The Norwegian Datatilsynet has just imposed a fine of NOK 20 million on Elkjøp Nordic for using customer data for marketing without a valid legal basis. The decision is a clear signal to any company that combines customer management with targeted marketing: the rules are non-negotiable – and the price of not following them is high.
What happened?
Elkjøp Nordic is the Nordic chain behind Elgiganten in Denmark and Sweden, among others. The company has one of the largest loyalty programs in the Nordic region with millions of registered customers.
The Norwegian Datatilsynet determined, among other things:
(1) Elkjøp had not obtained valid consent for the customer club – the consent was neither specific, voluntary nor informed, among other things because the newsletter, profiling and analysis were bundled into one “all or nothing” package.
(2) Personal data from the customer club was further processed in a customer match tool for targeted advertising on social media and search engines. This means that the personal data was reused for new purposes without a valid basis for processing.
(3) The company had not handled data subjects' rights in a timely manner
The result: 20 million NOK in fines – equivalent to approximately 13,5 million Danish kroner. The amount has been set significantly lower than the starting point, among other things, taking into account Elkjøp's constructive cooperation and the almost four-year case processing time.
The cross-talk between data protection and marketing law
The Elkjøp case illustrates a classic and widespread problem in practice: the tension between two sets of rules, both of which regulate the use of customer data for marketing, but with different starting points.
GDPR requires a clear legal basis for all processing of personal data. For marketing, consent is typically the relevant basis – and that consent must be freely given, specific, informed and unambiguous.
The Danish Marketing Act also operates with its own consent requirements for electronic direct marketing in connection with e-mail, SMS, etc. In the Elkjøp case, it is the GDPR violation that is sanctioned – but the same errors in the consent architecture will typically also constitute a violation of the marketing rules.
In practice, we see three typical errors:
- Consent has been obtained, but is worded too broadly or unspecifically
- There is no sufficient distinction between different processing purposes and it therefore does not meet the requirement for granular consent.
- Consent is reused for new purposes without a valid basis for processing
What should your company do now?
The Elkjøp decision should serve as a wake-up call for those who have been passive about consent until now. Here are the most concrete steps you can take in your business:
- Map your data flows for marketing
Which personal data is used for which marketing activities? And what is the legal basis for each processing? This exercise alone often reveals gaps that otherwise remain hidden.
- Review your consent basis
Are your consents clear, specific and documentable? Do they meet the requirements of both the GDPR and the Marketing Act, including the requirements for informed, voluntary and specific consent? And do you have a system to record when and how consent was given?
- Check your loyalty program and CRM setup
Loyalty programs are a particular area of risk because they almost by definition involve the massive collection and further processing of customer data for commercial purposes. Here, it is crucial that the purpose limitation in GDPR Article 5(1)(b) is respected. The decision also states that models where general discounts are only obtained by signing up to a customer club with full data processing are legally risky when general discounts are used as a consideration for consent.
The Danish Datatilsynet However, in their “Direct Marketing Guide” they write:
“You can to some extent create an incentive and motivate data subjects to give consent by providing a benefit for consenting. However, it is important to be aware of whether lack of consent (or withdrawal thereof) leads to negative consequences for data subjects, e.g. in the form of additional costs.”
You should therefore pay particular attention to the latter, as to whether lack of consent or withdrawal thereof creates negative consequences for the data subject.
- Establish internal governance
Who in your organization is responsible for ensuring that marketing campaigns are screened against data protection regulations before they are sent? Many companies have strong compliance functions, but forget to connect them to the marketing team's daily work.
The fine is one thing – the damage to trust is another
20 million NOK is a large amount in absolute terms – but Datatilsynet emphasizes that the fine has been set significantly lower than the normal starting point, among other things because Elkjøp cooperated constructively and has improved its processes since the inspection in 2022. This does not change the fact that the full bill for many companies is not the fine itself, but the work it takes to put things right: new consent architecture, updated data processing agreements, legal review of advertising practices and new processes for the rights of data subjects. In addition, as a company, you may risk losing trust from customers and partners.
Companies that proactively communicate how they handle customer data and can document their compliance gain an advantage. Companies that wait for a regulatory case pay double the price.
Are you ready?
At Unitas We advise companies on navigating the interface between data protection law and marketing law – from consent structures and data flow analyses to internal governance and ongoing compliance. If you need a look at whether your setup is sustainable, you are welcome to contact us.
See the case from the Norwegian Data Protection Authority here: Violation fee for Elkjøp | Datatilsynet