Verify any claim · lenz.io
Claim analyzed
Legal“In Norway, an AI service provider is legally allowed to disclose user-provided information to the police if the provider suspects a crime.”
Submitted by Wise Hawk 785f
The conclusion
Open in workbench →Norwegian law does not give AI providers a general right to disclose user-provided information to police whenever they suspect a crime. Disclosure may be allowed or required in narrow situations, especially to avert certain serious offences under Penal Code §196, but that is a much higher and more limited standard than ordinary suspicion. The claim captures a real exception, yet misstates the general rule.
Caveats
- The claim conflates narrow duty-to-avert rules for specified serious crimes with a general permission to report suspected crime.
- The legal threshold is not ordinary suspicion; the key exception applies when a listed serious offence is certain or most likely.
- Telecom and police-data disclosure rules do not automatically apply to private non-telecom AI service providers.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
Section 12 a. Disclosure of personal data between public authorities Public authorities may disclose personal data to each other when it is necessary in order to prevent, uncover, forestall or sanction work-related crime. The first sentence does not apply to personal data as mentioned in Article 9 of the General Data Protection Regulation. Section 16. Restrictions to the rights of the data subject The rights of access, information, rectification and restriction of processing pursuant to the provisions of the Personal Data Act and the Personal Data Regulations may be restricted if ... (b) it is necessary to keep secret for the purposes of prevention, investigation, detection and prosecution of criminal offences.
According to the Electronic Communication Act (based on the EU E-Privacy Directive) Section 2-9, third subsection, the police in Norway can request user information directly from telecom providers, without court order. This does not apply to non-telecom internet services, for example website hosting.
Section 196 of the Norwegian Penal Code establishes a general **duty to avert criminal acts**. It states that a penalty of a fine or imprisonment for up to one year shall be applied to any person who fails to report or otherwise seek to avert a criminal act or its consequences when this is still possible and it appears certain or most likely that the act has been or will be committed. The provision lists specified serious offences and clarifies that the duty to avert applies **regardless of any duty of confidentiality** for those offences.
Under Section 2-9 of the Act, telecommunications providers must safeguard the secrecy of the content of telecommunications. The duty of confidentiality, however, does not prevent such information from being given to the prosecuting authority or the police, or to another authority pursuant to the law.
The police and the prosecuting authority may disclose data if they are allowed to do so under the provisions on the duty of confidentiality in chapter 6, and the conditions governing disclosure laid down in section 8, second paragraph, and section 20 have been met for such data as are mentioned there. … Moreover, data may be disclosed or otherwise made available to foreign authorities or international organisations when this is prescribed by statute or convention or an agreement that is binding on Norway, or by an agreement between Norwegian and other Nordic authorities.
However, unless the statutory obligation of professional secrecy prevents disclosure, image recordings may be disclosed to the police in connection with the investigation of criminal acts or accidents. Personal data which are collected by means of image recordings made in places which are frequented by the public may only be disclosed to the controller if the subject of the recording consents thereto or if there is statutory provision for such disclosure.
The GDPR was incorporated into the EEA agreement and became applicable in Norway on 20 July 2018. Norway is thus bound by the GDPR in the same manner as EU Member States. Sector-specific data protection legislation, including: Act relating to the processing of data by the police and the prosecuting authority (the Police Databases Act). The Personal Data Act implements the General Data Protection Regulation (GDPR) into Norwegian law and also contains national rules with Norwegian adaptations.
The website explains that "everyone in Norway has a duty to avert criminal acts" and that this duty covers serious crimes such as murder, rape, domestic violence and sexual abuse of children. It notes: "If it is not safe for you to intervene, you still have a duty to notify the police" and emphasises: "Remember that the duty to avert a criminal act always takes precedence over a duty of confidentiality!" The duty is said to stem from Section 196 of the Penal Code and applies "to everyone, both those who work with people and have a duty of confidentiality, and private individuals"; it can be fulfilled by notifying the police or other authorities or otherwise seeking to prevent the act.
Pursuant to § 2–8 a retained data may be disclosed to “the police or prosecuting authority” in a criminal investigation. As indicated in § 2–8 a, the investigation must concern “serious crime”, and the relevant offences are further specified in § 2–8 b. … Providing access to IP-addresses etc., is deemed to interfere with the right to private communication. To be lawful, such interference must be “necessary” to the investigation of a serious crime, as per § 2–8 b. A concrete assessment of the necessity of the data for the purpose of the investigation must be made, and it is implied that the assessment also involves proportionality.
The research project on mandatory reporting of intimate partner violence states that service providers "may have a duty of mandatory reporting when receiving information with potential to prevent serious criminal acts." The threshold is that "it appears certain or most likely to the service provider that such an act will be committed." It explains that in Norway, "reporting to the authorities as a means of preventing a wide range of harm is regulated in section 196 of the penal code, applying to all citizens, including (but not restricted to) (health) professionals." Mandatory reporting under section 196 "is not restricted by any professional law of confidentiality, as it applies to all adult citizens," and the duty to report may be executed "by notifying the police or by averting the criminal act or its consequences ‘by other means’."
The guide on mandatory reporting of criminal offences in Norway states: "There is no general obligation to report criminal offences." It clarifies that entities subject to the Anti-Money Laundering Act have "a duty to investigate and report suspicious transactions with regards to money laundering and terror financing." It further notes: "Lastly, one also has an obligation to avert certain crimes in accordance with the Penal Code, which could involve reporting to the relevant authorities." The guide adds: "There are no general legal consequences for failure to report a criminal offence," distinguishing the specific duties (e.g. AML, pollution, workplace accidents, duty to avert serious crimes) from any general obligation.
Public authorities may disclose personal data that is subject to confidentiality when it is necessary to prevent, cover, forestall or sanction work-related crime. The Ministry may issue regulations with further rules concerning which public authorities may exchange personal data pursuant to this provision.
The Norwegian Financial Supervisory Authority explains that under the Anti-Money Laundering legislation, "banks and other obliged entities must check information about potential customers when establishing customer relationships" and follow them up on an ongoing basis. It states that "Suspicious transactions made by customers must be reported to Økokrim (the Norwegian National Authority for Investigation and Prosecution of Economic and Environmental Crime)." It further notes that an entity that fails to meet its obligations under the Anti-Money Laundering Act "can be penalised with a fine," including for "failure to report suspicious transactions to Økokrim."
Civil authorities and private operators processing personal data are subject to the rules set out in the Personal Data Act of 2000. Most importantly, the Act prescribes that all processing of personal data must have a legal basis, i.e. have the consent of the data subject, be prescribed by law, or be necessary for certain specified purposes. The processing must furthermore be limited to a particular purpose, and the data must not be used for other incompatible purposes.
The GDPR does not apply to law enforcement activities which are instead subject to the Law Enforcement Directive. The Personal Data Act provides exemptions from the right of access and information, including where ‘the information must be kept secret for the purpose of the prevention, investigation, detection and prosecution of criminal offenses’. Pursuant to the Personal Data Act, the processing of special categories of personal data and data relating to criminal convictions and offences is permitted when the processing is necessary to perform obligations or exercise rights in the field of employment.
The Norway chapter of the Corporate Investigations Laws and Regulations report states: "With respect to investigation of potential economic or other crime, there are in general no formal procedures that require companies to self-report under Norwegian law, and consequently no required steps for making a disclosure." It adds that enforcement authorities, including ØKOKRIM, "encourage companies to disclose any suspicions of corporate crimes and to cooperate with the authorities on any subsequent investigation." It clarifies: "Entities covered by the Anti-Money Laundering legislation must conduct further examinations" when possible money laundering or terrorist financing is indicated, and if suspicions remain, "the obliged entity shall report" to ØKOKRIM.
The Personal Data Act provides exemptions from the right of access and information provided that: (i) the information is of importance to Norway's national security interests or the defence of the country; (ii) the information must be kept secret for the purpose of the prevention, investigation, detection and prosecution of criminal offenses; (iii) it is considered inadvisable for the data subject to gain knowledge of the information out of consideration for the health of the person concerned or for the relationship to persons close to the person concerned; (iv) the information is subject to a statutory obligation of professional secrecy; (v) the information is solely found in texts drawn up for internal preparatory purposes and which have not been disclosed to other persons; and (vi) disclosure of the information would conflict with obvious and fundamental private and public interests.
According to the PDA, the processing of information about criminal offences is subject to the regulations as GDPR article 9(2)(a), (c) and (f) as well as the PDA sections 6, 7 and 9, i.e. the same provisions as the processing of special categories of personal data. The PDA also contains provisions allowing exemptions from data subjects’ rights, for example where the information must be kept secret in order to prevent, investigate, disclose and prosecute criminal acts or where disclosure would conflict with obvious and fundamental private and public interests.
Processing of personal data is only lawful if there is a legal basis for the processing in accordance with GDPR article 6. Such legal basis may be consent from the data subject, that the processing is necessary for the performance of a contract, or for compliance with a legal obligation. The legal basis may also be that the processing is necessary for the purposes of legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Processing of sensitive personal data, such as health data, must in addition have a legal basis for the processing in GDPR article 9 no. 2.
The HR Internal Investigations 2026 – Norway guide notes: "Under Norwegian law, an employer who receives a notice of concern or handles a case involving a notice of concern is not obliged to inform the public authorities." It further states: "There are no statutory procedures imposing a duty on the employer to report a notice of concern to the police, but where there is suspicion of criminal offences the employer should consider referring the matter to the police as soon as possible." It reiterates that "There is no general duty for employers to report criminal offences to the police, but the employer should consider doing so where a notice of concern relates to possible criminal conduct."
The Norwegian government white paper refers to various reporting obligations for entities handling financial transactions. It notes that "Banks and others who handle transactions are also subject to a reporting obligation under the Norwegian Money Laundering Act" and that such entities "will be able to prevent involvement in economic crime through good control procedures." It further explains that in certain administrative contexts, "the administrator must notify the prosecuting authority" as early as possible when criminal offences are presumed to exist.
Section 16 of the Personal Data Act restricts information, access, and breach notification rights where disclosure could compromise national security, crime prevention, secrecy obligations, health, or private interests. These restrictions allow controllers to limit what is disclosed to data subjects in cases where secrecy is necessary for the prevention, investigation, detection, and prosecution of criminal offences.
Section 12a introduces a provision allowing public authorities to disclose personal data to each other to combat work-related crime. This specific provision addresses collaboration among public authorities for a particular purpose. Public authorities may share personal data with other authorities when it is necessary to prevent, uncover, forestall or sanction work-related crime, subject to limitations for special categories of data as defined by the GDPR.
According to section 222d CPA, the district court may make an order permitting the police to carry out communication surveillance pursuant to section 216a when there is just cause to suspect that someone will perform an act contrary to certain provisions of the Penal Code. According to section 17d PA, the district court may issue an order permitting the Norwegian Police Security Service (the “PST”) to mandate the disclosure of communications metadata as set out in section 216b CPA and information from computer systems as set out in section 216o, as well as carrying out other investigatory control measures, if there is reason to suspect that an offence under certain sections of the Penal Code will be committed.
On July 6, 2018, the GDPR became applicable to the non-EU EEA countries of Iceland, Liechtenstein, and Norway through a Joint Committee Decision. Norway incorporated the GDPR through the ‘Act of 15 June 2018 no. 38 relating to the processing of personal data,’ commonly known as the Personal Data Act. The law became effective in Norway on July 20, 2018.
In Norway, the Personal Data Act implements and supplements the GDPR. Private operators processing personal data must ensure that any disclosure to law enforcement has a legal basis under the GDPR (such as legitimate interests or legal obligation) and complies with purpose limitation and necessity requirements. Disclosure for crime prevention or investigation generally requires either a specific legal provision or that the processing is necessary for purposes in the public interest.
Article 6 lists the instances in which it’s legal to process personal data. Don’t even think about touching somebody’s personal data — don’t collect it, don’t store it, don’t sell it to advertisers — unless you can justify it with one of the following: The data subject gave you specific, unambiguous consent to process the data… You need to process it to comply with a legal obligation of yours (e.g. you receive an order from the court in your jurisdiction)… You have a legitimate interest to process someone’s personal data. This is the most flexible lawful basis, though the ‘fundamental rights and freedoms of the data subject’ always override your interests, especially if it’s a child’s data.
The proposed scheme will allow the police and PST to collect IP data, not only during investigation of criminal acts, but also to prevent serious offences, that is, before anything illegal has happened. … Service providers (internet providers) will be obliged to hand over this information.
Norwegian GDPR enforcement is primarily focused on security failures, unlawful processing or disclosure of personal data and weak governance/internal controls, with a particularly strong emphasis on the public sector. Norwegian enforcement in 2024–2025 suggests a focus on insufficient technical and organisational security measures, processing or disclosure without a valid legal basis and weak privacy governance/internal controls.
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Norwegian law recognises circumstances where confidentiality yields to crime-prevention needs, most clearly through the Penal Code's duty to avert certain serious offences, which applies to “any person” and explicitly operates regardless of any duty of confidentiality—meaning a private AI provider is legally permitted (and in those cases effectively compelled) to notify police when it believes such a listed serious crime has been or will be committed (Source 3; see also the plain-language explanation in Source 8 and academic discussion in Source 10). More broadly, Norway's GDPR-based framework requires a lawful basis for disclosure, and the materials show that disclosures to police are lawful when prescribed by law or necessary for criminal investigation/prevention (e.g., telecom secrecy rules not barring disclosure to police and statutory regimes enabling police access to retained data), supporting that Norwegian law allows providers to disclose user-provided information to police upon crime suspicion where a legal basis like these applies (Source 4; Source 9; Source 7).
The Proponent's reliance on Penal Code Section 196 overstates its scope, as that duty applies solely to specified serious offences where commission appears certain or most likely rather than upon mere suspicion, and does not establish a general disclosure permission for AI providers (Source 3, Source 8). The Proponent further errs by conflating narrow statutory exceptions for telecom providers and public authorities with a broad lawful basis under the Personal Data Act applicable to private AI services, ignoring explicit statements that no general reporting obligation exists (Source 2, Source 11, Source 26).
Argument against
The claim is false because Norwegian law imposes no general permission for private AI service providers to disclose user data to police upon mere suspicion of crime, as confirmed by the absence of any such authority in the Personal Data Act and explicit statements that there is no general reporting obligation (Source 11, Source 16, Source 20, Source 26). Instead, disclosure is restricted to narrow duties such as averting only specified serious offences under Penal Code Section 196 where the act appears certain or most likely, which does not extend to routine suspicion or non-telecom providers (Source 3, Source 8, Source 2).
The Opponent commits a non sequitur by treating “no general obligation to report” as “no legal permission to disclose,” even though the motion asks whether disclosure is legally allowed in at least some crime-suspicion scenarios, and Penal Code §196 expressly authorises (and for listed serious offences effectively compels) notifying police “regardless of any duty of confidentiality” when the provider believes such an offence is most likely (Source 3; corroborated by Source 8 and Source 10). The Opponent also misdirects to telecom/non-telecom access-request rules (Source 2) and the Personal Data Act's lack of a blanket disclosure clause, while ignoring that Norwegian law recognises lawful bases and statutory carve-outs where confidentiality yields to crime-prevention needs—so the absence of a universal permission does not negate the existence of concrete permissions like §196 that make the claim true as stated (Source 3; Source 7).
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
The Proponent's chain is that Penal Code §196 creates a duty to avert certain serious crimes that can be fulfilled by notifying police and applies regardless of confidentiality, so a private AI provider is at least legally permitted (and sometimes required) to disclose user-provided information in those §196 scenarios (Sources 3, 8, 10), but the remaining evidence about telecom/public-authority disclosure regimes and GDPR-style lawful bases does not logically establish a general permission triggered by mere “suspects a crime” for private non-telecom AI providers (Sources 1, 2, 4, 9, 7). Because the claim asserts a broad allowance upon suspicion of crime, while the evidence supports only narrow, thresholded exceptions (notably §196's listed serious offences and “certain/most likely” standard), the inference to the claim as stated does not hold and the claim is mostly false.
Reviewer 2 — The Source Auditor
The most reliable sources here are Lovdata (Sources 1, 3, 5) — the official Norwegian legal database — along with Datatilsynet (Source 7), the Nordic Council of Ministers (Source 9), and the Council of Europe presentation (Source 2), all of which are high-authority and independent. These sources collectively establish the following: (1) Penal Code §196 (Source 3, corroborated by Sources 8 and 10) creates a duty to avert specified serious crimes that overrides confidentiality obligations and applies to 'any person,' including private service providers — this constitutes a legal permission (and in fact a duty) to disclose to police when commission of listed serious offences appears certain or most likely; (2) telecom-specific rules allow police to request user information from telecom providers without a court order (Source 2, Source 4, Source 9), though this does not extend to non-telecom internet services; (3) the Personal Data Act and GDPR framework require a lawful basis for any disclosure, and disclosures to police are lawful when prescribed by law or necessary for criminal investigation (Sources 1, 7, 15, 17, 18); (4) however, multiple credible legal guides (Sources 11, 16, 20) confirm there is no general obligation or general permission to report criminal offences to police. The claim as stated says an AI service provider is 'legally allowed to disclose user-provided information to the police if the provider suspects a crime' — this is partially true but overstated. The legal permission exists in specific, narrow circumstances: for listed serious offences under §196 where commission appears certain or most likely (not mere suspicion), and where a lawful basis under GDPR/PDA exists. The claim's use of 'suspects a crime' is broader than what Norwegian law actually permits — §196 requires that commission appears 'certain or most likely,' not mere suspicion, and applies only to specified serious offences. For non-serious crimes or mere suspicion, no general disclosure permission exists. The claim captures a real legal phenomenon but overstates its breadth by omitting the threshold and scope limitations. This makes the claim mostly true in spirit but imprecise in framing.
Reviewer 3 — The Precision Analyst
The claim asserts that an AI provider in Norway is legally allowed to disclose user data to the police if they suspect a crime, but the evidence shows that Norway's GDPR-based framework and Penal Code Section 196 only permit or mandate disclosure for specific, highly restricted serious offenses where commission is 'certain or most likely' rather than on mere suspicion (Sources 3, 10, 11). There is no general legal permission or reporting obligation for private non-telecom providers based on general suspicion of crime (Sources 2, 11, 20).