We help organisations understand the regulatory framework and establish practical compliance structures for the GDPR, the Norwegian Digital Security Act (digitalsikkerhetsloven), the Electronic Communications Regulations (ekomloven), the Security Act (sikkerhetsloven) and other relevant legislation.
We have one of Norway’s leading data protection and cybersecurity teams, comprising more than 15 lawyers – several with previous experience as in-house counsel and with the Norwegian Data Protection Authority. We advise clients across all sectors, from global technology companies to Norwegian banks, shipping companies and industrial businesses.
Our strength lies in combining specialist regulatory expertise with commercial understanding and experience from complex matters where data, security, technology and business considerations need to be assessed together. We focus on solutions that are legally robust, practical to implement and tailored to the organisation’s risk profile.
Cybersecurity is a board and management responsibility. We advise on requirements relating to security governance, preparedness and reporting under the Security Act, the Digital Security Act and the NIS 2 framework, and assist organisations before, during and after cyber incidents.
Our advice includes
- Data protection and GDPR compliance: We help organisations comply with data protection requirements in practice. This includes internal procedures and policies, privacy notices, records of processing activities, data processing agreements, assessments of legal bases for processing, DPIAs, internal controls, training and dialogue with the Norwegian Data Protection Authority.
- Data compliance and use of personal data: We advise on how personal data and other business-critical data can be processed, shared and used lawfully and securely. This is particularly relevant in connection with new services, analytics models, customer solutions, digital marketing, intra-group data flows and cooperation with suppliers and other third parties.
- Electronic communications, cookies and digital marketing: We advise on matters relating to electronic communications, cookies, consent, direct marketing, newsletters, tracking technologies and the use of digital channels. Our advice covers the interaction between data protection rules, the Electronic Communications Regulations and marketing legislation.
- International data transfers and global compliance projects: Many organisations operate across borders and need to manage personal data within complex corporate structures, supply chains and cloud services. We advise on matters including global GDPR projects, international data transfers, Standard Contractual Clauses, Binding Corporate Rules and transfer risk assessments.
- Cybersecurity, information security and third-party risk: We advise on legal issues relating to information security, cyber risk, contractual security requirements, supplier management, internal controls and preparedness. We help organisations understand which requirements apply, how risks should be managed and how responsibilities should be allocated between the organisation, suppliers and business partners.
- The Digital Security Act and the NIS framework: We assist organisations in assessing requirements under the Digital Security Act and the NIS framework, including risk management, security measures, internal controls, incident management, reporting and management responsibility.
- Security breaches, cyber incidents and crisis management: We advise on contingency plans, notification procedures, exercises and crisis management in connection with security breaches. Thommessen acts as legal adviser to NORMA Cyber and serves on the legal panels of several national and international cyber insurers.
- The Security Act and national security: We advise organisations that are, or may become, subject to the Security Act on requirements relating to information security, security governance, risk assessments, classified procurements, security agreements and engagement with relevant authorities.
- Transactions, regulatory proceedings and disputes: Personal data, data security and cyber risk are key considerations in many transactions. We work closely with our transactional lawyers on M&A processes, investments and other transactions where data protection, information security and regulatory risk need to be assessed. We also advise in matters before the Norwegian Data Protection Authority, appeals, damages claims and disputes relating to data protection, security breaches and the use of data.