Skip to main content
Beta! Dokumentasjonen er automatisk generert. Informasjonen kan være ufullstendig og inneholde feil, spesielt skjermbilder og videoer. Se Om hjelpesidene. Vi vil veldig gjerne ha innspill: Kontakt oss via «Fant du det du lette etter?» nederst, i chatten nede til høyre eller på support@placepoint.no – vi svarer så fort vi kan!

GDPR

GDPR (General Data Protection Regulation, personvernforordningen) is the EU regulation on the processing of personal data, made Norwegian law through the Personal Data Act (personopplysningsloven) in 2018. The regulation covers all information that can be linked to an individual, and property data contains more of it than many people think: registered owners and ownership shares on a matrikkelenhet, buyer and seller in registered property transactions, names linked to an address and role holders in companies are all personal data when the party is a natural person.

GDPR distinguishes between a data controller, who decides the purpose of the processing, and a data processor, who processes data on behalf of others. If a company receives ownership data in which private individuals are identified, it must have its own legal basis for processing, for example a documented legitimate interest assessment. If the company itself sends personal data into a service, for example a national identity number in a lookup, article 28 of the regulation requires a data processing agreement.

For Grunnboken and matrikkel data, a further layer applies: the regulation on disclosure from Grunnboken and the matrikkel, section 4 governs which types of business can receive which information, regardless of the GDPR basis. A land register extract can therefore show different content to different recipients, and valuations or due diligence built on ownership data must take both sets of rules into account.

In Placepoint, private individuals appear in transaction data as Private person under standard access, and national identity numbers and D numbers are never delivered through the API. The supervisory authority in Norway is Datatilsynet (the Norwegian Data Protection Authority).

From Placepoint's dictionary: GDPR

More information: Lovdata: Personopplysningsloven, Datatilsynet: Lover og regler, Store norske leksikon: Personvernforordningen

English: GDPR (General Data Protection Regulation).

Is property data personal data?

Often, yes. The name of a registered owner, the parties to a property transaction and contact details linked to an address are personal data when the party is a natural person. Data about the property itself, such as area, year of construction and encumbrances without named individuals, is not.

What is the difference between a data controller and a data processor?

The data controller decides why and how personal data is processed, and carries the main responsibility under GDPR. A data processor processes the data on behalf of the controller, governed by a data processing agreement under article 28. The same company can hold both roles for different data sets.

Who can see who owns a property?

The registered owner's name is public in Grunnboken, but disclosure at larger scale is governed by section 4 of the disclosure regulation and requires a legal basis for processing under GDPR at the recipient. Services that distribute ownership data therefore often show Private person instead of a name, with identity reserved for businesses that have a documented legitimate interest.

Beta! Dokumentasjonen er automatisk generert. Informasjonen kan være ufullstendig og inneholde feil, spesielt skjermbilder og videoer. Se Om hjelpesidene. Vi vil veldig gjerne ha innspill: Kontakt oss via «Fant du det du lette etter?» nederst, i chatten nede til høyre eller på support@placepoint.no – vi svarer så fort vi kan!