I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M(thatprivacyguy.com)
410 points by speckx 17 hours ago | 249 comments
tl;dr: In 2021, the author told Elkjop's DPO that requiring customer club membership as a condition for receiving marketing emails violated GDPR's "freely given consent" rule, but the company refused to change. Five years later, Norway's Datatilsynet fined Elkjop NOK 20M (~€1.8M) for exactly that violation, plus repurposing club data for ad tracking without a compatibility assessment. The author only learned of the outcome via a volunteer-run wiki, and is now pressuring the Swedish DPA over its Article 77(2) duty to keep complainants informed, while preparing civil litigation.
HN Discussion:
  • Praise for the author's persistence and concern about social costs of exercising rights
  • Provides supporting documentation and links to the official decision
  • Extends the argument to similar privacy violations in other contexts like hiring and education
  • ~Questions whether the same logic should invalidate all ad-supported business models
  • Praises Norway's DPA while acknowledging the communication failure noted by author