TL;DR for the DPO
When the controller disappears — bankruptcy, liquidation, closure — the processor left as the only party able to reach the data does not become exempt: it becomes the controller for that processing. And an unpaid invoice does not suspend the right of access.
What happened
On 24 March 2020 a Norwegian retail chain goes bankrupt. Former employees ask the bankruptcy estate to cover the wages for the days they worked, and to do so they need their timesheets: hours, shifts, attendance. That data sits in the system of an external vendor, which processed it on the company's behalf. The estate has no access to the system. On 18 June a former employee files an access request for his own data; eighty of them arrive in total. On 23 June the vendor replies in writing that it has no independent right of disposal and is not allowed to disclose data to anyone, "not even to the data subjects themselves".
Processing without a controller does not exist
Article 28(10) says that a processor determining the purposes and means becomes the controller for that processing. After the bankruptcy the vendor was the only party with access to the systems, decided whether and to whom the data would be disclosed, set how long to keep it and handled data subject requests on its own. Those are decisions about the essential means of processing, and they belong to the controller. The Regulation does not contemplate a processor without a controller: someone must answer for every processing operation.
An invoice does not suspend rights
The vendor had asked the estate to settle its outstanding claims before handing over the timesheets, and offered to supply "raw data" only under a new paid engagement. The authority kept the two things apart: whether the vendor is owed a fee is a contractual question the GDPR does not govern, while access must be answered within one month (Article 12(3)) and free of charge as a general rule (Article 12(5)). An open account with a bankrupt client is not a legal basis for saying no to someone asking for their own data.
- What happens to the data if the controller goes bankrupt or ceases to exist. The standard "return or delete at the end of the contract" clause is not enough when workers need that data to pursue a claim: the contract must say who answers access requests in the meantime.
- If your client is a vendor, check that it can recognise the moment when nobody is giving it instructions any more. From then on it either identifies the successor — usually the trustee — or accepts that it is itself the controller.
- No access request may be made conditional on payment. That is the point on which the vendor lost, and it is also the easiest one to write into an internal procedure.
The detail that goes unnoticed
The vendor deleted the disputed data on 14 August 2020, while the requests were still open. Deleting does not cure a refused access request: it makes it permanently impossible to satisfy. In a retention matrix this is precisely the case where automatic deletion must be suspended, because proceedings are pending.
The fine, and why it is lower than it would have been
Two hundred and fifty thousand Norwegian kroner, roughly twenty-five thousand euro. In its April 2025 notice the authority had announced seven hundred and fifty thousand, then reduced the amount because of how long the case had taken: the complaint arrived on 30 June 2020 and the first request for explanations went out to the company on 15 October 2024. The case was handled as cross-border, with Sweden, Denmark and Spain among the concerned authorities.
Official source:Datatilsynet (Norway) — vedtak om ileggelse av overtredelsesgebyr, ref. 20/02911-20, 16 January 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free