[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcwlH9h-XHIHbwUF9FymkwiH2ti7Tr9nNe4UGsBp2uKM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"a202dc8c-63c8-474c-8b42-727d7d556ce6","lab-pharma-fined-for-retaining-influencer-data-after-contract-expiry-and-obstructing-dpa-investigati","0c966d10-a1f5-4806-9b6d-684cc8d3db61","Lab Pharma Fined for Retaining Influencer Data After Contract Expiry and Obstructing DPA Investigation","Lab Pharma AS failed to establish or maintain a valid legal basis for processing an influencer's personal data once their contractual relationship ended, a foundational GDPR requirement. This breach demonstrates a lack of data lifecycle management controls — organisations must ensure personal data is erased or anonymised when the original purpose for processing no longer exists. Compounding the violation, the company obstructed Datatilsynet's investigation through threats and delays, breaching the GDPR's cooperation obligation under Article 31. This behaviour escalated regulatory risk significantly, as non-cooperation with supervisory authorities is treated as a serious aggravating factor in enforcement decisions. The case serves as a stark reminder that both data handling practices and organisational conduct during investigations are subject to GDPR scrutiny.","**Immediate actions:**\n- Conduct an audit of all active and recently expired contracts to identify personal data being processed without a current legal basis.\n- Implement automated data retention triggers so personal data is flagged for deletion or review when a contract or consent period expires.\n\n**Long-term improvements:**\n- Establish a formal Data Retention and Disposal Policy that maps legal bases to data lifecycle stages for all categories of data subjects, including influencers and contractors.\n- Train legal, marketing, and operations teams on GDPR data subject rights and the obligation to erase data when processing purposes lapse.\n- Embed contractual data processing clauses that specify retention periods and deletion obligations before any influencer or third-party engagement begins.\n\n**Regulatory cooperation measures:**\n- Develop a documented DPA Inquiry Response Procedure that assigns clear ownership, timelines, and escalation paths for responding to supervisory authority requests.\n- Brief senior leadership on Article 31 GDPR obligations to ensure the organisation never obstructs or delays a regulatory investigation.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(e) – Storage Limitation Principle","GDPR Article 6 – Lawfulness of Processing","GDPR Article 17 – Right to Erasure","GDPR Article 31 – Cooperation with Supervisory Authority","NIST SP 800-53 SI-12 – Information Management and Retention","NIST SP 800-53 PM-25 – Minimization of Personally Identifiable Information","CIS Control 3 – Data Protection (Data Retention and Disposal)","ISO\u002FIEC 27001:2022 Annex A 5.33 – Protection of Records","ITIL Service Value Chain – Engage (Stakeholder\u002FRegulatory Communication)","published","2026-08-21T14:21:11.886391+00:00","2026-08-21T14:21:11.616+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Datatilsynet_(Norway)_-_23\u002F00435-62&diff=52749&oldid=0","datatilsynet-norway-23-00435-62-80ab69","Datatilsynet (Norway) - 23\u002F00435-62",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]