A pen signing a printed consent form on a wooden desk
Photo via Unsplash

TL;DR: Norway's data protection authority Datatilsynet fined the Nordic electronics retailer Elkjop NOK 20 million (€1,805,000) on 1 June 2026 after a five-year investigation into the company's customer club.[1][2] The decision names four infringements: invalid bundled consent, reuse of club data for advertising and conversion tracking without a legal-basis assessment, inadequate legitimate-interest balancing, and systematic delays answering data-subject access requests.[1][3] More than six million customer-club members across the Nordics were affected.[1]

The story behind the fine: a single privacy expert filed a complaint about not being able to opt out of marketing emails without cancelling his customer-club membership, and the regulator spent five years turning that complaint into a published decision that now sits in the public record. The complainant had to learn about the fine from a volunteer-run wiki, not from the regulator, which the GDPR itself requires the regulator to do under Article 77(2).[2]

The Complaint That Started It

Alexander Hanff is not a layperson. He is a privacy consultant who helped create the GDPR, has advised the European Data Protection Board, the European Parliament and the European Commission, and runs the consultancy That Privacy Guy (Hanff & Co. AB, Sweden).[2] On 30 July 2021 he emailed the Data Protection Officer of Elgiganten Kundklubb, the customer-club program run across the Nordics by Elkjop Nordic AS, and laid out a simple legal argument: forcing a customer to cancel their club membership in order to stop receiving marketing emails is not consent under GDPR.

The legal hook is Article 21(2) of the GDPR, which gives every person an absolute right to object to direct marketing, and Article 4(11), which says consent has to be freely given, which under Article 7 means it cannot be bundled into, or made a condition of, something else.[2] Elkjop's reply, in their own words: "in order to receive marketing / offers, it is a condition to be a member of the customer club." That single sentence is the violation, captured in writing by the company itself.[2]

Hanff escalated. He served a formal Article 18 restriction of processing, he filed a full Article 15 subject access request, and he filed a complaint with the Swedish supervisory authority Integritetsskyddsmyndigheten (IMY) under reference DI-2021-6660.[2] Elkjop's response: a vague privacy policy, then a 90-day extension on the access request citing "complexity and limited internal resources."[2]

How a Swedish Complaint Became a Norwegian Fine

The customer club is run by the Norwegian parent, Elkjop Nordic AS, and the decisions about the purposes and means of the processing are made in Norway. Under the one-stop-shop mechanism in Article 56(1) of the GDPR, the competent regulator is the one for the controller's main establishment, which in this case is Norway. In September 2022 IMY handed the case and the complaint file to Datatilsynet, the Norwegian DPA, which accepted the case.[2]

Datatilsynet's announcement confirms the timing: the regulator conducted on-site inspections of Elkjop Nordic AS and Elkjop Norge AS on 20 and 22 June 2022, the inspections were triggered not just by Hanff's complaint but by "several data breach notifications, complaints, and tips" about the customer club, and the decision was issued on 1 June 2026, published 5 June 2026.[1][2][3] The four-year gap between inspection and decision is not unusual for cross-border GDPR enforcement, but it is exactly the kind of gap that lets the original complainant fall out of the loop.

The Four Infringements Datatilsynet Found

Datatilsynet's official announcement lists four distinct violations, all clustered around the customer-club program.[1] The DPO tracker entry provides the legal-article specificity.[3]

  1. Invalid consent (Articles 6(1) and 4(11) GDPR). Elkjop did not collect valid consent for processing personal data in the customer club. The decision describes the consent as "bundled, vague, and inadequately informed." Members were not given a real choice: agree to all marketing, or cancel the club and lose whatever benefits came with membership.
  2. Reuse of personal data without a compatibility assessment (Article 6(4) GDPR). Elkjop took the personal data it had gathered through the customer club and put it to further use for advertising and conversion tracking, including so-called "customer matching" with third-party advertising platforms, without ever carrying out the compatibility assessment that Article 6(4) requires before you repurpose personal data like that.
  3. Insufficient legitimate-interest balancing (Article 6(1)(f) GDPR). For processing that was not based on consent, Elkjop relied on legitimate interest as the legal basis, but Datatilsynet found those balancing tests were not done with enough rigour. Hanff's blog post quotes the regulator's finding that the balancing was "not sufficiently specific," with general marketing and personalized profiling treated as a single purpose rather than separate ones.
  4. Systematic delays answering data-subject rights requests (Article 12(3) GDPR). Elkjop systematically missed the one-month statutory deadline for responding to data-subject access requests. The DPO tracker notes that the regulator rejected Elkjop's argument that requests could be categorised as "complex" by default: "Automatically qualifying all rectification requests (for example for email addresses) as complex is contrary to Article 12(3). Technical problems in one's own systems do not justify a departure from the obligation to facilitate."[3]

One aggravating factor Datatilsynet flagged: children's data was processed through the customer club, which pushed the fine upward.[3] Mitigating factors included "positive developments at Elkjøp" (the company had already started changing some practices during the long investigation) and the lengthy process duration itself.[3] The company did not contest the underlying facts; it disputed the legal conclusions and the size of the fine.[3]

Why €1.8M and Not More

The official fine is NOK 20 million, equivalent to €1,805,000 at the rate used in the regulator's decision.[1][3] That is a small fraction of Elkjop's Nordic turnover, and a small fraction of what a major retailer in this sector can be fined under the GDPR's 4-percent-of-global-turnover ceiling. Datatilsynet explained the calculation: the fine is proportionate to the turnover of the customer-club program specifically, scaled by the number of affected members, and discounted for the mitigating factors.[1]

The decision is limited to four topics. Other shortcomings Datatilsynet identified during the inspection, including joint-controllership questions and security-of-processing issues in the service and aftersales context, are not sanctioned in this decision, partly because of the lengthy process duration, but the regulator left the door open for future investigation.[3]

The Regulators' Own Failure: Nobody Told the Complainant

This is the part of the story that turns a routine fine into a structural scandal. Hanff did not find out about the decision from IMY. He did not find out from Datatilsynet. He found out from GDPRhub, a volunteer-run wiki, on a random Thursday morning, almost five years after he filed his complaint and well after the decision had already been made.[2]

Under Article 77(2) of the GDPR, a supervisory authority is under a binding legal obligation to keep a complainant informed of the progress and the outcome of their complaint. It is not a courtesy. It is written into the law.[2] The company that told Hanff to leave or put up with it has paid €1.8M for that choice. The regulators that were supposed to have his back the whole way through did not even send a notification when the case closed. Hanff has written to IMY, given the regulator five working days to explain, and signaled that if the answer is what he suspects, he will file under the European Union's infringement procedure, the same route he has used before, including the Phorm case over the UK's failure to implement the EU rules on the confidentiality of communications.[2]

That second front, the regulator's Article 77(2) failure, is the part of this story that does not fit into a routine "DPA fines retailer" frame. The GDPR gives individuals the right to file complaints precisely so that the regulator can use individual cases to develop the law. If the regulator does not even tell the individual the case closed, the complaint is effectively a free compliance audit for the company and a dead end for the person who filed it.

Why This Is the Dark-Pattern Enforcement Inflection

Elkjop is not alone. Forced consent, pay-or-consent, bundled consent, the agree-to-everything-or-you-cannot-use-the-service model: Hanff's blog post is blunt that this is "everywhere, and it is the default way an enormous part of the digital economy operates."[2] The Elkjop decision is one of the first published GDPR decisions that treats a customer-club membership program as a consent-mechanism dark pattern, where the price of admission is also the price of mandatory marketing.

The cross-jurisdictional comparison set is now clear. Spain's AEPD fined age-verification vendor Yoti €950,000 in March 2026 for unlawful biometric processing and invalid consent.[4] Luxembourg's CNPD issued the record €746 million GDPR fine against Amazon in 2023, which was overturned on a procedural technicality in March 2026, but the underlying violations were confirmed and Amazon had already changed the practices.[5] France's CNIL has been hitting cookie-banner dark patterns for years. The Elkjop decision adds the customer-club / loyalty-program class to that list, which is the class most retailers run.

Datatilsynet's own published guidance on customer-club programs has been updated in light of the Elkjop findings, with practical advice on bundling, specificity of consent, and third-party sharing of club data.[1] That guidance is the regulator's attempt to convert a five-year investigation into a forward-looking compliance document, and any retailer running a customer-club program in the EEA should read it before they ship their next membership T&Cs update.

What This Means If You Run a Customer Club or Loyalty Program

If you operate a customer club, a loyalty program, or any membership scheme that processes personal data and sends marketing, this decision sets a clear baseline. Three things have to be true for your program to survive a Datatilsynet-class inspection.

Marketing opt-out has to be free, in one click, and it has to be separate from club membership. If cancelling the club is the only way to stop the email, the consent is not freely given. The Elkjop case is the published-record version of that rule, and Article 21(2) has been on the books since May 2018. There is no longer a "we did not know" defence.

Every new use of the personal data needs its own legal-basis assessment. Datatilsynet found that Elkjop took club-member data and put it into third-party "customer matching" advertising workflows without ever doing the Article 6(4) compatibility test. If you are uploading member lists to Meta, Google, TikTok, or any ad-tech for matching, the compatibility test is the document that has to exist before the upload, not after.

Subject access requests have a one-month deadline, full stop. The Elkjop decision rejects the "complex by default" categorisation that the company used to push SAR deadlines out to ninety days. If your SAR workflow cannot answer a standard email-address change request inside a month, the workflow is the violation.

What to Watch

Four developments will tell whether this is the case that forces every Nordic retailer to overhaul their customer-club programs or the one that gets filed as a one-off.

Elkjop's appeal. The company did not contest the facts but disputed the legal conclusions and the fine.[3] An appeal is plausible. Watch the Norwegian courts for an Elkjop Nordic AS v. Datatilsynet filing, which would set the first Norwegian precedent on the customer-club-as-dark-pattern question.

Hanff's civil litigation. Hanff has signaled that civil litigation against Elkjop is coming now that the regulatory process has run its course.[2] That litigation will run in parallel with whatever appeal the company files, and the regulator's finding becomes near-conclusive evidence in the civil case.

The Article 77(2) infringement complaint. If Hanff follows through on the EU infringement complaint against the Norwegian regulator's Article 77(2) failure, the European Commission will have to assess whether Datatilsynet's process for keeping complainants informed meets the binding obligation in the GDPR. The Phorm precedent (Hanff's prior infringement work) is the template.

Other Nordic DPAs following up. Datatilsynet has updated its published customer-club guidance in light of the Elkjop decision.[1] Watch for Sweden's IMY, Denmark's Datatilsynet, and Finland's Ombudsman to publish parallel enforcement action, which would turn the Elkjop decision from a Norwegian precedent into a Nordic one.

Sources

  1. Datatilsynet: Administrative Fine Imposed on Elkjop (the Norwegian Data Protection Authority's official English-language announcement, published 5 June 2026, with the NOK 20 million fine figure, the four GDPR infringements, the 6+ million affected members, the link to the full Final Decision PDF, and the updated customer-club guidance for organisations)
  2. Alexander Hanff: I told them forced consent was unlawful. Five years later it cost Elkjop €1.8 million (the That Privacy Guy blog post dated 18 June 2026, written by the original complainant, a privacy expert who helped create the GDPR, with the 30 July 2021 complaint date, the IMY reference DI-2021-6660, the September 2022 one-stop-shop transfer to Datatilsynet, the specific GDPR articles cited in the decision, the Elkjop reply captured in writing, the 90-day SAR extension, and the disclosure that IMY/Datatilsynet never notified him of the outcome)
  3. The DPO: Norwegian Watchdog Fines Elkjop 20 Million NOK for Invalid Customer Club Consent (the European GDPR enforcement-tracker entry dated 4 June 2026, with the full list of violated articles [5(1)(a), 5(2), 6(1), 6(4), 12(3), 4(11)], the aggravating factor of children's data, the 1.805 million euro total, the cross-border lead-authority classification, the Elkjop non-contestation of facts, and the rejected "complex by default" SAR argument)
  4. State of Surveillance: Spain Fines Age Verification Company Yoti €950,000 for Biometric Data Violations (SoS coverage of the March 2026 AEPD fine on Yoti, with the biometric-processing and consent-basis specifics, for the cross-jurisdictional comparison)
  5. State of Surveillance: Amazon Escapes Record €746 Million Privacy Fine on a Technicality (SoS coverage of the March 2026 Luxembourg court ruling that annulled the CNPD's €746 million fine on procedural grounds, with the underlying GDPR violations confirmed and the Amazon behavioural-advertising compliance change)
  6. Hacker News: I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M (HN id 48589501, posted 18 June 2026, 439 points and 285 comments at the live Algolia snapshot 19 June 2026, the Day-5 evening-cycle compound that held above the 400p tier-1 threshold with the 0.07p/min post-promotion-ceiling deceleration signature, the full organic trajectory 41p at 22:17Z to 208p at 01:00Z to 328p at 06:57Z to 343p at 07:34Z to 357p at 08:02Z to 377p at 09:00Z to 382p at 09:22Z to 435p at 17:03Z to 439p at 18:01Z, no first-party push from Elkjop or Datatilsynet across the full five-day window, the 500p target outside the 22:17 UTC evening scan window at the current deceleration rate, Datatilsynet full ruling text release watch point at approximately 18:31 UTC 19 June 2026)
  7. Datatilsynet: Final Decision, Elkjop Nordic AS and Elkjop Norge AS (case 22/00049-28 and 22/00049-22) (the regulator's primary-record Final Decision PDF, linked from the substantive English writeup published at approximately 18:09 UTC on 19 June 2026, with the four enumerated GDPR infringements, the 6+ million affected customer club members across the Nordic countries, the cross-border cooperation and consistency mechanism through which Sweden, Iceland, Finland, and Denmark acted as concerned supervisory authorities, and the appeal-before-Oslo-District-Court provision that gates the 14-day appeal window closing 2 July 2026)