The Norwegian Data Protection Authority Datatilsynet has imposed a fine of 1.78 million euros on an electronics retail chain operating primarily in Northern Europe. The reasons were, in particular, invalid consent, using data beyond the allowed purpose, and insufficient data accountability. The case concerned the company’s loyalty programme, through which customers could benefit from discounts and bonuses.
Specifically, the authority objected to the inadequate information provided to customers about the scope of the data processing at the time of registration, the lack of a clear distinction between the marketing consent prompt and the acceptance of the loyalty programme terms, and the fact that the indicated purpose of the consent was too vague overall. Furthermore, internal customer data was combined with data from third-party platforms for personalised advertising, even though this data had originally been collected solely for the purpose of managing the loyalty programme membership. Personal data was obtained in exchange for general discounts, which further calls into question the voluntary nature of the consent.
The case illustrates the rule that consent granted for a specific purpose may not be extended to other processing purposes, such as personalized advertising without explicit consent.
Businesses should review their consent processes regularly, and processing purposes (such as contract fulfilment, loyalty programme membership and marketing) should be clearly separated from one another, rather than being bundled together under a general consent prompt. Customers must also be able to understand which data is being processed and for what purpose, before any data processing takes place; and their consent must be revocable at any time.
(Dr. Lukas Mezger, UNVERZAGT Law)