsely claimed visitor data was "completely anonymized." The health portal NHI.no had a dark pattern banner: a bright blue "Allow all cookies" button, while "Only necessary cookies" sat in plain black-on-white, visibly less prominent. The sanction was a reprimand plus an order to stop the Meta Pixel until consent is valid.
In 2023, Datatilsynet used emergency powers to impose a temporary ban on Meta's behavioral advertising in Norway, backed by a NOK 1 million per day coercive fine. That means every day of delay cost Meta another million. They then referred the matter to the EDPB, which extended the ban EU-wide. A 69-person authority in a country of 5.6 million forced a global advertising model change.
The Data Privacy Framework keeping GA4 alive
Google Analytics is technically legal in Norway right now. The Data Privacy Framework provides the legal basis for US data transfers. Google is DPF-certified. But Datatilsynet isn't optimistic about how long this lasts.
On February 26, 2025, Datatilsynet published explicit guidance warning businesses about the DPF's fragility. The Trump administration dismissed most members of the Privacy and Civil Liberties Oversight Board (PCLOB), leaving it with a single member. Datatilsynet considers PCLOB a key pillar of the adequacy decision.
Their February 2025 recommendation to all Norwegian businesses: "The most important advice is to have an exit strategy" for a scenario where US transfers become restricted. (The page has since been reworded to "think preparedness and have a plan.") They warn that if the DPF is revoked, "there will most likely not be a transition period."
In September 2025, the EU General Court upheld the DPF in the Latombe case. Datatilsynet acknowledged this as "good news" but cautioned that the ruling "assessed conditions from 2023" and doesn't address what has changed since. An appeal was filed with the CJEU in October 2025. The CJEU previously struck down Safe Harbor (2015) and Privacy Shield (2020). And the ground keeps shifting: FISA Section 702, the surveillance law at the heart of the EU's concerns, lapsed on June 12, 2026, with existing certifications keeping collection running to roughly March 2027. Datatilsynet updated its US-transfers guidance in July 2026, noting the PCLOB is down to a single member and pointing to a new US Supreme Court ruling that questions the independence of oversight bodies.
If the DPF falls, Datatilsynet has already established the legal reasoning. The Telenor ruling found that Standard Contractual Clauses plus supplementary measures were insufficient for Google Analytics. Every Norwegian website using GA4 would face the same legal situation that existed in March 2023, except now with a clear precedent on the books.
What you lose when visitors click "Reject"
Even if GA4 stays legal, you still need a cookie banner. And a cookie banner on a Norwegian website means data loss.
A 2025 study from Aarhus University (CHI 2025, 254,148 websites across 31 countries) found that only 11% of Norwegian cookie banners are minimally compliant. That's the lowest of all Nordic countries. Sweden scored 14%, Denmark 17%, Finland 18%. In plain English: 9 in 10 Norwegian banners fail.
A Cookie Information compliance report from April 2024 found that 86% of Norwegian websites have compliance issues and 81% fire non-essential cookies before consent is obtained. That means 4 sites in 5 fire cookies before anyone clicks. Norway had the lowest cookie banner adoption rate among the 10 European countries studied.
This isn't just a compliance problem. It's a data accuracy problem. Datatilsynet's own Personvernundersøkelsen 2024 (national privacy survey, 1,519 respondents) found that 74% of Norwegians have avoided downloading an app due to uncertainty about data handling. Only 29% feel they have control over how their data is used. Put another way: 3 in 4 Norwegians have skipped an app over data doubts.
Safari holds about 45% of Norwegian mobile browser traffic (June 2026) with Intelligent Tracking Prevention limiting cookie lifetime. Opera, founded in Oslo, holds about 24% of all Norwegian browser traffic, with tracker blocking built in. Add ad blockers on top, and a large slice of your Norwegian visitors never even load GA in the first place.
If Clickport tracks your Norwegian traffic, you see nearly every visitor. No consent needed for analytics, no scripts blocked, no data lost to rejection.
What's coming
The Digital Omnibus would create an EU-wide analytics consent exemption, but Norway faces an additional delay. EU legislation reaches Norway through the EEA Joint Committee, then requires Storting (parliament) action. The DPF's formal EEA incorporation took 12 months. Realistic timeline: 2028 at the earliest. Norway's current strict ekomloven rules will be in force for years before any Omnibus exemption arrives.
Datatilsynet isn't waiting. Their 2026 theme is "digital sovereignty", noting that approximately 80% of Europe's digital services are supplied by foreign vendors. They are inspecting all 357 Norwegian municipalities in 2026 for data security. They have been designated to oversee behavioral marketing under the Digital Services Act. And 11 noyb cookie banner complaints from 2021-2022, targeting companies like Innovation Norway, Toyota Norge, and Live Nation Norway, remain pending with no decisions issued.
What this means for your Norwegian website
If you're using Google Analytics with a cookie banner: your US data transfers are covered by the DPF (for now), but you need valid cookie consent under ekomloven § 3-15. That means equal-prominence accept and reject buttons, no pre-loaded cookies, granular purpose selection, and easy withdrawal. Datatilsynet's April 2025 guidance is explicit. The June 2025 tracking pixel action shows they're enforcing it.
If your cookie banner isn't compliant: you're in the 86%. Only 11% of Norwegian banners are minimally compliant. Both Datatilsynet and Nkom can sanction. The NHI dark pattern case (blue accept, invisible reject) shows that design choices are enforcement targets. If you're unsure whether your banner meets the standard, our cookie banner decision flowchart walks through the compliance requirements step by step, and a free scan of your site shows which trackers fire before consent.
If you want accurate data without the compliance risk: cookieless analytics sidestep ekomloven § 3-15 completely. Norway's new law targets device access. Remove the device access, and the consent requirement disappears with it. For a broader look at how privacy-first analytics works in practice across the EEA, see our privacy-friendly analytics guide, and our GA alternatives comparison for which specific tools fit Norway's framework.
Norway pioneered global connectivity in 1973 and enacted one of the world's first privacy laws five years later. Its citizens have near-universal internet access, 4.6 million BankID enrollments, and deep skepticism toward how private companies handle their data. When 86% of Norwegian cookie banners are non-compliant, the data you're collecting may not even be legal. The data you're missing is definitely real.
Frequently asked questions
Is Google Analytics legal in Norway?
Datatilsynet ruled in July 2023 that Telenor's use of Google Analytics violated GDPR Article 44 due to unlawful US data transfers. The EU-US Data Privacy Framework (adopted July 2023, applied in Norway from the same day and formally incorporated into the EEA Agreement in July 2024) resolved the specific transfer issue. GA4 is currently legal if Google is DPF-certified and you've valid cookie consent under ekomloven § 3-15. But Datatilsynet warns the DPF may not survive its next court challenge.
Do Norwegian websites need a cookie banner?
Yes, if you use analytics cookies. Ekomloven § 3-15 (in force since January 1, 2025) requires explicit, active consent before any non-essential data is stored on or accessed from a visitor's device. The only exemptions are for communication transmission and services the user explicitly requested. Analytics cookies aren't exempt. Cookieless analytics that don't store data on the visitor's device fall outside § 3-15 entirely.
What changed in Norway's cookie law in January 2025?
The old ekomloven § 2-7 b allowed browser settings to count as consent, the weakest standard in the EEA. The new § 3-15 requires full GDPR-grade consent: voluntary, specific, informed, unambiguous, active, documented, and easily revocable. Accept and reject must be equally prominent. No pre-ticked boxes. No cookie walls. Enforcement is shared between Datatilsynet and Nkom.
What is Datatilsynet?
Datatilsynet is Norway's Data Protection Authority. It has 69 employees, a budget of approximately EUR 7.5 million, and is headed by Director General Line Coll (in office since August 2022). It enforces GDPR in Norway through the EEA Agreement and the Norwegian Personal Data Act. It registered 4,736 cases in 2024 and its largest fine is NOK 65 million against Grindr.
Can I use cookieless analytics without consent in Norway?
Analytics tools that don't set cookies, don't fingerprint visitors, and don't track across sites avoid ekomloven § 3-15's consent trigger. The law applies to "storage of or access to information" on a user's device. If the tool also processes no personal data (anonymous aggregation only), the GDPR consent requirement doesn't apply either. This is why cookieless, privacy-first analytics operate without a consent banner in Norway.
Does GDPR apply in Norway?
Yes. Norway isn't an EU member but is an EEA (European Economic Area) member. GDPR was incorporated into the EEA Agreement on July 6, 2018 and is implemented through Norway's Personal Data Act. Datatilsynet sits on the EDPB but without voting rights. For day-to-day compliance, including cookie consent, Norway is treated identically to EU member states.
What are the fines for cookie violations in Norway?
Datatilsynet can impose standard GDPR fines up to EUR 20 million or 4% of global turnover. Nkom can impose infringement fines under the E-Com Act, sized by gravity, duration, fault, and the company's turnover. Which means a bad banner can cost you from either direction. The largest Norwegian GDPR fine to date is NOK 65 million against Grindr for sharing data without valid consent. For the 2025 tracking pixel enforcement, fines started at NOK 250,000 with an explicit warning that future penalties will be "much stricter."
What is the difference between Nkom and Datatilsynet?
Nkom (Norwegian Communications Authority) enforces the E-Com Act from the technical side: does a technology fall under § 3-15? Do exemptions apply? Datatilsynet enforces GDPR: is the consent valid? Is the data processing lawful? Both have sanctioning authority. A non-compliant cookie banner can trigger enforcement from either authority. In practice, Datatilsynet handles most analytics and tracking cases because they nearly always involve personal data.
A closing note, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or source it came from. If your setup is complicated, show this to your DPO or lawyer.
And if you're weighing a Norwegian analytics decision right now and something here doesn't match what you're seeing, email me.

Comments
Loading comments...
Leave a comment