Back to blog

Your Consent Banner May Be Illegal

Based on research by NOYB

schremsdata protectionaigdpr

Schibsted, the Nordic media giant behind Aftonbladet and VG, has triggered a regulatory backlash by implementing a “Pay or Okay” consent model. Complaints filed by NOYB and the Norwegian Consumer Council argue this practice forces users to either accept invasive ad tracking or pay a premium to reject it. For Swedish CTOs and CISOs, this is not just a media industry dispute; it is a direct warning that coercive consent mechanisms are being scrutinized as violations of fundamental privacy rights.

The core issue is that consent must be freely given. By making the rejection of tracking financially punitive, Schibsted effectively eliminates the choice, resulting in consent rates near 99% despite studies showing only a tiny fraction of users actually want to be tracked. This creates what critics call “North Korean consent,” where the illusion of choice masks a forced surrender of data. If a user declines because they cannot afford the fee, that is not consent; it is extortion.

The impact for Swedish companies is immediate and severe. The Swedish IMY has already received over 56 complaints against Schibsted’s Swedish subsidiary alone. If regulators determine that your consent banners or API data-sharing agreements rely on similar coercive structures, you face significant compliance gaps. The risk is not just reputational damage but substantial fines and mandatory operational overhauls. You must audit your data processing workflows to ensure that no financial barrier exists between a user and their right to say no.

This development reinforces the critical case for processing data locally within the EU and Sweden. When you rely on external platforms that enforce aggressive tracking or questionable consent models, you inherit their legal liabilities. By keeping data processing local and under your direct control, you eliminate the risk of third-party coercive practices affecting your compliance posture. It allows you to design privacy-by-default architectures that respect user autonomy without relying on predatory business models.

The takeaway is clear: consent is a legal obligation, not a business opportunity. If your data strategy depends on trapping users in tracking loops, you are building on unstable legal ground. Prioritize transparent, local data handling that respects user choice, and you will stay ahead of regulatory enforcement while building genuine trust with your audience.