Norway - Digital Public Sector Strategy (2019-2025)

One Digital Public Sector: Digital strategy for the public sector 2019–2025

Norway

RAI-NO-NA-ODPSDXX-2019
Effective: June 11, 2019
In Force(In Force)
PolicyGovernance and OversightData Protection and PrivacyCybersecurity and Model Security
Export PDF

The Norwegian national strategy "One digital public sector" (2019–2025) sets a common cross‑sectoral framework to deliver user‑centric, seamless public services, strengthen data sharing and reuse, promote digital‑friendly regulation, and build a coordinated national ecosystem for digital collaboration. The strategy emphasises cybersecurity, privacy, inclusiveness and cooperation between state and municipal actors, and is implemented through national agencies and joint governance structures.

Overview

One digital public sector: Digital strategy for the public sector 2019–2025 is Norway's cross‑sector strategy to create a coordinated, user‑centric and secure public sector. Published by the Ministry of Local Government and Modernisation on 11 June 2019, and presented on the government documents site, the strategy sets the primary objective of a "simpler everyday life" for citizens and businesses and defines goals and focus areas to be achieved by 2025. The strategy emphasises seven core focus areas (user‑centric services, data sharing, digital‑friendly regulation, national ecosystem and common solutions, governance and coordination, cooperation with the private sector, competence and cybersecurity) and assigns lead roles to ministries, the Norwegian Digitalisation Agency (Digdir) and KS for operational follow‑up. The full English text is available as a PDF on the Government of Norway website: One digital public sector — full text (PDF).

Definitions

The strategy uses several working definitions central to implementation: "digitalisation" as organisational and service transformation supported by technology; "common solutions" as national shared components and platforms (e.g. identity, authentication, basic registers, service platforms); "life events" as prioritised user journeys defined to drive cross‑agency service integration; and "ecosystem" as the governed set of architectures, standards, interfaces and roles that enable cross‑sector collaboration. These definitions align with terminology in the earlier Digital Agenda White Paper and OECD digital government reviews.

Governance and Institutional Framework

The strategy sets out a collaborative governance model where ministries retain sector responsibility, while national coordination is delivered through territorial cooperation with KS and operational follow‑up by the Norwegian Digitalisation Agency (Digdir). The strategy assigns life‑event ownership to specific ministries for political anchoring and requires joint handlingsplaner (action plans) produced by Digdir and KS. It also references existing oversight bodies (e.g. the Office of the Auditor General) and the need for clearer roles and responsibilities; these recommendations respond to OECD findings that Norway required stronger central coordination. Governance is therefore a hybrid: ministerial accountability combined with a cooperative, programmatic model implemented by directorates and agencies.

Key Focus Areas

The document organises digitalisation around interconnected focus areas: (1) Seamless, user‑centric services built around prioritised life events (such as having children, serious illness of a child, losing and finding work, new in Norway, starting and running a business, starting and running a voluntary organisation, and death and inheritance). (2) Increased sharing and reuse of data — including publication of open data and strengthened use of national registers — to enable better services and promote innovation. (3) Digitalisation‑friendly regulation and legal reviews that remove unnecessary obstacles to digital service delivery. (4) Development of a common ecosystem of national solutions, common architecture and shared components to avoid duplication and reduce costs. (5) Strengthened governance, incentives and funding models for cross‑level cooperation between state and municipal actors. (6) Enhanced public‑private cooperation to stimulate innovation while safeguarding public interest. (7) Measures to increase digital competence across the public sector workforce. (8) Cybersecurity and privacy, requiring that security be built into service development and operations, in line with national guidance and NSM principles (NSM). The strategy enumerates expected benefits and places a strong emphasis on systematic benefit realisation and measurement.

Implementation Framework

Operational follow‑up is assigned to Digdir and KS, with ministries maintaining political responsibility for life events and sector objectives. The strategy envisages action plans, common architectures, prioritisation of common solutions over bespoke systems and use of existing national building blocks (identity services, registers and platforms). It calls for funding models and incentive structures to encourage reuse and cross‑jurisdictional adoption, with Digdir producing guidance and technical standards. The strategy does not create new statutory obligations but sets expectations and governance mechanisms to drive implementation through directives, handlingsplaner and agency instructions.

Monitoring and Evaluation

The strategy mandates monitoring through periodic reporting, indicators linked to 2025 goals and a requirement for systematic realisation of benefits. Digdir, KS and responsible ministries are expected to publish follow‑up plans and progress reports and to use common indicators (service usage, share of digital communications, reuse of data, accessibility metrics). The Office of the Auditor General and other oversight bodies play a role in reviewing benefit realisation and use of public funds.

Penalties, Liability, and Appeals

The strategy itself does not set out novel criminal penalties. Accountability is achieved through governance instruments, budgetary incentives, reporting requirements and existing legal frameworks. Where digitalisation activities intersect with data protection or security obligations, supervisory authorities such as the Norwegian Data Protection Authority (Datatilsynet) and NSM retain enforcement powers under existing laws (e.g. GDPR and national security legislation). Administrative consequences for non‑compliance may include corrective orders, audit findings, funding restrictions and reputational consequences; liability and appeals follow standard administrative law processes.

Relationship to Other Instruments

The strategy is a follow‑up to the White Paper "Digital Agenda for Norway" (Meld. St. 27 (2015–2016)) and aligns with Norway's National Cyber Security Strategy and sectoral strategies (e‑health, AI strategy, Digital21). Instruments such as the Digitaliseringsrundskrivet provide operational guidance to agencies, while sector laws (health, social services, public procurement and privacy law) provide binding legal constraints and enforcement regimes that must be respected when implementing the strategy.

International Alignment

The strategy recognises international frameworks and EEA/EU developments (e.g. GDPR, EU digital policy and standards) and references OECD recommendations. Norway positions the strategy to be compatible with EU/EEA rules and international best practice for interoperability, data protection and cybersecurity. The document also highlights the need to follow EU initiatives on digital public administration and data sharing to maintain alignment and interoperability across borders.

Implementation Timeline

EventDate
Strategy published (original)2019-06-11
Action plan development (Digdir & KS)2019–2020 (ongoing updates)
Mid‑term review / progress reportingcirca 2022–2023
Target horizon for goals2025-12-31

Compliance Checklist

RequirementAgency Action
Adopt user‑centric design for servicesEmbed service design, involve users, prioritise life events
Use common solutionsAssess reuse before procuring bespoke systems
Integrate cybersecurityApply NSM and Digdir guidance, conduct risk assessments
Protect personal dataApply GDPR, perform DPIAs and privacy by design
Publish open data where appropriateRegister datasets and follow licensing guidance

Sources and References

SourceType
One digital public sector – Digital strategy for the public sector 2019–2025 (PDF)Primary Source
One digital public sector – Government summary page (English)Primary Source
Digitaliseringsdirektoratet (Digdir)Primary Implementation Agency
Norwegian Data Protection Authority (Datatilsynet)Primary Supervisor
Norwegian National Security Authority (NSM)Primary Cybersecurity Guidance
Plain English

Norway's "One Digital Public Sector" strategy, launched in 2019, sets a national framework for all state and municipal public sector entities to deliver more user-centric, seamless, and secure digital services by 2025.

This strategy applies to every part of the Norwegian public sector, from government ministries and national agencies to local municipalities. Its core aim is to simplify daily life for citizens and businesses by transforming how public services are designed and delivered. Key obligations for these entities include: - Building services around "life events" (like starting a business or having a child) to ensure a seamless user experience across different agencies. - Significantly increasing the sharing and reuse of data, including making more public data openly available, to foster innovation and better services. - Actively reviewing and updating existing regulations to remove barriers to digital service delivery. - Prioritising the use of common national digital solutions and shared infrastructure over developing bespoke systems, to reduce costs and duplication. - Embedding cybersecurity and privacy by design into all new services and operations, following national guidelines.

The strategy was published on June 11, 2019, with a target horizon for achieving its goals by the end of 2025. While this document itself does not introduce new criminal penalties, accountability is driven through a combination of governance mechanisms, budgetary incentives, and reporting requirements. Where digital activities touch on areas like data protection or cybersecurity, existing laws such as the General Data Protection Regulation (GDPR) and national security legislation provide the actual enforcement teeth, with bodies like the Norwegian Data Protection Authority (Datatilsynet) retaining their supervisory powers. Non-compliance with the strategy's principles could lead to administrative consequences, such as audit findings, funding restrictions, or reputational damage.

A practical pitfall for product managers or team leads is understanding that this is a *policy strategy*, not a binding law with direct statutory obligations. While it sets strong expectations and guides funding and coordination, the direct legal requirements and penalties for digital services typically stem from other existing legislation. Therefore, while adherence to the strategy is crucial for public sector projects, the ultimate legal compliance framework remains rooted in broader administrative and sector-specific laws.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Norway - Digital Public Sector Strategy (2019-2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalPenalties, Liability, and AppealsDec 31, 2025

    Applies to: Public sector entities handling personal data.

    supervisory authorities such as the Norwegian Data Protection Authority (Datatilsynet) and NSM retain enforcement powers under existing laws (e.g. GDPR and national security legislation).
  2. #2CriticalKey Focus AreasDec 31, 2025

    Applies to: Public sector entities developing and operating services.

    requiring that security be built into service development and operations, in line with national guidance and NSM principles
  3. #3ImportantKey Focus AreasDec 31, 2025

    Applies to: Public sector entities delivering services.

    Seamless, user‑centric services built around prioritised life events
  4. #4ImportantImplementation FrameworkDec 31, 2025

    Applies to: Public sector entities procuring or developing systems.

    prioritisation of common solutions over bespoke systems and use of existing national building blocks
  5. #5ImportantKey Focus AreasDec 31, 2025

    Applies to: Public sector entities.

    Increased sharing and reuse of data — including publication of open data and strengthened use of national registers
  6. #6ImportantKey Focus AreasDec 31, 2025

    Applies to: Public sector entities.

    including publication of open data
  7. #7ImportantKey Focus AreasDec 31, 2025

    Applies to: Ministries and regulatory bodies.

    Digitalisation‑friendly regulation and legal reviews that remove unnecessary obstacles to digital service delivery.
  8. #8ImportantKey Focus AreasDec 31, 2025

    Applies to: Public sector entities.

    Measures to increase digital competence across the public sector workforce.
  9. #9ImportantKey Focus AreasDec 31, 2025

    Applies to: Public sector entities.

    Enhanced public‑private cooperation to stimulate innovation while safeguarding public interest.
  10. #10ImportantGovernance and Institutional FrameworkDec 31, 2025

    Applies to: Norwegian Digitalisation Agency (Digdir) and KS.

    requires joint handlingsplaner (action plans) produced by Digdir and KS.
  11. #11ImportantImplementation FrameworkDec 31, 2025

    Applies to: Norwegian Digitalisation Agency (Digdir).

    with Digdir producing guidance and technical standards.
  12. #12ImportantMonitoring and EvaluationDec 31, 2025

    Applies to: Digdir, KS, and responsible ministries.

    The strategy mandates monitoring through periodic reporting, indicators linked to 2025 goals
  13. #13ImportantMonitoring and EvaluationDec 31, 2025

    Applies to: Digdir, KS, and responsible ministries.

    Digdir, KS and responsible ministries are expected to publish follow‑up plans and progress reports and to use common indicators

© Regulations.AI — created on 13-Jun-2026