Elkjop Group Fined €1.8 Million for Forced Consent and GDPR Violations
The Norwegian Data Protection Authority (Datatilsynet) has fined the Elkjop group NOK 20 million (approximately €1.8 million) for implementing "forced consent" practices. The regulator found that the company required users to cancel their customer club membership entirely to stop receiving marketing emails, effectively making the surrender of privacy rights a condition of membership benefits.
The Legality of Forced Consent under GDPR
Forced consent occurs when a service provider bundles the agreement to receive marketing or data processing with the access to a service or benefit. Under the General Data Protection Regulation (GDPR), this is unlawful because consent must be "freely given" to be valid.
Key Legal Violations
- Article 4(11) and Article 7: Consent is not freely given if it is bundled into a condition of service. Forcing a user to lose membership benefits just to exercise the right to object to marketing is a violation of these articles.
- Article 21(2): Every individual has an absolute right to object to direct marketing. This right cannot be made conditional upon the loss of other services.
- Article 6(4): The Elkjop group was found to have repurposed personal data gathered through the customer club for advertising and conversion tracking without performing the required compatibility assessment.
The regulatory decision concluded that the consent relied upon by the company was not valid because it was forced, not specific, and lacked proper transparency for members.
Regulatory Process and the One-Stop-Shop Mechanism
Because the customer club was managed by the Norwegian parent company, Elkjop Nordic AS, the case moved through the GDPR's "one-stop-shop" mechanism. A complaint filed with the Swedish supervisory authority (IMY) was transferred to the Norwegian regulator (Datatilsynet) under Article 56(1), as Norway is the location of the controller's main establishment.
This process took approximately five years from the initial complaint in 2021 to the final decision in June 2026. The timeline highlights the significant bureaucratic delays often associated with cross-border GDPR enforcement actions.
Failure of Supervisory Authorities to Notify Complainants
A critical failure in the regulatory process was the lack of communication from the supervisory authorities. Under Article 77(2) of the GDPR, supervisory authorities are legally obligated to keep complainants informed of the progress and outcome of their complaint.
In this case, the complainant—who initiated the action—was not notified by either the Swedish IMY or the Norwegian Datatilsynet. The outcome was discovered via a volunteer-run wiki (GDPRhub) rather than through official channels. This has led to further potential legal action against the regulators themselves for failing to meet their basic legal obligations to the people they protect.
Industry Implications and Community Perspectives
The decision against Elkjop serves as a warning to companies employing "take it or leave it" models of data processing.
Community Insights
Community discussions highlight that this practice is widespread across the digital economy, with users noting similar patterns in e-commerce and online pharmacies. Some users expressed concerns that similar "forced consent" models are used in job applications and academic software (e.g., TurnItIn.com), where consent to data processing is often a prerequisite for employment or academic progress.
"If you cannot say no without losing something you are entitled to keep, you have not freely given consent to anything."
While some observers questioned whether this applied to ad-supported services, the ruling emphasizes that the right to object to direct marketing is absolute and cannot be used as a price of admission for a service.