PrivacyForgeSign In
Back to Blog

Customer and Influencer Photos in Marketing: GDPR Rules

Norway ordered a retailer to delete an influencer's photos after her licence expired. Check the lawful basis before you reuse a customer image in marketing.

PFMariyan ValevAug 24, 2026 · 16 min read
GuideGuide

Key Takeaways

  • In a decision dated 12 August 2026, Norway's Datatilsynet ordered supplement retailer Lab Pharma AS to delete an influencer's name and photographs from every website it operates, and banned it from using her personal data in marketing until it obtains a lawful basis.
  • The 205,000 NOK fine was not for the marketing violation. It was imposed for breaching Article 31, the duty to cooperate with a supervisory authority.
  • The marketing agreement ran for one year from 18 March 2016. Once it expired in March 2017, Datatilsynet held, Article 6(1)(b) had nothing left to attach to: there was no contract to perform.
  • "It was already public on her own blog" was rejected — a lawful basis is still required, and the merchant is the controller for whatever it republishes on its own sites and newsletters.
  • Because several storefronts ran on Swedish, Danish and Finnish domains, the processing was cross-border, and those three authorities joined the case.

Introduction

Somewhere on your product pages there is probably a face that is not yours. A customer's before-and-after shot, a creator's unboxing still, a named testimonial beside a five-star rating. Someone signed something once, and the photo has been earning its keep ever since.

Norway's data protection authority has just published a decision about exactly that arrangement, and about what happens when the paperwork behind the photo quietly runs out. The Lab Pharma decision of 12 August 2026 is worth reading twice: once for what it says about lawful basis for marketing imagery, and once for the more expensive lesson about what happens after the regulator's first email arrives.

This is informational content, not legal advice.

Why "We Have a Contract" Is Not a Lawful Basis for Marketing Photos

A contract supports processing under Article 6(1)(b) only while it exists, and only for processing objectively necessary to perform it. Datatilsynet's finding was blunt: the agreement expired in March 2017, so by the time the complainant asked to be removed there was no contract left for the processing to be necessary for.

What the agreement said — and when it ran out

The complainant works as an influencer. In 2016 she signed a marketing agreement with Lab Pharma, a Norwegian company producing dietary supplements it markets and sells online. She signed on 31 March 2016; the company countersigned on 5 April 2016.

Point 3 was generous to the merchant. In Datatilsynet's quotation, Lab Pharma "har også rett til å vise utdrag av bilder, lyd, tekst og lignende fra samtlige omtaler [klager] har gjort av [Lab Pharmas] produkter i websider som [Lab Pharma] kontrollerer" — it also has the right to display extracts of images, audio and text from all reviews she made of its products, on websites it controls. (Translations here are ours; the decision is published in Norwegian.)

Point 8 was the sentence that mattered: the agreement entered into force on 18 March 2016 and applied for one year from that date.

Why Article 6(1)(b) does not survive the expiry date

Lab Pharma's position, set out in a solicitor's letter to the complainant dated 6 March 2018, was that its point 3 rights carried no time limit — because the matching obligation on her, not to delete her own posts, was likewise unlimited.

Datatilsynet did not accept it. "Ordlyden i punkt 8 i avtalen var derimot helt klar på at avtalen bare skulle gjelde i ett år etter at den trådte i kraft" — the wording of point 8 was entirely clear that the agreement applied only for one year. No clause carved out a survival period, and the conclusion follows mechanically: "For at behandlingen skal kunne baseres på artikkel 6 (1) bokstav b, så må det for det foreligge en avtale som klager er part i. Avtalen utløp i mars 2017."

This is not a Norwegian peculiarity. Datatilsynet grounded the reasoning in EDPB Guidelines 2/2019, which state at paragraph 31 that "a contract cannot artificially expand the categories of personal data or types of processing operation that the controller needs to carry out for the performance of the contract", and at paragraph 32 that necessity is judged from "a reasonable data subject's perspective when entering into the contract", not the controller's alone.

Our practical read: treat the licence term in a creator agreement as a retention schedule for personal data, not merely a commercial clause. If your template is silent on what happens to published assets at expiry, the silence is not working in your favour.

The fallback that also failed: legitimate interests

When Datatilsynet issued its notice of intended decision on 15 April 2026, Lab Pharma added Article 6(1)(f), legitimate interests. Two things sank it.

First, the company had never told the complainant it relied on legitimate interests. "[T]vert imot skrev selskapet i svaret på hennes krav om sletting at behandlingen hadde grunnlag i avtalen" — on the contrary, in its reply to her erasure request it wrote that the processing was based on the agreement. A lawful basis discovered three years into a complaint file is a difficult one to defend.

Second, Datatilsynet declined to run the balancing test at all, treating her request to stop and delete as an objection under Article 21(1). Once a data subject objects to processing based on legitimate interests, the controller must stop unless it demonstrates compelling legitimate grounds that override the individual's interests. Lab Pharma "har ikke lagt frem noen bevis" — presented no evidence that such grounds existed. That ends the analysis without anyone weighing anything.

"It was already public" is not a lawful basis either

Public availability does not create a lawful basis. Datatilsynet addressed it directly: a controller "[kan] ikke uten videre bruke personopplysninger bare fordi de er tilgjengelige på andre steder på internett. Det gjelder likevel et krav til behandlingsgrunnlag." It also addressed reasonable expectations, where most reuse arguments actually die: even though there had once been an agreement, it considered it unlikely she reasonably had to expect her data could be used indefinitely after expiry.

Who Is the Controller When the Content Lives on the Creator's Channels?

You are, for what you republish. Datatilsynet held that although the complainant's images and reviews sat on her own blog and social channels, Lab Pharma was the controller under Article 4(7) when it shared those personal data in marketing on its own websites and newsletters.

The creator's Instagram post is her processing. The same still, cropped into your product page and your abandoned-cart email, is yours — your purposes, your means, your obligation to name a basis. It is the same allocation that catches merchants out with vendor-sourced marketing data, where "our partner had consent" is not a defence for the controller.

Datatilsynet's site checks show how long this runs. In February 2026 it found her picture, name and reviews still visible on the Norwegian, Swedish, Danish and Finnish sites for the Care & Repair line. Even after the April 2026 notice, several instances had been deleted but some remained.

The cross-border trap in a country-domain rollout

Because those sites ran on Swedish, Danish and Finnish domains alongside the Norwegian ones, Datatilsynet classified the processing as cross-border under Article 4(23)(b). It became lead supervisory authority under Article 56(1), and the Swedish, Danish and Finnish authorities registered as concerned supervisory authorities. A draft decision went to them on 5 June 2026; no reasoned objections were filed, so it became binding under Article 60(6).

Worth pausing on if your growth plan involves spinning up .se and .dk storefronts. Adding a country domain is a marketing decision that quietly changes which regulators can take an interest in you.

The Obligation Most Merchants Have Never Read: Article 31

Article 31 is one sentence: "The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority in the performance of its tasks." No thresholds, no small-business exemption, and — as this decision shows — its own fine.

Where the line sits between disagreement and obstruction

Disagreeing with a regulator is not a breach; trying to make it stop is. Datatilsynet reads Article 31 as requiring the controller to comply with its orders and deadlines "på en ærlig og samarbeidsvillig måte" — in an honest and cooperative manner — and to facilitate its investigations by producing relevant documentation. It set a high bar for reacting to criticism, then drew the line: "man må skille mellom å benytte de ankemulighetene og rettsmidlene man har og det å true med rettsprosesser for å oppnå urettmessige fordeler." One must distinguish between using the remedies available to you and threatening legal proceedings to obtain improper advantages.

What happened here sits well past that line. After the information order of 1 July 2024, the managing director sent more than 15 emails between 12 July and 9 August 2024, escalating to the authority's director and legal director, who had not been involved in the case — the purpose, Datatilsynet found, being "å eskalere saken og legge press på saksbehandler om å avslutte den", to pressure the case handler into closing it. One email read: "Dersom du kontakter meg videre vil jeg anmelde deg for trakassering" — if you contact me again I will report you for harassment.

Lab Pharma argued Article 31 is breached only where a party makes investigation impossible. Datatilsynet rejected that threshold: one can obstruct without making the task objectively impossible, and attempts to delay or stop an investigation breach the duty "selv om forsøket ikke er vellykket"even if the attempt is unsuccessful.

The proper remedy, meanwhile, worked as designed. The company's objection went to Norway's Personvernnemnda (the Privacy Appeals Board), and on 27 October 2025 the board upheld the information order, confirming Datatilsynet was entitled to the agreement notwithstanding its confidentiality clause. Using the appeal route was never the problem.

Missing a deadline is the quieter half of the breach

The threats are memorable. The second limb is likelier to catch an ordinary merchant, because nobody has to lose their temper for it to happen.

After the board's ruling, Datatilsynet set a deadline of 8 December 2025. The company replied that evening without the agreement, saying it wanted a "secure channel" and that the authority should specify one. A further deadline of 7 January 2026 passed. Datatilsynet had itself given wrong information about the upload channel — corrected on 9 January with a direct link — but the company did not reply until 13 January, said it was going on holiday, uploaded a blank document on 22 January, and produced the agreement on 23 January 2026, two weeks late.

Datatilsynet called its own error "uheldig", then held it changed nothing: "Den etterfølgende forsinkelsen var Lab Pharmas skyld." Its standard reads as if written to every merchant — that it is "en alminnelig forventning at en profesjonell næringsdrivende klarer å forholde seg til frister for å svare på pålegg fra offentlige myndigheter", an ordinary expectation that a professional business can meet public-authority deadlines, and can ask how to submit its answers well before they expire.

How the Fine Was Calculated — and Why a Holding Company Did Not Help

Under Article 83(4)(a) the ceiling for an Article 31 breach is €10 million or 2% of global annual turnover, whichever is higher. Lab Pharma's turnover is far below €500 million, so the ceiling was €10 million, recorded in the decision as 111,916,000 NOK. Datatilsynet then applied EDPB Guidelines 04/2022.

StepBasisFigure
Statutory ceilingArt. 83(4)(a): €10m or 2% of turnover, whichever is higher111,916,000 NOK
Starting pointNature and gravity: an intentional attempt to evade supervision45% of the ceiling
Turnover adjustmentGuidelines 04/2022: turnover of €2–10m → 0.3–2% of the starting point; Datatilsynet chose 0.4%201,448 NOK
Final fineEffective, dissuasive and proportionate205,000 NOK

That is roughly €18,300 at the conversion rate the decision itself uses for the ceiling — modest in absolute terms, and entirely avoidable, since none of it was charged for the underlying marketing violation.

Two features travel beyond Norway. The first is who counts as the undertaking. Lab Pharma is wholly owned by Ter Rek AS, and the same individual is managing director and chair of one and chair and sole owner of the other. Datatilsynet applied the CJEU's Akzo Nobel and Others v Commission presumption (C-97/08 P, paras 59–61) that a parent owning 100% of a subsidiary forms a single undertaking, and — per ILVA (C-383/23, para 29) — took the whole group's economic capacity into account, combining their 2024 turnover: 26,747,720 NOK, stated in the decision as €2,409,969. That Ter Rek was, on the company's account, a passive property-holding vehicle with no permanent employees did not rebut it.

The second is that losses are not a defence: the calculation runs on turnover, not profit, and a reduction for inability to pay requires "ekstraordinære omstendigheter" plus objective evidence of irreparable damage to the undertaking's viability.

How to Licence Customer and Creator Content Without Repeating This

  1. Inventory every face on your estate. Each published customer photo, before-and-after, named testimonial and creator asset is a processing activity with a data subject attached. Record the person, source, basis and expiry.
  2. Pick the basis before the shoot, not after the complaint. For reuse of a customer's image or name in advertising, consent is usually the honest basis, and a defensible consent record must capture what was agreed, when, and for which channels.
  3. Give the licence a term and a takedown plan. Diary the expiry against the assets, not just the invoice. On the day the contract ends, which URLs, emails, paid ads and marketplace listings still carry this person's face — and who removes them?
  4. Separate on-site display from ad reuse. Permission to show a review on a product page is not obviously permission to cut it into a paid social campaign. Granularity is cheap at collection and expensive afterwards.
  5. Treat a stop request as an objection from the moment it arrives. Lab Pharma answered an Article 17 request the same day by asserting its contract and saying it would not respond to further enquiries. Route these through your data subject request workflow instead, with a clock and an owner.
  6. Write the regulator-contact runbook now. Name one owner for authority correspondence, a deputy for holidays, and a rule that no deadline is answered on its final evening.

Common Mistakes

  • Reading a licence clause as permanent because it doesn't say otherwise. The mistake at the centre of the case, and the most expensive one here. Silence about survival is not a survival clause.
  • Treating "already public" as a free pass. The most common argument in creator-content disputes, and Datatilsynet dismissed it in a sentence.
  • Switching lawful basis mid-complaint. Adding legitimate interests three years after telling the individual you relied on the contract creates a transparency problem on top of the original one.
  • Ignoring an objection while you decide whether you agree with it. Under Article 21(1) the burden is on you. Producing no evidence is not neutral — it is losing.
  • Answering a regulator emotionally. There is a high threshold for criticism and a hard floor under threats. The appeal route existed and worked; everything else was cost with no upside.
  • Assuming a holding company caps the exposure. Where one person owns and controls both entities, expect combined turnover to set the scale.

How PrivacyForge Helps

The gap this decision exposes is rarely a policy gap. It is that nobody can answer, on demand, which published assets contain a named individual's personal data, on what basis, and until when.

PrivacyForge's data mapping keeps marketing assets in the record of processing activities alongside the systems holding them, so a creator licence with a term shows up as a retention obligation rather than a filing-cabinet fact. Consent management captures per-channel permissions with a timestamped evidence trail. The DSAR workflow puts a clock and a named owner on erasure requests and objections, so a stop request cannot be closed with a same-day assertion that a contract covers it. Compliance scoring flags undocumented bases, expired terms and unowned request queues before a supervisory authority does.

None of that substitutes for legal advice on a specific licence — it is the operational layer that makes the answers retrievable when someone asks.

Frequently Asked Questions

You need a lawful basis, and for advertising reuse consent is usually the cleanest one. Datatilsynet's Lab Pharma decision of 12 August 2026 shows the alternatives are narrow: a contract only supports processing that is objectively necessary to perform it, and legitimate interests collapse once the individual objects and you cannot show compelling grounds.

Does an influencer contract cover using their content after it expires?

Only if the contract says so. In the Lab Pharma case the agreement ran one year from 18 March 2016, and Datatilsynet held that once it expired in March 2017 there was no contract left for Article 6(1)(b) to attach to. A clause granting reuse rights does not survive the agreement containing it merely because it does not mention an end date.

Can I use a photo a customer posted publicly on social media in my ads?

Not on the strength of its being public. Datatilsynet held that a controller cannot use personal data simply because they are available elsewhere on the internet — a lawful basis is still required. It also held the merchant is the controller under Article 4(7) for whatever it republishes on its own websites and newsletters.

What is GDPR Article 31 and does it apply to a small online store?

Article 31 requires controllers and processors to cooperate, on request, with the supervisory authority in the performance of its tasks. It applies to every controller, with no small-business exemption. Datatilsynet fined Lab Pharma 205,000 NOK under Article 31 alone — the unlawful marketing drew a deletion order and a processing ban, not a fine.

What should I do when a data protection authority emails my business?

Answer within the deadline, in writing, with the documentation requested. Datatilsynet's stated expectation is that a professional business can meet deadlines for responding to public-authority orders and can ask how to submit its answers well before the deadline expires. If you believe an order is invalid, use the formal appeal route rather than declining to respond.

Can I refuse to send a regulator a contract that has a confidentiality clause?

Not on that ground alone. Lab Pharma withheld its influencer agreement citing a confidentiality clause; Norway's Personvernnemnda upheld the information order on 27 October 2025 and confirmed the authority was entitled to the agreement despite the clause. Delaying disclosure formed part of the Article 31 breach the company was later fined for.

Conclusion

Two lessons come out of this decision, and they are worth different amounts of money.

The cheap one is about lawful basis: a licence to use someone's face is a permission with an expiry date, and the day it lapses your product pages become processing without a basis. Diary it like a retention rule, because Datatilsynet read the contract exactly as written and found nothing there after March 2017.

The expensive one is about temperament. The marketing violation cost Lab Pharma a deletion order and a ban. The 205,000 NOK went entirely on how the company answered the regulator that asked about it — and the appeal it was entitled to use was available the whole time.

Start with the inventory. If you cannot list, this afternoon, every published asset containing an identifiable customer or creator, on what basis and until when, that is the gap worth closing first. Map your marketing data with PrivacyForge and give every face on your storefront an owner, a basis and an end date.

Sources