Telenor ASA – €348,000 Fine (Norway, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Norway's Datatilsynet fined Telenor ASA EUR 348,000 for not following rules about having a Data Protection Officer (DPO). The company didn't provide necessary documents to show they properly assessed their need for a DPO. This case highlights the importance of having clear data protection roles and responsibilities.
What happened
Telenor ASA failed to provide documentation proving they properly assessed their need for a Data Protection Officer.
Who was affected
Employees and customers of Telenor ASA who rely on the company's data protection practices were affected.
What the authority found
The authority found that Telenor ASA did not meet the requirements for appointing a DPO and failed to document their assessment.
Why this matters
This ruling emphasizes that companies must take data protection seriously and maintain proper documentation. Other businesses should ensure they have qualified personnel and clear records to avoid similar penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Following receipt of anonymous tips, the Datatilsynet (Norwegian DPA) launched an investigation into Telenor ASA’s (data controller) compliance with the DPO requirements in Articles 37-39 GDPR. As part of the investigation, a site visit was conducted, as well as interviews with executives and employees of the controller. During the investigation, the controller noted that they had terminated their DPO as they did not believe they met the criteria for requiring one under Article 37(1) GDPR. The DPA requested documentation detailing this assessment but the controller did not provide it. After the investigation was launched, a temporary DPO was appointed. The investigation also showed that contact details of the DPO were not available on the controller’s website, but only on the internal intranet, accessible only by employees. The investigation revealed an incomplete Record of Processing Activity (ROPA) and an absence of evidence of involvement of the DPO in issues relating to data protection. The investigation found that the evidence showed involvement by the DPO as only consisting of meetings between the DPO and certain heads of function across the organisation, and that these meetings only began more recently, after the commencement of the investigation. The investigation concluded that outside of this meeting, the DPO was involved on a case-by-case basis with data protection matters. The investigation revealed that the DPO’s role was split 50/50 between the DPO duties and work as an associate lawyer. The controller claimed that in practice, most of the DPO’s working hours were spent on DPO work. The controller, however, was unable to produce any documentation to demonstrate this. The investigation showed that there was a “major backlog” of data protection related tasks in 2021. It was also shown that the (then) DPO had raised concerns in 2021 about the resources available, requesting 100% full time equivalent (FTE) allocation to the handling of data protection mat
Related Enforcement Actions (1)
Other enforcement actions involving Telenor ASA in NO
Details
Fine Date
10 March 2025
Authority
Datatilsynet (Norway)
Fine Amount
€348,000
4,000,000 NOK
About this data
Cite as: Cookie Fines. Telenor ASA - Norway (2025). Retrieved from cookiefines.eu
Last updated: