Skip to content
Make AI Good

Graph · Publication

Out of Control: How Consumers Are Exploited by the Online Advertising Industry

01 · In focus

One publication, in the field.

The structured facts the source records about Out of Control: How Consumers Are Exploited by the Online Advertising Industry, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

publication

2 declared connections

Kind
Publication
Status
active
Confidence
high
Type
report
Date
2020-01-14
Entity ID
pub-norwegian-consumer-council-out-of-control-2020
Network
View in network

Tags report, norway, scandinavia, nordics, adtech, surveillance-advertising, data-brokering, gdpr, consumer-rights, privacy, data-protection, behavioral-profiling, sexual-orientation-data, special-category-data, regulatory-complaint, grindr, enforcement-outcome, foundational-artefact, surveillance-capitalism, norwegian-consumer-council, nordic-civil-society

Out of Control: How Consumers Are Exploited by the Online Advertising Industry · 2 direct neighbours visible

02 · Connections

2 adjacencies, by relation.

Split by direction. Direct links are the ones Out of Control: How Consumers Are Exploited by the Online Advertising Industry’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

Direct from this record

2 links

Links named in this entity's structured fields.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

Out of Control: How Consumers Are Exploited by the Online Advertising Industry is a report published by the Norwegian Consumer Council (Forbrukerrådet) on 14 January 2020, led by Finn Myrstad, Director of Digital Policy, with technical analysis conducted by Norwegian cybersecurity firm Mnemonic AS and research contributions from Wolfie Christl of Cracked Labs. The report documents the scale and architecture of personal data flows from ten popular consumer apps to the global advertising technology industry, presents the conclusion that these practices constitute "comprehensive and systemic illegal collection and use of personal data" under the General Data Protection Regulation, and converts its findings directly into formal GDPR complaints lodged the same day at the Norwegian Data Protection Authority. It is the foundational Nordic civil-society publication on surveillance-based advertising as a structural legal violation — and the enforcement action it triggered produced one of the most significant GDPR adtech penalties in European regulatory history.

Technical methodology and findings

The investigation was designed as a technical audit rather than a policy survey. Mnemonic AS tested ten Android applications spanning consumer categories representing high-sensitivity data contexts: dating apps (Grindr, Tinder, OkCupid, Happn), period trackers (Clue, My Days), a makeup app (Perfect365), a keyboard app (Wave Keyboard), a children's app (My Talking Tom 2), and a religious app (Muslim: Qibla Finder). The methodology involved logging and analyzing more than 88,000 web requests generated by the apps during normal use, identifying the destination and content of each outbound data transmission. The ten apps collectively communicated with at least 216 unique third-party domains owned by at least 135 different companies operating within the advertising and behavioral profiling ecosystem — including advertising networks, data brokers, analytics providers, and real-time bidding intermediaries. The Android Advertising ID — the device-level persistent identifier that enables cross-app and cross-session behavioral tracking — was transmitted to at least 45 different third parties. Beyond device identifiers, the transmitted data included GPS location, IP address, age, gender, and behavioral data derived from in-app interactions. The scale of the data-sharing infrastructure revealed by the audit demonstrated that even without any individual "bad actor" — the entire architecture of the system as built and operated was illegally processing personal data at industrial scale.

Special-category data and the Grindr case

The report's most consequential finding concerned Grindr, the gay and bisexual men's dating application. Grindr transmitted user data — including GPS coordinates precise enough to locate an individual within meters, IP address, device model, advertising identifiers, age, and gender — to a range of adtech intermediaries including Twitter's MoPub (which then redistributed the data to further downstream recipients), AT&T's AppNexus, OpenX, AdColony, and Smaato. The character of the application is dispositive: a user's presence on Grindr reveals or strongly implies their sexual orientation or sexual identity, which falls within GDPR Article 9's list of special-category data — data whose processing is subject to strict prohibition except under narrow specified bases. By transmitting Grindr usage data to commercial adtech companies without an explicit, specific, and unambiguous consent for that particular processing purpose, the report argued that Grindr was transmitting GDPR Article 9 data to commercial third parties with no valid legal basis. The report connected this to the structural logic of the consent mechanism Grindr then used: users were required to accept the full privacy policy to access the application, with no specific ask about third-party advertising data sharing. The report concluded this did not meet the GDPR standard for freely given, specific, informed, and unambiguous consent.

Regulatory action and enforcement outcomes

The NCC filed three formal GDPR complaints simultaneously with the report's release, lodged with the Norwegian Data Protection Authority (Datatilsynet) in coordination with noyb (None of Your Business), the European privacy rights organisation founded by Max Schrems: one against Grindr, and one each against five adtech companies — Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, and Smaato — all on the ground that the receiving companies lacked a valid legal basis for the personal data being transmitted to them. More than 40 consumer, human rights, and digital rights organisations backed the report at release, with subsequent support from over 60 organisations across Europe and the United States; BEUC, the European Consumer Organisation of which the NCC is a member, mobilized its national member councils to file parallel requests with their own data protection authorities. The Grindr complaint produced the most far-reaching regulatory outcome: Datatilsynet imposed an administrative fine of NOK 65 million (approximately EUR 5.7–6.5 million at the time of issuance), a figure sustained through the Privacy Appeals Board (2022), the Oslo District Court (March 2024), and the Borgarting Court of Appeal (August 2025 hearing, dismissal confirmed). The years-long confirmation chain — Grindr appealing at every level and the fine upheld at each — produced one of the most thoroughly litigated adtech enforcement outcomes in European GDPR history. The Electronic Privacy Information Center (EPIC) awarded the NCC its International Privacy Champion Award in 2022, citing the "Out of Control" and subsequent "Time to Ban Surveillance-Based Advertising" work as having "played a major role in driving surveillance advertising reform globally".

Posture within the corpus

Out of Control is the corpus's first Nordic civil-society publication, closing the Scandinavian geographic gap in the Publications slice. It sits within a cluster of civil-society technical-audit reports — alongside the NCC's own earlier "Deceived by Design" (2018, dark patterns) and AlgorithmWatch's Automating Society Report 2020 — but occupies a distinct position: where Automating Society maps the European landscape of automated decision-making for a policy audience, Out of Control is primarily a legal-complaint instrument dressed as a consumer report. Its organizing logic is not "here is what we found, now regulators should consider acting" but rather "here is a technically documented violation of current law, and we are filing the complaint today." That move — publishing the investigation and the regulatory complaint simultaneously, with the investigation as the evidence base — has become a template within European consumer-rights digital-rights advocacy. EDRi highlighted the report at release as a demonstration that the adtech system's illegality was structural rather than incidental, and Privacy International engaged with the broader surveillance advertising enforcement ecosystem the report catalyzed. The report's publication in 2020 — the same year as the Automating Society Report 2020 and two years into the GDPR enforcement era — marks a point when civil-society organizations began converting their investigative research into formal legal instruments at scale.

04 · Sources

Where this came from.

6 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. storage02.forbrukerradet.no

    Checked 2026-06-10

    Full PDF of the "Out of Control" report — primary source for publication date (14 January 2020), the ten-app test methodology, the 135-third-party finding, the systemic illegality conclusion ("the system in its current form is based on the comprehensive and systemic illegal collection and use of personal data"), the list of GDPR complaints filed against Grindr and five adtech companies, and the report's policy demands

  2. forbrukerradet.no

    Checked 2026-06-10

    Norwegian Consumer Council report landing page — primary source for the report's official home and the NCC's institutional framing of the adtech complaint model

  3. storage02.forbrukerradet.no

    Checked 2026-06-10

    Mnemonic AS technical security test report — primary source for the ten apps tested (Clue, Grindr, Happn, Muslim: Qibla Finder, My Days, My Talking Tom 2, OkCupid, Perfect365, Tinder, Wave Keyboard), the methodology of logging and analyzing more than 88,000 web requests, the 216 unique third-party domains identified, and the technical taxonomy of data transmitted by type

  4. noyb.eu

    Checked 2026-06-10

    noyb press release on the three GDPR complaints filed simultaneously with the report — primary source for the complaint targets (Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, Smaato), the joint NCC–noyb filing structure, and the legal theory that neither Grindr nor the adtech recipients had a valid legal basis for the processing

  5. datatilsynet.no

    Checked 2026-06-10

    Datatilsynet news page confirming the Grindr fine — primary source for the NOK 65 million administrative fine, the Privacy Appeals Board upholding it in 2022, the Oslo District Court upholding it in March 2024, and the Borgarting Court of Appeal dismissing Grindr's further appeal after an August 2025 hearing

  6. edri.org

    Checked 2026-06-10

    EDRi coverage of the report at release — secondary source confirming the January 2020 release date, the NCC's systemic-illegality framing, and the report's positioning within the European civil-society adtech-enforcement ecosystem

Source: entities/publications/pub-norwegian-consumer-council-out-of-control-2020.md — movement-graph pin 5d136ad.