Back to Feed
GDPRAug 21, 2026

Datatilsynet (Norway) - 23/00435-62

Norway's Datatilsynet fines Lab Pharma AS NOK 205,000 for unlawful data use and non-cooperation.

Summary

Norway's Data Protection Authority (Datatilsynet) has fined pharmaceutical company Lab Pharma AS NOK 205,000 for continuing to use an influencer's personal data after their contract expired. The company also breached its duty to cooperate with the DPA during the investigation, refusing to provide requested information and even making threats against DPA employees. The influencer had requested erasure of her data under Article 17 GDPR, which Lab Pharma AS rejected.

Full text

Help Datatilsynet (Norway) - 23/00435-62: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:34, 21 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0] Latest revision as of 13:54, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 100: Line 100: }}}} The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under [[Article 31 GDPR|Article 31 GDPR]].The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under [[Article 31 GDPR]]. == English Summary ==== English Summary == Line 107: Line 107: Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her blog and social media profiles. The agreement also allowed the controller to use excerpts of her posts, including images, audio and text, in its own marketing.Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her blog and social media profiles. The agreement also allowed the controller to use excerpts of her posts, including images, audio and text, in its own marketing. After the agreement had expired, the controller continued using the data subject’s name, photographs and comments about its products on its websites. In February 2023, the data subject requested the erasure of her personal data under [[Article 17 GDPR|Article 17 GDPR]]. The controller rejected the request, claiming that the agreement entitled it to continue using the data and stating that it would not respond to further inquiries.After the agreement had expired, the controller continued using the data subject’s name, photographs and comments about its products on its websites. In February 2023, the data subject requested the erasure of her personal data under [[Article 17 GDPR]]. The controller rejected the request, claiming that the agreement entitled it to continue using the data and stating that it would not respond to further inquiries. The data subject lodged a complaint with the DPA arguing that the controller lacked a legal basis for the processing and requesting the erasure of her personal data.The data subject lodged a complaint with the DPA arguing that the controller lacked a legal basis for the processing and requesting the erasure of her personal data. In July 2024, the DPA initiated an investigation and ordered the controller to provide information concerning the processing. The controller challenged the DPA’s competence and refused to provide the agreement underlying the processing, arguing that it was confidential. The Privacy Appeals Board subsequently upheld the DPA’s information order. During the investigation, the controller repeatedly delayed providing requested information and documentation and its CEO sent numerous communications seeking to have the investigation discontinued, including threats of legal action and police reports against DPA employees.In July 2024, the DPA initiated an investigation and ordered the controller to provide information concerning the processing. The controller challenged the DPA’s competence and refused to provide the agreement underlying the processing, arguing that it was confidential. The Privacy Appeals Board subsequently upheld the DPA’s information order. During the investigation, the controller repeatedly delayed providing requested information and documentation and its CEO sent numerous communications seeking to have the investigation discontinued, including threats of legal action and police reports against DPA employees. === Holding ====== Holding === The DPA held that the controller processed the data subject’s personal data without a valid legal basis under [[Article 6 GDPR|Article 6(1) GDPR]] and failed to comply with its obligations under Articles 17, 21 and 31 GDPR.The DPA held that the controller processed the data subject’s personal data without a valid legal basis under [[Article 6 GDPR|Article 6(1) GDPR]] and failed to comply with its obligations under [[Article 17 GDPR|Articles 17]], [[Article 21 GDPR|21]] and [[Article 31 GDPR|31 GDPR]]. Regarding [[Article 6 GDPR|Article 6(1)(b) GDPR]], the DPA rejected the controller’s argument that the processing remained necessary for the performance of the agreement. The agreement expressly had a duration of one year and expired in March 2017. Nothing in its wording established that the controller could continue using the data subject’s personal data after its expiry. Consequently, [[Article 6 GDPR|Article 6(1)(b) GDPR]] could no longer provide a legal basis for the processing.Regarding [[Article 6 GDPR|Article 6(1)(b) GDPR]], the DPA rejected the controller’s argument that the processing remained necessary for the performance of the agreement. The agreement expressly had a duration of one year and expired in March 2017. Nothing in its wording established that the controller could continue using the data subject’s personal data after its expiry. Consequently, [[Article 6 GDPR|Article 6(1)(b) GDPR]] could no longer provide a legal basis for the processing. The controller also relied on legitimate interests under [[Article 6 GDPR|Article 6(1)(f) GDPR]]. The DPA noted that the fact that personal data had previously been made publicly available did not remove the requirement for a legal basis. Moreover, the data subject’s request to stop the processing constituted an objection under [[Article 21 GDPR|Article 21(1) GDPR]]. Since the controller failed to demonstrate compelling legitimate grounds overriding the data subject’s interests, it was required to cease the processing. As the processing was unlawful, the controller was also required under [[Article 17 GDPR|Article 17 GDPR]] to erase the personal data without undue delay.The controller also relied on legitimate interests under [[Article 6 GDPR|Article 6(1)(f) GDPR]]. The DPA noted that the fact that personal data had previously been made publicly available did not remove the requirement for a legal basis. Moreover, the data subject’s request to stop the processing constituted an objection under [[Article 21 GDPR|Article 21(1) GDPR]]. Since the controller failed to demonstrate compelling legitimate grounds overriding the data subject’s interests, it was required to cease the processing. As the processing was unlawful, the controller was also required under [[Article 17 GDPR]] to erase the personal data without undue delay. The DPA therefore ordered the controller to delete the data subject’s personal data from all websites it operated and to cease using her personal data for marketing purposes unless it obtained a lawful basis for doing so.The DPA therefore ordered the controller to delete the data subject’s personal data from all websites it operated and to cease using her personal data for marketing purposes unless it obtained a lawful basis for doing so. Regarding [[Article 31 GDPR|Article 31 GDPR]], the DPA held that the duty to cooperate requires controllers to facilitate supervisory investigations and comply with lawful information requests and deadlines. Attempts to delay or halt an investigation may breach [[Article 31 GDPR|Article 31 GDPR]] even where the supervisory authority is ultimately able to co

Entities

Datatilsynet (vendor)Lab Pharma AS (product)