:

ELKJOP FINED €1.8M FOR FORCED CONSENT PRACTICES

INDUSTRY DESK■ 1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Nordic electronics retailer Elkjop has been hit with a €1.8 million fine for implementing unlawful consent mechanisms. The penalty came five years after privacy advocates first flagged the practices as violations.

Elkjop's consent system required users to accept non-essential cookies and tracking before accessing services, a practice regulators determined violated EU privacy law. Users were not given genuine free choice, as refusing consent blocked access to core functionality. The company was warned about these practices years earlier but failed to implement compliant systems. When enforcement finally arrived, the scale of the violation—affecting numerous customers across multiple jurisdictions—resulted in the substantial fine. The case underscores enforcement gaps in privacy regulation. Despite clear guidance on consent requirements, companies can operate unlawfully for extended periods before facing consequences. GDPR requires affirmative, informed consent with equal friction for accepting and rejecting tracking. Forced consent arrangements that penalize users for privacy choices remain a widespread violation across e-commerce platforms.

■ SOURCES

► Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploits targeting critical vulnerabilities in SharePoint, WSO2, and Adobe Commerce. Attackers are actively leveraging these flaws in real-world attacks.

JUST NOW— Security Desk

Multiple Supabase customers have inadvertently exposed sensitive user data online due to misconfiguration and inadequate security settings. The incidents underscore risks inherent in rapidly deployed AI-generated and minimally-configured applications.

JUST NOW— Industry Desk

File transfer platform Kiteworks has urged customers to shut down their servers after receiving a credible threat of an imminent cyberattack from law enforcement.

2H AGO— Security Desk

Cryptocurrency exchange Bitget disclosed a breach of its hot and warm wallets, with hackers stealing $351.6 million. The attack is attributed to suspected North Korean threat actors.

4H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.