Key Takeaways
- In a decision dated 1 June 2026, Datatilsynet, the Norwegian data protection authority, fined Elkjop Nordic AS and Elkjop Norge AS NOK 20 million because one customer-club consent covered newsletters, text messages, profiling, personalisation and analytics at once. Norway is in the EEA, so this is the same GDPR an EU merchant answers to.
- The consent failed all three limbs at once: not specific (a "marketing" purpose is not specific enough), not freely given (bundled), not informed (the pitch was about discounts while the profiling went unmentioned).
- Elkjop's own compliance team called the consent "all or nothing", and Elkjop described membership as a "package". The regulator quoted those words back as evidence of bundling.
- A preference centre added after sign-up does not repair a bundled consent. Customers "should have been given that choice at the point they were asked to consent".
- Five months earlier the CNIL fined a company EUR 3.5 million for sending 10.5 million loyalty members' contact details to a social network for ad targeting, with nothing about it on the membership form.
Introduction
Find your own loyalty sign-up and read it the way a regulator would. Most say something close to: join the club, get member prices, and we will send you offers we think you will like. One tick, one yes — and behind it sit four or five genuinely different things: a mailing list, an SMS list, a profile built from purchase history, personalised pricing, and analytics that improve the whole machine.
In a decision dated 1 June 2026, Norway's data protection authority put a number on that design. Elkjop, the Nordic electronics chain, was fined NOK 20 million over a customer club with more than six million members. The finding was not a technicality about wording: the club's consent was invalid from the moment it was collected, and Datatilsynet expects the members to be re-consented.
This article reflects publicly available regulatory decisions and guidance as of August 2026. It is informational content, not legal advice.
Why Loyalty Programme Consent Fails Under GDPR
Loyalty consent usually fails because one checkbox is asked to carry several distinct purposes. Under Article 4(11) GDPR consent must be freely given, specific, informed and unambiguous. Bundle marketing, profiling and analytics into one yes and you have not obtained one strong consent — you have obtained none.
Datatilsynet inspected Elkjop's Oslo offices on 20 and 22 June 2022, prompted by breach notifications, complaints and tips about the customer club. The decision that followed nearly four years later found four separate infringements.
"Marketing" is not a specific purpose
Elkjop told inspectors that the club's consent covered newsletters, text messages, profiling, personalisation and analysis — and that these were all done for the same purpose, on the same legal basis. A marketing purpose, Datatilsynet held, is not in itself sufficiently specific. Sending general marketing communications, profiling in order to enable personalised marketing, and running analytics to improve marketing activities are separate purposes. Calling them one does not make them one.
The line the decision draws is the one most loyalty schemes cross without noticing: personalised marketing "is something other than merely offering general discounts to build customer loyalty".
The all-or-nothing package
The freely-given limb failed for a reason Elkjop supplied itself. Its compliance team described the consent as "alt eller ingenting" — all or nothing — and the company described membership as a "pakke", a package. You could not join the club without also accepting personalisation, analytics and newsletters.
Datatilsynet's test for whether purposes should have been separated is refreshingly concrete: can one activity be performed without the other? It can. You can send a newsletter carrying general offers without also profiling people to personalise it. Because the first does not require the second, they needed separate consents.
Elkjop's defence was the one most merchants would reach for: this is a fair exchange, customers get something in return for letting us market to them. The regulator rejected it, and its public summary of the principle is blunt — businesses "cannot require or pressure customers to disclose personal data as part of a trade-off in exchange for general discounts", and customers "should not be forced into an 'all-or-nothing' choice".
There is an uncomfortable detail in the file. Elkjop discussed this design internally in February 2022 and identified the risk that data protection authorities would find it invalid and order it to delete club members or collect fresh consent. It kept the design, and let people opt out of individual marketing activities after joining — which is the fix most stores have already deployed. Datatilsynet's answer was that customers should have been given that choice at the point they were asked to consent. A preference centre is a good thing to have. It is not a cure for a consent that was invalid when it was taken.
Discounts in the pitch, profiling in the footnotes
The informed limb failed because of what customers were told, and when. The material shown before consent "was primarily about discounts and benefits", while personalised marketing, profiling, analytics and their consequences "was not clearly communicated in advance".
Two details make this more than a copywriting note. The confirmation page shown after a customer clicked the sign-up link — the one that finally explained what had just been agreed — was held irrelevant to whether the consent was informed. Information arriving after the yes cannot inform it.
And because staff asked customers to join verbally in store, how much anyone actually learned "depended largely on the individual shop assistant". Datatilsynet called that a significant risk of arbitrary and inadequate information, noted it was avoidable by giving the information in writing in advance, and concluded that Elkjop must bear that risk. If your consent quality varies by who is on shift, that variance is yours.
The aggravating factor most clubs share
The club's stated minimum age was 15, but Elkjop did not record customers' ages and "lacked mechanisms to ensure the customer was actually over that age". The regulator noted that Elkjop markets products relevant to younger buyers — its gaming category, for instance — invoked Recital 38 on children deserving specific protection, and treated children's data in the club as an aggravating factor. Almost every consumer loyalty scheme has an age floor in its terms and nothing behind it.
Can You Require Marketing Consent for a Discount?
You can give every member the same general discount, and you can offer a better, personalised deal to people who opt into profiling. What you cannot do is make consent to profiling the price of admission to the basic scheme, or penalise someone who later withdraws it.
The EDPB drew this line before any of these decisions, in Guidelines 05/2020 on consent, and its Example 9 could have been written for a loyalty programme. A shopper subscribes to a fashion retailer's newsletter with general discounts. The retailer separately asks for consent to collect more data to tailor those offers. When the shopper later revokes that consent, "he or she will receive non-personalised fashion discounts again. This does not amount to detriment as only the permissible incentive was lost."
The structure is the whole answer: general discounts sit underneath and stay, personalisation sits on top as a genuine, separable choice. As the Guidelines put it, "The GDPR does not preclude all incentives but the onus would be on the controller to demonstrate that consent was still freely given in all the circumstances."
Merchants get caught by inverting that. If the only route to member pricing is accepting profiling, the incentive is no longer an incentive — it is the consideration for the data, and Article 7(4) treats consent bundled with a service that does not need it as presumptively not freely given.
The Four Purposes Hiding in One Loyalty Checkbox
Most loyalty schemes are four processing activities wearing one coat. Splitting them is less painful than it sounds, because only two of the four usually need consent at all.
| What it does | Typical lawful basis | Can it share a consent? |
|---|---|---|
| Running the scheme — issuing a card or account, tracking points, redeeming rewards, honouring member pricing | Contract (Art 6(1)(b)) — the member asked for the scheme | No consent needed; do not fold it into a marketing tick |
| Marketing communications — newsletters, SMS, push | Consent (and ePrivacy rules for email and SMS) | Its own opt-in, per channel |
| Profiling and personalisation — building a customer profile from purchase history to tailor offers | Consent | A separate opt-in, never merged with the newsletter one |
| Analytics on member behaviour — segmentation and measurement to improve the programme | Consent, or legitimate interests with a documented assessment | Separate, and it must survive a real balancing test |
Two rules follow. The scheme's own mechanics do not belong in a marketing consent, because a member who joins to collect points has asked for exactly that. And profiling never rides along with newsletters — that pairing is the one Datatilsynet used to show the purposes were separable.
This split is also what makes a consent register defensible: one timestamped yes against five purposes proves nothing about any of them. Our guide to proof-of-consent records for eCommerce sets out the per-purpose fields a regulator will actually ask for.
Where Loyalty Data Leaks Next: Audience Matching
The consent finding was one of four infringements, and the other three show how a bad club consent becomes an expensive one.
Customer match. Elkjop planned to match club members' email addresses and phone numbers against advertising platforms' own user identifiers. Its team told inspectors the purpose was the same as the club's, so no compatibility assessment under Article 6(4) had been done — while also saying customer match was a new activity on a different basis, legitimate interests. Datatilsynet found Article 6(4) breached and rejected legitimate interests too: it was not within members' reasonable expectations that data given on the basis of consent would later serve a purpose that consent never covered. That is a fairness failure under Article 5(1)(a).
Offline conversions. Used to measure how digital advertising drove in-store sales, again on legitimate interests. The assessment behind it was inadequate, so Elkjop could not demonstrate the processing was lawful — a breach of Article 5(2) with Article 5(1)(a).
Rights requests. Requests to correct an email address were automatically classified as complex, auto-extending the one-month deadline under Article 12(3). Extensions require a case-by-case assessment, and Elkjop admitted missing even the extended three-month deadline in some cases.
France reached the same place by another route. On 30 December 2025 the CNIL fined an unnamed company EUR 3.5 million for transferring more than 10.5 million loyalty members' email addresses and phone numbers to a social network for targeted advertising, continuously since February 2018. The membership form said nothing about it, so consent "did not allow individuals to give explicit and informed consent". Neither authority cites the other, which is what makes the pairing worth noticing: two regulators reached the same conclusion independently about the same everyday pipeline.
Your Members Are Already on a Bad Consent. Now What?
This is the question no competitor answers, and the one that matters if you are reading with a database in front of you. Datatilsynet did not leave it open: the decision records the expectation that Elkjop remedies ongoing infringements, "including that Elkjop obtains valid consent from its customer club members". Re-consent, not a quiet edit to the privacy policy.
Work it purpose by purpose rather than as one migration.
- Inventory what the old tick actually covered. Pull the sign-up copy as it appeared on the date each cohort joined, not today's version — Datatilsynet dated Elkjop's own landing page from a web archive capture. Map each activity you run today to the wording members actually saw.
- Split out what never needed consent. Points, rewards, redemptions and member pricing rest on the contract the member asked for. Move them onto Article 6(1)(b) and stop treating them as hostages of the marketing tick. This is usually the largest slice, and it means an invalid marketing consent does not shut the scheme down.
- Decide, per remaining purpose, between re-consent and a different basis. Analytics may survive on legitimate interests if you write and keep a real balancing assessment — the Elkjop offline-conversions finding is what an inadequate one costs. Profiling and direct marketing messages will need fresh, separate opt-ins.
- Run the re-consent campaign on the old permission, once. Use the channel the member already agreed to, keep the message about the choice rather than the offer, and present each purpose as its own switch defaulted to off. Do not attach a discount to saying yes.
- Set the rule for non-responders before you start. Silence is not consent. When the window closes, stop the purposes that depended on the invalid consent for everyone who did not opt in — and keep their membership running. Deleting members who ignored an email is usually wrong: the unlawful thing was the profiling, not their membership.
- Record it as evidence. Timestamp, purpose, exact wording shown, channel, form version. Accountability under Article 5(2) is judged on documentation, not intent.
- Fix the collection point last, but do fix it. A clean re-consent flowing back into the same bundled sign-up form recreates the problem with a fresher timestamp.
One sequencing note: do step 2 first, always. Merchants who start at step 4 discover mid-campaign that they have made their own loyalty scheme contingent on a marketing answer — the original mistake in reverse.
Common Mistakes
- Treating a preference centre as the fix. Datatilsynet addressed this head-on: the choice belongs at the point of consent, not after it.
- Assuming an EEA decision is someone else's problem. Norway applies Regulation (EU) 2016/679, and Sweden, Iceland, Finland and Denmark were concerned authorities under the Article 60 cooperation procedure.
- Reading NOK 20 million as the going rate. Under EDPB Guidelines 04/2022 the starting band against the parent group's turnover was NOK 434 million to 868 million. The regulator went far below it for specific mitigating reasons — Elkjop's compliance improvements, its own four-year case handling, no proven special-category data — then warned that absent those factors, a fine within that band "or higher" may be necessary.
- Taking consent verbally with no written record. If quality varies by who is on shift, the regulator assigns that variance to you.
- Forgetting that rights-request handling is judged alongside consent. Elkjop's automatic "complex" classification cost it a fourth infringement on a separate article.
How PrivacyForge Helps
The purpose split above is only as good as the record behind it. PrivacyForge's consent management stores each opt-in as its own record — purpose, timestamp, the wording shown, channel and form version — so a per-purpose question from a regulator gets a per-purpose answer rather than one undifferentiated yes. If you are running a re-consent exercise, those same records produce the cohort lists that step 1 of the playbook depends on.
The data mapping module is where the four-way split becomes visible: each loyalty activity is logged as its own processing activity with its own lawful basis, which makes an untested legitimate-interests claim easy to spot before an inspector does. For the wider framework these obligations sit inside, start with our complete guide to GDPR compliance.
Frequently Asked Questions
Does a loyalty programme need consent under GDPR?
Not for everything. Running the scheme itself — issuing accounts, tracking points, redeeming rewards — normally rests on contract under Article 6(1)(b), because the member asked for it. Consent is required for the marketing layers: newsletters and SMS, and separately for profiling and personalisation. Bundling those layers into the join button is what invalidates the consent.
Can you require marketing consent for a discount?
No, not as the price of entry. You may offer general discounts to all members and a personalised offer to those who opt into profiling, but the basic scheme cannot be conditioned on consent it does not need. EDPB Guidelines 05/2020 Example 9 confirms that when a shopper withdraws personalisation consent and returns to non-personalised discounts, only "the permissible incentive was lost".
Do marketing, profiling and analytics each need their own consent?
Yes — bundling them into one yes is what invalidates the lot. Datatilsynet held that general marketing communications, profiling to enable personalised marketing, and analytics to improve marketing are separate purposes. EDPB Guidelines 05/2020 paragraph 44 puts it directly: where a controller "has conflated several purposes ... and has not attempted to seek separate consent for each purpose, there is a lack of freedom".
Does a preference centre fix a bundled loyalty consent?
No. Letting members opt out of individual activities after joining does not repair a consent that was invalid when taken. Datatilsynet considered exactly this argument in the Elkjop decision and held that customers should have been given that choice at the point they were asked to consent. A preference centre is good practice going forward, not remediation.
What do you do with loyalty members collected under an invalid consent?
Split by purpose. Move the scheme's own mechanics onto contract so membership survives, then either re-consent or move to a documented legitimate-interests basis for each remaining purpose. Run one re-consent campaign with per-purpose switches defaulted off, treat silence as refusal, and stop the affected processing for non-responders while keeping their membership.
Is legitimate interest a safe fallback instead of consent for loyalty marketing?
Not for profiling or personalised marketing. Datatilsynet rejected legitimate interests for Elkjop's customer match because reusing consent-collected data for an uncovered purpose fell outside members' reasonable expectations, and separately fined it for an inadequate assessment behind offline conversions. It may cover narrow operational messages, but only with a documented balancing test.
Conclusion
The Elkjop decision is not really about Elkjop. It describes a design that ships as the default in most loyalty apps: one tick, several purposes, discounts in the pitch and profiling in the small print, with a preference centre bolted on afterwards to make it feel voluntary. Two regulators have now put a price on that design, and the Norwegian one told the company to go back and collect the consent properly.
The work is smaller than it looks, because most of a loyalty scheme never needed consent at all. Separate the contract from the marketing, the newsletter from the profiling, write down which is which, and what remains is a consent you can defend. Start with the inventory: pull your sign-up copy and count the purposes hiding behind the tick. If it is more than one, you already know the next step.
Sources
- Datatilsynet — Vedtak om overtredelsesgebyr, Elkjop (decision PDF, 1 June 2026, ref 22/00049-13)
- Datatilsynet — Administrative fine imposed on Elkjop (English announcement)
- Datatilsynet — Overtredelsesgebyr til Elkjop (case page)
- EDPB — Guidelines 05/2020 on consent under Regulation 2016/679
- CNIL — Transfer of data to a social network for advertising purposes: a fine of EUR 3.5 million