What happened
Datatilsynet imposed an administrative fine of 250,000 Norwegian kroner on Timegrip AS for breach of Article 15(1) and (3). Timegrip supplied the time recording system used by Enklere Liv Retail AS, which was declared bankrupt on 24 Mar 2020. The requester, one of its former shop staff, asked Timegrip on 18 Jun 2020 for a copy of the records of the week they had worked before the bankruptcy, so that they could document a wage claim to the estate. Timegrip refused in a letter of 23 Jun 2020, written to them and to the other former employees who had asked, on the view that the processing agreement had ended with the bankruptcy, that there was now no controller to instruct it, and that it had no independent right to release anything; it offered the estate the raw data instead, against payment of its outstanding invoices and under a new agreement. The authority held that the Regulation leaves no room for a situation in which there is a processor and no controller; that controller is a functional concept turning on who actually exercises control over the processing; and that Timegrip decided what the data were kept for, for how long and who received them, which are decisions about essential means reserved to a controller, so Article 28(10) made it the controller for that processing when it answered. It found no valid ground for the refusal: the request was clearly worded and clearly bounded, there was no reason to doubt the requester's identity and none to think disclosure would affect anyone else's rights, and whether the estate owed Timegrip money is a question of contract that the Regulation does not govern. Eighty former employees had asked. The breach was intentional though at the lower end of fault, and the fine was cut substantially from the 750,000 kroner the authority had notified, because the complaint had lain with it unhandled for years. No order was made: the data were deleted in August 2020 and the requester, paid in 2022 from the state fund that covers unpaid wages in an insolvency, no longer needed them.
What changes at the desk
If you are the only party holding the data and nobody above you is issuing instructions, the request is yours to answer. When a customer fails, establish who the controller now is and get the instruction in writing; where there is nobody to give one, decide the request yourself, because continuing to store the data while refusing to answer for it is the position the authority rejected. A commercial dispute with an administrator, an unpaid invoice, and an argument about the form the data should take are each separate from the right of access, and none of them is a ground to refuse. And a refusal written once to a group is counted across the group: one letter here reached eighty people, and how many they were is in the size of the fine.
Primary source
DecisionNorway16 Jan 2026
This entry is a draft. No practitioner has reviewed it, and it should be read against the document it names rather than relied on as advice.