Datatilsynet (Norway) - 22/00049-13
| Datatilsynet - 22/00049-13 | |
|---|---|
![]() | |
| Authority: | Datatilsynet (Norway) |
| Jurisdiction: | Norway |
| Relevant Law: | Article 4(11) GDPR Article 5(1)(a) GDPR Article 5(2) GDPR Article 6(1)(a) GDPR Article 6(1)(f) GDPR Article 6(4) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 01.06.2026 |
| Published: | |
| Fine: | 20,000,0000 NOK |
| Parties: | Elkjøp Nordic AS Elkjøp Norge AS |
| National Case Number/Name: | 22/00049-13 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Norwegian |
| Original Source: | Datatilsynet (in NO) |
| Initial Contributor: | bms |
The DPA fined a retail company NOK 20 million (€1,829,000) for relying on unspecific, insufficiently informed and forced consent for its customer club. Also, the retailer further processed customer data for ad targeting and conversion tracking without performing the required compatibility test.
English Summary
Facts
The DPA carried out an on-site inspection at Elkjøp Nordic AS, the controller, and Elkjøp Norge AS on June 2022. The inspection concerned the controller’s processing of customer information. It followed several personal data breach notifications, complaints and tips concerning the controller’s customer club.
The controller operated a customer club for marketing purposes. Membership was presented to customers mainly as a way to receive discounts, exclusive offers and other benefits. However, membership also involved several processing activities, including newsletters, SMS marketing, profiling, personalisation and analysis. The controller relied on consent under Article 6(1)(a) GDPR for this processing.
The controller described the customer club consent as an “all or nothing” solution and as a “package”. A customer could not join the customer club without also accepting profiling, personalisation, analysis and marketing communications. The controller considered these activities to form one commercial value proposition. After joining, customers could opt out of certain marketing channels, but they were not given a granular choice before giving consent. The controller also tested the use of customer match tools. This involved matching customer email addresses and/or telephone numbers with identifiers held by advertising platforms. The personal data used for this tool had originally been collected in connection with the customer club. The controller relied on Article 6(1)(f) GDPR for this processing and did not carry out a compatibility assessment under Article 6(4) GDPR, as it considered the purpose to be the same as the customer club purpose.
In addition, the controller used offline conversion tools to measure and estimate the effect of digital marketing on purchases made in physical stores. After an in-store purchase, the controller sent information to Google and Facebook to compare purchases with clicks on digital advertisements. The controller relied on Article 6(1)(f) GDPR for this processing.
Finally, the DPA reviewed the controller’s handling of data subject rights requests. The controller had unresolved rights requests, including rectification requests, where the one-month deadline had expired. Some requests dated back to at least December 2021, and documentation also indicated unresolved cases from February 2021. Requests for rectification of email addresses were automatically treated as complex, which led to an automatic extension of the deadline.
Holding
Invalid customer club consent
The DPA held that the controller violated Article 6(1)(a) GDPR, read together with Article 4(11) GDPR, because the customer club consent was not valid.
First, the consent was not specific. The DPA considered that sending general marketing communications, profiling for personalised marketing and analysing customer behaviour to improve marketing were separate purposes. A broad reference to marketing was not sufficiently concrete to cover all these processing activities.
Second, the consent was not freely given. The DPA found that the controller bundled several processing purposes into one customer club membership. The data subject could not join the customer club and receive general benefits without also accepting profiling, personalisation and analysis. The possibility to opt out after joining did not cure this issue, because the data subject should have been able to make a granular choice before giving consent.
Third, the consent was not informed. The information provided to customers before consent was mainly focused on discounts and benefits. The DPA found that the controller did not clearly explain, before consent was given, that the customer club involved personalised marketing, profiling and analysis, nor the consequences of such processing. The DPA also noted that the information depended largely on individual store employees, which created a significant compliance risk.
Processing of children's personal data
The DPA further held that the seriousness of this infringement was increased by the fact that children’s personal data was also processed. The customer club was open to customers from the age of 15 at the time of the inspection, but the controller did not register age and had no mechanism to verify that customers met the age requirement.
Customer match and compatibility assessment
Regarding customer match, the DPA held that the controller violated Article 6(1) GDPR and Article 6(4) GDPR. The controller used personal data originally collected for the customer club for a new advertising-related purpose. The DPA considered that customers who consented to joining a customer club to receive discounts and benefits could not reasonably expect their data to later be used for customer matching with advertising platforms, especially where this involved sharing data with third parties. Therefore, Article 6(1)(f) GDPR could not serve as a valid legal basis. The controller also failed to assess whether the new purpose was compatible with the original purpose, as required by Article 6(4) GDPR.
Offline conversions and accountability
Regarding offline conversions, the DPA held that the controller violated Article 5(2) GDPR, read together with Article 5(1)(a) GDPR. The DPA did not decide whether Article 6(1)(f) GDPR could in principle be used for offline conversions. Instead, it found that the controller had failed to demonstrate that the processing was lawful. Its legitimate interest assessment was too brief and omitted key elements, including the number of data subjects affected, categories of personal data, possible processing of children’s data, reasonable expectations of the data subjects and potential negative consequences of sharing data with Google and Facebook.
Data subject rights requests
Regarding rights requests, the DPA held that the controller violated Article 12(3) GDPR. A rectification request concerning an email address was not, in itself, complex. The controller could not automatically extend the one-month deadline for all such requests. Any extension had to be based on a specific assessment of the number and complexity of the requests. The DPA also found that some requests were not handled even within the extended three-month deadline.
Administrative fine and mitigating factors
The DPA imposed an administrative fine of NOK 20,000,000 under Article 58(2)(i) GDPR. It considered that the infringements concerned core GDPR principles and affected many data subjects, including children. The DPA also considered the infringements intentional, since the controller had consciously chosen the relevant customer club structure and marketing tools, and had been aware of risks linked to the consent model.
At the same time, the DPA took mitigating factors into account. The controller cooperated during the investigation, had shown increased privacy awareness, implemented improvements after the inspection and addressed some of the identified issues. The DPA also considered the long case handling time as a mitigating factor. Overall, the DPA considered the infringements to be of medium seriousness, but at the lower end of that scale. The DPA also expected the controller to correct any ongoing infringements, including by obtaining valid consent from customer club members.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Norwegian original. Please refer to the Norwegian original for more details.
Your reference Our reference Date
22/00049-13 01.06.2026
Decision on infringement fee - Customer Club and the rights of the data subjects
1. Introduction................................................................................................................................3
2. Decision................................................................................................................................................4
3. Summary and limitations................................................................................................................4
3.1 Summary .....................................................................................................................................4
3.1.1 The consent of the customer club was not valid..................................................................4
3.1.2 The use of customer match lacks a legal basis..................................................................5
3.1.3 The use of offline conversions was not sufficiently assessed or documented......5
3.1.4 Rights requests are not handled in accordance with the General Data Protection Regulation........5
3.2 Imposition of infringement fee..................................................................................................6
3.3 Delimitations................................................................................................................................6
4. The Danish Data Protection Authority's competence, tasks and authority..................................................................7
5. The Danish Data Protection Authority's assessment of the violations................................................................................8
5.1 Consent to the processing of personal data in Elkjøp's customer club................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ Trelastgata 3 +47 22 39 69 00 974 761 467 www.datatilsynet.no
0105 OSLO 0191 OSLO 5.2.3 The Norwegian Data Protection Authority's assessment................................................................................17
5.2.4 Elkjøp's comments on the advance notice..................................................................18
5.3 Offline conversions................................................................................................................20
5.3.1 Details of the facts of the case.................................................................................20
5.3.2 Legal basis..................................................................................................................20
5.3.3 The Norwegian Data Protection Authority's assessment..................................................................................................20
5.3.4 Elkjøp's comments on the advance notice..................................................................................21
5.4 Deadline for processing requests from data subjects (rights requests)................ 5.4.2 Legal basis................................................................................................................23
5.4.3 The Danish Data Protection Authority's assessment..................................................................................23
5.4.4 Elkjøp's comments on the advance notice.................................................................24
6. Imposition of a violation fee.................................................................................................25
6.1 Introduction........................................................................................................................25
6.2 Assessment of whether a violation fee should be imposed..................................................27
6.2.1 Overview..................................................................................................................27
6.2.2 The nature, severity and duration of the violations..................................................28
6.2.3 The requirement of fault (whether the violation was committed intentionally or negligently)................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................. the advance notice..................................................................32
6.3 Conclusion on whether a violation fee should be imposed .....................................33
6.4 Determination of the violation fee................................................................................33
7. Right to appeal .........................................................................................................35
8. Publicity.............................................................................................................................35
21. Introduction
On 20 and 22 June 2022, the Norwegian Data Protection Authority carried out an on-site inspection pursuant to Article 58(1) of the GDPR at Elkjøp Nordic AS and Elkjøp Norge AS
(hereinafter referred to as "Elkjøp") at Elkjøp's office premises in Nydalen, Oslo. The inspection concerned Elkjøp's
2
processing of customer information. The background to the inspection was several reports of breaches of
personal data security, complaints and tips about the customer club.
3
A preliminary inspection report (hereinafter the “inspection report”) was sent to Elkjøp on 1 June 2023,
and the Danish Data Protection Authority received Elkjøp’s comments on 22 June 2023. Elkjøp has provided further information on the privacy measures implemented following the on-site inspection. 5
The Danish Data Protection Authority sent a notification of decision to Elkjøp on 30 October 2025 (hereinafter the “notice”). At Elkjøp’s request, the deadline for providing comments was extended from 10 December 2025 to 1 February 2026. Elkjøp submitted comments on the notification on 1 February 2026.
Elkjøp does not dispute the factual presentation in the notification and the inspection report. However, Elkjøp
disputes the Danish Data Protection Authority’s conclusions that the GDPR has been breached, and
argues that there is no basis for imposing a fine.
In this decision, we take into account Elkjøp's comments. In our view, Elkjøp's comments do not give any reason to change our assessment, which we will explain in more detail in the sections below. Each individual statement is not treated separately in the decision, but all the statements have been assessed and weighed in the final conclusions.
Several of Elkjøp's comments concern changes and measures that have been implemented following the on-site inspection. The Data Protection Authority emphasizes that the relevant time for the assessment of whether Elkjøp has violated the Privacy Regulation is the time of the on-site inspection. This is further
described in section 6.2.5 of the decision.
1Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ [2016] L 119/1.
The Norwegian Data Protection Authority sent a notice of inspection to Elkjøp on 19 May 2022, see document 22/00049-3. The Norwegian Data Protection Authority informed Elkjøp of the company's rights under Sections 14 and 15 of the Public Administration Act in the notice of inspection. Elkjøp did not appeal the inspection or any of the orders to provide information during the inspection.
3See document 22/00049-10.
4See document 22/00049-11.
5See document 22/00049-14.
32. Decision
Pursuant to Article 58(2)(i) of the General Data Protection Regulation, Elkjøp Nordic AS
and Elkjøp Norge AS are hereby imposed a fine of NOK 20,000,000 for
1. having violated Article 6(1) of the General Data Protection Regulation, cf. Article 4(11), by not
obtaining informed, specific and free consent to the processing of
personal data in its customer club (cf. Section 5.1)
2. having violated Article 6(1) of the General Data Protection Regulation, cf. Article 6(4), by
further processing personal data previously collected in connection with
the customer club, through the use of the customer match tool, without a valid legal basis
and without assessing the compatibility of the purposes (cf. Section 5.2)
3. having violated Article 5(2) of the General Data Protection Regulation, cf. Article 5(1)(a), by to
not carry out and document a proper assessment of the legal basis
for, and thus the lawfulness of, the processing of personal data in connection with
the use of the offline conversions tool (cf. section 5.3)
4. to have violated Article 12(3) of the General Data Protection Regulation by not handling requests
for rectification within the one-month deadline in cases where there are no grounds for extending
the deadline; by automatically considering requests for rectification as complex and thus
invoking an extension of the deadline by one month; and by failing to handle
requests from data subjects within the extended three-month deadline (cf. section 5.4)
The Danish Data Protection Authority assumes that Elkjøp corrects any ongoing violations, including that
Elkjøp obtains valid consent from its customer club members.
3. Summary and limitations
3.1 Summary
3.1.1 The consent of the customer club was not valid
Elkjøp bases the processing of personal data in its customer club on consent.
The Data Protection Authority believes that the consent collected by Elkjøp was invalid for the following reasons:
• The consent was not specific, as the processing activities were linked to
different purposes and purposes that were not sufficiently defined.
• The consent was not given voluntarily, as it was not possible to give separate consent to
the different processing activities.
4 • The consent was not informed, as Elkjøp did not provide the customers with sufficient
information about the planned processing when the consent was obtained, including
information that enabled them to foresee the consequences of giving consent.
The Data Protection Authority therefore concludes that the consent obtained was not valid under
the GDPR.
The processing has therefore been carried out without a valid legal basis in accordance with Article 6(1)(a) of the GDPR, cf. Article 4(11). The fact that some of the data subjects were children is an aggravating factor. (Section 5.1)
3.1.2 Use of customer match lacks legal basis
Elkjøp explained that personal data that was originally collected in the customer club on the basis of consent would be processed in the customer match tool. The Norwegian Data Protection Authority believes that this is processing for a purpose other than that for which the personal data was originally collected, and thus requires a compatibility assessment, cf. Article 6(4) of the GDPR.
Since Elkjøp had not carried out such an assessment, the Norwegian Data Protection Authority concludes that Article 6(4) of the GDPR has been violated. (Section 5.2)
According to Elkjøp, Article 6(1)(f) of the GDPR is the processing basis for the customer match tool. The principle of fairness requires that personal data not be processed in a way that is unexpected or misleading for the data subject. In the opinion of the Norwegian Data Protection Authority, it was not within the reasonable expectations of the data subjects that personal data collected on the basis of consent would later be processed for another purpose that was not covered by the consent. The Norwegian Data Protection Authority therefore concludes that Article 6(1)(f) of the General Data Protection Regulation was not a valid basis for processing personal data in the customer match tool. (Section 5.2)
3.1.3 Use of offline conversions was not sufficiently assessed or documented
Elkjøp used the offline conversion tool to measure the effect of digital marketing on in-store sales based on Article 6(1)(f) of the GDPR. The controller must be able to demonstrate that the processing of personal data is lawful pursuant to Article 5(2), cf. Article 5(1)(a). In the opinion of the Norwegian Data Protection Authority, Elkjøp's assessment of Article 6(1)(f) was insufficient. The Norwegian Data Protection Authority therefore concludes that
Elkjøp could not demonstrate that the processing was lawful. This is a violation of Article 5(2), cf.
Article 5(1)(a). (Section 5.3)
3.1.4 Rights requests are not handled in accordance with the GDPR
According to Article 12(3) of the GDPR, the controller shall inform the data subject of the action taken in response to a request from a data subject within one month of receipt. This period may be extended by a further two months if necessary, taking into account the number of requests and the complexity of the requests.
5In Elkjøp's case, requests for rectification of data subjects' e-mail addresses were automatically categorized as complex, which led to an automatic extension of the deadline.
The Danish Data Protection Authority believes that it cannot be assumed that such requests are always complex
and therefore allows an extension of the deadline. An extension of the deadline is only permitted after a specific assessment in each individual case. Elkjøp also acknowledged that they did not respond to some requests from data subjects themselves within the extended deadline. This is a violation of Article 12(3) of the GDPR. (Section 5.4)
3.2 Imposition of a violation fee
The Norwegian Data Protection Authority believes that the violations provide grounds for a violation fee pursuant to Article 83(1) of the GDPR, see our assessment in Section 6. In assessing whether we should impose a violation fee, we placed particular emphasis on the fact that the violations concern key provisions and principles in the GDPR and that many data subjects are affected by the violations, including children.
The Norwegian Data Protection Authority believes that the violations are of medium seriousness, but at the lower end of the scale. Furthermore,
we have found several mitigating circumstances, including a positive development at Elkjøp in recent years, both before and after the on-site inspection. We have taken this development into account in our assessment. The fee has also been reduced due to the long case processing time. (Section 6)
3.3 Limitations
This decision is based on the factual circumstances that were revealed during the on-site inspection, including interviews with employees of Elkjøp and documentation that Elkjøp provided prior to the on-site inspection. The factual circumstances are described in more detail in the
6 inspection report.
The Data Protection Authority investigated several matters during the on-site inspection. The Norwegian Data Protection Authority examined in particular: i) joint processing responsibility and sharing of personal data within the group, ii) the security of personal data in connection with the handling of products containing personal data in service and after-sales (customer support), iii) the lawfulness of the processing of customer data in connection with the customer club and for marketing purposes and iv) Elkjøp's organisational measures and documented guidelines to ensure the timely and lawful exercise of data subjects' rights.7
This decision is limited to the lawfulness of the processing of customer data in connection with the customer club and the organisational measures and guidelines to ensure the timely and lawful exercise of data subjects' rights. We deal with these issues in section 5.
6
7See document 22/00049-12.
See document 22/00049-7 “Inspection 20 and 22 June 2022, Elkjøp Nordic AS and Elkjøp Norge AS – Agenda for the fieldwork” sent to Elkjøp on 13 June 2022.
6During the on-site inspection, the Norwegian Data Protection Authority also identified deficiencies related to joint processing responsibility, personal data security in connection with the handling of products containing personal data during service and after-sales (customer support), including non-conformity handling and customers’ right to access their own personal data. The Norwegian Data Protection Authority believes that these deficiencies do not provide grounds for a formal sanction in the form of a violation fee in the current inspection and decision here. The decision not to follow up on these aspects in this decision is also due to the long case processing time in this case. This does not exclude the possibility of investigating Elkjøp’s compliance with these aspects in the future.
4. The Danish Data Protection Authority's competence, tasks and authority
Elkjøp is the Nordic region's leading retailer of consumer electronics and delivers its products directly to customers both online and through more than 400 physical stores. Elkjøp consists of a group of companies that operate under the brands Elkjøp and Elkjøp Phonehouse in Norway, Elgiganten and Elgiganten Phonehouse in Sweden, Elgiganten in Denmark, Gigantti in Finland, Elko in Iceland, Elding in the Faroe Islands and Pisiffik in Greenland. Elkjøp Nordic AS is the parent company of the group, and this is also where the group management and overall responsibility for compliance lies. Among the Elkjøp stores operating under the different brands in the Nordic countries, there are both wholly owned stores and franchisees. Elkjøp Nordic has wholly owned stores and franchise stores established in Norway, Sweden and Finland, wholly owned stores in Denmark and franchise operations in Greenland, Iceland and the Faroe Islands. 9
The Elkjøp companies process personal data in connection with the activities of their operations in the EEA. The GDPR therefore applies to all processing of personal data in the group, cf. GDPR Article 3(1). Elkjøp has its main business in Norway, cf. GDPR Article 4(16).
The documentation in the case shows that Elkjøp has the same internal procedures and guidelines for data protection and processing of personal data in all countries where the Elkjøp companies operate. We therefore consider the processing of personal data in this case to be cross-border processing pursuant to GDPR Article 4(23)(a).
Since this case is cross-border and Elkjøp has its main business in Norway, the cooperation mechanism and procedures set out in GDPR Articles 56(1) and 60 apply. The Norwegian Data Protection Authority is competent to act as the lead supervisory authority in the case pursuant to Article 56(1). The Norwegian Data Protection Authority shall cooperate with other supervisory authorities concerned, cf. Article 60 of the General Data Protection Regulation. This involves exchanging relevant information about the case and submitting a draft decision to the other supervisory authorities concerned, so that they can make comments or objections. Their views have been duly taken into account when deciding on this case. 8
9See https://www.elkjopnordic.com/what-we-do - about-elkjop, last visited May 27, 2026.
See https://elkjopnordic.com/about-us, last visited May 27, 2026.
75. The Norwegian Data Protection Authority's assessment of the violations
5.1 Consent to the processing of personal data in Elkjøp's customer club
5.1 1 Further details on the facts of the case
Elkjøp's legal basis for the processing of personal data in the customer club is consent.
During the on-site inspection, Elkjøp stated that the purpose of the customer club is to market
products and services. 10
At the time of the on-site inspection, Elkjøp had a landing page for the customer club on its
website, which provided an overview of the benefits of becoming a member. On the website, the customer club was marketed as offering all members general discounts on the specific products and services listed. 11
Elkjøp stated that consent to membership in Elkjøp's customer club includes the processing
of personal data in connection with sending newsletters, sending
text messages, profiling, personalization and analysis. During the on-site inspection, Elkjøp's compliance team explained that these activities are carried out for the same purpose and are based on
13
the same processing basis.
After the on-site inspection, Elkjøp explained that when customers are asked by a service employee in an Elkjøp store whether they wish to become a member of the customer club, the employee shall inform the customer of the terms and conditions for being a member of the customer club:
“Do you want to become a member of our Customer Club?
• Contact you electronically (e.g. via SMS and email), by telephone and post with personal offers and other relevant information.
• Collect and analyse information about you and your customer relationship.
• Create a customer profile, in order to provide more relevant information and better service.
• You must be at least 15 years old and can unsubscribe from the customer club at any time.” 14
After consenting by clicking on a link in an SMS, the customer is directed to a website that
contains information about the benefits of being a member of the customer club, including discounts
and exclusive offers. 15
10
11See the final inspection report, section 3.3.1.2.
See https://web.archive.org/web/20220613175535/https:/www.elkjop.no/kundeklubb/kundeklubb/, last visited
12 March 2026.
See document 22/00049-4 “e) CRM – response to the Norwegian Data Protection Authority” p. 2.
13See the final inspection report, section 3.3.1.2.
14See Elkjøp’s comments on the preliminary inspection report, 22.06.2023, pp. 25–26. See also the final
inspection report, section 3.3.1.2.
15See the final supervisory report, section 3.3.1.2 and document 22/00049-9 “RPReplay_Final1629892124”
(video showing the SMS sent to customers when they agree to become a member of the customer club).
8The Norwegian Data Protection Authority has received several complaints and tips about data subjects who have become members of the customer club without consent and inquiries about the validity of the consent. 16
5.1.2 Legal basis
The processing of personal data must have a legal basis in Article 6(1) to be lawful. If the processing is based on consent pursuant to Article 6(1)(a), the controller must be able to demonstrate that the data subject has consented to the processing of personal data concerning him or her. The data subject shall have the right to withdraw his or her consent at any time, cf. Article 7 of the GDPR. Consent should be given in the form of a clear statement by which the data subject “freely, specifically, informed and unambiguously gives his or her consent to the processing of personal data relating to him or her”, cf.
Article 4(11) and recital 32 of the GDPR. These conditions are cumulative.
Consent must be informed. This means that when consent is used as a basis for processing,
data subjects must be informed of what they are consenting to, including which personal data will be processed and what the purpose of the processing is. The purpose must be explicitly stated. It must therefore be clearly communicated, and an implicit purpose will not be sufficient.
The data subject must be able to foresee the consequences of giving consent based on the information provided by the controller.
The consent must be linked to one or more specific purposes of the processing, cf. Article 6
No. 1 letter a. That the purpose of the processing must be specific means that the purpose must
be sufficiently concrete to make it possible to assess whether it is necessary to process the personal data in question and whether the processing is in accordance with
19
the General Data Protection Regulation. The European Data Protection Board (EDPB)
guidance on consent refers to the Article 29 Working Party's Opinion 3/2013 on
purpose limitation. There, the Board's predecessor stated that for a purpose to be
specific, "it must be detailed enough to determine what kind of processing is and is not
included within the specified purpose, and to allow that compliance with the law can be
assessed and data protection safeguards applied". Furthermore, it says that "a purpose that is vague
or general, such as for instance … ‘marketing purposes’ … will – without more detail –
usually not meeting the criteria of being 'specific'. That said, the degree of detail in which a
purpose should be specified depends on the particular context in which the data are collected
and the personal data involved.” 21
16 See the Norwegian Data Protection Authority's cases 20/02200, 21/02368, 23/00258, 22/04698, 20-653/ 20-576 and 21-1292 / 21-1308.
17 See C-61/19 Orange Romania footnote 17.
18
See C-61/19 Orange Romania para. 40 and C-673/17 Planet49 para. 74. See also the Advocate General's Opinion in C-61/19 Orange Romania, paras 46–47.
See Skullerud et al. "The Data Protection Regulation. Legal Commentary", under "Chapter II. Principles (§§ 5–11)" and
"Article 5. Principles for the processing of personal data", last accessed 24 March 2026 at juridika.no. See also
Article 29 Working Party Opinion 03/2013 on purpose limitation, p. 15.
20See the Data Protection Council Guidelines 05/2020 on consent under Regulation 2016/679, footnote 28, p. 13 and footnote 30, p. 14. The Article 29 Working Party was established by Directive 95/46/EC. It was replaced by the European Data Protection Board when the GDPR entered into force.
21See the Article 29 Working Party's Opinion 03/2013 on purpose limitation, pp. 15–16.
9Consent "is presumed not to be freely given if it is not possible to give separate consent for different processing activities, even if it is appropriate in the individual case", cf. recital 43 of the GDPR. The Data Protection Council has stated that a service may include several processing activities for more than one purpose. In such cases, data subjects should be free to
choose which purpose they accept, instead of having to consent to a bundle of combined
processing purposes (so-called "bundling"). Such granularity is necessary for the consent to be considered voluntary.
5.1.3 The Norwegian Data Protection Authority's assessment
The Norwegian Data Protection Authority believes that the consent obtained by Elkjøp for the processing activities in the
customer club was not specific, voluntary and informed, and thus not in line with the
GDPR.
According to Elkjøp, the consent to membership in Elkjøp's customer club includes the processing of personal data in connection with the sending of newsletters, sending text messages, profiling, personalization and analysis. Elkjøp has explained that these activities are carried out for the same purpose. During the on-site inspection, Elkjøp stated that the purpose of the customer club is to market products and services. Elkjøp explained that in order to conduct good marketing and provide customers with the information they want, it is important to be able to perform analysis, segment customers and adapt the information to the individual. The Data Protection Authority interprets this practice from Elkjøp as personalized marketing. This is something other than just offering general discounts to create customer loyalty. The overall purpose of the processing activities may be to conduct marketing to the members of the customer club. However, the Data Protection Authority believes that the consent was not specific. As mentioned above, marketing purposes in themselves are not sufficiently specific, and in this case the processing activities are linked to different purposes. Sending general marketing communications, profiling to facilitate personalized marketing, and performing analysis to improve marketing activities are separate purposes.
According to Elkjøp, there is no so-called “bundling” of purposes as there are no different processing activities for different purposes. 25 Elkjøp’s compliance team described the consent as “all or nothing”. The team explained that the consent solution used by Elkjøp was discussed internally within Elkjøp in February 2022. Elkjøp identified some risks in keeping the solution. One of these risks was that the data protection authorities would conclude that the consent was not valid and order Elkjøp to delete customer club members or obtain new consent. It was decided that the consent should be kept as it was, but that it should be possible to opt out of the different marketing activities after becoming a member of the customer club. 26
22See the Norwegian Data Protection Council's Guidelines 05/2020 on consent under Regulation 2016/679, paragraphs 42–44.
23See document 22/00049-4 “e) CRM - response to the Norwegian Data Protection Authority” p. 2. See also the final supervisory report, paragraph
3.3.1.2.
24See the final supervisory report, paragraph 3.3.1.2.
25Ibid.
26See document 22/00049-9 “Answers to questions after day 1”, slide 5.
10Elkjøp described membership in the customer club as a “package”, and explained that it is not
possible to be a member of the customer club unless you also accept personalization,
analysis, newsletters, etc. Elkjøp’s compliance team explained that they believe it is okay that
customers must receive relevant marketing when they accept membership in the customer club,
as it is a barter transaction; customers receive something in exchange for Elkjøp being able to send them
marketing. 27
The Norwegian Data Protection Authority believes that the consent Elkjøp describes is a case of so-called “bundling”, as
it would be appropriate to obtain separate consent for at least some of the
described purposes. Therefore, such consent is not assumed to be given voluntarily, cf.
28 GDPR recital 43. For example, it is possible to send out a newsletter with general offers without also performing profiling for personalisation – the first processing activity (general marketing through newsletters) can be done without the second (profiling).
Our assessment that the consent is “bundled” is supported by Elkjøp’s own description of the consent as “all or nothing” and as a “package”, which in itself suggests that the consent is “bundled”. Elkjøp has not given customers the opportunity to give consent to the separate processing activities in the customer club.
Customers could have been given a choice to accept different marketing activities. Elkjøp also pointed out that it was decided that customers would be given the opportunity to opt out of different marketing activities after joining the customer club. In the opinion of the Norwegian Data Protection Authority, customers should have been given this choice at the time they were asked to give their consent to the customer club.
Information to customers emphasizes the customers’ ability to receive offers and discounts. For example, Elkjøp stated that when customers are asked if they want to become a member of the customer club, they are asked if they want to receive offers. This is also the focus of the marketing material on Elkjøp’s website, as mentioned above.
Following the on-site inspection, Elkjøp explained that when customers are asked by a service employee in an Elkjøp store if they want to become a member of the customer club,
30 the service employee informs the customers about the conditions for becoming a member of the customer club. The customer then consents by clicking on a link in an SMS. When the customers click on the link, they are sent to a website that confirms that they are a member and that consent has been given. This website
27See the final inspection report, point 3.3.1.2.
28See also the Opinion of the Advocate General in Case C-673/17 Planet49, para. 74–75.
29See the inspection report, section 3.3.1.2. See also the privacy statement on Elkjøp's website
https://www.elkjop.no/kundeservice/gdpr-personvernerklaring, last visited on 27 May 2026.
30See Elkjøp's comments on the preliminary inspection report, 22.06.2023, pp. 25–26. See also the final
inspection report, section 3.3.1.2.
11contains information about the benefits of membership in the customer club, including discounts and
31exclusive offers, and an overall description of what the customer has now consented to.
In the opinion of the Norwegian Data Protection Authority, Elkjøp has not provided customers with sufficient information about what they consent to when consent is obtained in this way, including information that allows
customers to foresee the consequences of giving consent. In our view, the consent cannot be considered as informed, as the information provided to the customers primarily concerned discounts and benefits. However, it was not clearly communicated in advance that this would be offered through personalized marketing, including profiling and analysis, and the consequences of this. The extent to which the customers actually received information also depended largely on the individual store employee. This created a significant risk that the information provided was arbitrary and even less sufficient in practice. This is a risk that could have been avoided by providing the information in writing in advance, and this risk must be borne by Elkjøp. The conclusion is that the consent to become a member of Elkjøp's customer club was not valid pursuant to Article 6(1)(a), cf. Article 4(11), as it was not specific, voluntary and informed. The processing therefore lacked a valid processing basis. The seriousness of the breach is exacerbated by the fact that children's personal data has also been unlawfully processed in the customer club. During the on-site inspection, Elkjøp explained that they do not register the age of their customers or store information about their age. The age limit for membership in the customer club was 15 years, but Elkjøp lacked mechanisms to ensure that the customer was actually over this age. 33
As we understand it, Elkjøp's customer club was not specifically aimed at children. However, Elkjøp markets and offers several products that are also relevant to a younger customer segment. Some products are particularly relevant to young customers, such as the products under the category
"gaming" on the website.
As stated in recital 38 of the GDPR, children's personal data deserve special protection, as children may be less aware of the risks, consequences and safeguards involved, as well as of the rights they have with regard to the processing of personal data. Children should therefore not be subjected to profiling for marketing purposes,
regardless of the legal basis – and this also applies to children aged 15–17.
5.1.4 Elkjøp's comments on the advance notice
Elkjøp states in its comments that the consent was informed, specific and voluntary.
31See the inspection report, section 3.3.1.2 and document 22/00049-9 "RPReplay_Final1629892124" (video showing
the SMS that is sent to customers when they agree to become a member of the customer club).
32At the time of the inspection, the age limit was 15 years. However, the Data Protection Authority is aware that Elkjøp has changed the age limit to 18 years following
the inspection.
33See the final inspection report, section 3.3.1.2.
12Elkjøp refers to the Data Protection Authority's statements in another case concerning Elkjøp,
the "Christmas calendar case". Elkjøp states that in this case the Danish Data Protection Authority is based on a stricter understanding of specificity compared to the Christmas calendar case, where the Danish Data Protection Authority accepted that different processing activities can take place for one overarching purpose. However, the Danish Data Protection Authority believes that our understanding in this case is consistent with the previous case. In the Christmas calendar case, the Danish Data Protection Authority examined the consent to the processing of personal data in Elkjøp's Christmas calendar, which also included consent to further marketing and profiling activities, as the customer was also registered in Elkjøp's customer club. The Danish Data Protection Authority concluded that the consent was not valid, as it was neither specific nor voluntary. The Danish Data Protection Authority emphasised that profiling is an intrusive processing activity, which is not initially necessary to achieve the very broadly defined purpose of "promoting sales of Elkjøp's services and products". The Danish Data Protection Authority further stated that when consent is the basis for processing, different processing activities cannot be legitimised by defining them under one broad and overarching purpose. The Norwegian Data Protection Authority also noted that when the purpose is the same and sufficiently specified, consent is not necessarily required for each individual activity. For example, the Norwegian Data Protection Authority pointed out that processing personal data to offer customer club benefits would be one purpose, while profiling customers would be another purpose. The Norwegian Data Protection Authority therefore believes that our view in this case is in line with the reasoning in the Christmas calendar case. Elkjøp was thus already aware of the Norwegian Data Protection Authority's view on these matters in May 2022. The Norwegian Data Protection Authority has also expressed this view for several years and has published guidance on customer clubs and the processing of personal data. The guidance emphasizes that "there are strict requirements for how consent is obtained. Consent must be voluntary, so it must be possible to say no to analysis without being excluded from the service. Furthermore, the business must provide concise and understandable information about what consent entails. Consent can only be given for one specific purpose at a time. Consent must be given by an active action (as opposed to passively completing a registration process), and the consent request must be separate from other information and conditions. Remember that consent must be documented.” As mentioned above, there is also similar guidance in the more general guidelines from the Norwegian Data Protection Council. Elkjøp’s claim of a lack of guidance in this area is therefore incorrect. Elkjøp further states that “[processing] activities have always been clearly presented to club members as part of one and the same value promise, and that they are naturally dependent on each other” (our translation). As an example, Elkjøp mentions that marketing and competitions 34See the Data Protection Authority’s document 20/02350-14, 9 May 2022. This decision was overturned as a result of new information indicating that the case should have been treated as a “cross-border case” under Chapter VII of the GDPR. However, the cancellation is of a procedural nature and does not affect the material assessments in the case.
35Ibid. p. 12. See Elkjøp's comments on the notification pp. 3–5.
36See the Data Protection Authority's document 20/02350-14 p. 13.
37See https://www.datatilsynet.no/personvern-pa-ulike-omrader/kundehandtering-handel-og-
medlemskap/kundeklubber-og-personvern/ (from June 2018).
13must be relevant and meaningful to the club members, and that this requires profiling and
38 segmentation.
Although Elkjøp states that the activities in the customer club concern one overarching purpose,
the Data Protection Authority does not agree that the consent was given for one or more specific purposes, as we have
explained in more detail in the assessment above.
The Danish Data Protection Authority further believes that marketing can be made relevant and meaningful for the customer club members by allowing them to choose which categories and forms of marketing they wish to receive, and which personal data they are willing to share in order to receive such marketing.
Elkjøp states that a strict requirement for specificity may be to the disadvantage of the data subjects, as customer club members who do not consent may, for example, be denied early access to Black Friday offers or the opportunity to participate in competitions. This appears to be a misunderstanding of the issue, which is actually the opposite: the data subjects sign up to access general discounts or competitions, while at the same time being forced to accept profiling for marketing purposes. It is also not given that consent must be the basis for processing for access to general discounts or to participate in competitions.
Furthermore, Elkjøp states that they “do not agree with the Data Protection Authority’s apparent interpretation that
voluntariness necessarily requires separate consent for each individual processing activity in
every situation, including if the activities are closely linked to each other…” (our
39
translation). The Data Protection Authority does not believe that individual processing activities always require
separate consent. However, it may be necessary to give data subjects the opportunity to provide
granular consent in specific cases where it is appropriate. For example, it is necessary when processing is carried out for different purposes. The Data Protection Authority believes that sending
general marketing communications, conducting profiling to facilitate
personalized marketing and performing analysis to improve marketing activities
constitute separate purposes. We therefore believe that the consent is “bundled”. 40
We note that not all processing activities that take place in a customer club necessarily
require consent as a basis for processing. In some cases, a separate processing basis is not required if the processing is carried out in accordance with Article 13(2) of the GDPR. However, in cases where consent is the most appropriate basis for processing, consent cannot be so broad as to undermine the data subject's freedom of choice by requiring them to accept everything or nothing. The Danish Data Protection Council has stated that "[i]f the controller has conflated several purposes for processing and has not attempted to seek separate consent for each purpose, there is a lack of freedom." This granularity is closely related to the need for consent to be specific (…) When data
processing is done in pursuit of several purposes, the solution to comply with the conditions
38See Elkjøp's comments on the notification p. 4.
39See Elkjøp's comments on the notification p. 5.
40See the Data Protection Council's Guidelines 05/2020 on consent under Regulation 2016/679, paragraph 42.
41See case C-654/23.
14for consent lies in granularity, i.e. the separation of these purposes and obtaining consent for
each purpose.» 42
Elkjøp claims that the processing activities in question constitute a “value exchange”.
The implication of this seems to be that Elkjøp may require certain personal data in return for discounts and competitions. Although it is generally up to the controllers to define their value propositions, such promises must respect the limits of the law, and there are some special conditions that must be met when consent is the basis for processing. In these cases, controllers cannot require or force data subjects to share the relevant personal data, as this is in itself incompatible with voluntariness. The fact that Elkjøp believes this to be a fair trade-off is not relevant when assessing whether consent is given voluntarily under Article 4(11) of the GDPR. Elkjøp writes that “the purpose of consent under the GDPR is not to give each individual the opportunity to tailor the offer exactly as they want” (our translation). However, this is a cover-up. The purpose of consent is for data subjects to be able to freely choose whether they want to accept the relevant processing of personal data, without being subjected to pressure. When controllers base processing on consent, they must design their offers in such a way that the data subject has real self-determination, as the consent should express.
Elkjøp further claims that the consent was informed. We maintain our conclusions that it was not. Any improvements made after the on-site inspection are not relevant
for the assessment of whether the consent was actually informed at the time of the on-site inspection.
The Danish Data Protection Agency further notes that the reference in Elkjøp's comments to the "SMS text"
applies to the information displayed to customers after they have given consent. It is therefore
not relevant for the assessment of whether the consent was "informed". The material that was
presented before consent was given presented the offer as a way to obtain discounts and
promotional offers.
5.2 Customer Match
5.2.1 Details of the facts of the case
During the on-site inspection, Elkjøp informed us that they were conducting a trial period for
using the customer match tool. The use of this tool involves matching customers' email addresses and/or telephone numbers with advertising platforms that have identifiers for their users. Elkjøp explained during the inspection that they envisaged introducing this tool from
June/July 2022. Elkjøp explained that in the customer match tool they would process
personal data that was originally collected for the customer club. 43
42
43See the Danish Data Protection Council's Guidelines 05/2020 on consent under Regulation 2016/679, sections 42–44.
Ibid. See also document 22/00049-4 “Supervisory documentation to 2.6.2022 (part 1)”, slide 35.
15Elkjøp explained that the purpose of the customer match tool is to achieve more efficient marketing, target specific customer groups and make better use of media investments. 44
The Norwegian Data Protection Authority asked whether Elkjøp had considered whether the purpose of the processing in the customer match tool is compatible with the purpose for which the personal data was originally
collected, cf. Article 6(4) of the General Data Protection Regulation. Elkjøp’s compliance team explained
that the purpose is the same when processing personal data in the customer club and when using the customer club’s information for customer match. Elkjøp had therefore not carried out a
45 compatibility assessment pursuant to Article 6(4).
However, Elkjøp’s compliance team stated that these are different processes with different processing bases. The team explained that the consent to processing in the customer club does not
cover the processing of personal data in the customer match tool. Customer match is a new
processing activity. The basis for processing is Article 6(1)(f).
5.2.2 Legal basis
The principle of fairness in Article 5(1)(a) of the GDPR requires that
personal data shall not be processed in a way that is unexpected or misleading for
the data subject. The processing shall be open, transparent and in accordance with the data subject's
reasonable expectations. In addition, data subjects should be given the greatest possible degree of self-determination regarding
the use of their personal data. 46
If the processing for a purpose other than that for which the personal data were collected is not based on the consent of the data subject or on Union or Member State law, the controller shall determine, pursuant to Article 6(4), whether the processing for another purpose is compatible with the purpose for which the personal data were originally collected. In this assessment, the controller shall take into account the elements in Article 6(4)(a) to (e). See also recital 50 of the GDPR.
The Data Protection Council has stated in its guidance on consent that “[n]otwithstanding the provisions
on compatibility of purposes, consent must be specific to the purpose. Data subjects will give
their consent with the understanding that they are in control and their data will only be
processed for those specified purposes.” Controllers must obtain new and specific consent if the purpose of the processing changes after consent48 was obtained, or they additionally want to use the data for new purposes. If the controller wants to process data collected with consent for new purposes, the controller must, as a general rule, collect the personal data again on the basis of consent or another basis for processing pursuant to Article 6(1).
44See document “Supervision documentation as of 2.6.2022 (part 1)”, slide 35.
45See the final supervision report, section 3.3.1.2. See also document 22/00049-4 “Supervision documentation as of 2.6.2022 (part 2)”, slide 7.
46See the Guidelines 4/2019 of the Norwegian Data Protection Council on Article 25 Data Protection by Design and by Default, section 69 and 70.
47See the Guidelines 05/2020 on consent under Regulation 2016/679, paragraph 58.
48Ibid. paragraph 90.
16For the processing of personal data based on Article 6(1)(f) of the GDPR to be lawful, three cumulative conditions must be met: 1) that the controller pursues a legitimate interest, 2) that the processing of the personal data is necessary for the purposes of the legitimate interest, and 3) that the interests or fundamental rights and freedoms of the data subject are not overridden by the legitimate interests of the controller or of a third party. 49
In the final part of the three-step test, the balancing of interests, the controller must assess the reasonable expectations of the data subjects. The interests and fundamental rights of the data subject may in particular override the interests of the controller if the personal data are processed in circumstances where the data subject reasonably expects that the data will not be further processed. In cases where the initial processing is based on consent, this will normally exclude further processing based on Article 6(1)(f). The Norwegian Data Protection Council has on several occasions stated its views on the conditions for further processing of personal data collected on the basis of consent. 52
5.2.3 The Norwegian Data Protection Authority's assessment
We refer to our assessment under point 5.1 regarding consent to membership in the customer club. We
concluded that the purpose of the processing is not sufficiently specified, cf.
Article 6(1) of the General Data Protection Regulation. It is therefore not possible for Elkjøp to determine that the purposes of processing personal data in the customer club and customer match are
identical.
49 See C-252/21 Bundeskartellamt para. 106, C‑708/18 Asociaţia de Proprietari bloc M5A-ScaraA dep. 40.
50 See C-252/21 Bundeskartellamt desp. 110–116.
51
52 See the Personal Protection Ordinance's recital 47 and C-252/21 Bundeskartellamt section 112.
This has been discussed in particular in connection with the collection of personal data through tracking tools, because
the Data Protection Directive requires consent for such collection, cf. Directive 2002/58/EC Article 5(3).
The consent requirement is the same under the Data Protection Directive and the General Data Protection Regulation, cf.
Article 2(f) of the Data Protection Directive. The statements of the Norwegian Data Protection Council are therefore also relevant for other
cases where personal data have been collected on the basis of consent and the controller wishes to
process the personal data. The Norwegian Data Protection Council's Guidelines 4/2020 on the use of location data
and contact tracing tools in the context of the COVID-19 outbreak, version 1.1, adopted on 21 April 2020, section 13,
state the following: «i)ndeed, when data have been collected in compliance with Art. 5(3) of the ePrivacy Directive,
they can only be further processed with the additional consent of the data subject or on the basis of a Union or
Member State law which constitutes a necessary and proportionate measure in a democratic society to
safeguard the objectives referred to in Art. 23 (1) GDPR." See also the Norwegian Privacy Council's Guidelines 01/2020 on
processing personal data in the context of connected vehicles and mobility related applications, version 2.0,
adopted on 9 March 2021, sec. 53: "When data is collected on the basis of consent as required by art. 5(3) of the
ePrivacy directive or on one of the exemptions of art. 5(3), and subsequently processed in accordance with art. 6
GDPR, it can only be further processed either if the controller seeks additional consent for this other purpose or
if the data controller can demonstrate that it is based on a Union or Member State law to safeguard the
objectives referred to in Art. 23 (1) GDPR. The EDPB considers that further processing on the basis of a
compatibility test according to Art. 6(4) GDPR is not possible in such cases, since it would undermine the data
protection standard of the ePrivacy directive. Indeed, consent, where required under the ePrivacy directive,
needs to be specific and informed, meaning that data subjects must be aware of each data processing purpose
and entitled to refuse specific ones. Considering that further processing on the basis of a compatibility test
according to Art. 6(4) of the GDPR is possible would circumvent the very principle of the consent requirements
set forth by the current directive."
17In cases where customers have agreed to become members of the customer club in order to receive discounts, the processing of personal data in the customer match tool, in particular with the aim of ensuring better utilisation of media investments, cannot be considered to be the same purpose for which the data was originally collected.
Elkjøp therefore incorrectly assumed that a compatibility assessment was not necessary. By failing to assess whether the purpose of the processing of personal data in the customer match tool was compatible with the purpose for which the personal data was originally collected, Elkjøp violated Article 6(4) of the GDPR.
In assessing whether Article 6(f) can be a basis for processing, the controller must assess the reasonable expectations of the data subject. In light of the principle of fairness, the customer could not reasonably expect that the personal data collected with consent would at a later date be processed for other purposes and in a different manner than the one to which the customer had consented, cf. Article 6(1)(f). The very aim of consent is that the data subjects should be able to make a choice and foresee the consequences of such a choice. The processing of personal data in customer match includes, for example, sharing personal data with third parties – something that the customers neither consented to nor could reasonably expect when they joined the customer club. 54
We conclude that Elkjøp has processed personal data in the customer match tool without an appropriate legal basis, as Article 6(1)(f) does not apply, in light of Article 5(1)(a).
5.2.4 Elkjøp's comments on the prior notice
Elkjøp disputes the Danish Data Protection Authority's conclusion that Elkjøp has breached both Article 6(4) and
Article 6(1), and claims that "Elkjøp assessed the compatibility issue as part of its overall legal assessment" (our translation). In this regard, the Danish Data Protection Authority notes that Elkjøp stated during the on-site inspection that they had not carried out any assessment under Article 6(4), because they considered it unnecessary. Any assessments made after the on-site inspection do not affect the Danish Data Protection Authority's conclusion as to whether there was a breach of Article 6(4) at the time of the inspection. As Elkjøp did not document such an assessment, and during the on-site inspection expressly stated that such an assessment was not made, the Norwegian Data Protection Authority has no reason to conclude otherwise.
Elkjøp further states that “the Norwegian Data Protection Authority’s current emphasis on an assessment under Article 6(4) appears to deviate from the approach in the Christmas calendar case” (our translation). The Norwegian Data Protection Authority did not assess Article 6(4) in the Christmas calendar case, as the case did not concern a situation of further processing. In the Christmas calendar case, the Norwegian Data Protection Authority took a position on a situation where the various
53See recital 50 of the General Data Protection Regulation.
54See final inspection report, section 3.3.1.2. See also information in Elkjøp's privacy policy, point 7, at
https://www.elkjop.no/kundeservice/gdpr-personvernerklaring, last visited on 27 May 2026.
55See Elkjøp's comments on the notice, p. 8.
56Ibid. p. 8.
18The purposes of the processing were known to Elkjøp at the time of the collection of the personal data. In this case, however, Elkjøp has implemented customer match, which meant that personal data that was previously collected in the customer club was processed for new purposes at a later date.
The Norwegian Data Protection Authority emphasizes that the establishment of a new basis for processing according to the principle of legality does not give rise to a derogation from the independent requirement to carry out a compatibility assessment in line with the purpose limitation principle. The Article 29 Working Party has stated that “[p]rocessing of personal data in a way incompatible with the purposes specified at
collection is against the law and therefore prohibited. The data controller cannot legitimise
incompatible processing by simply relying on a new legal ground”. 57
As described above, further processing based on Article 6(1)(f) will normally be excluded when personal data are collected with consent, cf. Article 6(1)(a),
since it would undermine the very purpose of the consent. In light of the principle of fairness
data subjects cannot reasonably expect that personal data will be processed beyond what they have consented to. Elkjøp’s statements on the balancing of interests under Article 6(1)(f) do not change this. The EDPB has repeatedly stated that when personal data are collected on the basis of consent, further processing is only permitted if the data subject gives further consent or on the basis of Union or Member State law. It is beyond the scope of this case to assess documentation submitted after the time of the inspection, but this point seems to be missing from Elkjøp's assessments. We note for the record that in cases where all processing purposes have been identified and specified in advance, Article 6(4) does not apply, as there is no further processing. In these cases, Elkjøp does not need to carry out a compatibility assessment. Instead, Elkjøp must identify the appropriate grounds for processing and ensure transparency towards data subjects, so that they are informed at the time of collection how their personal data will be processed. 57
58See Article 29 Working Party Opinion 03/2013 on purpose limitation p. 3.
Council Guidelines 4/2020 on the use of location data and contact tracing tools in the context of the
COVID-19 outbreak, version 1.1, adopted on 21 April 2020, paragraph 13. See also Council Guidelines 01/2020
on processing personal data in the context of connected vehicles and mobility related applications, version 2.0,
adopted on 9 March 2021, paragraph 53. We understand that the European Commission has expressed a similar view, cf.
https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/principles-
gdpr/purpose-data-processing/can-we-use-data-another-purpose_en. The Commission has stated that “If your company/organisation has collected the data on the basis of consent or following a legal requirement, no further processing beyond what is covered by the original consent or the provisions of the law is possible. Further processing would require obtaining new consent or a new legal basis”.
59We also note Elkjøp’s claim that only names and contact information will be shared. Information on which segment a data subject belongs to, which advertisements they should see, and information on online behaviour can often be shared in connection with customer matching. This can also constitute personal data.
195.3 Offline conversions
5.3.1 Further details on the facts of the case
Elkjøp uses offline conversions to measure and estimate the effect of digital marketing on in-store sales. After a purchase in an Elkjøp store, Elkjøp sends information to Google and
60
Facebook to measure sales in the store against "clicks" on Facebook and Google ads.
Elkjøp has informed us that the processing basis for this processing is
Article 6(1)(f) of the GDPR 61
During the on-site inspection, Elkjøp explained that offline conversions are used for
customer club members. Following the on-site inspection, Elkjøp has informed the Norwegian Data Protection Authority
that they have discontinued the use of offline conversions with Meta (Facebook), due to
63
unclear terms in Meta's data processing agreement. As we have not received information to the contrary, we assume that Elkjøp continued the use of offline conversions with Google.
64
We refer to the final inspection report, section 3.3.1.2.
5.3.2 Legal basis
In line with the accountability principle in Article 5(2), the controller is responsible for
and must be able to demonstrate that the principles for the processing of personal data are complied with. This
means, among other things, that the controller must ensure, and must be able to demonstrate, that
the processing is lawful pursuant to Article 5(1)(a), i.e. that the processing has a valid
legal basis.
See the explanation of Article 6(1)(f) under section 5.2.2.
5.3.3 The Norwegian Data Protection Authority's assessment
In advance of the on-site inspection, Elkjøp submitted an assessment of legitimate interest as a basis for
processing for the use of offline conversions. 65
In the opinion of the Norwegian Data Protection Authority, this assessment does not meet the requirements of
Article 6(1)(f) of the GDPR. In general, the assessments are quite brief, and
the balancing of interests lacks key elements such as the number of data subjects affected, the categories of data processed, the processing of children's personal data, the reasonable expectations of the data subjects and, in addition, the possible negative consequences of potentially sharing the data subjects' personal data with Facebook and Google. Without having
60
61See document 22/00049-4 “Supervision documentation to 2.6.2022 (part 1)”, slide 35.
See document 22/00049-4 “f) Legitimate interest offline conversions”.
62See the final supervision report, section 3.3.1.2.
63See Elkjøp’s comments to the preliminary supervision report, 22.06.2023, in the email dated 22.06.2023.
64The Danish Data Protection Agency has received a complaint that Elkjøp shares personal data with Facebook. See the Danish Data Protection Agency’s case
21/01054 and Elkjøp’s response to the Danish Data Protection Agency’s questions in document 21/01054-8.
65See document 22/00049-4 “f) Legitimate interest offline conversions”.
20 having mapped the possible negative consequences for the data subjects, Elkjøp is not able to
conduct a correct balance of interests, cf. Article 6(1)(f) of the General Data Protection Regulation. Elkjøp can therefore not determine that the processing is lawful pursuant to Article 5(1)(a) of the General Data Protection Regulation.
The Danish Data Protection Authority has not concluded whether Article 6(1)(f) can be a basis for processing for Elkjøp's possible use of the offline conversions tool. However, Elkjøp should
make thorough assessments before continuing to use this tool.
The conclusion is that the inadequate assessment and documentation of the basis for processing, and thus the lawfulness of the use of offline conversions, constitutes a
violation of Article 5(2) of the General Data Protection Regulation, cf. Article 5(1)(a).
5.3.4 Elkjøp's comments on the prior notice
Elkjøp states that the Danish Data Protection Authority sets unreasonably strict requirements for the assessment of low-risk processing. Elkjøp states that the assessment of legitimate interests correctly reflects the limited scope of the processing and that the measures taken are industry standard.
According to Article 5(1)(a) and Article 5(2), it is the controller who must demonstrate that personal data are processed lawfully, fairly and transparently. An inherent element of Article 6(1)(f) is the assessment of whether the controller’s legitimate interests are overridden by the interests or fundamental rights and freedoms of the data subject, which means that the interests, rights and freedoms of the data subject must be assessed explicitly. In this case, Elkjøp has omitted such elements from its assessment of legitimate interests.
We emphasize that the level of detail in a balancing of interests (which is the third step in the 67 three-step assessment of legitimate interests) depends on the processing in question.
However, Elkjøp's assessment lacks the most fundamental elements that must always be part of a balancing of interests, and therefore does not meet the minimum criteria in any case. Without mapping out the possible consequences and the impact on the data subjects, there is in practice no balancing of interests.
Elkjøp requests clarification on the level of detail expected to meet the requirement. Elkjøp must identify which interests, rights and freedoms may be affected by the processing in question, including how and to what extent these may be affected. Elkjøp's assessment of legitimate interests does not include an overview of the interests of the data subjects that may be negatively affected by the processing in question, even though this is an element that must be assessed in accordance with Article 6(1)(f). Elkjøp claims that the processing in question meets the balancing of interests. However, a proper assessment of, among other things, the number of data subjects affected, the categories of data processed, whether and in
66
67See C-252/21 Bundeskartellamt para. 95.
Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR paras. 45–49. See also Article
29 Working Party Opinion 06/2014 on the legitimate interests of the controller under Article 7 of Directive
95/46/EC (WP 217, adopted on 9 April 2014).
21the extent to which data concerning children are likely to be processed, the reasonable expectations of the data subjects and also the possible negative consequences of potentially sharing the data subjects' personal data with third parties such as Facebook and Google. These elements will help the controller to assess how and to what extent the processing affects the interests, rights and freedoms of the data subjects. The Board has published comprehensive guidelines on the legitimate interests assessment. The guidelines contain a methodology for the balancing of interests, including how the processing of children's personal data should be reflected in the assessment. 68
The Danish Data Protection Agency is concerned that Elkjøp will not have sufficient understanding of the processing to be able to determine whether it is lawful before the necessary elements have been included in the assessment of legitimate interests. Unfortunately, Elkjøp’s comments to the notification have substantiated this concern. For example, Elkjøp claims that Google only receives personal data that it already possesses. At the same time, Elkjøp states that they share the fact that a person has made a purchase in an Elkjøp store together with “conversion data”, which is information that Google may not already possess. Elkjøp also claims that the processing is not directed at children and that children’s personal data will only be processed incidentally. However, this claim overlooks the fact that the age limit for the customer club was 15 years and that children’s personal data was therefore an intended part of the processing. An updated assessment of legitimate interests will help Elkjøp to assess these matters further.
5.4 Time limit for processing requests from data subjects (rights requests)
5.4.1 Details of the facts of the case
During the on-site inspection, Elkjøp informed us that there were unresolved rights requests from data subjects dating back to at least December 2021. In the documentation submitted after the on-site inspection, Elkjøp showed that they had cases that were opened in February 2021 and that had not been resolved at the time of the inspection in June 2022. 70
Elkjøp also shared documentation showing that as of 1 June 2022, there were 75 unresolved rights requests where the one-month deadline had expired. According to Elkjøp’s procedures, the customer center will send these customers a notification.
According to Elkjøp’s compliance team, the customer center is instructed to resolve all requests within 30 days. Furthermore, Elkjøp has explained that if the routine has been exceeded in individual cases, this is due to deviations from their processes or that the case is particularly complex. 71
According to a Data Protection Authority customer service employee interviewed during the on-site inspection, there is
no routine for how the employee should assess the complexity of a request and thus
extend the deadline. The customer service employee explained that he has not previously assessed
68Ibid. paras. 44 and 91–97.
69See the final inspection report, section 3.4.2.2.
70See document 22/00049-9 “Report on cases older than 30 days 2022-06-22”.
71See the final inspection report, section 3.4.2.2.
22the complexity of a request. According to Elkjøp’s compliance team, requests for rectification of the data subject’s email address are considered complex, and Elkjøp therefore extends the deadline by one month when processing such requests. 72
When the deadline is missed in new rectification cases, the customer receives a message from Elkjøp explaining that they are “currently experiencing technical difficulties”, that they are unable to correct the error and are working on finding a solution. When Elkjøp contacts the customer about an old rectification case where the one month deadline has been missed, they inform the customer that they are having problems correcting customer profiles following changes made to their systems and that they have not yet succeeded in correcting the error.
5.4.2 Legal basis
Article 12 of the GDPR sets out the method and procedure for handling requests (rights requests) from data subjects. The purpose of Article 12 is to ensure that data subjects can exercise their rights effectively, so that they have control over their personal data.
According to the first and second sentences of Article 12(3) of the GDPR, the controller shall inform the data subject of the action taken on a request pursuant to Articles 15-22 without undue delay and no later than one month after receipt of the request. This period may be extended by a further two months where necessary, taking into account the number and complexity of the requests.
According to the third and fourth sentences of Article 12(3) of the GDPR, the controller shall inform the data subject of any such extension no later than one month after receipt of the request, together with a justification for the delay.
5.4.3 The Danish Data Protection Authority’s assessment
In the opinion of the Danish Data Protection Authority, a request for rectification of an email address is not in itself complex. Unless exceptional circumstances arise, e.g. When a large number of data subjects request rectification at the same time, it will not normally be necessary under Article 12(3) of the GDPR to extend the one-month deadline for such requests. We understand that there have been technical problems, but it is nevertheless Elkjøp's obligation to facilitate the exercise of data subjects' rights under Article 12(2). If Elkjøp's systems are designed in such a way that it is not possible to rectify personal data, this does not justify an exception to the obligation to facilitate the rights of data subjects. However, it raises the question of whether Elkjøp has fulfilled its obligations under Article 12(2) in a satisfactory manner. Elkjøp should therefore have been able to comply with these requests within the one-month deadline, and by failing to do so, Elkjøp has breached Article 12(3).
72
73Ibid.
Ibid. The Norwegian Data Protection Authority has received complaints that requests for data subjects' rights are not processed within the deadline in Article 12(3) of the GDPR.
23The possibility of extending the deadline in Article 12(3) of the GDPR is an exception to the one-month deadline and shall be treated as such. It is therefore only possible to invoke an extension after a specific assessment in each individual case. The fact that Elkjøp considers all requests for redress as complex, and thus automatically extends the deadline by one month, is therefore not in accordance with Article 12(3).
Furthermore, Elkjøp has explained that for several requests the two-month extension has also been exceeded, and there are unresolved requests dating back to February 2021. This is also a
violation of Article 12(3).
The conclusion is that Elkjøp has violated Article 12(3) of the GDPR by failing to
process requests for redress that were not complex within the one-month deadline, by
automatically considering requests for redress as complex, which triggered an extension of the deadline
by one month, and by not processing requests from data subjects within the extended three-month deadline.
5.4.4 Elkjøp's comments on the pre-notification
Elkjøp acknowledges that some requests were not processed within the GDPR deadline. However, Elkjøp reiterates the background to this error and emphasises that the majority of requests were handled correctly. Based on this, Elkjøp argues that there is no basis for a breach fee, as the underlying issue has now been resolved. We interpret this as an argument as to whether it is necessary and proportionate to impose a fee. The seriousness of the breaches will be assessed in section 6.2.
Furthermore, Elkjøp argues that some of the requests may fall outside the scope of GDPR Article 16 on rectification, stating that "it is not obvious that an email address provided as a unique identifier is incorrect as such, even if 75n data subjects would like to change to a different email address" (our translation).
The deadline in Article 12(3) applies to requests for rights, cf. Articles 15-22. In cases where the controller refuses a request after having thoroughly assessed the accuracy of the personal data, cf. Article 16, the refusal shall be communicated within the deadline set out in Article 12(4), which corresponds to the time frame in Article 12(3). The refusal shall state the reasons for not taking action and the possibility of lodging a complaint with the supervisory authority. This has not happened in any of the cases in question. If Elkjøp now claims that it considered some of the requests to rectify
as unfounded, this would amount to admitting a breach of Article 12(4), which is
just as punishable as a breach of Article 12(3).
In this case, however, the e-mail addresses are not only used as identifiers, but also to
send receipts, newsletters and marketing material to the data subjects. If Elkjøp's
systems do not correctly reflect the data subjects' current electronic address for receiving
74
See point 3.4.2.2 of the final supervisory report and document 22/00049-9 "Report on cases older than 30 days
7522-06-22".
See Elkjøp's comments on the notification p. 13.
24such communication, it can be claimed that the personal data are incorrect. In the notes to the notification, Elkjøp points out that the members of the customer club expect and want to receive such information from Elkjøp. If the email addresses are not updated, the customers may miss out on this information. Furthermore, messages containing personal data may be shared with unintended recipients. The problem of delayed processing of rights requests is also not limited to cases where the data subject simply wants to change their email address. During the inspection, Elkjøp informed the Norwegian Data Protection Authority76 that one of the cases with a delay concerned a receipt that was registered to the wrong customer. Another example can be found in our case with reference no. 20/02353, where a data subject had provided the wrong email address during the registration process. As a result, Elkjøp's systems sent the data subject's personal data, including receipt and payment information, to the wrong recipient. The data subject contacted Elkjøp repeatedly from
April 22, 2020 to request rectification. However, the email address was not corrected until November 27, 2020. We closed the case in June 2021 because Elkjøp assured that they were working to resolve the
problem.
In other words, Elkjøp was aware of extensive violations of the data subjects' rights long before
the time of the inspection, which is an aggravating circumstance.
Elkjøp states that while the technical problem was being resolved, customers were informed that they
could create a new account and request that the old one be deleted. The Danish Data Protection Authority notes that this
is not sufficient, as it is the responsibility of the controller to facilitate
the data subject's exercise of his or her rights under Article 12(2), including the right to rectification. In addition, such a solution may entail the deletion of information that the customer wishes to keep in their account, such as purchase history and receipts.
For the record, the Data Protection Authority notes that the violation of Article 12(3) in itself is not very serious. However, we believe that it is necessary to impose a fine, as Elkjøp has violated several provisions of the GDPR, and together these violations are of medium seriousness, as explained below. We would like to emphasize that due consideration has been given to the seriousness of the violation when determining the fine.
6. Imposition of a fine
6.1 Introduction
The Data Protection Authority may impose fines, cf. Article 83(1), for violations of provisions of the GDPR if the conditions for a fine are met. A fine is considered a penalty under the European Convention on Human Rights (ECHR).
76
77See the final supervisory report p. 30.
See the Public Administration Act § 43. See also Rt. 2012 p. 1556.
25In order to impose a fee, there must be a clear preponderance of probability for the violations. A
violation fee can only be imposed if a controller has intentionally or negligently
violated the General Data Protection Regulation. 78
As explained above, the Danish Data Protection Authority has found four breaches of the GDPR that provide grounds for sanctions: i) GDPR Article 6(1), cf. Article 4(11), by failing to obtain valid consent for the processing of personal data in Elkjøp's Customer Club, ii) GDPR Article 6(1) and (4) by further processing personal data through the use of the customer match tool without a valid legal basis and without assessing the compatibility of the purposes, iii) GDPR Article 5(2), cf.
GDPR Article 5(1)(a), by failing to demonstrate the lawfulness of the processing of personal data through the use of the offline conversions tool and iv) GDPR Article 12(3) by failing to process requests from data subjects within the statutory deadlines.
The violations have been revealed through evidence presented by Elkjøp and documented during the on-site inspection. The facts of the case are documented in the inspection report, which Elkjøp has commented on.
The Norwegian Data Protection Authority finds that there is a clear preponderance of probability that Elkjøp has committed these violations.
The Norwegian Data Protection Authority further concludes that there is a clear preponderance of probability that
79
the fault requirement has been met in this case. In the Norwegian Data Protection Authority's opinion, the violations show that
Elkjøp has acted intentionally. We will return to this in section 6.4.
The decision whether to impose a violation fee, as well as the size of the fee, is based
on an overall assessment of several factors, cf. Article 83 of the General Data Protection Regulation. Corresponding factors can be found in Section 46 of the Public Administration Act.
The Norwegian Data Protection Authority believes that there are grounds for imposing a fine in this case. In the following, we explain why we believe it is necessary to impose a fine, as well as the determination of the amount of the fine.
78See C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin, paragraph 78, with reference to Article 83 of the General Data Protection Regulation. See also Section 46 of the Public Administration Act.
79The minimum requirement for imposing a fine is that the violation was committed negligently. Anyone who acts in violation of the requirement for responsible conduct in an area, and who can be blamed based on his personal circumstances, is negligent, cf. Section 23 of the Criminal Code. The Norwegian Data Protection Authority notes that the standard of care is normally considered to be strict for undertakings that conduct economic activities, cf. Bill 81 L (2021–2022) point 5.5. The Danish Data Protection Authority believes that the strict standard of care must be applied in this case. Elkjøp is a commercial multinational company that processes personal data on a large scale. In the Danish Data Protection Authority's opinion, it must therefore be expected that Elkjøp is familiar with the key data protection requirements, including legality and the rights of the data subject. In light of the low threshold for establishing negligence for large commercial operators and the fact that the violations concern some of the most central provisions of the GDPR, the Danish Data Protection Authority concludes that there is a clear preponderance of probability that Elkjøp has at least acted negligently when they committed the violations. 266.2 Assessment of whether to impose a violation fine 6.2.1 Overview Article 83(1) of the GDPR stipulates that the imposition of violation fines in each individual case must be effective, proportionate and dissuasive.
Article 83(2) further provides that “when deciding whether to impose a fine and the amount of the fine, due regard shall be had in each case to the following:
(a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purposes of the processing concerned and the number of data subjects affected and the extent of the damage suffered by them;
(b) whether the infringement was committed intentionally or negligently;
(c) any measures taken by the controller or processor to limit the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor, taking into account the technical and organisational measures implemented by them in accordance with
Articles 25 and 32;
(e) any relevant previous infringements committed by the controller or processor;
(f) the degree of cooperation with the supervisory authority to remedy the infringement and to mitigate its possible adverse effects,
(g) the categories of personal data affected by the infringement,
(h) the manner in which the supervisory authority became aware of the infringement, in particular whether and, where appropriate, to what extent the controller or processor has notified the infringement,
(i) where measures referred to in Article 58(2) have previously been taken against the controller or processor concerned in respect of the same subject matter,
compliance with those measures,
(j) compliance with approved standards of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 and
(k) any other aggravating or mitigating factors in the case, such as economic benefits gained or losses avoided, directly or indirectly, as a result of the infringement.
The Norwegian Data Protection Authority has carefully considered the elements in Article 83(2)(a)–(k). Below, we will consider the elements that we consider to be particularly relevant and that we have placed great emphasis on. This applies in particular to letter a concerning the nature, seriousness and duration of the violations, which we believe indicate that a violation fee is appropriate, and the mitigating
circumstances under letters f and k. In this case, we believe that letter h also tends to be somewhat aggravating. In the opinion of the Norwegian Data Protection Authority, the elements in Article 83(2)(e),
i and j are irrelevant in this case. The elements in Article 83(2)(c), d and g are also less relevant. We believe that these elements neither tend to be mitigating nor aggravating
6.2.2 Nature, gravity and duration of the infringements
The infringements in this case are subject to the highest level of sanction in the two-tier system of the GDPR (i.e. Article 83(5)). The Data Protection Board has stated the following in Article 83(2)(a): “in setting up two different maximum amounts of administrative fine (10/20 million EUR), [the GDPR] already indicates that a breach of some
provisions of the Regulation may be more serious than for other provisions”. 81
We also note that the infringements concern key provisions and principles of the GDPR and data protection legislation, including the principles of fairness, purpose limitation, legal basis and the rights of the data subject. Lack of a
basis for processing in combination with a failure to enforce the rights of the data subject
can potentially significantly undermine the fundamental rights of individuals. We therefore find that the violations are of such a nature that they affect key parts of the right to privacy.
Elkjøp is the Nordic region's leading retailer of consumer electronics and delivers its products directly to customers both online and through more than 400 stores. Elkjøp has reported a customer base of 11 million, and that 6.7 million are members of the customer club. The 82 cross-border element in this case and the large number of customers and customer club members mean that a large number of data subjects are affected. The Danish Data Protection Authority believes that a large and multinational company such as Elkjøp should have sufficient routines and procedures in place to be able to respond quickly and adequately to rights requests from data subjects, and a legal basis for its processing of personal data. In addition, the processing activities include the processing of children's personal data. This makes the violations more serious.
When assessing the seriousness of the infringements, we also take into account that the processing in question is related to business activities. We believe that the purpose of the processing in the customer club falls within Elkjøp's core business, as this is a way for Elkjøp to conduct marketing. The more central the processing is to the controller's core business, the more serious any irregularities in this processing will be. 83
81Article 29 Working Party Guidelines on the application and setting of administrative fines for the purposes
of Regulation 2016/679 (WP 253, adopted 3 October 2017) p. 9.
82See the final inspection report, point 3.3.1.2 and document 22/00049-4 “Inspection documentation as of 2.6.2022
(part 1)”, slide 24.
83Personvernrådets Guidelines 04/2022 on the calculation of administrative fines under the GDPR, point 4.2.1
paragraph 53(b)(iii).
28As regards the duration of the infringements, Elkjøp informs the Data Protection Authority that the customer club was established in Norway, Denmark and Finland in 2019 and in Sweden in 2016. The Customer Match tool was launched in June/July 2022, after a trial period. Following the on-site inspection, Elkjøp shared documentation showing that there were unanswered requests from data subjects back to February 2021. 85Based on the above, we consider the infringement to be of medium seriousness. The nature and severity of the infringement, as well as the duration of the infringements, are aggravating factors. In this case, several data subjects brought some of the infringements to the attention of the Data Protection Authority, as a result of Elkjøp failing to process the requests that various data subjects brought to Elkjøp’s attention over a three-year period. The Norwegian Data Protection Authority considers this to be aggravating, cf. Article 83(2)(h). 86
6.2.3 The requirement of fault (whether the infringement was committed intentionally or negligently)
As mentioned in point 6.1, intent or negligence is a condition for imposing an infringement fine
under Article 83(2).
In addition to being a condition for imposing an infringement fine, the intentional or negligent nature of the infringement is also a factor in the assessment of whether an infringement fine should be imposed, and in determining the amount, cf. Article 83(2)(b).
As the Court of Justice of the European Union has noted, “it is not necessary for there to have been action by or even 87 knowledge on the part of the management body of that legal person” in order to establish fault.
Intention exists when a controller commits an act that covers the description of the offence in the relevant provision, with the intention or awareness that the act
88 will certainly or most likely cover the description of the offence. This means that the controller must be aware of all the relevant factual circumstances that constitute the offence. On the other hand, it is not necessary to establish that the controller was aware that the act
89 was unlawful.
The Norwegian Data Protection Authority believes that the infringements in this case were committed intentionally. Elkjøp, including
persons in relevant management positions and employees at Elkjøp, have deliberately chosen the relevant
84See the final supervisory report, section 3.3.1.2.
85Ibid. section 3.4.2.2.
86The Norwegian Data Protection Authority acknowledges that Elkjøp was not obliged to report the infringements to us on its own initiative, and that
it is not an aggravating circumstance that a controller has not immediately reported a
violation to the Norwegian Data Protection Authority. The controller's negligent conduct before the supervisory authority became aware of the infringement(s) in question, which ultimately triggered the supervisory authority's involvement in the case, may also
be considered by the Norwegian Data Protection Authority as warranting a more severe penalty. See the Article 29 Working Party Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679 (WP 253, adopted 87 October 2017) p. 15.
See C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin, paragraphs 76–77.
88See the Penal Code, section 22. It follows from the case-law of the Supreme Court that the starting point is that the requirement of guilt must be interpreted in the same way as in criminal law, cf. Rt-2012-1556, paragraph 63.
89Rt-2015-1124, paragraph 11.
29the consent solution. The design of the consent was a deliberate commercial choice. Any 90misunderstanding or misinterpretation of the requirements of the law cannot be considered excusable. Elkjøp
had discussed the solution internally, and acknowledged that there was a risk that the data protection authorities
would find the consent solution to be in breach of the GDPR. 91
Similarly, Elkjøp has actively chosen to use the tools customer match and offline conversions. However, Elkjøp’s assessments of the legality of the tools have not been in line with the requirements of the GDPR. Regardless of whether Elkjøp itself considered these assessments to be satisfactory, the use of these tools and the way in which the assessments were carried out are deliberate actions. We therefore believe that these breaches were committed intentionally.2
Furthermore, Elkjøp has overstayed the deadline for processing requests from data subjects for a significant period of time. Requests for redress have been automatically categorised as “complex”, which has led to the deadline being extended. This systematic problem had not been handled and resolved, even though the problems had existed since at least December 2021. Elkjøp has stated that they were aware of this, but that they were experiencing technical problems. This may be an explanation, but it does not excuse or exempt Elkjøp from the fact that the use of the technical solution was the result of a conscious choice. It is not necessary to refer to identified persons who have acted negligently or intentionally on behalf of the company, beyond pointing out that someone has clearly made the choices on behalf of Elkjøp. 93 In the opinion of the Norwegian Data Protection Authority, the violations are therefore intentional. The degree of culpability indicates that there is a basis for a fee in this case, and that the fee should be of a certain size. Elkjøp's comments on the advance notice
In its written comments, Elkjøp acknowledges that the consent solution for the customer club, as well as the use of customer match and offline conversions, were conscious business choices. However, Elkjøp claims that the solutions and tools were not used knowingly and intentionally to violate the GDPR, and that there is therefore no basis for a violation fee. Firstly, we emphasize that intent is not a prerequisite for imposing a violation fee.
Negligent violations are also covered, as explained below. Secondly, the concept of intent is linked to the controller's awareness of the action itself, not to the controller's awareness that the action is illegal.
In this regard, we refer to the judgment of the European Court of Justice in the Deutsche Wohnen case. In interpreting
the concept of fault, the court clarified that a controller can be sanctioned “whether
90See Section 26 of the Penal Code: “Anyone who, at the time of the act, due to ignorance of legal rules, is unaware that
the act is illegal shall be punished when the ignorance is negligent.”
91See document 22/00049-9 “Answers to questions after day 1”, slide 5.
92See the final supervisory report, point 3.3.1.2. See also document 22/00049-4 “Supervisory documentation until
2.6.2022 (part 2)”, slide 7.
93Cf. HR-2022-1271-A, paragraphs 36–50 and C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft, paragraphs 44–46 and 51.
30 94
or not it is aware that it is infringing the provisions of the GDP”. Borgarting Court of Appeal
had a similar approach in LB-2024-154313 (Grindr), where the court concluded that
Grindr acted intentionally because persons acting on behalf of Grindr were aware of and made a demonstrable choice to carry out the acts that constituted the infringements of the GDPR.
The intentional or negligent nature of the infringement is explicitly listed as one of the factors that the supervisory authority must take into account in the decision whether to impose an infringement fine and the determination of the amount of the fine, cf. GDPR Article 83(2)(b).
Intentional infringements – even where the controller was not aware that the acts were unlawful – are generally considered to be more serious than negligent infringements.
Elkjøp's argument that they did not intend to infringe the GDPR must therefore be rejected. Firstly, lack of intent does not in itself exclude liability, and secondly, we find it proven that the conduct that constituted the infringements of the GDPR was intentional within the meaning of GDPR Article 83(2)(b).
6.2.4 Cooperation with the supervisory authority and long case processing time
The Danish Data Protection Authority considers Elkjøp's cooperation to be a mitigating circumstance pursuant to Article 83(2)(f). Elkjøp has been cooperative throughout the inspection.
Furthermore, there appears to be an increasing awareness and knowledge of data protection at Elkjøp, and there has been a positive development in recent years. Elkjøp itself uncovered some violations, and
initiated processes to rectify this immediately after the on-site inspection. For example, Elkjøp has informed us that they completed and implemented a technical solution for
handling requests for corrections in June 2023, and that they have put in place a solution that allows
customers to unsubscribe from newsletters via My Page. 96
The Danish Data Protection Board's practice indicates that long case processing time is a factor that must be assessed
pursuant to Article 83(2)(k) of the GDPR. In this case,
the case processing time has been considerable. Although the documentation is extensive and the inspection in
the initial had a broad scope, the complexity of the case does not justify the processing time. Part of the delay is due to slow progress on the part of the Danish Data Protection Authority. We believe that this is a mitigating circumstance. We have taken these mitigating circumstances into account in determining the amount of the fee, cf. point 6.4 below. 94 See C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft, paragraph 76. See analogously C-681/11 Schenker & Co. and Others, EU:C:2013:404, paragraph 37 and the cited case law. 95 See LB-2024-154313 Grindr under the section "The requirement of fault and the degree of fault" 96 See Elkjøp's comments on the preliminary supervisory report, 22.06.2023. 97 See the decisions PVN-2021-03, PVN-2021-13, PVN-2021-16, PVN-2022-03 and PVN-2024-19.
316.2.5 Elkjøp's comments on the advance notice
Elkjøp states that the mitigating circumstances have not been given sufficient weight when
assessing whether a fine should be imposed, and when determining the amount of the fine.
Elkjøp states that several improvements have occurred since the on-site inspection and suggests that
the Danish Data Protection Authority has not placed sufficient weight on these improvements. In this regard,
the Danish Data Protection Authority notes that due consideration has been given to developments since the inspection as mitigating
circumstances, as explained in section 6.4 below. The fee of NOK 20,000,000 is significantly
lower than the starting point in the Norwegian Data Protection Council's guidelines, where 0.4–0.8% of global
turnover (approx. 450,000 000–900 000 000 000 NOK) is given as a starting point. The Data Inspectorate
has taken particular account of the long case processing time and the relevant developments following the
on-site inspection.
With regard to the significance of improvements following the inspection, the Data Inspectorate also refers to the
Borgarting Court of Appeal's judgment in the Grindr case, which states that changes made to
99
bring an illegal relationship to an end cannot in itself be considered mitigating. In light of this, the Data Inspectorate believes that it is not appropriate to reduce the fee further.
Elkjøp states that the fee should have been further reduced due to the long case processing time. Elkjøp refers to the Telenor case100 and claims that the Data Inspectorate's own
practice indicates that long case processing time may indicate a greater reduction in the
violation fee. 101 In this regard, the Data Inspectorate notes that the decision to reduce the
notified fee in the Telenor case was mainly due to the fact that notification, new information was presented that significantly changed the Data Protection Authority's conclusions and the seriousness of the case. That is not the situation in this case.
The Data Protection Authority also notes that the Norwegian Data Protection Board's decision of 17 November 2025
signals a shift towards a percentage fee reduction linked to how long a case has been inactive.102 The Data Protection Authority's assessment and reduction based on the case processing time is
already more favourable to Elkjøp than the percentages that were used as a basis in the Norwegian Data Protection Board's decision following the notification.
Elkjøp further refers to an alleged industry practice, and claims that a significant number of stores103
structure customer clubs and similar marketing practices in similar ways.
The Data Protection Authority believes that this cannot be considered mitigating. This position is in line with the Borgarting Court of Appeal's decision in the Grindr case. In that case, the court warned that
if widespread illegal industry practices were to be emphasized in a mitigating manner, it could
weaken the deterrent effect of the infringement fee. It would also have undermined the purpose
98See Elkjøp's comments on the notice, p. 14.
99See LB-2024-154313 Grindr, p. 32.
100See Data Protection Authority case 21/03823.
101See Elkjøp's comments on the notice, p. 14–15.
102See PVN-2025-30 p. 11.
103See Elkjøp's comments on the notice p. 17.
32with the GDPR's enforcement regime. The fact that many in the industry are violating the law
104
underpins rather than reduces the need for a fee with a deterrent effect.
For the record, we emphasize that we have not imposed any sanction on Elkjøp for lack of
age verification measures, and we therefore do not consider Elkjøp's argument on this point to be
relevant.
According to Elkjøp, the Norwegian Data Protection Authority has claimed that violations are still ongoing. This is not correct,
as the Norwegian Data Protection Authority has only assessed Elkjøp's compliance at the time of the inspection.
6.3 Conclusion on whether a violation fee should be imposed
The Norwegian Data Protection Authority believes that the aggravating circumstances outweigh the mitigating ones in
the assessment of whether a violation fee should be imposed in this case. A violation fee is
necessary to have a real deterrent effect and prevent Elkjøp, as well as other
companies, from committing similar violations in the future, cf. Article
83(1) of the GDPR, which states that violation fees must be effective, proportionate and dissuasive. Enforcement must create sufficient pressure to make it economically unattractive in practice not to comply with the regulations. 105
6.4 Determination of the violation fee
Determination of the fee is not a mathematically precise exercise. 106The supervisory authorities have a certain margin of discretion in this regard. 107
In determining the amount, it follows from the case-law of the Court of Justice of the European Union that «where the addressee of the
administrative fine is or forms part of an undertaking, within the meaning of Articles 101 and
102 TFEU, the maximum amount of the administrative fine is calculated on the basis of a
percentage of the total worldwide annual turnover in the preceding business year of the
undertaking concerned», 108 cf. also recital 150 of the Data Protection Regulation. 109
104See LB-2024-154313 Grindr p. 31.
105See the Advocate General's Opinion in C-304/02 Commission v. France, paragraph 39.
106See, inter alia, T-425/18 Altice Europe NV v Commission, paragraph 107. 362 and T-11/06 Romana Tabacchi v Commission
107. 266.
See, inter alia, T-192/06 Caffaro Srl v Commission, paragraph 38. The supervisory authorities should nevertheless indicate which
circumstances have influenced the exercise of their discretion when setting a fee, cf. Decision
01/2022 of the Council on the dispute arising from the draft decision of the French Supervisory Authority regarding Accor SA under
Article 65(1)(a) GDPR, adopted on 15 June 2022, paragraph 75.
108See C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin, paragraph 57 and C-383/23 Anklagemyndigheden v.
ILVA A/S, paragraph 23. See also Guidelines 4/2022 on the calculation of administrative fines under the GDPR p. 36. In another case, the Data Protection Council has also adopted a binding decision instructing the data protection authority to take into account the total turnover of all the companies included in the individual undertaking, i.e. the total turnover of the group managed by the parent company. See Binding decision 3/2022 on the dispute submitted by the Irish SA on Meta Platforms Ireland Limited and its Facebook service (Art. 65 GDPR) adopted on 5 December 2022, para. 356. 109 Recital 150 of the GDPR states: “Where an undertaking is subject to an infringement fine, an undertaking shall be understood for these purposes as an undertaking within the meaning of Articles 101 and 102 TFEU.” 33Elkjøp Nordic AS and Elkjøp Norge AS are owned by Currys plc (Dixon group) (hereinafter "Currys"),
a leading retailer of technology products and services, operating online and through
110
708 stores in 6 countries. In this case, the infringement fee should therefore be calculated on the basis of
a percentage of Currys' annual turnover. 111
The infringements in this case qualify for an infringement fee pursuant to
Article 83(5) of the GDPR, cf. letters a and b of the provision. The maximum amount pursuant to
Article 83(5) of the GDPR is EUR 20,000,000, or in the case of an
undertaking, up to 4% of the total global annual turnover in the preceding
financial year, whichever is the higher.
When determining the infringement fee, the Norwegian Data Protection Authority takes into account Currys' turnover in the
112 preceding financial year. According to the annual accounts in Currys’ 2024/25 annual report, Currys’ total turnover in 2024/25 was GBP 8,706,000,000,113which is equivalent to approximately NOK 108,563,800,000 and EUR 10,052,205,000. 115
According to the Data Protection Board’s Guidance 4/2022, the first step in determining the infringement fee is to set the starting amount. As we have concluded that the infringements are of medium seriousness and Currys has a turnover of over EUR 500 million, the starting amount of the fee should be within the range of 0.4–0.8% of turnover. After this, the size of the infringement fee will be somewhere between 434,255,000 and 868,510,000 kroner.
Based on the elements in Article 83(2)(a)–(k), we believe that the infringements are of medium seriousness, but at the lower end of the scale. However, we believe that it is not necessary to impose an infringement fee within the range for starting amounts in the Data Protection Council's guidance of 0.4–0.8% of (global) turnover for the fee to be effective and dissuasive in this case.
In light of all the relevant elements of Article 83(2)(a) to (k), and in particular taking into account the
mitigating circumstances such as the long processing time and the developments following the inspection,
we conclude that the fee should be significantly lower than 0.4% of turnover (which
would correspond to approximately NOK 450,000,000). A lower amount would still be effective and dissuasive in this case, while being proportionate.
We consider that an infringement fine of NOK 20,000,000 is not disproportionate and is not
higher than necessary in this case to achieve the objective of the GDPR.
110See the final inspection report, section 3.1.1.2 and Curry's website at https://www.currysplc.com/our-brands/,
accessed 27 May 2026.
111
See the Data Protection Council's Guidelines 04/2022 on the calculation of administrative fines under the GDPR, section 124.
112also C-383/23 Anklagemyndigheden v. ILVA A/S, sections 23, 29 and 36.
113Guidelines 4/2022 on the calculation of administrative fines under the GDPR, section 38.
See Curry's annual report and accounts 2024/25, last accessed at Results, Reports & Presentations | Currys PLC, 24 March 2026.
114Based on the current exchange rate on 27 May 2026 of 12.47 for GBP to NOK, as provided by Norges Bank, Currency Rates
(norges-bank.no), last accessed 27 May 2026.
115Based on the current exchange rate on 24 March 2026 of 10.80 for EUR to NOK, as provided by Norges Bank, Currency Rates
(norges-bank.no), last accessed 27 May 2026.
34This does not mean that an infringement fee of 0.4–0.8% of turnover may not be appropriate in other cases of similar infringements. In this case, there are some factors that argue for a significant reduction in the fee – in particular Elkjøp's efforts to improve compliance more generally, the long case processing time at the Data Protection Authority, and the fact that it has not been proven that sensitive personal data has been processed. In other cases, in the absence of such circumstances, a violation fee within the above fee range (or higher) may be necessary.
7. Right to appeal
This decision has been made by the Data Protection Authority in accordance with Article 56 of the General Data Protection Regulation and Chapter VII and cannot therefore be appealed to the Data Protection Board, cf. Section 22, second paragraph of the Personal Data Protection Act. However, this decision may be reviewed before Norwegian courts in accordance with Article 78, paragraph 1 of the General Data Protection Regulation.
8. Publicity
Elkjøp AS and Elkjøp Nordic AS – as parties to this case – have, pursuant to Sections 18 and 19 of the Public Administration Act, the right to familiarise themselves with the documents in the case.
The Norwegian Data Protection Authority is subject to the Freedom of Information Act, and the starting point is that case documents are public, cf. Section 3 of the Act. If Elkjøp believes that there is a basis for excluding all or part of the document from public access, we ask that this be justified.
Best regards
Line Coll
Director
Tobias Judin
Head of Section, International
This letter has been approved electronically and therefore has no handwritten signatures
35




