Forced consent finally costs money: Elkjop fined €1.8M after 5-year warning

5 min read 1 source clear_take
├── "Forced consent is a settled legal violation that companies knowingly deploy anyway"
│  └── thatprivacyguy (thatprivacyguy.com, 330 pts) → read

The author personally warned Elkjop in 2020 with a written legal analysis that conditioning loyalty program access on marketing consent violated GDPR Article 7(4). Five years later Datatilsynet reached the same conclusion almost verbatim, proving the company made a deliberate business decision to ignore clear legal advice rather than acting out of ambiguity.

├── "The Elkjop ruling extends consent-or-pay fragility beyond ad-funded media into mainstream retail"
│  └── top10.dev editorial (top10.dev) → read below

The synthesis argues that the same dark pattern — gating a service on marketing consent — is the default across loyalty programs, newsletter walls, and cookie banners throughout Europe. Combined with the CJEU's Meta Platforms ruling, Datatilsynet's decision signals that this design is now legally indefensible well outside the publishing sector where most enforcement has focused.

└── "The regulator's decision is legally unremarkable — the real story is the five-year enforcement lag"
  └── top10.dev editorial (top10.dev) → read below

The editorial emphasizes that Article 4(11), Article 7(4), EDPB guidelines, and CJEU case law all made this outcome predictable in 2020. The noteworthy element is not that Datatilsynet agreed with the consultant, but that it took half a decade for settled law to produce an enforcement action — a gap that lets companies extract value from unlawful designs in the interim.

What happened

Norway's data protection authority, Datatilsynet, has fined electronics retailer Elkjop NOK 20 million (roughly €1.8M) for unlawful processing of customer data tied to its loyalty program. The mechanism at the center of the ruling is what GDPR practitioners call forced consent: customers could not use the loyalty program — and in practice could not complete certain purchases on equal terms — without ticking a marketing-consent box. The 'consent' was the price of admission, not a free choice.

The blog post driving the Hacker News discussion is written by the privacy consultant who, by his account, told Elkjop in 2020 that this exact design was illegal. He produced a written analysis, the company chose not to change the flow, and five years later the regulator arrived at the same conclusion he did — with a fine attached. The interesting fact is not that the regulator agreed; it is that the warning, the legal analysis, and the eventual enforcement action all describe the same dark pattern, almost word for word, with a five-year delay.

The legal substance is not novel. Article 4(11) of GDPR defines consent as 'freely given,' and Article 7(4) says that when assessing whether consent is free, regulators must take 'utmost account' of whether performance of a contract is conditional on consent to processing that isn't necessary for that contract. The EDPB has reiterated this in guidelines. The CJEU has reinforced it (Meta Platforms v. Bundeskartellamt, C-252/21, 2023). Datatilsynet's decision is, in that sense, boring: it applies settled law to an obvious case.

Why it matters

For anyone who builds product, the pattern Elkjop got fined for is not exotic. It is the default in most loyalty programs, most newsletter-gated content, and most 'accept all or pay' cookie walls deployed across European media properties in the last three years. The Meta ruling already made consent-or-pay legally fragile in the ad-funded press; the Elkjop fine extends the same logic to retail. If your product makes a customer click 'I agree to marketing' to get the discount, the loyalty card, or the warranty registration, you are running the exact playbook a regulator just put a €1.8M price tag on.

The second thing worth noticing is the cadence. Five years is not unusual for GDPR enforcement — it is roughly the median for substantive fines against mid-tier companies. The Irish DPC took six years to fine Meta over Facebook–Instagram data sharing. The French CNIL took four years on Google's cookie banner. The lag is not because regulators are asleep; it's because cross-border cases route through the one-stop-shop mechanism, and national authorities want airtight files before issuing fines that will be appealed. The practical effect on engineering teams is that 'no one has been fined yet' is not a defense — it's a countdown. The fines are coming; they're just coming late.

Third, the economics of the fine are worth a second look. NOK 20M is not a corporate-killer for a chain Elkjop's size — it's roughly a single quarter's marketing spend at one of their formats. That's the trap: the fine is small enough that the rational business response, in isolation, is to pay it and continue. But fines under GDPR are cumulative, the cap is 4% of global turnover, and a second offense after a documented warning becomes evidence of bad faith. The Norwegian decision specifically cites the consultant's 2020 warning as an aggravating factor. The company can no longer claim ignorance, and the next fine — when it comes — won't have a ceiling that looks like Q3 marketing budget.

Fourth, the community reaction on Hacker News is interesting on its own. The top-rated comments are not 'GDPR is overreach' — that was the dominant register in 2018-2020. The mood has shifted toward 'finally,' even from people who build ad-funded products. Several commenters who run European SaaS noted that they had quietly removed forced-consent flows in the last 18 months specifically because customers were starting to ask, in procurement, whether the vendor's analytics stack would create regulatory risk for them. The buyer-side pressure is now ahead of the regulator.

What this means for your stack

Three concrete checks. First, audit any flow where a user must click 'accept' to proceed and the thing they're accepting includes processing that isn't strictly necessary for the service. Cookie walls, loyalty enrollments, newsletter-gated downloads, and 'create account to view price' patterns are all in scope. The test isn't whether the user clicked the box; it's whether they had a real alternative. A 'reject all' button that costs €5/month and a free version that doesn't is, after the Meta ruling and now Elkjop, a legally precarious design.

Second, separate the consents. Loyalty membership and marketing emails are two different processing purposes; bundling them is the specific failure mode Datatilsynet hit Elkjop on. If your signup form has one checkbox for 'I agree to the terms and to receive marketing,' split it. If your analytics SDK fires before consent is granted, fix that — Google's Consent Mode v2 and equivalents exist precisely because the regulator-side patience for 'we'll ask later' has run out.

Third, document the warnings you've received. The Elkjop decision treats the 2020 consultant memo as evidence the company knew the design was unlawful. If your legal or privacy team has flagged a flow and product has deferred the fix, that paper trail will be discoverable in any future enforcement. The corollary, useful for engineers: when you raise a concern about a consent flow, write it down. It's both protective and accelerating — documented concerns tend to get prioritized faster than verbal ones.

Looking ahead

The Elkjop fine won't be the last of its shape. Datatilsynet, the Dutch AP, and the French CNIL have all signaled in 2025 that consent-or-pay and bundled-consent cases are an enforcement priority for 2026. The cases under investigation include several large media properties and at least two retailers. The next round of fines will arrive faster — regulators now have the Meta and Elkjop decisions to lean on, and the legal analysis is essentially copy-paste. The window for 'we'll fix it when someone makes us' is closing, and the bill for waiting is no longer hypothetical.

Hacker News 434 pts 278 comments

I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M

→ read on Hacker News
engeljohnb · Hacker News

I'm glad it all worked out for this individual. I hope more people live their lives like this as the dystopia progresses.Unfortunately, especially in the US, exercising your rights, or even just reading every paper you're expected to put your name to, not only constantly pisses people off

buzer · Hacker News

Actual decision (Norwegian): https://www.datatilsynet.no/contentassets/c8d0551d2a64403285...Machine translation of overview & 5.1 which is what the blog post is about (covers some other things as well): https://chatgpt.com/share/6a34732c-0fa4-83e8-aae1-95c

0xfffafaCrash · Hacker News

> The reply I received a few days later did me the favour of putting the violation on the record. Their position, in their own words, was that "in order to receive marketing / offers, it is a condition to be a member of the customer club." That one sentence is the whole case. They

Insimwytim · Hacker News

There's also issue with EU companies forcing candidates to agree to their anti-privacy policies (confusingly named "privacy policies") as a requirement before the job interview.Those anti-privacy policies will state, that you grant the company and third-parties (so, anyone) permission

ambicapter · Hacker News

I understand where he's coming from, but it is still hilarious that he sued the legal entity that won the case for him, after they found the case in his favor.

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.