Skip to main content
SECURITY AND PRIVACY · 2026

Security and privacy.

Digilist is built to handle personal data safely. All data is stored in Norway and the EU, the platform is ISO 27001 and 27701 certified and GDPR compliant, with sign-in through the Norwegian national identity services and an audit log on every change. A booking system public bodies and operators can rely on.

In brief

Data locationNorway · EU
CertificationISO 27001 · 27701
PrivacyGDPR · DPA
Sign-inBankID · ID-porten
I. SECURITY PRINCIPLES

Security built in, not bolted on.

Twelve principles that make Digilist safe for public and private data.

  • Data stored in Norway and the EU — never outside the EEA
  • ISO 27001 certified (information security)
  • ISO 27701 certified (privacy)
  • GDPR compliant, with a data processing agreement
  • Sign-in through the national identity services
  • Role-based access control
  • Encrypted in transit and at rest
  • An audit log on every change
  • Data minimisation — only what the booking requires
  • Access, rectification and erasure for data subjects
  • Breach notification under GDPR (72 hours)
  • Ready for Norwegian public procurement (SSA-L 2026)
II. AREAS

How we look after the data.

From where data lives and how we are certified, to sign-in and traceability.

Privacy and GDPR

A data processing agreement with every customer, data minimisation, and access, rectification and erasure for data subjects. We process only the personal data a booking actually requires.

Data stored in Norway and the EU

All data is stored within the EU/EEA, never outside it. That meets the data-location requirements in Norwegian public procurement and under the data protection rules.

ISO 27001 and 27701

Information security and privacy are managed under a certified, audited framework. Controls, risk assessment and improvement are built in rather than ad hoc.

Secure sign-in

BankID and ID-porten, the Norwegian national identity services, give strong authentication at the level public services require. Role-based access means each user sees only what they should.

Traceability and audit log

Every change is recorded with a timestamp and the user who made it. That gives public bodies full traceability, and gives both parties a verifiable record if a rental or booking is disputed.

Encryption and operations

Data is encrypted in transit and at rest. Operations, security updates and monitoring are handled by us, so public bodies and operators do not have to run their own security management.

PILOT FOR NORWEGIAN MUNICIPALITIES

An invitation to Norwegian municipalities.

Digilist is a modern, accessible platform for managing municipal venues, sports facilities, meeting rooms and events — and for making them visible to the people who want to use them.

We are inviting municipalities to join a pilot, where we help make municipal venues and activities more available, simpler to administer, and easier for residents, clubs, organisations and event organisers to find.

The aim is not to replace existing systems or ways of working, but to explore how Digilist can work as a modern complement for residents and for the administration.

We help with setup and publishing at no cost during the pilot. The municipality gets its own administrative access to carry on from there.

Request a pilot
Ibrahim RahmaniXala Technologies AS
WHAT WE PROVIDE

Digilist provides

  • A real-time availability calendar
  • Straightforward booking and requests
  • Seasonal allocation for clubs and associations
  • An overview of venues and sports facilities
  • A digital case-handling flow
  • Administrative approval of requests
  • Invoicing basis and payment overview
  • A mobile-friendly, accessible interface
  • Simple administration and content updates
  • Better visibility for municipal facilities and activities
INPUT FROM THE MUNICIPALITY

What we need from the municipality

  • The venues or facilities the municipality administers
  • Short descriptions
  • Images or links, where available
  • Contact details
  • Any information about booking or seasonal allocation

The pilot is free of charge. The municipality takes on no commitment to continue or to procure.

III. QUESTIONS AND ANSWERS

Common questions about security and privacy.

Is Digilist GDPR compliant?
Yes. Digilist meets the requirements of GDPR and the Norwegian Personal Data Act. We enter into a data processing agreement with every customer, process only the personal data the booking requires, and give data subjects access, rectification and erasure. All data is stored in Norway and the EU.
Where is data stored?
All data is stored in Norway and the EU, never outside the EEA. The database runs on infrastructure within the EU/EEA, so public and private customers alike meet the data-location requirements in Norwegian procurement and under the data protection rules.
Is Digilist ISO 27001 certified?
Yes. Digilist is certified against ISO 27001 (information security) and ISO 27701 (privacy information). That means security and privacy are managed under an established, audited framework rather than ad hoc.
How do users sign in securely?
Sign-in uses BankID and ID-porten, the Norwegian national identity services, for strong authentication at the level public services require. Access is role-based, so case officers, operators and residents each see only what they should.
How are traceability and access control handled?
Access is role-based, and every change is recorded in an audit log with a timestamp and the user. That gives full traceability of who did what and when — necessary both for public administration and for resolving a dispute about a rental.
What happens in the event of a security breach?
Digilist has procedures for incident handling and notification. In the event of a personal data breach we notify the customer without undue delay, so that it can be reported to the Norwegian Data Protection Authority within 72 hours as GDPR requires.

See also the booking system for municipalities or the booking system for venue rental.