legal247

Duty to cooperate with the Data Protection Authority: what does it require?

In brief

The duty to cooperate under GDPR Art. 31 means a business must answer the Norwegian Data Protection Authority within the deadline and produce the documents it asks for, including contracts with a confidentiality clause. The business may disagree and appeal the order. Threats against case officers and repeated stalling are a breach, and cost Lab Pharma AS a NOK 205,000 fine in August 2026.

On a Wednesday in July, the managing director of an online shop opens a letter from the Norwegian Data Protection Authority (Datatilsynet) headed “Request for an explanation”. A former customer has complained. The letter asks eleven questions, requests a copy of a contract and sets a reply deadline five weeks out. The managing director thinks the complaint is baseless and that the authority is meddling in a private dispute. What he writes back over the next few days may cost more than the complaint itself.

The example is invented, but Lab Pharma AS ended up in a similar position. Datatilsynet fined the company NOK 205,000 for breaching the duty to cooperate, in a decision dated 12 August 2026. According to a senior legal adviser at Datatilsynet, quoted in Altinget, it is the first time the authority has imposed a fine for a breach of GDPR Art. 31.

What is the duty to cooperate with the Data Protection Authority?

The duty to cooperate is set out in Article 31 of the GDPR. The controller and the processor must, on request, cooperate with the supervisory authority in the performance of its tasks. The provision is short. Its content comes from the authority’s powers in GDPR Art. 58(1), which allow Datatilsynet to order the business to provide any information it needs, to obtain access to personal data and to carry out audits.

In the Lab Pharma decision, Datatilsynet describes the duty as requiring the business to comply with orders and deadlines “in an honest and cooperative manner” (our translation) and to facilitate the investigation. Under Personal Data Act § 23 in the Personal Data Act (personopplysningsloven), the investigative powers apply notwithstanding any duty of confidentiality. A confidentiality clause in a contract with a third party is therefore no ground for withholding that contract.

The duty also applies to processors. A SaaS supplier that receives questions from the authority about a customer’s processing cannot simply reply that the matter belongs to the customer.

What happened in the Lab Pharma case?

In February 2023 an influencer complained that Lab Pharma was still using her name and photos in its marketing, several years after their collaboration agreement had expired. Datatilsynet sent a request for an explanation on 1 July 2024, with a deadline of 12 August.

Between 12 July and 9 August 2024, the company’s managing director sent more than 15 emails to the case officer, the head of section, the director and the director of legal affairs. According to the decision, he threatened to report the case officers to the police for abuse of power, to sue for damages and to sue for defamation, and he set his own deadlines for when the authority had to close the case. Datatilsynet treated his dissatisfaction as an appeal against the order and passed it to the Privacy Appeals Board (Personvernnemnda). The Board upheld the order on 27 October 2025 and found that the authority could require the influencer contract.

Then came a second round. The company was given an extended deadline of 8 December 2025, answered in part and held back the contract because it had to be sent through a “secure channel”. Datatilsynet first gave the wrong instruction to use Altinn and corrected it the day after the company pointed this out. The company then uploaded a blank document, and the contract only arrived on 23 January 2026.

The decision has three parts. The company was ordered to erase the influencer’s personal data under GDPR Art. 58(2)(g), was banned from using them in marketing under GDPR Art. 58(2)(f) until it has a lawful basis, and was fined under GDPR Art. 83.

Where is the line between disagreement and a breach of the duty to cooperate?

The line is crossed when the business tries to stop or delay the investigation by improper means. Datatilsynet says in the decision that it must tolerate criticism, and that the threshold for reacting to complaints and abusive language is fairly high. What triggered the fine was that the threats were expressly tied to a demand that the case be closed.

Lab Pharma argued that GDPR Art. 31 is breached only where the authority is objectively prevented from doing its job, and that warning of a police report or a lawsuit is simply the use of lawful remedies. Datatilsynet disagreed. An unsuccessful attempt to stop or delay the investigation is also a breach. The authority added that threatening to report someone to the police in order to make them refrain from acting may fall under Penal Code § 251(2) in the Penal Code (straffeloven), without deciding whether that provision had been breached.

Lawful and normal Breach of the duty to cooperate
Disputing the authority’s legal basis and appealing the order Demanding that the case be closed, or else reporting the case officer to the police
Asking for an extension in good time, with reasons Missing the deadline and raising practical obstacles only afterwards
Asking for secure transmission and agreeing the channel before the deadline Withholding the key document or sending an empty attachment
Writing sharply to the case officer about facts and law Sending a stream of emails to senior management to put pressure on the case officer
Complaining to the Parliamentary Ombud (Sivilombudet) or going to court Using threats of legal action to apply pressure

Lab Pharma disagrees with the decision. According to Altinget, the company has asked for the decision to be reversed without success and is working on taking the case to the Parliamentary Ombud. We have found no information that the decision has been brought before the courts.

Disagreeing with Datatilsynet is lawful. What costs money is trying to get the investigation stopped.

What can a breach of the duty to cooperate cost?

A breach falling under GDPR Art. 83(4)(a) carries a ceiling of EUR 10 million or 2 per cent of global annual turnover, whichever is higher. If the business refuses access contrary to GDPR Art. 58(1), the higher ceiling in GDPR Art. 83(5)(e) applies, at EUR 20 million or 4 per cent. Datatilsynet may also impose a daily coercive fine under Personal Data Act § 29 until an order has been complied with.

The calculation in the Lab Pharma case shows how the figure was reached. The authority started at 45 per cent of the maximum amount, because the breach was intentional and concerned an attempt to evade supervision. The amount was then adjusted down by reference to turnover. Here the parent company’s turnover was added to Lab Pharma’s, on the basis of the group case law of the Court of Justice of the EU, giving a combined turnover of NOK 26.7 million in 2024. It also counted against the company that the missed deadlines were negligent and that the case had required more resources and management involvement than normal. The company’s argument that it was in a weak financial position failed because it was not documented.

For a larger company, the same conduct would have produced a far higher amount. For the board, it is also a question of internal control, as discussed in our article on the board’s responsibility for AI.

How should a business respond to a letter from Datatilsynet?

  1. Appoint one person to own the case on the day the letter arrives, preferably the data protection officer or the head of legal, and route all contact with the authority through that person.
  2. Read the legal basis. An order to provide information must state its legal basis under Public Administration Act § 14 in the Public Administration Act (forvaltningsloven), and the deadline for appealing the order itself is only three days.
  3. Ask for an extension in writing and in good time if you need more time. Lab Pharma was granted one when it asked.
  4. Agree how sensitive documents are to be sent before the deadline. Datatilsynet has a form, accessed with electronic ID, for documents exempt from public disclosure.
  5. Answer every question, attach the documents and say plainly if anything is missing and when it will follow.
  6. Keep the tone factual. Disagreement on facts and law belongs in the reply and in any appeal.
  7. Request access to the case documents under Public Administration Act § 18 if you have not seen the complaint or the basis for the questions.

If the case may end in a fine, or you are considering challenging the authority’s competence, bring in a lawyer before the first reply is sent. The first reply sets the frame for the rest of the case. Separate deadlines apply to a personal data breach. Where the case was triggered by a data subject asking for their data, it helps to go through the rules on subject access requests under the GDPR at the same time.

Can the decision be appealed?

As a rule, yes. Decisions by Datatilsynet can be appealed to the Privacy Appeals Board within three weeks under Public Administration Act § 29, and before a fine is imposed the business must have received advance notice and an opportunity to comment under Public Administration Act § 16.

The Lab Pharma decision is an exception. The case concerned cross-border processing, because the company’s websites also targeted Sweden, Denmark and Finland, and the decision was made under the cooperation procedure in GDPR Art. 60. Under Personal Data Act § 22(2), such decisions cannot be appealed to the Privacy Appeals Board. The route then goes to Oslo District Court, and under Personal Data Act § 27 the court can review every aspect of a case concerning an administrative fine. A business selling to customers in several Nordic countries should expect any decision against it to follow the same track.

The Public Administration Act of 1967 still applies. A new Public Administration Act has been passed but has not entered into force, and the section numbers above will change when it does.

If you have received a request for an explanation, put the reply deadline and the three-day appeal deadline in the calendar before reading the rest of the letter. More on the rules is collected on the data protection topic page.

Questions and answers

Can we refuse to give Datatilsynet a contract because it has a confidentiality clause?

No. Datatilsynet exercises its investigative powers notwithstanding any duty of confidentiality under Personal Data Act § 23, and in the Lab Pharma case the Privacy Appeals Board (Personvernnemnda) held that the authority could require the contract even though it contained a confidentiality provision. The contract can be sent through the authority's form for documents exempt from public disclosure.

Is answering late a breach of the duty to cooperate?

A single missed deadline after an agreed extension will rarely lead to a fine on its own. In the Lab Pharma case, however, repeated missed deadlines and stalling were treated as a negligent breach of GDPR Art. 31. Ask for an extension well before the deadline expires, and send what you have by the deadline.

How large can the fine be for breaching the duty to cooperate?

A breach of GDPR Art. 31 can lead to a fine of up to EUR 10 million or 2 per cent of global annual turnover under Art. 83(4)(a). If the business refuses access to information contrary to Art. 58(1), the higher ceiling in Art. 83(5)(e) applies, up to EUR 20 million or 4 per cent.

Next legal review: 15 January 2027