Skip to main content

The fine against Elkjøp shows: GDPR is a business-critical project

By 24. June 2026#!31Tue, 07 Jul 2026 12:53:41 +0000Z4131#31Tue, 07 Jul 2026 12:53:41 +0000Z-12+00:003131+00:00202631 07pm31pm-31Tue, 07 Jul 2026 12:53:41 +0000Z12+00:003131+00:002026312026Tue, 07 Jul 2026 12:53:41 +00005312537pmTuesday=746845#!31Tue, 07 Jul 2026 12:53:41 +0000Z+00:007#July 7th, 2026#!31Tue, 07 Jul 2026 12:53:41 +0000Z4131#/31Tue, 07 Jul 2026 12:53:41 +0000Z-12+00:003131+00:00202631#!31Tue, 07 Jul 2026 12:53:41 +0000Z+00:007#News

The Norwegian Data Protection Authority’s fine of NOK 20 million against Elkjøp/Elgiganten shows how serious the consequences can be when consent, data processing and documentation are not sufficiently managed.

However, the case should not be seen merely as a story about one company’s mistake.

It should be seen as an example of a broader challenge faced by many large companies: customer data is used across systems, channels and purposes, and the more complex the business becomes, the harder it is to ensure that data is processed correctly.

That is precisely why GDPR should not only be seen as a legal matter, but as a business-critical project.

Most GDPR mistakes are not caused by bad intentions

Most companies want to process customer data correctly. They often have teams, processes, internal policies and systems designed to create control and security.

Even so, mistakes still happen.

Not necessarily in an attempt to bypass the rules, but because reality is complex. A modern customer journey often spans e-commerce, CRM, marketing, apps, physical stores and customer service, with each system having its own data model, rules and way of handling consents and profiles.

This means that one customer may exist in several places at once, where consents, profiles and preferences are not always updated or synchronised correctly.

Fragmented customer data creates real business risk

For many companies, customer data has become one of their most important assets. Data is used for personalisation, loyalty programmes, segmentation, campaigns, service, analytics and automated communication.

But the value of data depends on whether the company actually has control over it.

If consents and profiles are scattered across systems, it becomes difficult to confidently answer basic questions:

  • What data do we have about the customer, and where does it come from?
  • What has the customer consented to, and for which purposes are we allowed to use the data?
  • How do we ensure that changes are reflected across all relevant systems?

Without a unified overview, compliance quickly becomes dependent on manual processes, interpretations and technical workarounds. This may work for a while, but it does not scale well in organisations with many touchpoints, departments and markets.

This is where the risk tends to arise – in the gaps between systems.

Compliance requires governance – not just good intentions

GDPR compliance is not only about having the right texts, policies and legal assessments. It is about being able to translate the rules into everyday practice.

This requires governance.

Governance means that the company has clear rules for how customer data is created, updated, used, documented and deleted. It ensures that responsibility does not disappear between departments, and that systems support the organisation’s decisions.

For larger companies, central governance should especially cover four areas:

1️⃣  A unified overview of profiles, so the customer can be identified and duplicates can be avoided.
2️⃣  Central management of consents and preferences, so it is clear what the customer has accepted.
3️⃣  Operationalisation of retention rules, so deletion deadlines can be enforced across systems.
4️⃣  Accessible documentation, so decisions, processes and the data foundation can be accounted for.

RubiqCloud: A central foundation for consents and profiles.

RubiqCloud is developed for companies that need a central consent and preference master. Not as yet another system, but as a layer designed to create coherence between CRM, CDP, marketing automation and customer service.

With RubiqCloud, companies can create a central overview of customers’ consents, preferences and permitted data use. At the same time, consents and customer profiles can be kept updated across channels and systems, so the entire organisation works from the same data foundation.

This reduces the risk of miscommunication, missing documentation and uncertain use of customer data.

But the value is not only found in avoiding compliance risk. When the data foundation is structured and reliable, the value especially lies in being able to:

  • Communication becomes more relevant
  • The customer experience becomes more transparent
  • Customer service gets a better customer overview
  • Marketing becomes more targeted

From legal requirement to business-critical foundation

The most important lesson from cases like Elkjøp’s is not that companies should be afraid to use customer data. Quite the opposite.

But data must be managed, documented and activated correctly. That is why consent and compliance should not be considered only at the end of a project, but should be part of the foundation.

When GDPR is placed solely within the legal department, it risks becoming a control point.

For large companies with many systems, channels and markets, the question is therefore not whether GDPR is important, but whether the company has the data governance needed to comply with the rules in practice.

That is a business-critical foundation.

Share