Back to all lessons
Awareness Lessons
4 months ago

Norwegian retailer fined €1.83M for GDPR consent violations and improper data handling

Elkjøp Nordic violated GDPR by improperly bundling consent for their customer loyalty program, making it difficult for customers to provide specific consent for different data processing purposes. The company also used customer data for advertising targeting without establishing a proper legal basis, and failed to respond to data subject rights requests within the required timeframes. These violations demonstrate how improper consent mechanisms and inadequate data governance processes can lead to significant regulatory penalties and erosion of customer trust.

Tactical Insight

Immediate actions

  • Audit all current consent mechanisms to ensure they are specific, informed, and unbundled
  • Review all data processing activities to verify proper legal basis is documented
  • Establish dedicated processes to handle data subject rights requests within GDPR timeframes

Long-term improvements

  • Implement consent management platforms that allow granular consent control
  • Develop comprehensive data governance frameworks with clear accountability structures
  • Create regular GDPR compliance training programs for marketing and customer service teams

Monitoring measures

  • Deploy automated tracking systems to monitor data subject request response times
  • Conduct quarterly audits of consent records and legal basis documentation
  • Establish KPIs for GDPR compliance and integrate them into business performance reviews