:

ELKJOP FINED €1.8M FOR FORCED CONSENT PRACTICES

INDUSTRY DESK■ 1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Nordic electronics retailer Elkjop has been hit with a €1.8 million fine for implementing unlawful consent mechanisms. The penalty came five years after privacy advocates first flagged the practices as violations.

Elkjop's consent system required users to accept non-essential cookies and tracking before accessing services, a practice regulators determined violated EU privacy law. Users were not given genuine free choice, as refusing consent blocked access to core functionality. The company was warned about these practices years earlier but failed to implement compliant systems. When enforcement finally arrived, the scale of the violation—affecting numerous customers across multiple jurisdictions—resulted in the substantial fine. The case underscores enforcement gaps in privacy regulation. Despite clear guidance on consent requirements, companies can operate unlawfully for extended periods before facing consequences. GDPR requires affirmative, informed consent with equal friction for accepting and rejecting tracking. Forced consent arrangements that penalize users for privacy choices remain a widespread violation across e-commerce platforms.

■ SOURCES

► Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Hackers claim to have compromised the Federal Bureau of Investigation and obtained personal data on all FBI employees. The breach's scope and authenticity have not yet been independently verified.

3H AGO— Security Desk

Researchers at Cisco Talos developed a new framework to detect malware and hacking tools powered by AI chatbots. The discovery revealed an unusual threat: autonomous malware operating without human handlers.

4H AGO— AI Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.

5H AGO— Security Desk

WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.

7H AGO— Industry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.