France: Issued ruling in CNIL investigation into CRITEO compliance with GDPR obligation to obtain user consent for collecting and processing data

Description

Issued ruling in CNIL investigation into CRITEO compliance with GDPR obligation to obtain user consent for collecting and processing data

On 15 June 2023, the French Data Protection Authority (CNIL) issued its ruling in the investigation into CRITEO, a company specialising in online advertising, imposing a EUR 40 million fine for failing to ensure that the people whose data it processes have given their consent. The CNIL opened an investigation after complaints were filed by Privacy International and None of Your Business. CRITEO is a company specialising in behavioural retargeting and personalised advertising and tracks the browsing habits of internet users through a tracker (cookie) placed on their devices when they visit certain partner websites. This data is analysed to determine which personalised advertisements to display to users. The CNIL identified five specific infringements by CRITEO, including failure to obtain valid consent from users, lack of information and transparency, failure to provide complete access to personal data, failure to comply with the right to withdraw consent and erase data, and the absence of an agreement between joint controllers. The violations included a lack of evidence of consent from individuals for data processing, insufficient information and transparency, and failure to respect individuals' rights. The penalty considered the large number of people affected by CRITEO's data processing, the significant amount of data collected, and the company's business model relying on targeted advertising.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
online advertising provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2019-12-27
under deliberation

On 27 December 2019, the French Data Protection Authority (CNIL) instructed the Secretary-General t…

2023-06-15
in force

On 15 June 2023, the French Data Protection Authority (CNIL) issued its ruling in the investigation…