All news
Enforcement August 26, 2026 6 min

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

Datatilsynet orders SATS to correct the notice on the membership photo. Twenty-six complaints, three findings, and one of them follows from the wrong legal basis declared at the start

In short

Three findings: Art. 13(1) (legal basis stated incorrectly), Art. 13(2) (insufficient information on the right to object), Art. 21(1) (objections rejected without demonstrating compelling legitimate grounds). Twenty-six complaints between May and November 2025, from Norwegian and Finnish members. Deadline: 11 September 2026.

The processing

SATS asks members for a membership photograph. The image stays in the membership management system and staff use it at entry to check that whoever passes the turnstile is the person enrolled. This is not video surveillance: it is an identifying detail used by hand, at the desk.

The first mistake produces a second

The notice stated a legal basis that was not the right one. A mistake that looks formal — the photo gets collected either way — and instead changes the person's rights.

If the processing rests on performance of the contract, the right to object under Article 21 does not exist. If it rests on legitimate interests, it very much does, and a controller receiving an objection must stop unless it demonstrates compelling legitimate grounds overriding the person's interests.

Hence the other two findings. The notice did not properly explain the right to object — consistently with the wrong legal basis, because under contract there would have been nothing to explain. And when members objected, the objections were rejected without demonstrating those compelling grounds.

Why this is a lesson rather than a news item

Whoever declares «contract» does not build the machinery for handling objections, because in their account those objections cannot exist. Then they arrive anyway, and at that point there is neither the procedure nor the documented balancing. These are not two independent defects: the second follows from the first.

Twenty-six complaints between May and November 2025, from Norwegian and Finnish members. Datatilsynet imposed no fine: it issued an order and a reprimand, requiring members to be given correct information on the legal basis and the legitimate interests by 11 September 2026.

Two questions to put to a client

For every processing based on legitimate interests: where is the balancing written down, and who redoes it when an objection arrives? And for every processing declared «necessary for the performance of the contract»: is it really necessary to perform it, or merely convenient? The gym works without the photo — less well, but it works. That is exactly the difference Article 6(1)(b) asks you to measure.

Official source:Datatilsynet — Pålegg og irettesettelse til SATS (2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min
Enforcement
80access requests refused

The client goes bankrupt, the vendor is left alone with the data — and becomes the controller

A retail chain goes bankrupt. Former employees need their own timesheets to document unpaid wages, but the only party holding them is the time-tracking software vendor, which replies that it may disclose nothing to anyone — "not even to the data subjects themselves" — because the contract with the controller has ended. The Norwegian authority decided the opposite: when you are the only one left deciding about the data, you are the controller.

Aug 21, 2026New 4 min