

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- This fills my heart with joy. If only ICO in the UK would do the same.by sscaryterry
- ICO bothers to whine and plead sometimes!
But usually even the extensive evidence is indeed met with "eh, mate, can't you just ask them again?"
by subscribed - Well John Edwards just resigned yesterday so maybe you will get a real Commissioner this time - although that said, John was hired specifically as someone who would do nothing, so I guess he did what he was paid to do.
He has largely been ostracised by the privacy and data protection community (even at regulatory events) I have seen him wandering around alone and aimlessly at a number of regulatory events, he didn't seem very comfortable and didn't really have a lot of interaction with his peers.
- Good to know that this is illegal. One of my email providers also does this, maybe I’ll also have to try reporting them and see what happens.by echoangle
- EU only though. You can get away with pretty much anything outside of EU.by TurdF3rguson
- Go for it! If nobody reports things they don't get fixed.
I have found this to be true not just when it comes to companies breaking laws, but also to much more benign things. Such as reporting potholes in town or broken microwaves at work. Those can be in need of fixing for an extended period of time, yet when I report them, they usually get fixed within days. I suspect most people can't be bothered or think that surely someone else will report the issue. But that doesn't work if everyone thinks that way.
by VorpalWay - And how much did it make them over those 5 years?by peaseagee
- The fine is largely irrelevant, now they have faced enforcement we have a decision to file a Representative Actions Directive (equivalent of a US class action) claim with - the cost of that will be 100-1000x more than the fine and will likely lead to shareholder revolt as well (institutional shareholders will likely sue the parent Currys PLC for breach of fiduciary duty and not disclosing these issues during earnings calls and annual reports.)
So the fine is the first step to a much wider legal action.
The fine also puts other loyalty clubs on notice that if they do this, they are going to face consequences - so it has a much wider impact than simply monetary.
- The fine is only part of the story. They likely spent more money than the fine fighting it over 5 years as fines increase next time if you don’t stop.by Retric
- Excellent outcome. I wish we had these rights in the USA! Too bad justice took 5 years though.by ryandrake
- There are some state laws - California, Virginia and Colorado, a bunch of others. And the SECURE Data Act currently in Congress. https://statescoop.com/house-subcommittee-secure-data-act-pr...by Mathnerd314
- This is extremely cool reading! I'm impressed that they actually fined Elkjøp (as they should!) but very surprised that they didn't keep you informed!
Thank you for sharing!
by tomtom1337 - It was not their responsibility to keep me informed, it was the responsibility of IMY (the Swedish Regulator) to keep me informed.
- The image isn't loading for me, all I see is the prompt used to generate it - which is genuinely preferable.by pavel_lishin
- mildly amusing that the model was instructed to generate it in the style of a "wide angle film still" but it seems to have gone for a painting insteadby voidUpdate
- Is it a prompt or accessibility description for screen readers?by kuboble
- For me it was showing the image and the prompt, but the whole page was unstyled. But when I reloaded the page now, the css loaded also and the prompt is not shown.
I guess the web server was temporarily overwhelmed by traffic resulting in images (like for you) and css files (like for me) not being consistently served to all visitors.
- Datatilsynet, the Norwegian DPA, from my experience, consistently has the user in mind. It (sadly) takes a long time for things to pass through the system, but they consistently come to good decisions.by Telaneo
- I understand where he's coming from, but it is still hilarious that he sued the legal entity that won the case for him, after they found the case in his favor.by ambicapter
- Seeing that he influenced the creation of the GDPR, the general sense of hopelessness in the rest of the populace, and the failure of the governing body to do it’s jobs - I suppose he is the only person who would be taking people to account.by intended
- Looking at the report from datatilsynet (Norwegian Data Protection Agency), they cite "multiple reports and tips" as the background. I suspect what happened here is that IMY concluded that this laid outside of their authority, submitted the complaint to datatilsynet and either closed the case and forgot to inform Hanff, or they may have never gotten any response from datatilsynet.by TonyStr
- What do you mean? It sounds like he is planning to sue company in question and possibly lodging complaint against Swedish DPA. Norwegian DPA is the one who found case in his favor.by buzer
- There's also issue with EU companies forcing candidates to agree to their anti-privacy policies (confusingly named "privacy policies") as a requirement before the job interview.
Those anti-privacy policies will state, that you grant the company and third-parties (so, anyone) permissions to use your data (including voice and image) for any purpose. (Of course, it is stated in a slightly obscure fashion, so a layman may not comprehend it.)
I wonder if there has been any similar action taken against those.
by Insimwytim - I grated a bit at an EU company's use of https://www.crosschq.com/ recently.by CalRobert
- I haven't personally encountered that, but you are free to lodge complaint with your local DPA about it.
That exact language is unlikely to be compliant. If you want to maximize your effect you could make Article 15 request to the company in question, get the list of actual recipients of data (make sure to be ask for this specifically) and then make another request to all of those companies. That will then allow you to possibly make further complaints (e.g. why exactly they didn't send Article 14 information to you, are the legal basis they use actually proper in your case especially if the original one was consent and it was not freely given).
by buzer - > The reply I received a few days later did me the favour of putting the violation on the record. Their position, in their own words, was that "in order to receive marketing / offers, it is a condition to be a member of the customer club." That one sentence is the whole case. They had taken a right I am entitled to exercise for free and turned it into the price of admission.
I don’t understand… it would be one thing if it said “receiving marketing/offers is a condition of being a member of the customer club” but that’s not what is being stated above… rather that being a member of the club is required to receive marketing — perhaps something has been misworded or lost in translation?
- He was an Elkjøp/Elgiganten customer club member. He wanted to keep the club membership and discounts/offers, but stop the marketing emails. Elkjøp’s setup told him the only way to stop the marketing was to cancel the club membership altogether.
To me, Elkjop seems perfectly reasonable here. But EU policy disagrees.
by cm2012 - I actually stopped reading right there and came to the comments because I was really confused.by rpdillon
- Alternative approximate translation: while I urinate on you tell me it's raining.by contubernio
- Yea, I don't get it either. Receiving being a condition on membership means (in my understanding) only that non-members can't (shouldn't) receive anything, not that members will or must receive something. Which sounds perfectly normal and sane to me.by drdaeman