Norway Annex

ANX-NO · Draft of October 6, 2026 · revision 1 · version 1.0

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

This is the controlling text.

SHA-256 of this text: 52f15efe5e6e4382fb6cd05c1e4234d6995d2b203e2800579a53e32e73068227

Norway — ANX-NO: Norway Annex

Document ID: ANX-NO · Version: 1.0 · Effective date: [[TO CONFIRM: publication date]] Language: English, with a Norwegian courtesy copy [[TO CONFIRM: Norwegian translation]]. English controls. Applies to: Clinics established in Norway, together with the MDPA and the EEA Transfer Module (TM-EEA), as incorporated into the EEA Agreement. Terms defined in the MDPA have the same meaning here. Status: PREPARED, NOT YET OFFERED to new Clinics. Norway opens when DentalX logs every read access to patient data (clause 2A.2). An existing Norwegian Clinic accepts this Annex now, with the dated plan in clause 2A.2.


1. Duty of confidentiality (Health Personnel Act, § 21)

1.1 Flow-down. Health personnel are bound by a duty of confidentiality under § 21 of the Health Personnel Act. VstreamX and its personnel are bound by an equivalent duty of confidentiality for all information about the Clinic's patients (MDPA clause 5.3). VstreamX's Sub-processors are bound by the confidentiality obligations in their data processing terms, as MDPA Schedule 3 records, and the Clinic Data is protected in their hands by the encryption in MDPA Schedule 2. VstreamX does not represent that they are bound by § 21. [[TO CONFIRM: Norwegian counsel's view that this suffices]]

1.2 Duration. That duty is permanent.

2. The Norm for information security (Normen)

2.1 What VstreamX does. VstreamX aligns DentalX's security measures with the Norm for informasjonssikkerhet og personvern i helse- og omsorgssektoren ("Normen"), as far as Normen applies to a supplier.

2.2 Gap check. It gives the Clinic, on request:

  • a Normen gap check: a statement of how MDPA Schedule 2 meets Normen's requirements for data processors, and of any gaps; and
  • the information Normen requires the Clinic to obtain from its data processor.

[[TO CONFIRM: completed Normen gap check before Norway opens]]

2A. Access logs

2A.1 What DentalX provides. The Clinic must be able to document who has accessed a patient's record, and patients may ask who has had access [[VERIFY: the provisions of the Patient Records Act (pasientjournalloven) and its regulations on access logging and the patient's right to an access overview]]. DentalX provides a log of every access to patient data, including every read, with the User, the patient, the time and the action, which the Clinic can export (MDPA Schedule 2, C.12).

2A.2 Opening condition. That log is a condition for offering DentalX to Norwegian Clinics. Until it is live, DentalX's audit trail covers chart openings, exports, deletions and changes only. For a Norwegian Clinic that already uses DentalX, VstreamX delivers it on this dated plan: [[TO CONFIRM: dated plan for read-access logging]].

3. Patient records

3.1 The Clinic's duty. The Clinic keeps patient records under the Patient Records Act and the Patient Records Regulation. In practice it keeps them for at least 10 years after the last entry, and longer where needed.

3.2 DentalX's default. DentalX applies 10 years as the default for Norwegian Clinics, and does not auto-delete clinical records.

4. Transfers

The EU-U.S. Data Privacy Framework applies to Norway as incorporated into the EEA Agreement. [[TO CONFIRM: EEA incorporation of the Data Privacy Framework decision]] Otherwise, the SCCs in TM-EEA apply as that Module provides.

5. Prescriptions

DentalX's prescriptions are not e-prescriptions (e-resept) in the national system.

6. Security breaches

VstreamX's notice within 24 hours (MDPA clause 9) allows the Clinic to notify Datatilsynet within 72 hours.


Items to confirm before publication (Norway)

  1. Publication date.
  2. The Norwegian courtesy translation.
  3. The completed Normen gap check (§2.2).
  4. EEA incorporation of the Data Privacy Framework decision (§4).
  5. The Norwegian access-log provisions, and the dated plan for read-access logging; Norway opens to new Clinics only when it is live (§2A).
  6. Norwegian counsel's view on the Sub-processors' confidentiality (§1.1).