Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement July 22, 2026 3 min

Norway: loyalty programme under scrutiny, more than six million members involved

Datatilsynet finds invalid consent, new purposes never assessed, insufficient legitimate-interest balancing and late responses to data subjects

TL;DR for the DPO

Four findings that recur wherever there is a loyalty card: (1) invalid consent; (2) new purposes added over time without ever reassessing the processing; (3) legitimate interest invoked without adequate balancing; (4) data subject requests answered beyond the Art. 12(3) deadline.

The three points that matter

  • Loyalty programmes grow by accretion: they start as point collection, then come profiling, personalised offers, purchase-behaviour analytics, partner sharing. Each layer is a new purpose that had to be assessed when it was added, not afterwards.
  • Consent collected at sign-up does not cover what comes later. If the purpose changes, you either update the legal basis or collect fresh consent: silence is not a third option.
  • Response deadlines are a measurable duty and the easiest to challenge: one month, extendable by two with justification. It is among the first things an authority checks, because it only takes looking at the dates.

What to do now, in practice

For clients with loyalty programmes, apps or communities: 1) reconstruct the timeline of purposes: what the programme did at launch and what it does today; 2) check each added purpose has its own legal basis and sits in the register; 3) reread the consent wording: if it is generic or bundled, rebuild it granular; 4) measure response times over the last six months: if you cannot state them, that is already a problem; 5) review sharing with commercial partners and the related agreements.

Why it matters for your clients

The case comes from Norway but the shape of the problem is identical in any retail chain with a loyalty card: features layered over the years on top of consent collected once. It is an audit you can propose concretely, with a clear scope and a verifiable outcome.

Official source:Datatilsynet (Norway) - decision following an audit of the Nordic entities of a retail group

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free