Person
1 link
Graph · Voice
01 · In focus
The structured facts the source records about Finn Myrstad, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.
voice
↑2 declared connections
02 · Connections
Split by direction. Direct links are the ones Finn Myrstad’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity. Some records appear in both because the corpus names them from both sides — those rows carry a note.
1 link
Links named in this entity's structured fields.
1 link
1 link
Other records that name this entity.
1 link
03 · Background
Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.
Finn Lützow-Holm Myrstad is Director of Digital Policy at the Norwegian Consumer Council (Forbrukerrådet), Oslo — the state-funded Norwegian consumer watchdog. He is tracked here as a Voice because his public-facing output has produced the corpus's clearest institutional embodiment of the evidence-first regulatory-complaint model: empirical investigation, followed by coordinated complaint filing, followed by regulatory enforcement and legislative follow-through. Across twelve-plus years in the role, his work has driven the highest GDPR fine in Norwegian history, influenced EU legislation from the Cyber Resilience Act to the AI Act debate, and installed "surveillance-based advertising" and "dark patterns" as actionable regulatory categories rather than academic concepts. See the linked Person entry for affiliations and biography.
The Voice anchors three movement-area registers that the corpus's voices slice had previously left empty or underrepresented.
The first Nordic consumer-digital-rights Voice. The corpus's Nordic and Scandinavian presence had been near-zero before this entry. Myrstad anchors it by occupying the position that distinguishes the Nordic digital-rights tradition from its UK and continental equivalents: a state-funded consumer body that wields GDPR complaints, parliamentary testimony, and coordinated international complaint campaigns as tools of structural accountability — not litigation-first (like Foxglove or NOYB) and not pure-advocacy (like EFF) but the hybrid investigative-complaint model that sits between them. Norway's EEA membership rather than EU membership means the NCC operates at the margins of EU law in a position that amplifies outside-EU civil-society pressure on inside-EU regulatory processes — an unusual structural position with disproportionate leverage.
The regulatory-complaint pipeline model. No other Voice in the corpus has institutionalised the full cycle — investigation, public report, coordinated GDPR complaint, regulatory fine, legislative reform — at comparable scale. The "Out of Control" adtech report is the clearest case: it produced a specific enforcement outcome (the NOK 65 million Grindr fine, upheld through all appeals to August 2025), a coordinated international complaint against six adtech companies, and contributed to EU DSA debate provisions on surveillance-based advertising. The model has been replicated through TACD, where the NCC's transatlantic complaint-coordinating role has influenced policy outcomes across jurisdictions.
Consumer rights as epistemic autonomy. Myrstad consistently frames what most consumer-protection discourse calls "data misuse" in a register that elevates it to fundamental-rights terrain: "our freedom to think and act freely is under pressure" from surveillance and data-driven manipulation. This framing connects consumer-rights enforcement to the broader epistemic-autonomy concerns that animate the digital-rights movement — treating dark patterns and surveillance advertising not as unfair trade practices but as threats to the cognitive and political conditions of democratic self-government. This register is underrepresented among the corpus's advocacy voices, which tend to frame harms in either civil-liberties (privacy as right) or algorithmic-accountability (disparate impact) terms rather than the epistemic-autonomy-of-consumers register.
Myrstad's public output is organised around a succession of landmark NCC investigations, each following the same structural pattern: empirical app-testing or interface analysis, rigorous published report, coordinated complaint filing or policy submission, regulatory and legislative follow-through.
"Deceived by Design" (June 2018). The NCC's post-GDPR analysis of how Google, Facebook, and Microsoft deployed dark patterns in their privacy-settings interfaces — defaulting to the least privacy-protective settings, using obstruction to make data-sharing easy and refusal hard, deploying misleading symbols and wording. The report is an early and influential mainstreaming of "dark patterns" analysis in EU regulatory discourse, and Myrstad's 2018 TED talk "How tech companies deceive you into giving up your data and privacy" brought the manufactured-consent argument to a popular audience: his team read all the terms of service installed on a standard smartphone, taking nearly 1.5 days, demonstrating that consent frameworks premised on reading terms are structurally unworkable.
"Out of Control" (January 2020). The NCC's major adtech investigation tested 10 popular apps — Grindr, OkCupid, Tinder, and others — and found real-time data transmission to at least 135 third parties involved in advertising or behavioural profiling. Grindr was found sharing GPS location, advertising ID, IP address, age, gender, and the fact of using a gay dating app with every adtech call. The report triggered coordinated GDPR complaints against Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, and Smaato; the Norwegian Data Protection Authority fined Grindr NOK 65 million in December 2021; the fine was upheld by the Privacy Appeals Board (September 2023) and by Oslo District Court (March 2024), reaching finality through Borgarting Court of Appeal (August 2025). Myrstad's public statement captured the investigation's normative framing: "Every time you open an app like Grindr, advertisement networks get your GPS location, device identifiers and even the fact that you use a gay dating app... This massive commercial surveillance is systematically at odds with fundamental rights."
"Ghost in the Machine" (June 2023). The NCC's 100-page consumer-harms framework for generative AI identified six harm categories — privacy violations, manipulation and deception, personal integrity breaches, fraud, disinformation, and environmental/resource costs — and argued that existing EU legal frameworks must be enforced immediately against generative AI products rather than waiting for new AI-specific legislation. The report's overarching formulation: "Technology is not some uncontrollable force, but must be adapted and formed by fundamental rights, regulations, and societal values." It fed into EU AI Act civil-society consultations and positioned the NCC as a major consumer-rights voice in AI governance.
Five formulations recur across Myrstad's public output and have done the most to install his register into EU regulatory discourse.
"Surveillance-based advertising" as a ban target, not a regulatory-adjustment target. Myrstad consistently uses "surveillance-based advertising" — rather than "behavioural advertising" or "targeted advertising" — as a precise category label that names the harm (surveillance, not targeting) and forecloses the soft-regulation response of notice-and-consent. His advocacy position is an outright ban: "A ban will contribute to a healthier marketplace that helps protect individuals and society." TACD and NCC have co-authored open letters to EU and US institutions calling for a full ban on surveillance-based advertising in DSA and related proceedings, and the EPIC award citation specifically credits his "Time to Ban Surveillance-Based Advertising" work as a driver of this regulatory framing.
"Dark patterns" as a structural regulatory category. The "Deceived by Design" report was among the earliest systematic applications of the dark-patterns concept to a policy-regulatory audience — translating what had been a UX research term into a legal-regulatory category with specific GDPR-violation implications. The investigation created the evidential base that Myrstad subsequently deployed in regulatory complaint filings, parliamentary testimony, and the TACD coordinated campaign that ultimately led Amazon to remove deceptive designs for EU users.
"Information asymmetry" as the structural mechanism of consumer harm. Myrstad's analytical frame for why individual consent is inadequate: "increased power and information asymmetries put people at an unprecedented disadvantage, which is reinforced by dark patterns, addictive design and artificial intelligence." This framing treats consumer harm not as individual bad behaviour by specific companies but as a structural power imbalance requiring structural regulatory remedy — a position that places his consumer-rights advocacy in the same structural-critique register as algorithmic-accountability and data-justice voices, while arriving from the consumer-protection institutional tradition rather than the civil-liberties or academic one.
"We cannot trust the big tech companies to fix this on their own." Myrstad's consistent position against voluntary industry self-regulation and AI ethics principles as substitutes for enforcement. Deployed in AI governance contexts — most prominently in "Ghost in the Machine" (2023) — it places him explicitly on the regulatory-mandate rather than industry-stewardship side of the AI governance debate and names the historical record (adtech non-reform despite GDPR) as the empirical basis for that position.
"Technology must be adapted and formed by fundamental rights, regulations, and societal values." Myrstad's normative grounding for the whole programme: technological development is not autonomous but is shaped by choices that can and must be regulated. This framing counters technological determinism and positions enforcement as the appropriate democratic response to AI and digital-platform harms — placing the Norwegian Consumer Council within the broader regulatory-accountability wing of the make-AI-good movement rather than in the "AI safety" or "AI alignment" registers that dominate Northern European AI discourse.
Myrstad's EU Co-chairship of the Transatlantic Consumer Dialogue (TACD) Digital/Information Society Committee is the primary mechanism through which the NCC's Nordic-base investigations have reached transatlantic regulatory scale. TACD coordinates approximately 75 US and European consumer organisations, and the NCC has used this platform to run coordinated complaint campaigns (Grindr adtech, Amazon subscription dark patterns) and to co-author open letters with US advocacy organisations — including EPIC — calling for surveillance advertising bans and AI consumer protections in DSA, EU AI Act, and US legislative processes.
The Mozilla Rise 25 Award citation (Berlin, October 2023) explicitly traces his work's regulatory reach to the EU Cyber Resilience Act, Amazon's removal of deceptive designs for EU users following coordinated TACD complaints, and California cybersecurity legislation — a rare award citation confirming legislative-outcome attribution across three distinct jurisdictions. The EPIC International Champion of Freedom Award (2022) confirmed the transatlantic reception of the NCC's surveillance-advertising and adtech work.
His appointment to the Norwegian government Privacy Commission (2020–2022) embedded the NCC's consumer-rights framing in the governmental advisory process shaping Norway's data protection reform priorities. His speaking platforms include the FTC, OECD Digital Ministerial, Nobel Prize Summit (2023), Harvard Belfer Center, Princeton Center for Information Technology Policy, and SXSW — a scope that marks him as internationally mobile rather than a purely national figure despite heading a national consumer body.
A Voice entry is created here, rather than additional structure on the Person entry, because Myrstad's public-facing output is itself the load-bearing object the corpus needs to track. The output runs through four channels: the NCC's landmark investigations ("Deceived by Design", "Out of Control", "Ghost in the Machine") that have produced concrete regulatory outcomes; the framings — surveillance-based advertising as ban target, dark patterns as structural category, information asymmetry as the mechanism of consumer harm, technology-must-be-formed-by-rights as normative grounding — that have installed into EU regulatory discourse a vocabulary connecting consumer-protection enforcement to democratic-rights terrain; the TACD transatlantic coordination that has amplified Nordic complaint-filing into multi-continental regulatory pressure; and the public-communication register (TED talk, institutional keynotes) that has made the regulatory-complaint model legible to audiences beyond specialists. No other Voice in the corpus has delivered a confirmed NOK 65 million enforcement outcome from a complaint-driven investigation, or has been credited by award citations with regulatory-text influence across three jurisdictions. The corpus's voices slice had no Nordic anchor, no consumer-rights-as-epistemic-autonomy Voice, and no practitioner of the investigative-complaint-to-regulation model at this scale; this entry gives all three their first representation. Affiliation and biographical structure are recorded on the linked Person entry per the corpus's Person/Voice split.
04 · Sources
9 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.
Forbrukerrådet staff page — primary source for Director of Digital Policy title, current employment, and institutional role at the Norwegian Consumer Council since approximately 2013
NCC "Deceived by Design" investigation (June 2018) — primary source for the dark-patterns investigation documenting how Google, Facebook, and Microsoft deployed deceptive interfaces to steer users toward privacy-invasive settings post-GDPR; Myrstad named as investigation lead; the report mainstreamed dark-patterns analysis in EU regulatory discourse and contributed to GDPR enforcement precedent on deceptive design
NCC "Out of Control" investigation (January 2020) — primary source for the adtech surveillance ecosystem report testing 10 popular apps and finding data transmission to at least 135 third parties; triggered GDPR complaints against Grindr, Twitter's MoPub, AT&T's AppNexus, OpenX, AdColony, and Smaato; led to a NOK 65 million Grindr fine (imposed December 2021, upheld through all appeals to August 2025); Myrstad: "This massive commercial surveillance is systematically at odds with fundamental rights"
NCC "Ghost in the Machine: Addressing the Consumer Harms of Generative AI" (June 2023) — primary source for the consumer-harms framework applied to generative AI (privacy violations, manipulation and deception, personal integrity breaches, fraud, disinformation, environmental costs) and for Myrstad's formulation "history has shown that we cannot trust the big tech companies to fix this on their own"; report fed into EU AI Act civil-society consultation
Forbrukerrådet press announcement (October 2023) — primary source for Myrstad's Mozilla Rise 25 Award (Berlin, October 2023) and award citation crediting NCC work as contributing to EU Cyber Resilience Act provisions, Amazon removing deceptive designs for EU users, and California cybersecurity law
EPIC announcement (May 2022) — primary source for the EPIC International Champion of Freedom Award to Forbrukerrådet (Myrstad accepting), citing "Out of Control" and "Time to Ban Surveillance-Based Advertising" work; confirms TACD-NCC partnership on coordinated transatlantic complaint campaigns
TACD profile — primary source for Myrstad's EU Co-chair role on the Transatlantic Consumer Dialogue Digital/Information Society Committee, connecting approximately 75+ US and European consumer organisations in coordinated transatlantic advocacy
Forbrukerrådet press announcement (23 June 2020) — primary source for Myrstad's appointment to the Norwegian government Privacy Commission (Personvernkommisjonen), 2020–2022
TED talk (2018) "How tech companies deceive you into giving up your data and privacy" — primary source for the manufactured-consent argument: Myrstad's team read all terms of service on a standard smartphone, taking nearly 1.5 days, demonstrating that GDPR's consent-based model cannot be operationalised at scale and that privacy defaults are the only effective protection
Source: entities/voices/voice-finn-myrstad.md — movement-graph pin 5d136ad.