What Happened
In early 2021, Datatilsynet proposed a $12 million fine against Grindr following a complaint from the Norwegian Consumer Council. The enforcement action focused on the dating app's consent mechanism, which the supervisory authority found violated GDPR requirements through manipulative design practices. Grindr claimed it had improved its consent interface, but the case proceeded, marking the highest fine Norway's supervisory authority had issued at that time.
The NCC's complaint was based on years of research into "dark patterns", interface designs that push users toward choices benefiting the company rather than the user. The organization released a comprehensive report on these practices in 2018, setting the stage for regulatory scrutiny of consent mechanisms that technically comply with GDPR's letter while undermining its spirit.
Timeline
2018: The Norwegian Consumer Council published its dark patterns report, documenting manipulative design techniques across consumer applications.
Early 2021: The NCC filed a formal complaint with Datatilsynet regarding Grindr's consent mechanism.
Early 2021: Datatilsynet issued its notice of intent to fine Grindr $12 million.
Following the notice: Grindr responded, claiming it had improved its consent interface, but the enforcement action continued.
Which Controls Failed or Were Missing
Grindr's consent mechanism failed at the interface design level. While the company likely implemented technical controls for recording and managing consent choices, the presentation layer violated core GDPR principles.
- Pre-ticked boxes or default consent: If users had to actively opt out rather than opt in, the mechanism violated Article 7's requirement for clear affirmative action.
- Confusing language or visual hierarchy: Consent requests that buried the "no" option or used design elements to make acceptance appear easier than refusal failed the "freely given" test.
- Bundled consent without granularity: If users couldn't separately consent to different processing purposes, the mechanism violated Article 7(4)'s prohibition on consent as a condition for service when unnecessary.
- Absence of user testing: No evidence suggests Grindr tested whether users genuinely understood what they were consenting to, which matters when supervisory authorities assess whether consent was "informed."
The deeper failure was organizational: treating consent as a legal checkbox rather than a user rights mechanism. Your consent interface reflects your data protection culture. If your design team's incentives reward conversion rates over clarity, you're building a compliance liability.
What the Relevant Standard Requires
Article 7(1) establishes that controllers must demonstrate consent was freely given, specific, informed, and unambiguous. Article 4(11) defines consent as "any freely given, specific, informed and unambiguous indication of the data subject's wishes."
Recital 32 adds critical context: "Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement."
Article 7(2) requires that consent requests be "clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language."
Article 7(4) addresses the power imbalance directly: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
The European Data Protection Board's Guidelines 05/2020 on consent specify that dark patterns violate these requirements. The guidelines describe scenarios where visual design, timing, or interface choices manipulate users into consenting when they wouldn't have otherwise.
Your consent mechanism must pass this test: if you removed all visual styling and presented the choice in plain text, would users still make the same decision at the same rate? If your consent rate drops significantly with a plain interface, you're relying on manipulation, not genuine agreement.
Lessons and Action Items for Your Team
Audit your consent interface with hostile eyes. Don't ask whether it technically complies. Ask whether it manipulates. Show your consent flow to someone unfamiliar with your product. If they can't immediately identify how to refuse consent, you've failed.
Separate your design incentives from your consent mechanism. Your product team optimizes for engagement. Your consent interface must optimize for informed choice. These goals conflict. Establish a review process where your DPO or legal team approves consent interface changes independently of product metrics.
Document your design decisions. When Datatilsynet or another supervisory authority questions your consent mechanism, you'll need to demonstrate that each design choice served user clarity, not company conversion. Keep records of user testing, alternative designs you considered, and why you rejected more manipulative options.
Test comprehension, not just completion rates. After users complete your consent flow, ask them what they just agreed to. If they can't accurately describe the processing purposes, your mechanism fails the "informed" requirement regardless of your completion rate.
Implement granular consent at the interface level. If you process data for multiple purposes, present separate toggles for each. Yes, this complicates your data flows. That's the point. Article 7(4) prohibits bundling consent for unnecessary processing with service access.
Review your consent mechanism after every product change. When you add a new data processing purpose or share data with a new third party, you need fresh consent. Don't assume your existing mechanism covers new uses. The compatibility assessment required under Article 6(4) rarely permits significant purpose expansion.
Build a consent refresh workflow. GDPR doesn't specify consent expiration periods, but supervisory authorities expect you to periodically reconfirm consent, especially for sensitive processing. Document your refresh schedule and the triggers that require new consent requests.
The Grindr case demonstrates that technical compliance isn't enough when your interface undermines user autonomy. Datatilsynet didn't fine Grindr for lacking a consent mechanism; it fined them for building one that manipulated users into choices they wouldn't have made with clear information and neutral presentation.
Your consent rate should reflect genuine user preference, not interface optimization. If that distinction makes you uncomfortable, you're probably using dark patterns.



