Norway's data protection authority ordered SATS ASA on July 15, 2026 to rewrite the way it explains the photographs it takes of gym members at check-in, finding that the legal basis the chain published was the wrong one and that members hold a right to object which the company had told them did not exist.

The decision, reference 25/05417-8, was signed by Tobias Judin, section chief at the Norwegian Data Protection Authority, and Filip Bach, legal counsel. It follows 26 complaints lodged against SATS ASA, organisation number 892 625 522, between May and November 2025. SATS has until September 11, 2026 to comply with the orders and to send the authority documented confirmation that it has done so.

No fine was imposed. The company was reprimanded on three counts and ordered to make four changes. The substance sits in the reclassification: the authority concluded that photographing members at check-in cannot rest on Article 6(1)(b) of the General Data Protection Regulation, the contractual necessity basis, and must instead rest on Article 6(1)(f), legitimate interests. That single move switches on Article 21, and Article 21 is what SATS had spent the preceding year telling members did not apply to them.

A requirement that predates the app

The processing at issue is narrow. SATS photographs members at the front desk and stores the image in its membership system. According to the decision, the chain has imposed that requirement on members since 2004. What changed was enforcement: from August 11, 2025, members without a photo on file were to be denied entry.

The mechanics are set out in some detail. The photograph must be taken at the SATS front desk, and members are not permitted to upload one themselves. When a member arrives, the member's name and photo appear on the computer screen at reception so that the receptionist can verify who is checking in. Access itself does not turn on the image. Members scan a membership card, either physical or digital, the latter held in the SATS app as a QR code.

Asked by the Finnish supervisory authority when staff actually consult the photograph, SATS replied: "[...] access is typically automated through membership cards or app-based QR codes. However, member photos are used by staff for manual verification in specific situations - such as lost cards, forgotten login details, or suspected misuse of membership. While photos are not checked at every entry, they are readily available when needed."

That answer became load-bearing. So did a second one, given in response to a request for an explanation, in which the company set out the full range of uses: "Member photos are used for several purposes, all aimed at ensuring the secure and proper use of our services. Primarily, they are used to verify a member's identity during check-in, helping to confirm that access is being granted to the rightful account holder. Photos also play a key role in preventing misuse or unauthorized transfer of memberships by enabling staff to detect when a membership is being used fraudulently. In addition, they assist in resolving customer service issues, such as identifying members in cases of lost cards or forgotten credentials. Lastly, member photos may support internal security investigations in the event of incidents, policy violations, or other concerns requiring verification of member presence."

The photograph is also visible to group exercise instructors and personal trainers so they can identify the correct person. For that purpose SATS invoked Article 6(1)(f) from the outset, and none of the complainants challenged it.

Twenty-six complaints, two authorities

The paper trail runs through Helsinki before it reaches Oslo. The Finnish supervisory authority forwarded five complaints on July 22, 2025, a further 12 on August 22, 2025, and two more in September 2025, for a Finnish total of 19. The Norwegian authority received seven of its own during the autumn, including two appeals dated October 3 and November 3, 2025. Separately, across the second and third quarters of 2025, the Norwegian authority logged 17 reports concerning the check-in photo requirement.

The complaints divide into two groups. Most raised the lawfulness of the processing or the absence of information about it. A smaller set went further: five Finnish complainants and one Norwegian complainant objected to the processing and were told they would be denied access to the fitness centre if they did not provide a photograph. Three of the Finnish objections and the Norwegian one were rejected on the ground that the processing was necessary for the contract, or by reference to the SATS website saying the same. One was additionally rejected on legitimate interest grounds. Two received no justification at all.

Because SATS ASA has its main establishment in Norway and operates centres and offices in Denmark, Finland and Sweden, the processing is cross-border under Article 4(23). The decision to introduce the requirement was taken at group level by the company's central administration and legal team in consultation with local management. That makes the Norwegian authority the lead supervisory authority under Article 56(1), with the Swedish, Danish and Finnish regulators as concerned authorities. The same structure produced the NOK 20 million penalty when Datatilsynet ruled against Elkjop's Nordic loyalty club in June 2026, a case that also turned on an inadequate legitimate interest assessment.

The contract argument fails on its own facts

Article 6(1)(b) permits processing that is necessary for the performance of a contract. The authority worked through the established test: the data must be objectively indispensable for a purpose integral to the controller's contractual obligation, and the controller must demonstrate that the primary purpose of the contract cannot be achieved without the processing. The decision cites the Court of Justice in Mousse, case C-394/23, at paragraph 33, and Meta Platforms v Bundeskartellamt, case C-252/21, at paragraph 99, alongside EDPB Guidelines 2/2019.

Then it applied that test to what SATS sells. The cheapest membership, Basic, obliges the company to grant the member "Access to your favorite center", access to group classes at that centre, one trial session with a personal trainer, and a consultation with a physical therapist. The other two tiers carry at least the same rights. On that reading, the primary purpose of a gym membership agreement is to grant the member physical access to the fitness centre, a characterisation the authority noted applies generally to fitness chains.

Two facts supplied by SATS itself undercut the necessity claim. Photographs are not checked at every visit. And the company already permits exemptions in special cases, naming police officers, individuals in sensitive professions, and those with protected identities. A requirement that can be waived for some members and is not consulted at most entries is difficult to describe as objectively indispensable.

The authority also flagged the precedent problem. If additional identity verification were accepted as necessary to fulfil a gym membership, then any provider of personal, non-transferable rights, public transport season tickets among them, could argue that photo-based identification is contractually required. That would expand Article 6(1)(b) well beyond what the Court of Justice and the EDPB have established, and would imply that providers who do not run such checks are in breach of their own contracts.

SATS pushed back in its response to the notice of decision. "If, in practice, the membership can be used by parties other than the contracting party who entered into and pays for the membership, SATS is providing a service other than the one agreed upon," the company wrote. It added: "The question is therefore not whether access can technically be granted by scanning a membership card, but whether the contract can be considered properly fulfilled if SATS lacks real and practical means to ensure that access is granted to the right person."

The authority accepted the consideration as relevant and rejected the conclusion. Non-members using a centre fraudulently does not mean the core service went undelivered to the paying member; it means the service was also supplied to a non-paying third party, which is a separate problem. The same reasoning appeared in a German administrative court ruling this year, where a solar installer's attempt to justify pre-contractual credit checks under Article 6(1)(b) collapsed because the processing was useful rather than indispensable.

Legitimate interest survives, with conditions

The outcome is not a prohibition. The authority found Article 6(1)(f) to be the correct basis and, unusually for a decision of this kind, largely endorsed the company's own balancing.

SATS described its interest as "[...] a clear and legitimate interest in protecting members, employees, and the business from unauthorized access, misuse of membership, and incidents that could threaten safety or security at the centers. The purpose is to ensure sound operations, comply with the obligation to provide a safe work environment, and maintain members' trust in the service." The authority agreed those interests are legitimate.

On necessity, the company argued that alternatives had been weighed and found wanting: "The processing of images is necessary to safeguard these interests in an effective and proportionate manner. Alternatives such as manual verification of identification, the use of membership cards, or biometric identifiers - which have been evaluated or piloted - are considered less suitable, more intrusive to privacy, and less effective in preventing unauthorized access. Photo-based identity verification, on the other hand, provides a fast, non-biometric, and relatively non-intrusive solution that reduces the risk of unauthorized access." The authority accepted that the alternatives named appear neither more effective nor less intrusive. Fingerprint readers had been considered and set aside; membership cards alone were said to offer "limited assurance of identity."

The criticism of the balancing exercise was procedural rather than fatal. The authority observed that the assessment could usefully explain in more detail why the inconvenience is limited and what data subjects reasonably expect, and that it ought to acknowledge consequences such as discomfort arising from repeated identification. It nonetheless agreed with the conclusion, and accepted that image processing for access control may fall within members' reasonable expectations. That is a narrower failure than the pattern documented across European enforcement, where an EDPB case digest published in March 2026 identified the third condition, the balancing test, as the stage at which most controllers stumble.

Two caveats sit in the text. The decision expressly does not conclude that SATS actually meets the Article 6(1)(f) conditions; under Article 5(2), the company must document its assessment and demonstrate compliance. And the authority did not examine security of processing under Article 32 or Article 5(1)(f), while emphasising the importance of a sufficiently secure and well-maintained infrastructure for storing a large image database. Deployments of biometric and identity data at scale have drawn repeated regulatory attention, from Spain's 950,000 euro fine against Yoti to the complaint filed against Ryanair over mandatory facial recognition. SATS uses no biometric analysis or profiling, which is why the case never entered Article 9 territory.

What members were told

The transparency findings turn on published text. The SATS privacy policy lists the photo among personal data processed on the basis that "The processing is necessary to fulfill the contract with you (Article 6(1)(b) of the GDPR)." The customer service pages carried the same framing, together with an announcement: "We care about you and your experience at SATS. To ensure a safe and secure training environment, all members will need to provide a check-in photo at SATS starting August 11."

The decisive sentence appears under the FAQ question about whether a member can decline: "We process your photo to fulfill our agreement with you, in accordance with GDPR Article 6(1)(b). Since this processing is not based on consent or legitimate interest, it is not possible to opt out of the storage of the photo itself." Members in special cases were invited to submit "a formal request" with valid ID and a brief explanation, assessed case by case.

Because the legal basis was misstated, three separate obligations went unmet. Article 13(1)(c) requires the correct basis to be disclosed. Article 13(1)(d) requires the legitimate interests pursued to be described, which SATS never did, having claimed a different basis. Article 13(2)(b) and Article 21(4) require members to be told about the right to object, clearly and separately from other information. The published text pointed the other way.

The consequences show up in the complaint file. One Finnish complainant wrote that a permission could be applied for by official letter, adding that they had no idea what such a letter would need to contain, and objected to their data being widely accessible to employees given public sector work. A second asked whether there was any way to prevent being photographed without holding a sensitive job or a protected identity. A third wrote: "Do I have any way to refuse to be photographed? Not even my employer has a photo of me, because I've tried to keep photos of myself to a minimum. This is because someone is stalking me."

The objection procedure that was not one

SATS was candid about why it preferred the contractual basis. "If the processing of images is nevertheless not considered to be based on Article 6(1)(b), we believe it can still be based on Article 6(1)(f) (legitimate interest). We emphasize, however, that a basis in subparagraph (f) alone would create a certain degree of practical and legal uncertainty, as data subjects would then be able to exercise their right to object under Article 21. In practice, this could be exploited by individuals seeking to circumvent identity verification, thereby undermining the measure's function and purpose (identity verification) and the organization's ability to ensure a safe and secure training environment."

Responding to one Norwegian complaint, the company described what it had built instead: "At the same time, we are aware that there may be individuals who cannot or do not wish to submit a photo, for example, out of consideration for their workplace or because they live under a concealed identity. For these cases, we have established a narrow exception provision under which documentation of such a sensitive status may be submitted."

The authority read the wording covering police officers, sensitive professions and protected identities as narrower than the Article 21 standard, which turns on reasons relating to the individual's particular situation. It also noted that Article 21 carries no formal submission requirements, and that identity documents may be requested only where there is reasonable doubt as to the identity of the person objecting, under Article 12(4). Requiring a formal request with valid ID as a precondition therefore added a barrier the regulation does not contain.

On the rejections themselves, the finding is that SATS applied the wrong threshold. Under Article 21(1), a controller must stop processing unless it can demonstrate compelling legitimate grounds that override the individual's interests, with the burden resting on the controller, as the Court of Justice set out in SCHUFA Holding, joined cases C-26/22 and C-64/22. A legitimate interest assessment cannot serve as the standard for refusing objections, because the two tests are different: Article 6(1)(f) asks whether the individual's rights take precedence, while Article 21(1) asks whether the controller can show grounds that override them. Sweden's regulator applied the same distinction when it reprimanded Flightradar24 in 2025 for handling objections with blanket documentation requirements.

The authority also acknowledged the practical worry. Members do not hold an absolute right to object; they must supply reasons tied to their particular situation, and where those reasons are thin the controller may ask for further specification. What a controller cannot do, following EDPB Guidelines 1/2024, is treat the absence of elaboration as sufficient reason to refuse.

Changes made before the ruling landed

SATS revised its procedures during the proceedings. According to the decision, objections are now assessed case by case on the reasons given; where a member has not elaborated on their particular situation, the company will request further information before considering rejection; rejections are justified by reference to the compelling legitimate grounds invoked in the individual case; and the formal request requirement with supporting documentation is being reassessed so that objections may be submitted without formalities, with identification sought only where Article 12(4) applies.

The authority acknowledged the revisions and the willingness to implement corrective measures, then issued the reprimand anyway and required SATS to respond to every unanswered objection. The company maintains that Article 6(1)(b) is valid and that Article 21(1) does not apply, and asked for that interpretation to be weighed in the final assessment. It was not adopted.

The decision cannot be appealed to the Norwegian Data Protection Authority under Section 22 of the Personal Data Act, having been taken under Article 56 and Chapter VII. It may be brought before Norwegian courts under Article 78(1). Whether SATS takes that route will become visible around the September 11 deadline. European regulators' decisions do get overturned: Luxembourg's administrative court annulled the 746 million euro fine against Amazon in March 2026 and sent the case back to the regulator.

Why this reaches beyond the gym floor

The reasoning is portable, and that is the point for anyone running an identity or verification layer over a subscription product. Three things travel.

First, contractual necessity is being read narrowly and consistently. The test is not whether a control makes the service work better, or protects margin, or stops account sharing. It is whether the main subject matter of the contract can be delivered without the processing. Anti-fraud and anti-sharing measures may be commercially sensible and legally defensible, but the defence runs through legitimate interests rather than contract.

Second, the choice of basis determines which rights attach. Article 6(1)(b) carries no right to object. Article 6(1)(f) does. A controller that names the more convenient basis in its privacy policy is not merely mislabelling a document; it is describing a rights position that does not exist, and the misdescription is itself a transparency violation. The catalogue of data subject rights published by Belgium's regulator in 2026 makes the same dependency explicit.

Third, an objection process with its own paperwork requirements is an obstacle, not a courtesy. Demanding a formal letter, valid ID, and documentation of a sensitive status converts a statutory right into a discretionary exemption. Any consent or preference interface that asks users to justify themselves before a request is processed carries the same exposure.

Nordic enforcement has been steady rather than spectacular. Datatilsynet criticised Schibsted's 39-krone monthly charge for declining tracking in April 2026, then received a formal complaint against the same model from noyb and the Norwegian Consumer Council on June 3, 2026. The authority's 100 million kroner fine against Grindr in 2021 established its appetite for cross-border cases early. The SATS decision adds a case where the corrective measure is textual: change what the policy says, describe the interest, surface the right, and answer the people who wrote in.

For a chain with centres in four countries, that means rewriting the same FAQ in Norwegian, Swedish, Danish and Finnish, and reopening every objection it closed with the wrong reasoning. The deadline is documented, and the confirmation has to be filed.

Timeline

  • 2004: SATS begins requiring check-in photographs from members
  • May 5 to July 2, 2025: Five complaints are lodged with the Finnish supervisory authority
  • June 12, 2025: SATS responds to the Finnish authority's request for an explanation
  • July 22, 2025: The Finnish authority forwards the first five complaints to Norway
  • August 2 to August 25, 2025: Twelve further complaints reach the Finnish authority
  • August 4 to August 18, 2025: Four complaints are filed directly with the Norwegian authority
  • August 11, 2025: The photo requirement is enforced strictly; members without photos face denial of entry
  • August 22, 2025: The Finnish authority forwards the additional 12 complaints
  • September 2025: Two more Finnish complaints are transferred to Norway
  • September 30, 2025: The Norwegian authority sends SATS a request for an explanation
  • October 3, 2025: A first appeal is filed with the Norwegian authority
  • October 16, 2025: SATS responds to the Norwegian authority
  • November 3 and November 17, 2025: A second appeal and a seventh Norwegian complaint are filed
  • March 2026: The European Data Protection Board publishes its case digest on Article 6(1)(f) failures
  • June 1, 2026: Datatilsynet fines Elkjop NOK 20 million in a comparable cross-border Nordic case
  • July 15, 2026: The Norwegian Data Protection Authority issues its decision on order and reprimand
  • September 11, 2026: Deadline for SATS to comply and file documented confirmation

Summary

Who: The Norwegian Data Protection Authority, acting as lead supervisory authority, issued the decision against SATS ASA, organisation number 892 625 522, the Nordic fitness chain headquartered in Norway with centres in Denmark, Finland and Sweden. The decision was signed by Tobias Judin, section chief, and Filip Bach, legal counsel. The Finnish authority transferred 19 of the 26 complaints. The Swedish, Danish and Finnish regulators are concerned supervisory authorities.

What: An order and reprimand finding that Article 6(1)(b) of the GDPR is not a valid basis for photographing members at check-in, that Article 6(1)(f) is the correct basis, and that SATS violated Article 13(1)(c) and (d), Article 13(2)(b), Article 21(4) and Article 21(1). SATS must correct its stated legal basis, describe the legitimate interests pursued, present the right to object clearly and separately, and respond to all outstanding objections by either ceasing the processing or demonstrating compelling legitimate grounds. No fine was imposed.

When: The decision is dated July 15, 2026. The complaints span May to November 2025. The photo requirement dates from 2004 and was enforced strictly from August 11, 2025. The compliance deadline is September 11, 2026.

Where: Oslo, Norway, where the authority and SATS ASA's main establishment are located. The processing was implemented across all countries where SATS operates, and the corrective measures extend to the equivalent FAQ pages in Finland, Denmark and Sweden.

Why: The authority found that the main component of a gym membership contract is access to the fitness centre in exchange for payment, and that access can be granted by scanning a physical or digital membership card. Since photographs are not checked at every entry and exemptions already exist for some members, the processing is not objectively indispensable to the contract. Legitimate interest applies instead, which gives members a right to object that SATS had told them did not exist and had rejected without meeting the burden of proof set by Article 21(1).