Skip to content
Make AI Good

Graph · Event

Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020)

01 · In focus

One event, in the field.

The structured facts the source records about Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020), the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

event

3 declared connections

Kind
Event
Status
historical
Confidence
high
Type
report launch
Date
2020-01-14
Location
Oslo, Norway
Entity ID
event-ncc-out-of-control-report-launch-2020-01
Network
View in network

Tags norway, oslo, scandinavia, nordics, behavioral-advertising, surveillance-advertising, adtech, gdpr, data-protection, privacy, consumer-rights, dating-apps, health-apps, regulatory-complaints, datatilsynet, report-launch, empirical-audit, special-category-data, mnemonic, noyb, grindr

Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020) · 2 direct neighbours visible

02 · Connections

3 adjacencies, by relation.

Split by direction. Direct links are the ones Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020)’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity. Some records appear in both because the corpus names them from both sides — those rows carry a note.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

On 14 January 2020, the Norwegian Consumer Council (Forbrukerrådet) published "Out of Control: How consumers are exploited by the online advertising industry" — a 186-page technical investigation of data-sharing practices in ten popular consumer apps — and simultaneously filed three formal GDPR complaints at Norway's Data Protection Authority (Datatilsynet), co-filed with the privacy-law organisation NOYB. The simultaneous publication-and-complaint structure was deliberate: by converting audit findings into regulatory filings on the same day, the NCC ensured that international media coverage of the report coincided exactly with a live enforcement proceeding, making it difficult for companies or regulators to treat the findings as informational rather than actionable. The report received media coverage in more than 70 countries and catalysed parallel advocacy in the United States within weeks. The event anchors the NCC Out of Control campaign and is the corpus's first Scandinavia-based event entry.

The audit methodology and scope

The NCC developed the investigation in collaboration with Norwegian cybersecurity firm Mnemonic, which performed the technical traffic analysis, and independent US researcher Zach Edwards. Ten consumer apps were selected to represent high-risk categories — dating, women's health, religion, children's games, and utilities — that handled personal data users might expect to be treated with heightened sensitivity. The apps were Grindr, Tinder, OkCupid, and Happn (dating), Clue and MyDays (women's health and period tracking), Perfect365 (beauty), Qibla Finder (Muslim prayer direction), My Talking Tom 2 (children's game), and Wave Keyboard (keyboard). The methodology intercepted and catalogued network traffic from each app, identifying every third-party recipient of user data and characterising the data types transmitted.

Core findings

The traffic analysis found that the ten apps were transmitting user data to at least 135 different third parties involved in advertising or behavioral profiling. The most sensitive data flows involved Grindr: the gay and bisexual dating app's pipeline exposed GPS location, IP addresses, advertising identifiers, age, gender, and — by the nature of the app — the user's sexual orientation, a special-category data type under GDPR Article 9 commanding the regulation's strongest consent and processing protections. The report's summary conclusion was that the adtech system "is based on the comprehensive and systemic illegal collection and use of personal data" — framing the problem as structural to behavioral advertising as a business model, not a collection of individual design failures correctable through better consent interfaces. EDRi characterised this framing at release as demonstrating that adtech illegality was structural rather than incidental.

The GDPR complaints

On the same day, the NCC, in cooperation with NOYB, filed three complaints at Datatilsynet. The complaints targeted Grindr directly (for sharing sexual orientation — a special-category datum under GDPR Article 9 — with adtech partners without a valid legal basis), and the five adtech companies that had received Grindr users' data: Twitter's MoPub, AT&T's AppNexus (later Xandr), OpenX, AdColony, and Smaato. The core legal argument was that Grindr's consent mechanism — requiring users to accept the full privacy policy to access the app, with no granular ask about third-party sharing — did not constitute the freely given, specific, informed, and unambiguous consent that GDPR Article 7 requires; and that this defect propagated to every adtech recipient downstream, who accordingly also lacked a valid legal basis for processing.

Immediate international response

The "Out of Control" report's US reception produced parallel action within weeks. Nine American consumer and privacy organisations — the ACLU of California, the Campaign for a Commercial-Free Childhood, the Center for Digital Democracy, Consumer Action, the Consumer Federation of America, Consumer Reports, the Electronic Privacy Information Center (EPIC), Public Citizen, and US PIRG — jointly urged the Federal Trade Commission, congressional lawmakers, and the state attorneys general of California, Texas, and Oregon to investigate the apps identified in the NCC report. The joint request called for a strong federal digital privacy law with a data protection agency, a private right of action, and strong enforcement mechanisms. The US coalition response, drawing nine major advocacy organisations across a jurisdictional and cultural divide within weeks of a Norwegian DPA filing, demonstrated that the NCC's audit-to-complaint methodology could function as a transnational civil-society forcing mechanism — a single technically rigorous report converting simultaneously into enforcement pressure in Europe and legislative pressure in the United States.

04 · Sources

Where this came from.

5 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. storage02.forbrukerradet.no

    Checked 2026-06-08

    "Out of Control: How consumers are exploited by the online advertising industry" (14 January 2020) — primary source for the ten-app scope (Grindr, Tinder, OkCupid, Happn, Clue, MyDays, Perfect365, Qibla Finder, My Talking Tom 2, Wave Keyboard), the finding that these apps transmitted data to at least 135 different third parties, the summary conclusion that the adtech system represents "comprehensive and systemic illegal collection and use of personal data", and the simultaneous filing of three GDPR complaints at Datatilsynet

  2. noyb.eu

    Checked 2026-06-08

    NOYB announcement of the three GDPR complaints co-filed with the NCC on 14 January 2020 — primary source for NOYB's co-filing role, the named respondents (Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, Smaato), and the complaints' legal basis under GDPR Article 7 (absence of valid consent for special-category sexual-orientation data processing)

  3. techcrunch.com

    Checked 2026-06-08

    TechCrunch coverage of the "Out of Control" report on the day of publication — independent secondary source corroborating the ten-app list, the 135-third-party finding, and the global media reach of the report at release

  4. citizen.org

    Checked 2026-06-08

    Public Citizen's January 2020 action page — primary source for the nine US consumer groups' joint request to the FTC, Congress, and the state AGs of California, Texas, and Oregon; names the ACLU of California, Campaign for a Commercial-Free Childhood, Center for Digital Democracy, Consumer Action, Consumer Federation of America, Consumer Reports, EPIC, Public Citizen, and US PIRG as the nine co-signers

  5. edri.org

    Checked 2026-06-08

    EDRi coverage of the "Out of Control" report at release — secondary source confirming the January 2020 publication, the NCC's framing of adtech illegality as structural rather than incidental, and the report's positioning within the European digital-rights advocacy ecosystem

Source: entities/events/event-ncc-out-of-control-report-launch-2020-01.md — movement-graph pin 5d136ad.