Claim analyzed

Legal

“In Norway, an AI service provider is legally allowed to disclose user-provided information to the police if the provider suspects a crime.”

Submitted by Wise Hawk 785f

Mostly False
4/10

Norwegian law does not give AI providers a general right to disclose user-provided information to police whenever they suspect a crime. Disclosure may be allowed or required in narrow situations, especially to avert certain serious offences under Penal Code §196, but that is a much higher and more limited standard than ordinary suspicion. The claim captures a real exception, yet misstates the general rule.

Caveats

  • The claim conflates narrow duty-to-avert rules for specified serious crimes with a general permission to report suspected crime.
  • The legal threshold is not ordinary suspicion; the key exception applies when a listed serious offence is certain or most likely.
  • Telecom and police-data disclosure rules do not automatically apply to private non-telecom AI service providers.

Sources

Sources used in the analysis

#1
Lovdata 2018-06-15 | Lov om behandling av personopplysninger (personopplysningsloven)

Section 12 a. Disclosure of personal data between public authorities Public authorities may disclose personal data to each other when it is necessary in order to prevent, uncover, forestall or sanction work-related crime. The first sentence does not apply to personal data as mentioned in Article 9 of the General Data Protection Regulation. Section 16. Restrictions to the rights of the data subject The rights of access, information, rectification and restriction of processing pursuant to the provisions of the Personal Data Act and the Personal Data Regulations may be restricted if ... (b) it is necessary to keep secret for the purposes of prevention, investigation, detection and prosecution of criminal offences.

According to the Electronic Communication Act (based on the EU E-Privacy Directive) Section 2-9, third subsection, the police in Norway can request user information directly from telecom providers, without court order. This does not apply to non-telecom internet services, for example website hosting.

#3
Lovdata 2005-05-20 | Straffeloven (The Penal Code)

Section 196 of the Norwegian Penal Code establishes a general **duty to avert criminal acts**. It states that a penalty of a fine or imprisonment for up to one year shall be applied to any person who fails to report or otherwise seek to avert a criminal act or its consequences when this is still possible and it appears certain or most likely that the act has been or will be committed. The provision lists specified serious offences and clarifies that the duty to avert applies **regardless of any duty of confidentiality** for those offences.

#4
WorldLII / EPIC Privacy and Human Rights Report – Norway

Under Section 2-9 of the Act, telecommunications providers must safeguard the secrecy of the content of telecommunications. The duty of confidentiality, however, does not prevent such information from being given to the prosecuting authority or the police, or to another authority pursuant to the law.

#5
Lovdata 2010-05-28 | Act relating to the processing of data by the police and the prosecuting authority (Police Databases Act) – §9. Disclosure of data

The police and the prosecuting authority may disclose data if they are allowed to do so under the provisions on the duty of confidentiality in chapter 6, and the conditions governing disclosure laid down in section 8, second paragraph, and section 20 have been met for such data as are mentioned there. … Moreover, data may be disclosed or otherwise made available to foreign authorities or international organisations when this is prescribed by statute or convention or an agreement that is binding on Norway, or by an agreement between Norwegian and other Nordic authorities.

#6
afyonluoglu.org 2000-04-14 | Norway Personal Data Act (No. 31 of 14 April 2000)

However, unless the statutory obligation of professional secrecy prevents disclosure, image recordings may be disclosed to the police in connection with the investigation of criminal acts or accidents. Personal data which are collected by means of image recordings made in places which are frequented by the public may only be disclosed to the controller if the subject of the recording consents thereto or if there is statutory provision for such disclosure.

#7
Datatilsynet Regulations

The GDPR was incorporated into the EEA agreement and became applicable in Norway on 20 July 2018. Norway is thus bound by the GDPR in the same manner as EU Member States. Sector-specific data protection legislation, including: Act relating to the processing of data by the police and the prosecuting authority (the Police Databases Act). The Personal Data Act implements the General Data Protection Regulation (GDPR) into Norwegian law and also contains national rules with Norwegian adaptations.

#8
plikt.no Duty to avert criminal acts

The website explains that "everyone in Norway has a duty to avert criminal acts" and that this duty covers serious crimes such as murder, rape, domestic violence and sexual abuse of children. It notes: "If it is not safe for you to intervene, you still have a duty to notify the police" and emphasises: "Remember that the duty to avert a criminal act always takes precedence over a duty of confidentiality!" The duty is said to stem from Section 196 of the Penal Code and applies "to everyone, both those who work with people and have a duty of confidentiality, and private individuals"; it can be fulfilled by notifying the police or other authorities or otherwise seeking to prevent the act.

#9
Nordic Council of Ministers 2024-05-15 | Data Retention Law in the Nordic Countries – 9. Norway

Pursuant to § 2–8 a retained data may be disclosed to “the police or prosecuting authority” in a criminal investigation. As indicated in § 2–8 a, the investigation must concern “serious crime”, and the relevant offences are further specified in § 2–8 b. … Providing access to IP-addresses etc., is deemed to interfere with the right to private communication. To be lawful, such interference must be “necessary” to the investigation of a serious crime, as per § 2–8 b. A concrete assessment of the necessity of the data for the purpose of the investigation must be made, and it is implied that the assessment also involves proportionality.

#10
Høgskulen i Volda Avvergeplikt og partnervold (Mandatory reporting and partner violence)

The research project on mandatory reporting of intimate partner violence states that service providers "may have a duty of mandatory reporting when receiving information with potential to prevent serious criminal acts." The threshold is that "it appears certain or most likely to the service provider that such an act will be committed." It explains that in Norway, "reporting to the authorities as a means of preventing a wide range of harm is regulated in section 196 of the penal code, applying to all citizens, including (but not restricted to) (health) professionals." Mandatory reporting under section 196 "is not restricted by any professional law of confidentiality, as it applies to all adult citizens," and the duty to report may be executed "by notifying the police or by averting the criminal act or its consequences ‘by other means’."

#11
CMS Mandatory Reporting Of Criminal Offences In Norway

The guide on mandatory reporting of criminal offences in Norway states: "There is no general obligation to report criminal offences." It clarifies that entities subject to the Anti-Money Laundering Act have "a duty to investigate and report suspicious transactions with regards to money laundering and terror financing." It further notes: "Lastly, one also has an obligation to avert certain crimes in accordance with the Penal Code, which could involve reporting to the relevant authorities." The guide adds: "There are no general legal consequences for failure to report a criminal offence," distinguishing the specific duties (e.g. AML, pollution, workplace accidents, duty to avert serious crimes) from any general obligation.

#12
PwC Legal Data. Protection. Adding Value. (Norway section)

Public authorities may disclose personal data that is subject to confidentiality when it is necessary to prevent, cover, forestall or sanction work-related crime. The Ministry may issue regulations with further rules concerning which public authorities may exchange personal data pursuant to this provision.

#13
Finanstilsynet Money laundering and financing of terrorism

The Norwegian Financial Supervisory Authority explains that under the Anti-Money Laundering legislation, "banks and other obliged entities must check information about potential customers when establishing customer relationships" and follow them up on an ongoing basis. It states that "Suspicious transactions made by customers must be reported to Økokrim (the Norwegian National Authority for Investigation and Prosecution of Economic and Environmental Crime)." It further notes that an entity that fails to meet its obligations under the Anti-Money Laundering Act "can be penalised with a fine," including for "failure to report suspicious transactions to Økokrim."

#14
OHCHR Norway – background paper on privacy and surveillance

Civil authorities and private operators processing personal data are subject to the rules set out in the Personal Data Act of 2000. Most importantly, the Act prescribes that all processing of personal data must have a legal basis, i.e. have the consent of the data subject, be prescribed by law, or be necessary for certain specified purposes. The processing must furthermore be limited to a particular purpose, and the data must not be used for other incompatible purposes.

#15
White & Case GDPR Guide to National Implementation: Norway

The GDPR does not apply to law enforcement activities which are instead subject to the Law Enforcement Directive. The Personal Data Act provides exemptions from the right of access and information, including where ‘the information must be kept secret for the purpose of the prevention, investigation, detection and prosecution of criminal offenses’. Pursuant to the Personal Data Act, the processing of special categories of personal data and data relating to criminal convictions and offences is permitted when the processing is necessary to perform obligations or exercise rights in the field of employment.

#16
ICLG 2026-03-07 | Corporate Investigations Laws and Regulations 2026 – Norway

The Norway chapter of the Corporate Investigations Laws and Regulations report states: "With respect to investigation of potential economic or other crime, there are in general no formal procedures that require companies to self-report under Norwegian law, and consequently no required steps for making a disclosure." It adds that enforcement authorities, including ØKOKRIM, "encourage companies to disclose any suspicions of corporate crimes and to cooperate with the authorities on any subsequent investigation." It clarifies: "Entities covered by the Anti-Money Laundering legislation must conduct further examinations" when possible money laundering or terrorist financing is indicated, and if suspicions remain, "the obliged entity shall report" to ØKOKRIM.

#17
Linklaters Data Protected – Norway

The Personal Data Act provides exemptions from the right of access and information provided that: (i) the information is of importance to Norway's national security interests or the defence of the country; (ii) the information must be kept secret for the purpose of the prevention, investigation, detection and prosecution of criminal offenses; (iii) it is considered inadvisable for the data subject to gain knowledge of the information out of consideration for the health of the person concerned or for the relationship to persons close to the person concerned; (iv) the information is subject to a statutory obligation of professional secrecy; (v) the information is solely found in texts drawn up for internal preparatory purposes and which have not been disclosed to other persons; and (vi) disclosure of the information would conflict with obvious and fundamental private and public interests.

#18
DLA Piper Data Protection Laws of the World – Norway

According to the PDA, the processing of information about criminal offences is subject to the regulations as GDPR article 9(2)(a), (c) and (f) as well as the PDA sections 6, 7 and 9, i.e. the same provisions as the processing of special categories of personal data. The PDA also contains provisions allowing exemptions from data subjects’ rights, for example where the information must be kept secret in order to prevent, investigate, disclose and prosecute criminal acts or where disclosure would conflict with obvious and fundamental private and public interests.

#19
Littler Norway GDPR - Personal data protection

Processing of personal data is only lawful if there is a legal basis for the processing in accordance with GDPR article 6. Such legal basis may be consent from the data subject, that the processing is necessary for the performance of a contract, or for compliance with a legal obligation. The legal basis may also be that the processing is necessary for the purposes of legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Processing of sensitive personal data, such as health data, must in addition have a legal basis for the processing in GDPR article 9 no. 2.

#20
Chambers and Partners 2024-09-16 | HR Internal Investigations 2026 – Norway | Trends and Developments

The HR Internal Investigations 2026 – Norway guide notes: "Under Norwegian law, an employer who receives a notice of concern or handles a case involving a notice of concern is not obliged to inform the public authorities." It further states: "There are no statutory procedures imposing a duty on the employer to report a notice of concern to the police, but where there is suspicion of criminal offences the employer should consider referring the matter to the police as soon as possible." It reiterates that "There is no general duty for employers to report criminal offences to the police, but the employer should consider doing so where a notice of concern relates to possible criminal conduct."

#21
Regjeringen.no Meld. St. 15 (2023–2024)

The Norwegian government white paper refers to various reporting obligations for entities handling financial transactions. It notes that "Banks and others who handle transactions are also subject to a reporting obligation under the Norwegian Money Laundering Act" and that such entities "will be able to prevent involvement in economic crime through good control procedures." It further explains that in certain administrative contexts, "the administrator must notify the prosecuting authority" as early as possible when criminal offences are presumed to exist.

#22
CMS CMS Expert Guide to data protection and cyber security laws – Norway

Section 16 of the Personal Data Act restricts information, access, and breach notification rights where disclosure could compromise national security, crime prevention, secrecy obligations, health, or private interests. These restrictions allow controllers to limit what is disclosed to data subjects in cases where secrecy is necessary for the prevention, investigation, detection, and prosecution of criminal offences.

#23
Centraleyes Norwegian Personal Data Act

Section 12a introduces a provision allowing public authorities to disclose personal data to each other to combat work-related crime. This specific provision addresses collaboration among public authorities for a particular purpose. Public authorities may share personal data with other authorities when it is necessary to prevent, uncover, forestall or sanction work-related crime, subject to limitations for special categories of data as defined by the GDPR.

#24
Telenor 2017-03-01 | NORWAY – COUNTRY REPORT: Handling Access Requests from Authorities

According to section 222d CPA, the district court may make an order permitting the police to carry out communication surveillance pursuant to section 216a when there is just cause to suspect that someone will perform an act contrary to certain provisions of the Penal Code. According to section 17d PA, the district court may issue an order permitting the Norwegian Police Security Service (the “PST”) to mandate the disclosure of communications metadata as set out in section 216b CPA and information from computer systems as set out in section 216o, as well as carrying out other investigatory control measures, if there is reason to suspect that an offence under certain sections of the Penal Code will be committed.

#25
Usercentrics 2018-07-20 | Global Data Privacy Laws: Your 2025 Guide (GDPR, CCPA, etc.)

On July 6, 2018, the GDPR became applicable to the non-EU EEA countries of Iceland, Liechtenstein, and Norway through a Joint Committee Decision. Norway incorporated the GDPR through the ‘Act of 15 June 2018 no. 38 relating to the processing of personal data,’ commonly known as the Personal Data Act. The law became effective in Norway on July 20, 2018.

#26
LLM Background Knowledge Context on GDPR-based disclosure of data to police in Norway

In Norway, the Personal Data Act implements and supplements the GDPR. Private operators processing personal data must ensure that any disclosure to law enforcement has a legal basis under the GDPR (such as legitimate interests or legal obligation) and complies with purpose limitation and necessity requirements. Disclosure for crime prevention or investigation generally requires either a specific legal provision or that the processing is necessary for purposes in the public interest.

#27
GDPR.eu What is GDPR, the EU's new data protection law?

Article 6 lists the instances in which it’s legal to process personal data. Don’t even think about touching somebody’s personal data — don’t collect it, don’t store it, don’t sell it to advertisers — unless you can justify it with one of the following: The data subject gave you specific, unambiguous consent to process the data… You need to process it to comply with a legal obligation of yours (e.g. you receive an order from the court in your jurisdiction)… You have a legitimate interest to process someone’s personal data. This is the most flexible lawful basis, though the ‘fundamental rights and freedoms of the data subject’ always override your interests, especially if it’s a child’s data.

#28
Reddit (quoting Norwegian news/government proposal) 2024-10-17 | Regjeringen vil innføre ny lov: utlevering av IP-adresser

The proposed scheme will allow the police and PST to collect IP data, not only during investigation of criminal acts, but also to prevent serious offences, that is, before anything illegal has happened. … Service providers (internet providers) will be obliged to hand over this information.

#29
CMS Law Data protection laws and GDPR enforcement in Norway

Norwegian GDPR enforcement is primarily focused on security failures, unlawful processing or disclosure of personal data and weak governance/internal controls, with a particularly strong emphasis on the public sector. Norwegian enforcement in 2024–2025 suggests a focus on insufficient technical and organisational security measures, processing or disclosure without a valid legal basis and weak privacy governance/internal controls.

Full Analysis

Debate

Two AI advocates debated this claim using the research gathered.

Argument for

P
Proponent Argues TRUE

Norwegian law recognises circumstances where confidentiality yields to crime-prevention needs, most clearly through the Penal Code's duty to avert certain serious offences, which applies to “any person” and explicitly operates regardless of any duty of confidentiality—meaning a private AI provider is legally permitted (and in those cases effectively compelled) to notify police when it believes such a listed serious crime has been or will be committed (Source 3; see also the plain-language explanation in Source 8 and academic discussion in Source 10). More broadly, Norway's GDPR-based framework requires a lawful basis for disclosure, and the materials show that disclosures to police are lawful when prescribed by law or necessary for criminal investigation/prevention (e.g., telecom secrecy rules not barring disclosure to police and statutory regimes enabling police access to retained data), supporting that Norwegian law allows providers to disclose user-provided information to police upon crime suspicion where a legal basis like these applies (Source 4; Source 9; Source 7).

O
Opponent Rebuttal

The Proponent's reliance on Penal Code Section 196 overstates its scope, as that duty applies solely to specified serious offences where commission appears certain or most likely rather than upon mere suspicion, and does not establish a general disclosure permission for AI providers (Source 3, Source 8). The Proponent further errs by conflating narrow statutory exceptions for telecom providers and public authorities with a broad lawful basis under the Personal Data Act applicable to private AI services, ignoring explicit statements that no general reporting obligation exists (Source 2, Source 11, Source 26).

Argument against

O
Opponent Argues FALSE

The claim is false because Norwegian law imposes no general permission for private AI service providers to disclose user data to police upon mere suspicion of crime, as confirmed by the absence of any such authority in the Personal Data Act and explicit statements that there is no general reporting obligation (Source 11, Source 16, Source 20, Source 26). Instead, disclosure is restricted to narrow duties such as averting only specified serious offences under Penal Code Section 196 where the act appears certain or most likely, which does not extend to routine suspicion or non-telecom providers (Source 3, Source 8, Source 2).

P
Proponent Rebuttal

The Opponent commits a non sequitur by treating “no general obligation to report” as “no legal permission to disclose,” even though the motion asks whether disclosure is legally allowed in at least some crime-suspicion scenarios, and Penal Code §196 expressly authorises (and for listed serious offences effectively compels) notifying police “regardless of any duty of confidentiality” when the provider believes such an offence is most likely (Source 3; corroborated by Source 8 and Source 10). The Opponent also misdirects to telecom/non-telecom access-request rules (Source 2) and the Personal Data Act's lack of a blanket disclosure clause, while ignoring that Norwegian law recognises lawful bases and statutory carve-outs where confidentiality yields to crime-prevention needs—so the absence of a universal permission does not negate the existence of concrete permissions like §196 that make the claim true as stated (Source 3; Source 7).


Panel Review

3 specialized AI experts evaluated the evidence and arguments.

Reviewer 1 — The Logic Examiner

Focus: Inferential Soundness & Fallacies
Mostly False
4/10

The Proponent's chain is that Penal Code §196 creates a duty to avert certain serious crimes that can be fulfilled by notifying police and applies regardless of confidentiality, so a private AI provider is at least legally permitted (and sometimes required) to disclose user-provided information in those §196 scenarios (Sources 3, 8, 10), but the remaining evidence about telecom/public-authority disclosure regimes and GDPR-style lawful bases does not logically establish a general permission triggered by mere “suspects a crime” for private non-telecom AI providers (Sources 1, 2, 4, 9, 7). Because the claim asserts a broad allowance upon suspicion of crime, while the evidence supports only narrow, thresholded exceptions (notably §196's listed serious offences and “certain/most likely” standard), the inference to the claim as stated does not hold and the claim is mostly false.

Logical fallacies

The Proponent risks a hasty generalization by inferring a broad permission to disclose upon crime suspicion from a narrow statutory duty limited to specified serious offences with a high likelihood threshold.The Proponent's argument contains a non sequitur where telecom/public-authority disclosure rules are treated as support for what private non-telecom AI providers may disclose absent a specific legal basis.The Opponent risks a false dichotomy by implying that lack of a general reporting obligation entails lack of any legal permission to disclose, even though narrow permissions/duties can still exist.
Confidence: 8/10

Reviewer 2 — The Source Auditor

Focus: Source Reliability & Independence
Mostly True
7/10

The most reliable sources here are Lovdata (Sources 1, 3, 5) — the official Norwegian legal database — along with Datatilsynet (Source 7), the Nordic Council of Ministers (Source 9), and the Council of Europe presentation (Source 2), all of which are high-authority and independent. These sources collectively establish the following: (1) Penal Code §196 (Source 3, corroborated by Sources 8 and 10) creates a duty to avert specified serious crimes that overrides confidentiality obligations and applies to 'any person,' including private service providers — this constitutes a legal permission (and in fact a duty) to disclose to police when commission of listed serious offences appears certain or most likely; (2) telecom-specific rules allow police to request user information from telecom providers without a court order (Source 2, Source 4, Source 9), though this does not extend to non-telecom internet services; (3) the Personal Data Act and GDPR framework require a lawful basis for any disclosure, and disclosures to police are lawful when prescribed by law or necessary for criminal investigation (Sources 1, 7, 15, 17, 18); (4) however, multiple credible legal guides (Sources 11, 16, 20) confirm there is no general obligation or general permission to report criminal offences to police. The claim as stated says an AI service provider is 'legally allowed to disclose user-provided information to the police if the provider suspects a crime' — this is partially true but overstated. The legal permission exists in specific, narrow circumstances: for listed serious offences under §196 where commission appears certain or most likely (not mere suspicion), and where a lawful basis under GDPR/PDA exists. The claim's use of 'suspects a crime' is broader than what Norwegian law actually permits — §196 requires that commission appears 'certain or most likely,' not mere suspicion, and applies only to specified serious offences. For non-serious crimes or mere suspicion, no general disclosure permission exists. The claim captures a real legal phenomenon but overstates its breadth by omitting the threshold and scope limitations. This makes the claim mostly true in spirit but imprecise in framing.

Weakest sources

Source 28 is a Reddit post and carries minimal evidentiary weight despite quoting a government proposal, as it is an unverified secondary source with no editorial oversight.Source 27 is a general GDPR explainer website with no specific analysis of Norwegian law and adds little independent value to the Norway-specific claim.Source 25 is a commercial consent management platform's guide that provides only background GDPR context without Norway-specific legal analysis relevant to the claim.Source 29 is a CMS Law enforcement tracker summary that describes enforcement trends rather than the substantive legal permissions at issue in the claim.
Confidence: 8/10

Reviewer 3 — The Precision Analyst

Focus: Claim Precision & Quantitative Accuracy
Mostly False
3/10

The claim asserts that an AI provider in Norway is legally allowed to disclose user data to the police if they suspect a crime, but the evidence shows that Norway's GDPR-based framework and Penal Code Section 196 only permit or mandate disclosure for specific, highly restricted serious offenses where commission is 'certain or most likely' rather than on mere suspicion (Sources 3, 10, 11). There is no general legal permission or reporting obligation for private non-telecom providers based on general suspicion of crime (Sources 2, 11, 20).

Precision issues

The claim's scope is overly broad, implying a general permission to disclose data on any 'suspicion of a crime', whereas Norwegian law only permits or mandates disclosure for specific, highly restricted serious offenses.The claim mischaracterizes the legal threshold, substituting a general 'suspicion' for the strict statutory standard of 'certain or most likely' required under Penal Code Section 196.
Confidence: 8/10

Panel summary

See the full panel summary

Create a free account to read the complete analysis.

Sign up free
The claim is
Mostly False
4/10
Confidence: 8/10 Spread: 4 pts

Your annotation will be visible after submission.

Embed this verification

Every embed carries schema.org ClaimReview microdata — recognized by Google and AI crawlers.

Mostly False · Lenz Score 4/10 Lenz
“In Norway, an AI service provider is legally allowed to disclose user-provided information to the police if the provider suspects a crime.”
29 sources · 3-panel audit · Verified Jul 2026
See full report on Lenz →