Datatilsynet (Norway) - 23/00435-62
Norway's Datatilsynet fines Lab Pharma AS NOK 205,000 for unlawful data use and obstructing investigation.
Summary
Norway's Data Protection Authority (Datatilsynet) has fined Lab Pharma AS NOK 205,000 for continuing to use an influencer's personal data after their contract expired without a valid legal basis. The company also breached Article 31 GDPR by failing to cooperate with the DPA's investigation, obstructing it with threats and delays. The DPA ordered Lab Pharma AS to erase the data and cease unauthorized processing.
Full text
Help Datatilsynet (Norway) - 23/00435-62: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:34, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:34, 21 August 2026 Datatilsynet - 23/00435-62 Authority: Datatilsynet (Norway) Jurisdiction: Norway Relevant Law: Article 6(1)(b) GDPR Article 6(1)(f) GDPR Article 17 GDPR Article 21 GDPR Article 31 GDPR Type: Complaint Outcome: Upheld Started: 02.02.2023 Decided: 12.08.2026 Published: Fine: 205000.0 NOK Parties: Lab Pharma AS National Case Number/Name: 23/00435-62 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Norwegian Original Source: Datatilsynet (in NO) Initial Contributor: bms The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under Article 31 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her blog and social media profiles. The agreement also allowed the controller to use excerpts of her posts, including images, audio and text, in its own marketing. After the agreement had expired, the controller continued using the data subject’s name, photographs and comments about its products on its websites. In February 2023, the data subject requested the erasure of her personal data under Article 17 GDPR. The controller rejected the request, claiming that the agreement entitled it to continue using the data and stating that it would not respond to further inquiries. The data subject lodged a complaint with the DPA arguing that the controller lacked a legal basis for the processing and requesting the erasure of her personal data. In July 2024, the DPA initiated an investigation and ordered the controller to provide information concerning the processing. The controller challenged the DPA’s competence and refused to provide the agreement underlying the processing, arguing that it was confidential. The Privacy Appeals Board subsequently upheld the DPA’s information order. During the investigation, the controller repeatedly delayed providing requested information and documentation and its CEO sent numerous communications seeking to have the investigation discontinued, including threats of legal action and police reports against DPA employees. Holding The DPA held that the controller processed the data subject’s personal data without a valid legal basis under Article 6(1) GDPR and failed to comply with its obligations under Articles 17, 21 and 31 GDPR. Regarding Article 6(1)(b) GDPR, the DPA rejected the controller’s argument that the processing remained necessary for the performance of the agreement. The agreement expressly had a duration of one year and expired in March 2017. Nothing in its wording established that the controller could continue using the data subject’s personal data after its expiry. Consequently, Article 6(1)(b) GDPR could no longer provide a legal basis for the processing. The controller also relied on legitimate interests under Article 6(1)(f) GDPR. The DPA noted that the fact that personal data had previously been made publicly available did not remove the requirement for a legal basis. Moreover, the data subject’s request to stop the processing constituted an objection under Article 21(1) GDPR. Since the controller failed to demonstrate compelling legitimate grounds overriding the data subject’s interests, it was required to cease the processing. As the processing was unlawful, the controller was also required under Article 17 GDPR to erase the personal data without undue delay. The DPA therefore ordered the controller to delete the data subject’s personal data from all websites it operated and to cease using her personal data for marketing purposes unless it obtained a lawful basis for doing so. Regarding Article 31 GDPR, the DPA held that the duty to cooperate requires controllers to facilitate supervisory investigations and comply with lawful information requests and deadlines. Attempts to delay or halt an investigation may breach Article 31 GDPR even where the supervisory authority is ultimately able to complete its investigation. The controller had intentionally attempted to obstruct the investigation through threats and pressure on DPA employees and had also negligently failed to comply with several deadlines for providing requested documentation. The DPA considered these circumstances sufficiently serious to warrant an administrative fine and imposed a fine of NOK 205,000 for the infringement of Article 31 GDPR. The decision cannot be appealed to the Privacy Appeals Board but may be challenged before the Oslo District Court. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Norwegian original. Please refer to the Norwegian original for more details. Retrieved from "https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_23/00435-62&oldid=52749" Categories: Datatilsynet (Norway)NorwayArticle 6(1)(b) GDPRArticle 6(1)(f) GDPRArticle 17 GDPRArticle 21 GDPRArticle 31 GDPR2026Norwegian This page was last edited on 21 August 2026, at 12:34. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers