All news
Enforcement August 21, 2026 4 min

The client goes bankrupt, the vendor is left alone with the data — and becomes the controller

The Norwegian authority fined a time-tracking provider that had refused access to eighty former employees. With nobody left to give instructions, the processor had become the controller

TL;DR for the DPO

When the controller disappears — bankruptcy, liquidation, closure — the processor left as the only party able to reach the data does not become exempt: it becomes the controller for that processing. And an unpaid invoice does not suspend the right of access.

What happened

On 24 March 2020 a Norwegian retail chain goes bankrupt. Former employees ask the bankruptcy estate to cover the wages for the days they worked, and to do so they need their timesheets: hours, shifts, attendance. That data sits in the system of an external vendor, which processed it on the company's behalf. The estate has no access to the system. On 18 June a former employee files an access request for his own data; eighty of them arrive in total. On 23 June the vendor replies in writing that it has no independent right of disposal and is not allowed to disclose data to anyone, "not even to the data subjects themselves".

Processing without a controller does not exist

Article 28(10) says that a processor determining the purposes and means becomes the controller for that processing. After the bankruptcy the vendor was the only party with access to the systems, decided whether and to whom the data would be disclosed, set how long to keep it and handled data subject requests on its own. Those are decisions about the essential means of processing, and they belong to the controller. The Regulation does not contemplate a processor without a controller: someone must answer for every processing operation.

An invoice does not suspend rights

The vendor had asked the estate to settle its outstanding claims before handing over the timesheets, and offered to supply "raw data" only under a new paid engagement. The authority kept the two things apart: whether the vendor is owed a fee is a contractual question the GDPR does not govern, while access must be answered within one month (Article 12(3)) and free of charge as a general rule (Article 12(5)). An open account with a bankrupt client is not a legal basis for saying no to someone asking for their own data.

  • What happens to the data if the controller goes bankrupt or ceases to exist. The standard "return or delete at the end of the contract" clause is not enough when workers need that data to pursue a claim: the contract must say who answers access requests in the meantime.
  • If your client is a vendor, check that it can recognise the moment when nobody is giving it instructions any more. From then on it either identifies the successor — usually the trustee — or accepts that it is itself the controller.
  • No access request may be made conditional on payment. That is the point on which the vendor lost, and it is also the easiest one to write into an internal procedure.

The detail that goes unnoticed

The vendor deleted the disputed data on 14 August 2020, while the requests were still open. Deleting does not cure a refused access request: it makes it permanently impossible to satisfy. In a retention matrix this is precisely the case where automatic deletion must be suspended, because proceedings are pending.

The fine, and why it is lower than it would have been

Two hundred and fifty thousand Norwegian kroner, roughly twenty-five thousand euro. In its April 2025 notice the authority had announced seven hundred and fifty thousand, then reduced the amount because of how long the case had taken: the complaint arrived on 30 June 2020 and the first request for explanations went out to the company on 15 October 2024. The case was handled as cross-border, with Sweden, Denmark and Spain among the concerned authorities.

Official source:Datatilsynet (Norway) — vedtak om ileggelse av overtredelsesgebyr, ref. 20/02911-20, 16 January 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min