Norway - AI Regulatory Sandbox

Datatilsynet Regulatory Sandbox for privacy-friendly innovation and AI (Sandbox for Responsible AI)

Norway

RAI-NO-NA-DRSPIXX-2020
Effective: December 1, 2020
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and OversightRisk Management
Export PDF

Datatilsynet's Regulatory Sandbox (launched December 2020) is a guidance and testing framework to support development of privacy-friendly and responsible AI and digitalisation in Norway. It provides dialogue-based advice, project intake, sectoral pilots and published findings to help organisations operationalise GDPR and Norwegian data protection law during innovation.

Overview

Datatilsynet's Regulatory Sandbox (the "sandkasse" or "Sandbox for Responsible AI") was established in late 2020 as a controlled advisory environment to support privacy-friendly innovation and responsible use of artificial intelligence. The sandbox was announced as part of Norway's national AI strategy and opened for applications on 1 December 2020. It offers iterative, dialogue-based guidance to organisations developing AI or digitalisation projects that involve personal data, with the objective of helping projects identify lawful bases for processing, implement privacy-by-design measures, and document accountability. Over the pilot phase the sandbox engaged with dozens of applicants across sectors and later became a permanent offering in 2023; Datatilsynet publishes summaries and learning outputs so that the wider market can benefit from anonymised lessons and guidance. The sandbox complements Datatilsynet's supervisory role by enabling early-stage advice that reduces regulatory uncertainty for innovators while preserving Datatilsynet's ability to enforce data protection law where necessary. More information and the central landing page are maintained by Datatilsynet on the sandkasse temaside: Datatilsynet – Sandkasse for kunstig intelligens.

Definitions

The sandbox adopts the following working definitions for participation and assessments: "Regulatory sandbox" – a controlled environment where organisations can test innovative products or services with regulatory oversight and tailored guidance; "Project participant" – an entity (public or private) accepted into the sandbox intake process; "Personal data" – as defined by the EU GDPR and Norwegian Personal Data Act (personopplysningsloven); "Privacy-by-design" – incorporation of data protection principles into design and architecture; "DPIA" – data protection impact assessment to identify and mitigate high risks; and "Responsible AI" – systems designed, developed and deployed with attention to lawfulness, transparency, fairness and accountability. Datatilsynet's sandkasse uses these definitions when reviewing proposals and when preparing public outputs to ensure clarity and comparability across projects.

Governance and Institutional Framework

The sandbox is governed and operated by Datatilsynet with funding and inter-ministerial support during the pilot phase. Initial funding and political mandate were provided following Norway’s national AI strategy; the Ministry of Local Government and Modernisation provided the main contribution while other ministries (including Health, Trade and Education) contributed funds and collaborative oversight. Datatilsynet manages intake, review and supervision of sandbox projects; it convenes an internal selection committee and an external reference group for expertise and sectoral perspective. Governance arrangements include documented intake procedures, confidentiality safeguards for proprietary information, and published anonymised outputs. The sandbox sits within Datatilsynet’s broader remit under the Personal Data Act and the GDPR; participation does not remove statutory obligations, but provides a structured forum for clarifying compliance pathways. For organisational details and governance commentary, see Datatilsynet’s landing pages and annual reports describing the sandkasse set-up and funding structure: Sandkassesiden and the 2023 annual report section on the regulatory sandbox: Datatilsynet Årsrapport 2023 – Regulatorisk sandkasse.

Key Focus Areas

The sandbox focuses on several cross-cutting legal and technical areas relevant to privacy-friendly AI and digitalisation: lawful basis and purpose limitation (ensuring projects can identify legal grounds for processing); data minimisation and retention constraints; security and model robustness (technical safeguards for confidentiality, integrity and availability); transparency and explainability to data subjects where feasible; DPIAs and risk assessment frameworks to identify and mitigate high-impact harms; accountability and documentation (logging, version control, governance records); testing and evaluation methodologies for models in operational settings; and accessibility and non-discrimination concerns for fundamental rights. Sectoral emphasis includes healthcare and finance but the sandbox explicitly invites projects across sectors. It also addresses practical engineering questions such as the use of synthetic data, privacy-enhancing technologies (PETs), anonymisation and secure data-sharing architectures. The sandbox encourages short-cycle experiments and produces generic learning summaries so that outputs inform wider compliance practice across industry and public administration.

Implementation Framework

Participation follows a staged process: public call for applications; intake and eligibility screening; selection by internal committee (with an external reference group providing expert input); formal onboarding including confidentiality and collaboration agreements; iterative advisory sessions (legal, technical and policy); midpoint reviews and documented mitigation plans (including DPIAs and technical test plans); and final reporting with anonymised learnings and practical guidance. Datatilsynet provides tailored advice but does not grant waivers from legal obligations; rather, it helps participants understand how existing regulation applies and how to operationalise compliance. The sandbox supports a mix of demonstrators, prototypes and limited pilots; projects are typically time-limited and scoped to reduce risk. Datatilsynet also organises seminars, webinars and educational materials (including a podcast series and videos) to disseminate findings. Operational details, FAQs and application forms are published on the sandbox site: Sandkassesiden.

Monitoring and Evaluation

Datatilsynet monitors projects through scheduled check-ins, documented DPIAs and security attestations. Evaluation criteria include compliance with data protection principles, effectiveness of mitigations, demonstrable improvements to privacy design, and the extent to which project learnings can be generalised for broader guidance. Datatilsynet has conducted internal and external evaluations of the sandbox and reports annually on activity, funding and outcomes in its Årsrapport (annual report). Monitoring outputs may include published project summaries, anonymised case studies, and sector guidance to scale the sandbox's impact. The authority also tracks indicators such as number of applications, diversity of participating organisations, and the number of outputs (reports, workshops, guidance materials) produced each year; see the 2020–2024 report sections for consolidated reporting and evaluation commentary: Datatilsynet Årsrapporter.

Penalties, Liability, and Appeals

Participation in the sandbox does not confer immunity from enforcement. Datatilsynet remains able to investigate and, where appropriate, impose administrative measures and fines under the Personal Data Act and GDPR if serious non-compliance is discovered. The sandbox’s advisory status reduces regulatory uncertainty but does not alter legal liability for data controllers and processors. Participants must maintain records, DPIAs and technical evidence that can be inspected; failure to implement agreed mitigation measures or evidence of wilful non-compliance can trigger enforcement action. Appeal rights against Datatilsynet’s decisions follow ordinary administrative law procedures. Detailed enforcement practice and the role of the sandbox in informing supervisory decisions are discussed in Datatilsynet’s enforcement and annual reporting documents: Årsrapporter.

Relationship to Other Instruments

The sandbox is explicitly designed to operate within the legal framework of the EU General Data Protection Regulation (GDPR) and Norway’s Personal Data Act (Personopplysningsloven). It also aligns with the national AI strategy and coordinates with other Norwegian authorities where sector-specific rules apply (e.g., health, finance). The sandbox outputs are intended to inform compliance with forthcoming and existing regulatory instruments — including guidance on interoperability with the EU AI Act's risk categorisation and technical requirements — and to provide operational examples that translate legal obligations into engineering practice. Datatilsynet has engaged with peer authorities (for example, the UK ICO) to share lessons and align approaches where appropriate; see the sandkasse landing page and podcasts for further cross-authority discussion: Datatilsynet sandkasse.

International Alignment

Datatilsynet’s sandbox model follows an international trend of regulatory sandboxes for fintech, data-sharing and AI innovation. The authority has actively engaged with the ICO and other EU/EEA authorities to exchange methodologies and documentation. The sandbox supports projects that must operate in cross-border environments and considers international transfer rules (including EU adequacy, SCCs and supplementary measures) in its guidance. The findings and generic guidance produced are intended to make Norwegian innovation interoperable with EU/EEA legal expectations and to assist Norwegian actors in preparing for cross-border compliance obligations. Datatilsynet’s external collaboration and references to peer approaches are documented on its sandkasse pages and in annual reporting: International cooperation & sandkasse.

Implementation Timeline

EventDate
National AI Strategy published (indicating sandbox measure)2020-01-01
Datatilsynet establishes and prepares the sandbox2020-09-01 to 2020-11-30
Sandbox opened for applications (first call)2020-12-01
First projects commence (pilot projects)2021-01-01
Selection and first project intake (25 applicants, selection of initial projects)2021-03-01
Pilot evaluation and ongoing operations2021–2022
Converted to permanent guidance offering2023-01-01
Ongoing project cycles, reporting and dissemination2023–present

Compliance Checklist

RequirementVerification
Submit complete application with project descriptionApplication form and selection acknowledgement
Document lawful basis for processing personal dataWritten legal basis statement and DPIA
Perform and share a Data Protection Impact Assessment (DPIA)Signed DPIA document and mitigation plan
Implement privacy-by-design and technical safeguardsArchitecture diagrams, security test reports
Ensure data minimisation and retention limitsData inventory and retention schedule
Maintain accountability documentation (logs, records)Governance records and change logs
Agree time-limited test conditions where applicableProject scope and timeline agreement
Provide transparency and subject informationDraft privacy notices and subject-access procedures

Sources and References

SourceType
Datatilsynet – Sandkasse for kunstig intelligens (landing page)Primary Source
Datatilsynet Årsrapport 2020 – Spesielt om regulatorisk sandkassePrimary Source
Datatilsynet Årsrapport 2023 – Regulatorisk sandkassePrimary Source
Datatilsynet – 25 søkarar til sandkassa (news)Primary Source
Plain English

Norway's Datatilsynet offers a Regulatory Sandbox to guide organisations developing artificial intelligence and digitalisation projects that handle personal data, helping them build privacy-friendly and responsible solutions. This framework, launched in December 2020 and made a permanent offering in 2023, is open to any public or private entity in Norway working on innovative projects involving personal data, with a focus on areas like healthcare and finance, but welcoming all sectors.

Organisations participating in the sandbox receive dialogue-based advice to help them navigate existing data protection laws like the EU General Data Protection Regulation (GDPR) and Norway's Personal Data Act. Key expectations for participants include: - Clearly identifying the legal grounds for processing personal data. - Incorporating privacy safeguards into the design of their systems from the outset. - Conducting and documenting Data Protection Impact Assessments (DPIAs) to identify and mitigate risks. - Maintaining thorough records to demonstrate accountability.

The sandbox aims to reduce regulatory uncertainty by providing early-stage advice. However, it's crucial to understand that participating does not grant immunity from enforcement. Datatilsynet retains its full power to investigate and impose administrative measures or fines under the Personal Data Act and GDPR if serious non-compliance is found, especially if agreed mitigation measures are not implemented. The sandbox helps clarify how to comply, but it does not waive legal obligations. Datatilsynet publishes anonymised summaries and learnings from projects to benefit the wider market.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 8 marked complete

Plain-English obligations under Norway - AI Regulatory Sandbox. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Document lawful basis for processing personal data
  2. #2CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Perform and share a Data Protection Impact Assessment (DPIA)
  3. #3CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Implement privacy-by-design and technical safeguards
  4. #4CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Ensure data minimisation and retention limits
  5. #5CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Maintain accountability documentation (logs, records)
  6. #6CriticalCompliance Checklist

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Provide transparency and subject information
  7. #7ImportantCompliance ChecklistBefore formal onboarding

    Applies to: Organisations applying to Datatilsynet's Regulatory Sandbox.

    Submit complete application with project description
  8. #8ImportantCompliance ChecklistBefore project commencement

    Applies to: Project participants in Datatilsynet's Regulatory Sandbox.

    Agree time-limited test conditions where applicable

© Regulations.AI — created on 13-Jun-2026