Pharma Company Fined for Ignoring GDPR Erasure Rights and Obstructing DPA Investigation
Lab Pharma AS continued to process an influencer's personal data beyond the contractual period and refused to honour a valid Article 17 GDPR erasure request, representing a fundamental failure in data lifecycle management. Compounding the violation, the company refused to cooperate with Norway's Datatilsynet and reportedly threatened DPA employees, escalating a compliance failure into active obstruction of a regulatory investigation. This case illustrates that data subjects' rights are legally enforceable obligations, not optional courtesies, and that non-cooperation with supervisory authorities carries its own significant penalties. Organizations must have clear, documented processes for managing personal data tied to third-party contracts and for responding lawfully to data subject requests within statutory timeframes.
Tactical Insight
Immediate actions
- Audit all active and recently expired contracts with influencers, freelancers, and third parties to identify personal data still being processed beyond the contractual basis.
- Establish a formal Data Subject Rights (DSR) intake process to log, track, and respond to erasure requests within the GDPR-mandated 30-day window.
- Brief legal and compliance teams on the duty to cooperate with supervisory authorities and the consequences of obstruction.
Long-term improvements
- Implement a data retention and deletion schedule tied directly to contract expiry dates, with automated reminders to trigger data purging workflows.
- Embed contractual data processing clauses that explicitly define permissible retention periods and deletion obligations upon termination.
- Develop a regulatory engagement policy that mandates timely, respectful, and complete responses to all DPA information requests.
Training & governance measures
- Train marketing and commercial teams on GDPR data subject rights, particularly the right to erasure and the conditions under which it applies.
- Appoint or empower a Data Protection Officer (DPO) with sufficient authority to enforce compliance decisions, including data deletion, against internal resistance.
- Conduct annual mock DSR and DPA-inquiry drills to ensure staff know the correct escalation and response procedures.