The Norwegian authority fines Lab Pharma AS 205,000 NOK for failure to cooperate and threats against its employees

The Norwegian Data Protection Authority sanctioned a company not for the initial breach that led to a complaint, but for violating its obligation to cooperate by threatening its officers and delaying the investigation process.

Facts and context

The Norwegian Data Protection Authority (Datatilsynet) today published a sanction decision against Lab Pharma AS (including the imposition of a fine of 205,000 NOK, approximately €17,800) for breaches related to its obligation to cooperate.

The case originated from a 2023 complaint concerning the use of a person's name and photos for marketing purposes, allegedly without a legal basis.

Reasons for the decision

  • Obligation to cooperate with the supervisory authority (Article 31 of the GDPR): The authority recalls that this obligation is essential to enable it to carry out its investigative and supervisory tasks, pursuant to Article 57(1) of the GDPR. In this case, following an injunction requesting information, the company responded by sending emails containing disparaging remarks and threats of criminal complaints and legal proceedings against the officers handling the case, aiming to stop the investigations. The authority considered that while the right to express disagreement and to challenge an injunction is legitimate, these deliberate threats constitute a clear violation of the obligation to cooperate. Furthermore, the company intentionally delayed the submission of the requested documents, failing to meet the deadline even after the injunction was validated by the Data Protection Tribunal (Personvernnemnda), which required multiple reminders.

Authority's decision

Consequently, the authority imposed a fine of 205,000 NOK (approximately €17,800) on Lab Pharma AS.

Moreover, the authority ordered the company to delete the complainant's personal data and prohibited any future use of these data without a valid legal basis.

Lessons learned

This decision reminds that:

  • The obligation to cooperate with the supervisory authority (Article 31 of the GDPR) is an autonomous obligation whose breach can be sanctioned independently of substantive violations.
  • The right to challenge a decision of the authority or to express disagreement does not justify resorting to threats or intimidation tactics aimed at obstructing an investigation.
  • Respecting deadlines set by the authority and proactive communication for the transmission of information are integral parts of the obligation to cooperate.
  • Deliberately delaying the provision of documents requested by an authority constitutes a violation of the obligation to cooperate, even if the documents are eventually submitted.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire