
Forced consent cost Elkjop €1.8M, five years after a complaint
Norway's data protection authority fined the Elkjop group NOK 20 million after finding that consent for its Nordic customer club was forced, not specific and not properly explained to members.
In the summer of 2021, privacy specialist Alexander Hanff was a member of Elgiganten Kundklubb, the customer club that the Nordic retailer Elkjop runs for shoppers. Buried under marketing email, he looked for a way to switch it off and found that the only option was to give up his club membership altogether.
A violation the company put in writing
On 30 July 2021 Hanff wrote to the retailer's data protection officer, setting out why he believed the arrangement was unlawful. Under Article 21(2) of the GDPR, he argued, every person has an absolute right to object to direct marketing, while the ePrivacy Directive allows marketing email only with consent or an existing customer relationship offering a simple opt-out. Consent, under Articles 4(11) and 7, must be freely given: it cannot be tied to another condition.
The company's reply, he says, confirmed the problem itself: its stated position was that "in order to receive marketing / offers, it is a condition to be a member of the customer club." Hanff followed with a restriction of processing request under Article 18 and a full subject access request under Article 15, then filed a complaint with Sweden's Integritetsskyddsmyndigheten (IMY) under reference DI-2021-6660. The company, he says, pointed him to a vague privacy policy and stretched the deadline on his access request to ninety days, citing "complexity" and "limited internal resources".
How a Swedish complaint became a Norwegian fine
The club is operated by the Norwegian parent, Elkjop Nordic AS. In September 2022 IMY decided it was not the competent authority and handed the case to Norway's Datatilsynet, the regulator of the controller's main establishment under the GDPR's one-stop-shop rule in Article 56(1).
On 1 June 2026 Datatilsynet fined the Elkjop group NOK 20 million — a little over €1.8 million. The findings matched Hanff's 2021 argument: the consent underpinning the customer club was not valid, because it was forced, it was not specific, and members were not properly informed. The authority also found that data gathered through the club had been reused for advertising and conversion tracking without the compatibility assessment required by Article 6(4). The decision cites Articles 4(11), 5(1)(a), 5(2), 6(1)(a), 6(1)(f) and 6(4).
Why it matters beyond one retailer
Hanff frames the case as a test of the wider "agree to everything or you cannot use the service" model, which he describes as the default across much of the digital economy. If refusing costs you something you are entitled to keep, he writes, you have not freely consented to anything.
He also criticises how his own complaint was handled. He learned of the decision from GDPRhub, a volunteer-run wiki, rather than from either authority, even though Article 77(2) obliges supervisors to keep complainants informed about the progress and outcome of their cases. Hanff has written to IMY requesting an explanation and says an EU infringement procedure is a possible next step; civil litigation against the Elkjop group is also outstanding.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.