Back to all lessons
Awareness Lessons
2 months ago

Lab Pharma Fined for Retaining Influencer Data After Contract Expiry and Obstructing DPA Investigation

Lab Pharma AS failed to establish or maintain a valid legal basis for processing an influencer's personal data once their contractual relationship ended, a foundational GDPR requirement. This breach demonstrates a lack of data lifecycle management controls — organisations must ensure personal data is erased or anonymised when the original purpose for processing no longer exists. Compounding the violation, the company obstructed Datatilsynet's investigation through threats and delays, breaching the GDPR's cooperation obligation under Article 31. This behaviour escalated regulatory risk significantly, as non-cooperation with supervisory authorities is treated as a serious aggravating factor in enforcement decisions. The case serves as a stark reminder that both data handling practices and organisational conduct during investigations are subject to GDPR scrutiny.

Tactical Insight

Immediate actions

  • Conduct an audit of all active and recently expired contracts to identify personal data being processed without a current legal basis.
  • Implement automated data retention triggers so personal data is flagged for deletion or review when a contract or consent period expires.

Long-term improvements

  • Establish a formal Data Retention and Disposal Policy that maps legal bases to data lifecycle stages for all categories of data subjects, including influencers and contractors.
  • Train legal, marketing, and operations teams on GDPR data subject rights and the obligation to erase data when processing purposes lapse.
  • Embed contractual data processing clauses that specify retention periods and deletion obligations before any influencer or third-party engagement begins.

Regulatory cooperation measures

  • Develop a documented DPA Inquiry Response Procedure that assigns clear ownership, timelines, and escalation paths for responding to supervisory authority requests.
  • Brief senior leadership on Article 31 GDPR obligations to ensure the organisation never obstructs or delays a regulatory investigation.