Altinn is Norway's national platform for digital government — forms and reporting, register access, authorisation, events and a citizen inbox — used by more than 70 agencies and reaching 90% of the population and nearly all businesses. It is a candidate for the collection: outstanding as national cross-sector infrastructure, with its adaptability to other countries the open question.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
3 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
Core functions are digital reporting, form submission, register access and cross-agency data exchange, placing it in the Data Exchange domain. It is genuinely cross-cutting, used by over 70 agencies across every sector, and reaches 90% of the Norwegian population and close to 100% of businesses.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
REST APIs are well documented with OpenAPI specifications. The platform uses REST/JSON standards with Maskinporten/OAuth for authentication, and exchanges government data as JSON and XML.
Is it a modular building block that does one thing well, rather than a monolithic platform?
Altinn Studio, Altinn Apps and the Altinn Platform are separate components across some 121 repositories, with a clear split between the platform core and the services built on top of it. Configuration, though, is deeply tied to the Norwegian governance context, and adaptability to other countries is not documented.
Can other public and private actors build on top of it?
Altinn Studio lets agencies build their own apps and services against well-documented APIs, and more than 70 agencies and municipalities do so. It is open source under BSD-3 and maintained by the Norwegian Digitalisation Agency, with no vendor lock-in.
Can it run in distributed or federated deployments suited to national infrastructure?
Norwegian data sovereignty is built in, with all data held in Norway under GDPR, and the production infrastructure demonstrably runs at national scale with high availability. The platform is centralised national infrastructure rather than a federated or multi-country design.
Does it meet the security and privacy bar for population-scale infrastructure?
A published data protection impact assessment and thorough security documentation back GDPR compliance and privacy by design for Norwegian data protection law. No clearly published vulnerability disclosure policy was found in the public documentation.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA