9 of 10 Norwegian public bodies run their email in the USA.
At least 97.7 % run Microsoft 365 and 99.2 % a US cloud provider (CLOUD Act jurisdiction). This is a floor — the real share is at least this high.
Among them: Datatilsynet (the Data Protection Authority), Forsvaret (the Armed Forces), NAV (the Labour and Welfare Administration), Skatteetaten (the Tax Administration), Politidirektoratet (the Police Directorate).
Skytilsynet maps how dependent Norwegian public bodies are on foreign cloud technology, starting with email. For each body we read the public DNS records that reveal who runs the mailbox, and derive the jurisdiction that data answers to. Every claim is sourced. The email axis is one axis — and the share below is a floor: bodies whose backend hides behind a mail gateway are not all unmasked, so the real US share is at least this high.
By the numbers
Every figure is computed from the same open dataset — municipalities (kommuner), state bodies (statlige organ), health trusts (helseforetak), universities and colleges, and county authorities (fylkeskommuner):
Why residency is not jurisdiction
The CLOUD Act reaches the provider, not the datacentre
A common defence is "the data is stored in the EU." That is data residency — and it is not the same as jurisdiction. Under the US CLOUD Act (2018), a US-headquartered provider — Microsoft, Google, Amazon — can be compelled by US authorities to hand over data it controls regardless of where in the world that data is physically stored. An "EU data boundary" changes where the bytes sit; it does not change whose law the operator must obey. So when a public body's email runs on Microsoft 365, the honest statement is not "the data is in Ireland" — it is "the data answers to US jurisdiction." That is the fact this site reports, body by body.
What good looks like
Sovereign public email is not hypothetical — European bodies are already doing it:
- Schleswig-Holstein (Germany) is moving ~30,000 government workstations off Microsoft to open-source (Linux, LibreOffice, Nextcloud, Open-Xchange), a shift the state budgets at roughly €15M/yr — framed as digital sovereignty, not cost-cutting.
- Denmark's government and the city of Copenhagen have announced moves away from Microsoft toward open, EU-controlled alternatives.
- Larvik (Norway) built the text editor into its Norwegian case-handling system (Acos WebSak) so standard letters — ~99% of outgoing mail — are produced without Microsoft Word or Google Docs; the sovereign path exists at home too. (Its email, though, still runs on Google — sovereignty is won system by system.)
The lesson from Munich's LiMux is that this is a durable procurement and strategy choice, not a flippable IT decision — so the ask is a change in the rules, never a personal attack on any official.
A second axis: the case-handling system
Email is only the front door. A second, distinct axis maps each body's case-handling and archive system (its NOARK-5 sakarkiv) — the system of record that holds correspondence, case files and decisions — and the jurisdiction that system's hosting answers to. Three vendors dominate the Norwegian market: Acos WebSak, Sikri Elements and Tietoevry Public 360.
National coverage. So far 126 public bodies are auto-mapped from their public innsyn-portal fingerprint (Sikri 65 · Acos 38 · Tietoevry 23); 0 have their hosting jurisdiction confirmed via a citable FOI answer. The method is a public
innsyn-portal fingerprint: a body publishes its case journal through
a portal hosted by its sakarkiv vendor (e.g. onacos.no,
elementscloud.no, 360online.com), so the portal
host anyone's browser loads identifies the vendor — no login, no private
data.
What the fingerprint proves — and what it doesn't
The tiering is deliberately conservative, matching the Norwegian site:
- A fingerprint identifies the vendor only — never the hosting jurisdiction.
- Hosting is then either inferred from an open vendor→hosting table (always flagged as inferred, never asserted as a per-body fact) or confirmed for a single body only via a citable FOI answer under the Norwegian Freedom of Information Act (offentleglova).
- State agencies (statlige organ) are masked: they
publish through the shared national portal
einnsyn.no, which carries no vendor fingerprint — so they stay not yet mapped and need an FOI request to identify their vendor at all.
Method & open data
The method is deliberately simple and reproducible: for each body's domain we
query public DNS (MX, SPF, autodiscover) with dig and classify
the email platform and its jurisdiction from those records alone. No login,
no scraping of private systems — just the records anyone can read. Where the
records are gateway-masked or ambiguous, the body is marked
undetermined rather than guessed, which is why the US figure is a
floor. The full methodology (in Norwegian) and the scanner source are open:
Full methodology (Norwegian) → · Open source & scanner on GitHub →
The dataset is open (CC BY 4.0). The CSV exports and the embeddable gauge/cartogram are language-neutral — reuse them directly:
- Combined — all bodies (CSV) skytilsynet-kombinert.csv
- Municipalities (CSV) skytilsynet-kommune.csv
- State bodies (CSV) skytilsynet-stat.csv
- Health trusts (CSV) skytilsynet-helse.csv
- Universities & colleges (CSV) skytilsynet-uni.csv
- County authorities (CSV) skytilsynet-fylke.csv
Embeddable, same-origin (no external dependency): the
gauge and the
Norway cartogram as iframes, or the
<script src="../embed/skytilsynet-embed.js"> web component.
Correction & contact
Spotted an error? We publish corrections openly and keep nothing personal — aggregate figures only. For corrections or press enquiries, open an issue in the project's public GitHub.