Telenor ASA – €348,000 Fine (Norway, 2025)

€348,000Datatilsynet (Norway)10 March 2025Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's Datatilsynet fined Telenor ASA EUR 348,000 for not following rules about having a Data Protection Officer (DPO). The company didn't provide necessary documents to show they properly assessed their need for a DPO. This case highlights the importance of having clear data protection roles and responsibilities.

What happened

Telenor ASA failed to provide documentation proving they properly assessed their need for a Data Protection Officer.

Who was affected

Employees and customers of Telenor ASA who rely on the company's data protection practices were affected.

What the authority found

The authority found that Telenor ASA did not meet the requirements for appointing a DPO and failed to document their assessment.

Why this matters

This ruling emphasizes that companies must take data protection seriously and maintain proper documentation. Other businesses should ensure they have qualified personnel and clear records to avoid similar penalties.

GDPR Articles Cited

AI-verified

View original scraped data
Art. 24(1) GDPR
Art. 24(2) GDPR
Art. 37 GDPR
Art. 38 GDPR
Art. 39 GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
amount discrepancy
Full Legal Summary
Detailed

Following receipt of anonymous tips, the Datatilsynet (Norwegian DPA) launched an investigation into Telenor ASA’s (data controller) compliance with the DPO requirements in Articles 37-39 GDPR. As part of the investigation, a site visit was conducted, as well as interviews with executives and employees of the controller. During the investigation, the controller noted that they had terminated their DPO as they did not believe they met the criteria for requiring one under Article 37(1) GDPR. The DPA requested documentation detailing this assessment but the controller did not provide it. After the investigation was launched, a temporary DPO was appointed. The investigation also showed that contact details of the DPO were not available on the controller’s website, but only on the internal intranet, accessible only by employees. The investigation revealed an incomplete Record of Processing Activity (ROPA) and an absence of evidence of involvement of the DPO in issues relating to data protection. The investigation found that the evidence showed involvement by the DPO as only consisting of meetings between the DPO and certain heads of function across the organisation, and that these meetings only began more recently, after the commencement of the investigation. The investigation concluded that outside of this meeting, the DPO was involved on a case-by-case basis with data protection matters. The investigation revealed that the DPO’s role was split 50/50 between the DPO duties and work as an associate lawyer. The controller claimed that in practice, most of the DPO’s working hours were spent on DPO work. The controller, however, was unable to produce any documentation to demonstrate this. The investigation showed that there was a “major backlog” of data protection related tasks in 2021. It was also shown that the (then) DPO had raised concerns in 2021 about the resources available, requesting 100% full time equivalent (FTE) allocation to the handling of data protection mat

Details

Fine Date

10 March 2025

Authority

Datatilsynet (Norway)

Fine Amount

€348,000

4,000,000 NOK

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Telenor ASA - Norway (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: