Campaign
1 link
Graph · Event
01 · In focus
The structured facts the source records about Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020), the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.
event
↑3 declared connections
02 · Connections
Split by direction. Direct links are the ones Norwegian Consumer Council "Out of Control" report launch and GDPR complaint filing (14 January 2020)’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity. Some records appear in both because the corpus names them from both sides — those rows carry a note.
2 links
Links named in this entity's structured fields.
1 link
Other records that name this entity.
03 · Background
Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.
On 14 January 2020, the Norwegian Consumer Council (Forbrukerrådet) published "Out of Control: How consumers are exploited by the online advertising industry" — a 186-page technical investigation of data-sharing practices in ten popular consumer apps — and simultaneously filed three formal GDPR complaints at Norway's Data Protection Authority (Datatilsynet), co-filed with the privacy-law organisation NOYB. The simultaneous publication-and-complaint structure was deliberate: by converting audit findings into regulatory filings on the same day, the NCC ensured that international media coverage of the report coincided exactly with a live enforcement proceeding, making it difficult for companies or regulators to treat the findings as informational rather than actionable. The report received media coverage in more than 70 countries and catalysed parallel advocacy in the United States within weeks. The event anchors the NCC Out of Control campaign and is the corpus's first Scandinavia-based event entry.
The NCC developed the investigation in collaboration with Norwegian cybersecurity firm Mnemonic, which performed the technical traffic analysis, and independent US researcher Zach Edwards. Ten consumer apps were selected to represent high-risk categories — dating, women's health, religion, children's games, and utilities — that handled personal data users might expect to be treated with heightened sensitivity. The apps were Grindr, Tinder, OkCupid, and Happn (dating), Clue and MyDays (women's health and period tracking), Perfect365 (beauty), Qibla Finder (Muslim prayer direction), My Talking Tom 2 (children's game), and Wave Keyboard (keyboard). The methodology intercepted and catalogued network traffic from each app, identifying every third-party recipient of user data and characterising the data types transmitted.
The traffic analysis found that the ten apps were transmitting user data to at least 135 different third parties involved in advertising or behavioral profiling. The most sensitive data flows involved Grindr: the gay and bisexual dating app's pipeline exposed GPS location, IP addresses, advertising identifiers, age, gender, and — by the nature of the app — the user's sexual orientation, a special-category data type under GDPR Article 9 commanding the regulation's strongest consent and processing protections. The report's summary conclusion was that the adtech system "is based on the comprehensive and systemic illegal collection and use of personal data" — framing the problem as structural to behavioral advertising as a business model, not a collection of individual design failures correctable through better consent interfaces. EDRi characterised this framing at release as demonstrating that adtech illegality was structural rather than incidental.
On the same day, the NCC, in cooperation with NOYB, filed three complaints at Datatilsynet. The complaints targeted Grindr directly (for sharing sexual orientation — a special-category datum under GDPR Article 9 — with adtech partners without a valid legal basis), and the five adtech companies that had received Grindr users' data: Twitter's MoPub, AT&T's AppNexus (later Xandr), OpenX, AdColony, and Smaato. The core legal argument was that Grindr's consent mechanism — requiring users to accept the full privacy policy to access the app, with no granular ask about third-party sharing — did not constitute the freely given, specific, informed, and unambiguous consent that GDPR Article 7 requires; and that this defect propagated to every adtech recipient downstream, who accordingly also lacked a valid legal basis for processing.
The "Out of Control" report's US reception produced parallel action within weeks. Nine American consumer and privacy organisations — the ACLU of California, the Campaign for a Commercial-Free Childhood, the Center for Digital Democracy, Consumer Action, the Consumer Federation of America, Consumer Reports, the Electronic Privacy Information Center (EPIC), Public Citizen, and US PIRG — jointly urged the Federal Trade Commission, congressional lawmakers, and the state attorneys general of California, Texas, and Oregon to investigate the apps identified in the NCC report. The joint request called for a strong federal digital privacy law with a data protection agency, a private right of action, and strong enforcement mechanisms. The US coalition response, drawing nine major advocacy organisations across a jurisdictional and cultural divide within weeks of a Norwegian DPA filing, demonstrated that the NCC's audit-to-complaint methodology could function as a transnational civil-society forcing mechanism — a single technically rigorous report converting simultaneously into enforcement pressure in Europe and legislative pressure in the United States.
04 · Sources
5 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.
"Out of Control: How consumers are exploited by the online advertising industry" (14 January 2020) — primary source for the ten-app scope (Grindr, Tinder, OkCupid, Happn, Clue, MyDays, Perfect365, Qibla Finder, My Talking Tom 2, Wave Keyboard), the finding that these apps transmitted data to at least 135 different third parties, the summary conclusion that the adtech system represents "comprehensive and systemic illegal collection and use of personal data", and the simultaneous filing of three GDPR complaints at Datatilsynet
NOYB announcement of the three GDPR complaints co-filed with the NCC on 14 January 2020 — primary source for NOYB's co-filing role, the named respondents (Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, Smaato), and the complaints' legal basis under GDPR Article 7 (absence of valid consent for special-category sexual-orientation data processing)
TechCrunch coverage of the "Out of Control" report on the day of publication — independent secondary source corroborating the ten-app list, the 135-third-party finding, and the global media reach of the report at release
Public Citizen's January 2020 action page — primary source for the nine US consumer groups' joint request to the FTC, Congress, and the state AGs of California, Texas, and Oregon; names the ACLU of California, Campaign for a Commercial-Free Childhood, Center for Digital Democracy, Consumer Action, Consumer Federation of America, Consumer Reports, EPIC, Public Citizen, and US PIRG as the nine co-signers
EDRi coverage of the "Out of Control" report at release — secondary source confirming the January 2020 publication, the NCC's framing of adtech illegality as structural rather than incidental, and the report's positioning within the European digital-rights advocacy ecosystem
Source: entities/events/event-ncc-out-of-control-report-launch-2020-01.md — movement-graph pin 5d136ad.