# Telenor ASA.: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Norwegian Supervisory Authority (Datatilsynet)
- Date: 2025-03-10
- Original: https://www.enforcementtracker.com/ETid-2573
- Canonical: https://overview.legal/posts/48688
- Topics: Supervisory Authorities, IP Address, Telecommunications, Processing Agreement, Processing, Privacy by Design & Default, Supervision

## Summary

The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and documentation regarding the role of the Data Protection Officer (DPO). Additionally, no direct and documented reporting line from the DPO to the highest management level had been established. The company also lacked adequate internal controls. The DPA further criticized the absence of appropriate organizational measures and guid

## Full text

The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and documentation regarding the role of the Data Protection Officer (DPO). Additionally, no direct and documented reporting line from the DPO to the highest management level had been established. The company also lacked adequate internal controls. The DPA further criticized the absence of appropriate organizational measures and guidelines for the DPO's role.

GDPR Articles: Art. 24 (1), (2) GDPR, Art. 37 (7) GDPR, Art. 38 (2), (3) GDPR
Industry: Media, Telecoms and Broadcasting

---
Generated by overview.legal · https://overview.legal/posts/48688 · 2026-08-22
