All terms
Website and technology

GDPR

General Data Protection Regulation

In short

GDPR is the EU's data protection regulation. It applies as Norwegian law and sets how businesses may collect and use information about people.

GDPR stands for General Data Protection Regulation. Norway is not in the EU, but the regulation applies here through the Personal Data Act (personopplysningsloven). The act implements the regulation in Norwegian law, so it applies as Norwegian law, as Lovdata sets out (in Norwegian). The act came into force on 20 July 2018. It covers every business that processes personal data, including the small ones.

What it means for your website

A contact form collects names, email addresses and phone numbers. That is personal data. So you need a purpose for collecting it, you must not ask for more than you need, and you must store it securely and delete it when you no longer need it. People have the right to access and deletion. And you must say openly what you do, which is the job of your privacy policy.

Tracking with cookies and ad pixels also has its own consent rules in the Electronic Communications Act (ekomloven), and that consent must meet the same standard as under GDPR.

Three things to check today

Open your website and find the privacy policy. It should be easy to find, ideally linked from the footer of every page. Then look at the contact form: does it ask for anything you do not need, like date of birth or home address? Finally, think about where the enquiries end up, and how long they stay there. If you want to read more, we have written about privacy and GDPR.

Need a new website?

Get a free design draft of your website's front page, tailored to your business and your goals. You see what your website could look like before you decide, and you commit to nothing.

Get a free draft of your website