# Norway

> Norway (Finanstilsynet · Norges Bank · Datatilsynet): MiCA via the EEA, with a privacy-innovation sandbox. Region: Europe. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: MiCA via the EEA, with a privacy-innovation sandbox
- Authority: Finanstilsynet · Norges Bank · Datatilsynet
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: MiCA via EEA, no threshold, privacy sandbox, no CBDC
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-norway

## What it actually says

Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down. That means the zero-threshold travel rule applies here as it does inside the union. The counterweight is unusual and worth knowing about: the Norwegian data protection authority has run a regulatory sandbox for privacy-enhancing innovation since 2020, and in 2024 ran a joint track with the financial supervisor. Few jurisdictions have both regulators in the same room on this question. Norges Bank concluded that a central bank digital currency is not currently warranted and closed its exploration phase in March 2026, so no retail privacy design question arises.

## The instruments that matter

- **Lov om kryptoeiendeler, in force 1 July 2025**: gives MiCA effect through the EEA Agreement following Joint Committee Decision No. 41/2025 of 20 February 2025
- **Travel rule extended to crypto**: simultaneous amendments to the anti-money-laundering act implemented the EU Transfer of Funds Regulation, with no de minimis
- **Transition closed 1 July 2026**: unauthorised providers must stop onboarding and wind down
- **Datatilsynet regulatory sandbox**: running since 2020 explicitly for privacy-enhancing innovation, including a joint track with the financial supervisor in 2024

## Sources

- [Finanstilsynet on MiCA](https://www.finanstilsynet.no/tema/kryptoeiendeler-mica/)
- [Datatilsynet sandbox](https://www.datatilsynet.no/en/regulations-and-tools/sandbox-for-artificial-intelligence/)

## Related entries

- [EU Transfer of Funds Regulation](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-travel-rule): Travel rule · Regulation (EU) 2023/1113
- [United Kingdom](https://www.sodalabs.xyz/privacy-hub/regulation/jur-united-kingdom): Risk-based, with an explicit central bank no-access pledge
- [CJEU on identifiability](https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability): Case law · is a wallet address personal data
- [EDPB blockchain guidelines](https://www.sodalabs.xyz/privacy-hub/regulation/reg-edpb-blockchain): Data protection guidance · Guidelines 02/2025
- [EU Data Act, Article 36](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-data-act): Smart contract requirements · Regulation (EU) 2023/2854
- [Georgia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-georgia): The one place where privacy oversight went backwards
