Privacy Policy
Updated 2 October 2026
In short
Bislab AS is a Norwegian credit information company. We hold information about individuals because the law allows credit information companies to collect specified data and give organisations a sound basis for assessing credit risk. We therefore do not normally need your consent for this processing.
This does not mean that anyone may check your credit. The customer must have an objective need, for example because you apply for a loan, want to pay by invoice, enter a subscription involving credit risk, or enter another relationship where ability to pay is relevant.
Want to see what we hold about you? Sign in to My Page using electronic identification. You can see the information linked to you, to whom we disclosed credit information during the last six months, and the sources of that information. You can also register or remove a voluntary credit freeze.
1. Who is the controller?
Bislab AS
Organisation number: 929 879 252
Postal address: Postboks 173 Bogstadveien, 0323 Oslo, Norway
Bislab AS is the controller when we determine why and how personal data is used for Norwegian credit information, directory enquiries, our own service development, security and the other processing described below.
When we provide an anti-fraud or AI-agent service solely on a customer's documented instructions, the customer is the controller and Bislab AS is a processor. The customer's privacy notice is then the main source of information about the purpose, lawful basis and your rights. We assist the customer in meeting its obligations.
Data Protection Officer: personvern@bislab.no
Support and corrections: support@bislab.no
2. What is credit information, and why do we hold it?
Credit information is data, assessments or advice that helps explain ability to pay, credit risk or financial reliability. Bislab collects and keeps permitted data up to date, combines it and may disclose a report, score, risk class or explanation to a customer with an objective need.
Credit information helps an organisation assess risk before entering a contract. It can support responsible credit, reduce losses and reduce over-indebtedness. Bislab does not normally decide whether you receive a loan, invoice purchase, subscription, tenancy or another service. The customer that requested the information makes the decision and must explain its own decision.
We may process credit information without consent. The lawful basis is GDPR Article 6(1)(f): the legitimate interests of Bislab, the customer and society in responsible credit and financial risk assessment, within the Norwegian Credit Information Act and Regulations.
We also process personal data to secure our services and platform, prevent and detect misuse, quality-assure data, develop and test services and models, and manage customer relationships. The lawful basis is GDPR Article 6(1)(f): our legitimate interest in secure, accurate and well-functioning services. Where we must retain information to comply with legal requirements, for example under the Bookkeeping Act, the lawful basis is Article 6(1)(c).
3. What information may be included in Norwegian credit information?
The law limits what a credit information database may contain. Not every item exists for every person. My Page shows the specific information currently linked to you.
Basic data about individuals and sole traders:
- name, registered address and any secondary address;
- telephone number from a publicly available directory, and other contact details where the required consent exists;
- national identity number or D-number and relevant population-register status;
- organisation number and public basic data for a sole trader you own.
Credit data from public sources:
- enforcement, attachments, liens, encumbrances and no-assets findings;
- tax assessment;
- final judgments that are relevant and lawful to use;
- debt arrangements, debt negotiations, bankruptcy, composition and business disqualification;
- business interests and roles;
- guardianship information where the law permits it;
- ownership of real property and motor vehicles.
Credit data from other permitted sources and Bislab calculations:
- payment defaults from authorised reporting sources;
- credit score, risk class, explanatory factors and sole-trader credit rating;
- voluntary credit freeze;
- enquiries, disclosures and evidence of the customer's objective need.
For legal entities we may also process company name and contact data, organisation number, industry, employee count, status, accounts and key figures, capital, payment history, recommended credit limit, rating, group and ownership structure, and relevant financial events permitted by law.
We do not use special categories of personal data, such as health, religion, political opinions, ethnicity or sexual orientation, to produce credit information.
4. Where does the information come from?
Sources may include you, Bislab customers, the Norwegian Tax Administration and National Population Register, the Brønnøysund Register Centre, the Register of Mortgaged Movable Property, the Norwegian Mapping Authority, enforcement authorities, courts and bankruptcy registers, authorised debt-collection reporters and other sources permitted by credit information law. Directory-enquiry telephone data comes from electronic communications providers.
5. When may we disclose a credit report?
A customer may obtain credit information about an individual only when it has an objective need under the Credit Information Act. The customer must state and document its purpose, use the information only for that purpose, and comply with its contract and the law. We use identity checks, access controls, logging, contract terms and monitoring to prevent misuse.
When credit information about you is disclosed, we send a free copy letter where the law requires it. The letter shows who requested the information, the date, sources and the data disclosed. Statutory exceptions apply, including certain risk assessments by financial institutions and some repeated checks in debt-collection cases.
If your question is why the check was made or why you were declined, contact the customer named in the copy letter. If you believe Bislab's data, score or disclosure is wrong, contact us.
6. Credit scoring, profiling and artificial intelligence
A credit score is a statistical estimate of risk. A model combines a limited set of lawful and relevant factors, which may include payment events, income and tax, enforcement or debt information, business interests, ownership and how recent the data are. The factors depend on the approved model.
Bislab may use machine learning and other AI tools for data quality, combination, pattern recognition, model development, scoring, fraud signals and explanations. We use AI in accordance with data protection law, the EU AI Act and other applicable law. This means, among other things, that we use only lawful and relevant data, use no more data than necessary, test quality, document our models and ensure human oversight where required.
The customer determines its own decision rules, and a Bislab score or AI output is normally one of several inputs to the customer's assessment. If a customer draws strongly on the score when deciding whether to enter into an agreement with you, calculating the score may itself be an automated decision under GDPR Article 22. You therefore have the right to an understandable explanation of the principles and factors actually used to calculate your score, to express your view and contest the result, and to ask for a person at Bislab to review it. Our customer contracts set requirements for how the score may be used.
We do not use credit information or directory-enquiry data to train external providers' general-purpose AI models.
7. Directory enquiries
Bislab AS also provides directory enquiries. Electronic communications providers may supply a directory provider with name, address, telephone number, organisation number and whether a number is fixed or mobile under the electronic communications rules. Secret or reserved details are not published, and reservations or deletions are applied when we receive the next available update.
Data received for directory enquiries is kept purpose-separated from credit information, anti-fraud, marketing and other services. It is not reused for another purpose without a separate lawful basis and consent where the electronic communications rules require it. To change a reservation, you will normally contact your communications provider.
The lawful basis for directory enquiries is GDPR Article 6(1)(f), within the framework of the Norwegian Electronic Communications Act and Regulations. The data is updated continuously from the communications providers, and data no longer supplied by the provider is deleted at the next update.
8. Anti-fraud and AI agents in customer journeys
We may help customers with identity checks, anomaly and fraud signals, security and AI-supported customer dialogue. A fraud signal means something should be reviewed; it does not mean that a person has committed fraud.
For many of these services Bislab AS is a processor. We then use data only on the customer's documented instructions, for agreed purposes and agreed deletion periods. The customer is responsible for the information provided to you, the lawful basis and the final decision. Where Bislab determines the purpose of processing, for example for the security of our platform or lawful model improvement, Bislab acts as controller for that processing and relies on a separate lawful basis.
Credit information and directory-enquiry data are not used in these services unless the reuse is permitted under the sector rules and has a separate, documented lawful basis.
9. Who receives the information?
Recipients may include customers with lawful and contractual access, Bislab companies and suppliers providing operations, storage, identity services, communications, security or support, and public authorities where required or permitted by law. Processors may use the data only under instructions and contract.
We do not sell personal credit information to the public. Directory information is publicly available only within the directory service and subject to applicable reservations.
10. Where is information stored, and is it transferred outside the EEA?
If personal data is transferred outside the EEA, we use a lawful transfer mechanism, such as an adequacy decision or the EU Standard Contractual Clauses, and additional safeguards where necessary. You may ask for information about the safeguard relevant to your data.
Personal data is stored and processed in the EU/EEA, mainly in Sweden. We do not transfer personal data outside the EEA.
11. How long do we retain information?
Credit information is deleted when no longer necessary and no later than the limits in the Credit Information Act. The general maximum for data not subject to earlier deletion is four years from first lawful registration, with specific rules and exceptions for liens, debt arrangements, bankruptcy and information changed or removed at source. Inaccurate or obsolete information is corrected or deleted earlier.
Details of to whom we disclosed your credit information, the associated sources and date are available to you for the last six months. Other logs may be retained longer where necessary for security, misuse investigation or legal claims.
12. Your rights
You may request access, correction, deletion or restriction where the conditions apply. You may also request an understandable explanation of the principles and factors actually used to calculate your score. Where processing is based on consent, you may withdraw your consent at any time.
Right to object: You may at any time object, on grounds relating to your particular situation, to processing based on legitimate interests. We will then stop the processing unless we can demonstrate compelling legitimate grounds or the Credit Information Act entitles us to continue.
Under the Credit Information Act, you may obtain free information about credit data we disclosed about you during the last six months, who received it and its sources. You may register a voluntary credit freeze. A freeze normally prevents a credit assessment, but statutory exceptions may apply.
Use My Page for the quickest access and credit freeze. You may also contact us in writing. We may require secure identity verification. If you are not satisfied with our response, you may complain to the Norwegian Data Protection Authority.
Changes to this notice
We may update this notice when our services, data sources, legal requirements, company roles or processing locations change. The current version and date will be published here. Any material changes will be made in accordance with applicable Norwegian rules.