Back to all lessons
Awareness Lessons
2 months ago

Pharma Company Fined for Ignoring GDPR Erasure Rights and Obstructing DPA Investigation

Lab Pharma AS continued to process an influencer's personal data beyond the contractual period and refused to honour a valid Article 17 GDPR erasure request, representing a fundamental failure in data lifecycle management. Compounding the violation, the company refused to cooperate with Norway's Datatilsynet and reportedly threatened DPA employees, escalating a compliance failure into active obstruction of a regulatory investigation. This case illustrates that data subjects' rights are legally enforceable obligations, not optional courtesies, and that non-cooperation with supervisory authorities carries its own significant penalties. Organizations must have clear, documented processes for managing personal data tied to third-party contracts and for responding lawfully to data subject requests within statutory timeframes.

Tactical Insight

Immediate actions

  • Audit all active and recently expired contracts with influencers, freelancers, and third parties to identify personal data still being processed beyond the contractual basis.
  • Establish a formal Data Subject Rights (DSR) intake process to log, track, and respond to erasure requests within the GDPR-mandated 30-day window.
  • Brief legal and compliance teams on the duty to cooperate with supervisory authorities and the consequences of obstruction.

Long-term improvements

  • Implement a data retention and deletion schedule tied directly to contract expiry dates, with automated reminders to trigger data purging workflows.
  • Embed contractual data processing clauses that explicitly define permissible retention periods and deletion obligations upon termination.
  • Develop a regulatory engagement policy that mandates timely, respectful, and complete responses to all DPA information requests.

Training & governance measures

  • Train marketing and commercial teams on GDPR data subject rights, particularly the right to erasure and the conditions under which it applies.
  • Appoint or empower a Data Protection Officer (DPO) with sufficient authority to enforce compliance decisions, including data deletion, against internal resistance.
  • Conduct annual mock DSR and DPA-inquiry drills to ensure staff know the correct escalation and response procedures.