惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Palo Alto Networks Blog
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
B
Blog
MyScale Blog
MyScale Blog
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
S
Schneier on Security
Project Zero
Project Zero
T
Tenable Blog
T
Tor Project blog
U
Unit 42
G
GRAHAM CLULEY
N
News and Events Feed by Topic
P
Proofpoint News Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Y
Y Combinator Blog
C
Cybersecurity and Infrastructure Security Agency CISA
腾讯CDC
博客园 - 叶小钗
M
MIT News - Artificial intelligence
Vercel News
Vercel News
T
Threat Research - Cisco Blogs
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
The Exploit Database - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
I
Intezer
博客园 - 聂微东
SecWiki News
SecWiki News
Scott Helme
Scott Helme
C
Cyber Attacks, Cyber Crime and Cyber Security
IT之家
IT之家
量子位
S
Secure Thoughts
The Cloudflare Blog
博客园 - 司徒正美
Know Your Adversary
Know Your Adversary
Hacker News: Ask HN
Hacker News: Ask HN
V
Vulnerabilities – Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
N
News | PayPal Newsroom
C
Check Point Blog
Spread Privacy
Spread Privacy
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
Lessons from CRITEO GDPR Fine | iubenda
Jessica Ryder · 2023-07-04 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

In a landmark decision, the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), has fined CRITEO SA, a leading ad-tracking company, €40 million for several infringements of the General Data Protection Regulation (GDPR). This case serves as a stark reminder of the importance of obtaining valid consent and complying with transparency obligations under the GDPR. 

In this article, we will explore the details of the case and highlight how businesses avoid similar legal pitfalls.

  • CRITEO: Background
  • How was the GDPR violated?
  • CNIL’s Decision against CRITEO
  • Importance of Valid Consent and Transparency
  • How to collect proof of consent?
CRITEO
Breaking News: Amsterdam District Court Orders Criteo to Cease Third-Party Cookie Use or Face Fines

In a landmark decision, the Amsterdam District Court, Rechtbank Amsterdam, has issued a significant ruling against online advertiser Criteo. The court has ordered Criteo to immediately cease the use of third-party cookies and take corrective measures to ensure compliance with the law. Failure to do so could result in daily fines, and the consequences could be severe.

The court’s decision comes after a thorough examination of the plaintiff’s claim, which alleged non-consensual cookie placement by Criteo. The findings were in favor of the plaintiff, highlighting the importance of protecting users’ privacy and ensuring their consent is obtained before tracking their online behavior.

As part of the court’s ruling, Criteo is now obligated to honor the plaintiff’s requests for access, receipt, and deletion of any data associated with their online activities. Moreover, Criteo is required to inform third parties about these requests, ensuring transparency and accountability in the handling of user data.

The potential financial consequences for Criteo in case of noncompliance with the court’s orders are substantial. The court has imposed the possibility of maximum total fines of up to 85,000 euros for each of the six court orders that Criteo fails to adhere to. Additionally, the company may be liable for covering legal fees associated with this case.

This ruling serves as a significant development in the ongoing conversation about online privacy and data protection. It underscores the need for companies to respect users’ consent and adhere to strict data privacy regulations. As the digital landscape continues to evolve, this decision sets a precedent for responsible data handling and reinforces the rights of individuals to have control over their online presence.

CRITEO: Background

CRITEO specializes in ad-tracking activities, particularly behavioral retargeting. Through the placement of its tracker (cookie) on user devices when a user visits CRITEO partner websites, CRITEO collects vast amounts of data related to users’ online behavior and preferences. However, the CNIL found that CRITEO had violated provisions of the GDPR. 

Failure to verify consent

One of the key violations cited by CNIL was CRITEO’s failure to verify whether individuals had given their consent for data processing, as required by Article 7(1) of the GDPR. CRITEO argued that its partners, who placed the tracking cookies, were responsible for obtaining consent. However, CNIL emphasized that CRITEO couldn’t rely solely on its partners and had an independent obligation to ensure consent was obtained. Additionally, CRITEO lacked mechanisms to confirm the validity of consent obtained by its partners. 

👀 See how to store proof of consent here →

Lack of information and transparency

CNIL found that CRITEO’s privacy policy was incomplete and lacked clarity. The policy did not adequately inform users about the purposes of the processing, including the improvement of CRITEO’s technologies. Article 12 and Article 13 of the GDPR require businesses to provide transparent and comprehensive information to users regarding the collection and use of their personal data.

Are you concerned about the lack of transparency and information in your privacy policy?

Our Privacy and Cookie Policy Generator is the solution you need to ensure your business complies with the strict regulations set forth by the GDPR.

Try us now

Non-compliance with the right of access

CRITEO failed to fulfill users’ right to access their personal data, as mandated by Article 15(1) of the GDPR. While CRITEO provided some data upon request, it omitted information from certain tables in its database, thereby denying users complete access to their personal data.

CNIL’s Decision against CRITEO

CNIL initially imposed a fine of €60 million on CRITEO in a preliminary decision in August 2022. However, the final decision reduced the fine to €40 million. Despite the reduced penalty, CRITEO has decided to file an appeal, claiming that the fine is “vastly disproportionate.”

The CNIL’s decision was based on the following factors:
  • Large number of individuals affected: approximately 370 million identifiers across the European Union by CRITEO’s data processing activities.
  • Extensive collection of data: CRITEO gathered a significant amount of data concerning users’ consumption habits.
  • Potential re-identification risk: Despite not having users’ names, the collected data was accurate enough to potentially re-identify individuals, according to the CNIL.
  • Failure to obtain valid consent: CRITEO’s lack of valid consent allowed the company to expand its processing scope and increase financial gains as an advertising intermediary.

The CNIL’s decision reinforces the significance of obtaining valid consent and ensuring transparency in data processing activities. Businesses must verify that consent has been obtained in a compliant manner, even when collecting data through partners or third-party trackers. Relying solely on partners’ responsibilities does not absolve businesses of their obligations under privacy legislation.

CRITEO argued that its partners, as joint controllers, should be responsible for obtaining user consent. However, the CNIL clarified that CRITEO, as a data processor, is responsible for obtaining user consent in compliance with data protection regulations. The CNIL emphasized that CRITEO cannot shift the responsibility onto its partners as joint controllers. As a data processor, CRITEO is obligated to ensure that it obtains valid and informed consent from users for processing their personal data.

🗣 The CNIL’s clarification reaffirms the importance of accountability and transparency in data processing activities. It emphasizes that data processors like CRITEO must take responsibility for obtaining consent and ensuring that it is collected in accordance with the principles outlined in data protection laws.

The decision made by the CNIL emphasizes the need for CRITEO to ensure that it verifies consents obtained by its partners and establishes an audit mechanism for its partners. This requirement becomes particularly important considering that the cookie was not placed in the user’s devices directly by CRITEO, but rather by its partners. By emphasizing these aspects, the CNIL aims to safeguard individuals’ rights and privacy. This decision serves as a reminder to other data processors of their responsibility to fulfill their obligations by obtaining consent from users and implementing mechanisms to verify and audit consent processes conducted by their partners. The obligation for joint controllers to have agreements in place in terms of Article 26 of the GDPR was also equally highlighted by CNIL and CRITEO has since also abided by this obligation.

Cookies often process personal data, triggering record-keeping requirements under the GDPR. To address this, Data Protection Authorities across the EU have strengthened their regulations on cookies and trackers, aligning them with the GDPR guidelines.

Enhance your compliance with GDPR and effortlessly manage user consent preferences with our Cookie and Consent Preference Log feature.

The Cookie and Consent Preference Log is now available within our Privacy Controls and Cookie Solution. With just one click, you can seamlessly integrate this feature and conveniently store and manage GDPR proofs of your users’ consent preferences.

To unlock the power of the Cookie and Consent Preference Log, simply activated this feature in the Privacy Controls and Cookie Solution. Just click on “Log” under your Dashboard > [Your website/app] > Privacy Controls and Cookie Solution to get started.

💡 Unsure if the Cookie and Consent Preference Log is right for you? Take our 1-minute quiz to find out!

The significant fine imposed on CRITEO by CNIL serves as a reminder that businesses must prioritize compliance with the GDPR’s consent and transparency requirements. 

Demonstrate your commitment to privacy and data protection and avoid potential legal consequences

Try it today, risk-free