Skip to content
Make AI Good

Graph · Campaign

Norwegian Consumer Council "Out of Control" campaign against behavioral advertising (2020–ongoing)

01 · In focus

One campaign, in the field.

The structured facts the source records about Norwegian Consumer Council "Out of Control" campaign against behavioral advertising (2020–ongoing), the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

campaign

6 declared connections

Kind
Campaign
Status
active
Confidence
high
Start
2020-01-14
End
ongoing
Entity ID
camp-ncc-out-of-control-behavioral-advertising-2020
Network
View in network

Tags norway, oslo, scandinavia, nordics, behavioral-advertising, surveillance-advertising, adtech, gdpr, data-protection, privacy, consumer-rights, dating-apps, health-apps, enforcement, regulatory-complaints, datatilsynet, ban-surveillance-advertising, transatlantic, coalition, empirical-audit, noyb

Norwegian Consumer Council "Out of Control" campaign against behavioral advertising (2020–ongoing) · 5 direct neighbours visible

02 · Connections

6 adjacencies, by relation.

Split by direction. Direct links are the ones Norwegian Consumer Council "Out of Control" campaign against behavioral advertising (2020–ongoing)’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity. Some records appear in both because the corpus names them from both sides — those rows carry a note.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

On 14 January 2020, the Norwegian Consumer Council (Forbrukerrådet) published "Out of Control: How consumers are exploited by the online advertising industry" — a technical investigation exposing systematic GDPR violations across ten popular consumer apps — and simultaneously filed three GDPR complaints at Norway's Data Protection Authority (Datatilsynet), in cooperation with the privacy-law organisation NOYB, against a dating app and five adtech companies. The campaign is the Nordic region's most consequential civil-society-initiated GDPR enforcement action against the behavioral advertising industry to date, producing a NOK 65 million fine against Grindr upheld through five years of appeals, and anchoring a subsequent transatlantic push — the 2021 "Time to Ban Surveillance-Based Advertising" campaign — for outright prohibition of surveillance-based advertising in the EU and the United States.

The "Out of Control" report

The 186-page "Out of Control" report was developed by the NCC in collaboration with cybersecurity firm Mnemonic and independent researcher Zach Edwards. Ten popular consumer apps were selected for technical traffic analysis: the queer and bisexual dating app Grindr, the heterosexual dating apps Tinder, OkCupid, and Happn, the women's health and period-tracker apps Clue and MyDays, the beauty app Perfect365, the Muslim prayer app Qibla Finder, the children's game My Talking Tom 2, and the keyboard app Wave Keyboard. The report found that these ten apps were transmitting user data to at least 135 different third parties involved in advertising or behavioral profiling. The data flows were particularly sensitive in the case of Grindr, whose pipeline exposed GPS location, IP addresses, advertising identifiers, age, gender, and — by the nature of the app — the user's sexual orientation, a special-category data type under GDPR commanding the regulation's strongest consent and processing protections. The report's summary finding was that "the system in its current form is based on the comprehensive and systemic illegal collection and use of personal data" — a formulation framing the problem as structural to behavioral advertising as a business model, not a collection of individual design failures. The report received media coverage in more than 70 countries, including the United States and Japan.

The GDPR complaints

On the same day the report was published, the NCC, in cooperation with NOYB, filed three formal GDPR complaints at Datatilsynet. The three complaints targeted: Grindr (for sharing special-category personal data — sexual orientation — with adtech partners without a valid GDPR legal basis); and Twitter's MoPub, AT&T's AppNexus (now Xandr), OpenX, AdColony, and Smaato (for receiving Grindr users' personal data without a valid legal basis for processing it). The core legal argument was that Grindr's consent mechanism — requiring users to accept the full privacy policy to access the app, without any specific or granular ask about third-party data sharing — did not constitute freely given, specific, informed, and unambiguous consent as GDPR Article 7 requires, and that this defect propagated to every adtech recipient downstream.

The US consumer coalition response

The NCC report's US reception produced an immediate parallel action. In January 2020, nine American consumer and privacy groups — the ACLU of California, the Campaign for a Commercial-Free Childhood, the Center for Digital Democracy, Consumer Action, the Consumer Federation of America, Consumer Reports, the Electronic Privacy Information Center (EPIC), Public Citizen, and US PIRG — jointly urged the Federal Trade Commission, congressional lawmakers, and the state attorneys general of California, Texas, and Oregon to investigate the apps named in the NCC report. The joint request called for a strong federal digital privacy law that would include a new data protection agency, a private right of action, and strong enforcement mechanisms. The US action demonstrated that the NCC's audit methodology — a technical investigation of app data-sharing traffic, converted on the same day into a regulatory complaint, released publicly to mobilise a civil-society coalition — could catalyse parallel enforcement advocacy across jurisdictions from a single published report.

Enforcement outcomes

Datatilsynet opened enforcement proceedings against Grindr on the basis of the NCC complaint. In January 2021, the authority issued an advance notification of a fine of NOK 100 million; the final administrative fine was set at NOK 65 million (approximately EUR 6.3 million). Grindr challenged the fine through successive appeal mechanisms: the Norwegian Privacy Appeals Board upheld the fine in 2022; the Oslo District Court upheld it in March 2024; and the Borgarting Court of Appeal dismissed Grindr's further appeal after an August 2025 hearing, confirming the fine across five years of litigation. The enforcement proceedings against the five adtech companies that received data from Grindr — Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, and Smaato — remained ongoing as of 2026.

Time to Ban Surveillance-Based Advertising (2021)

On 22 June 2021, the NCC published "Time to Ban Surveillance-Based Advertising: The case against commercial surveillance online" — a policy paper arguing that surveillance advertising's privacy violations were not correctable through better consent architecture and that the model should be prohibited outright. The report framed behavioral targeting as a system rendering consumers "vulnerable to manipulation, discrimination and fraud" by enabling companies to identify and exploit individual psychological vulnerabilities at the moment of highest susceptibility. The following day, on 23 June 2021, the NCC sent an open letter to EU and US policymakers co-signed by more than 60 organisations from Europe and the United States — including BEUC (the European Consumer Organisation) and EDRi — urging EU lawmakers to ban surveillance advertising through the Digital Services Act and urging the United States to enact a long-overdue federal privacy law. The campaign was, at its launch, one of the first transatlantic consumer-privacy advocacy efforts to frame surveillance advertising as a systemic wrong requiring categorical prohibition rather than a consent-architecture problem requiring stronger notice.

Place in the make-AI-good movement

The campaign matters to the wider corpus on four connected counts. First, it is the corpus's first Scandinavia-based campaigns entry and the first entry in the behavioral-advertising surveillance sector — filling a geographic gap in Nordic coverage and a movement-area gap in adtech-focused civil-society accountability work. Second, the "Out of Control" report's methodology — technical app traffic analysis conducted with a cybersecurity firm and a privacy-law organisation, converted on the same day into GDPR complaints, released publicly to mobilise international civil-society coverage and parallel national enforcement actions — is one of the field's most fully-developed implementations of the empirical-audit-and-expose strategy, and was recognised by EPIC's International Privacy Champion Award as having "played a major role in driving surveillance advertising reform globally". Third, the campaign demonstrates the transjurisdictional reach that a single technically rigorous civil-society report can generate: nine US consumer groups moved within weeks of the Norwegian DPA complaints, across an Atlantic divide and without coordination infrastructure. Fourth, the "Time to Ban" pivot — moving from complaint-by-complaint enforcement to a structural-prohibition argument addressed simultaneously to EU and US policymakers — is the campaign's most ambitious attempt to shift the behavioral advertising debate from consent-architecture regulation toward categorical prohibition, a policy position that has entered the vocabulary of European consumer-rights advocacy through the NCC's sustained advocacy even where it has not yet produced a legislative ban.

04 · Sources

Where this came from.

10 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. storage02.forbrukerradet.no

    Checked 2026-06-08

    "Out of Control: How consumers are exploited by the online advertising industry" (14 January 2020) — primary source for the ten-app scope (Grindr, Tinder, OkCupid, Happn, Clue, MyDays, Perfect365, Qibla Finder, My Talking Tom 2, Wave Keyboard), the finding that these apps transmitted data to at least 135 different third parties, the conclusion that the adtech system represents "comprehensive and systemic illegal collection and use of personal data", the methodology involving cybersecurity firm Mnemonic and researcher Zach Edwards, and the three GDPR complaints filed simultaneously at Datatilsynet

  2. noyb.eu

    Checked 2026-06-08

    NOYB announcement of the three GDPR complaints co-filed with the NCC at Datatilsynet on 14 January 2020 — primary source for NOYB's co-filing role, the named respondents (Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, Smaato), and the complaints' legal basis (absence of valid GDPR consent for special-category data processing including sexual orientation)

  3. noyb.eu

    Checked 2026-06-08

    NOYB page on the Grindr GDPR fine — primary source for the final NOK 65 million fine (approximately EUR 6.3 million), Datatilsynet's determination that Grindr's consent mechanism did not constitute valid GDPR consent, and confirmation of the fine by the Privacy Appeals Board in 2022

  4. datatilsynet.no

    Checked 2026-06-08

    Datatilsynet news page confirming the record Grindr fine through successive appeals — primary source for the NOK 65 million administrative fine, the Privacy Appeals Board upholding it in 2022, the Oslo District Court upholding it in March 2024, and the Borgarting Court of Appeal dismissing Grindr's further appeal after an August 2025 hearing

  5. storage02.forbrukerradet.no

    Checked 2026-06-08

    "Time to Ban Surveillance-Based Advertising: The case against commercial surveillance online" (22 June 2021) — primary source for the NCC's structural-prohibition argument that behavioral advertising cannot be reformed through consent architecture and should be banned outright, and for the framing that behavioral targeting renders consumers "vulnerable to manipulation, discrimination and fraud"

  6. edri.org

    Checked 2026-06-08

    EDRi event page for the June 2021 transatlantic discussion — primary source for the 23 June 2021 open letter to EU and US policymakers co-signed by 60+ organisations including BEUC and EDRi, Finn Lützow-Holm Myrstad's title as Director of Digital Policy, and the NCC's framing of the open letter as a request that policymakers "consider a ban of surveillance-based advertising as part of the Digital Services Act"

  7. citizen.org

    Checked 2026-06-08

    Public Citizen's January 2020 action page — primary source for the nine US consumer groups' joint request to the FTC, Congress, and the state AGs of California, Texas, and Oregon; names the ACLU of California, Campaign for a Commercial-Free Childhood, Center for Digital Democracy, Consumer Action, Consumer Federation of America, Consumer Reports, EPIC, Public Citizen, and US PIRG as the nine co-signers

  8. edri.org

    Checked 2026-06-08

    EDRi's coverage of the "Out of Control" report at release — secondary source confirming the January 2020 publication, the report's key findings, and EDRi's characterisation that the adtech system's illegality is structural rather than incidental

  9. forbrukerradet.no

    Checked 2026-06-08

    NCC's own page for the EPIC International Privacy Champion Award — primary source for EPIC's recognition of the "Out of Control" and "Time to Ban" work as having "played a major role in driving surveillance advertising reform globally"

  10. techcrunch.com

    Checked 2026-06-08

    TechCrunch coverage of the "Out of Control" report on the day of publication — independent secondary source corroborating the ten-app list, the 135-third-party finding, and the global media reach of the report

Source: entities/campaigns/camp-ncc-out-of-control-behavioral-advertising-2020.md — movement-graph pin 5d136ad.