France's supreme court has upheld the €40 million GDPR fine against advertising technology company Criteo, despite ongoing legal disputes over the regulatory logic. The ruling affects all adtech companies operating in the EU and reinforces strict enforcement of consent requirements under GDPR.
France's highest court has definitively upheld the €40 million GDPR fine imposed on Criteo, one of the world's largest advertising technology companies. This landmark decision comes despite significant legal challenges questioning the regulatory reasoning behind the penalty, marking a critical moment for GDPR enforcement in the digital advertising sector.
The fine, originally imposed by France's data protection authority CNIL (Commission Nationale de l'Informatique et des Libertés), represents one of the largest GDPR penalties issued against an adtech company to date.
Criteo's violation centered on its data processing practices for personalized advertising. The company was found to have inadequately obtained user consent for processing personal data, particularly regarding:
While the court upheld the fine, legal experts continue to debate the regulatory reasoning. The contested elements include:
This ruling has far-reaching consequences for the advertising technology industry:
This decision reflects broader trends in GDPR enforcement:
The Criteo case establishes important precedents for GDPR enforcement in the digital advertising industry. Organizations should expect continued regulatory scrutiny and ensure their compliance frameworks can withstand similar challenges.
The contested legal logic, while not affecting the immediate outcome, may influence future regulatory approaches and could prompt legislative clarifications around consent requirements in complex digital ecosystems.
Criteo was fined for inadequate user consent mechanisms, lack of transparency in data processing, and failing to provide accessible consent withdrawal processes for personalized advertising data.
The ruling sets a precedent requiring stricter consent mechanisms and enhanced transparency obligations for all advertising technology companies operating in the EU.
Companies should audit their consent mechanisms, review data processing disclosures, implement robust consent withdrawal processes, and engage specialized legal counsel for compliance guidance.
Legal experts questioned the proportionality of the penalty, interpretation of consent requirements in adtech, jurisdictional considerations, and the precedential impact on similar cases.
Publishers must evaluate vendor GDPR compliance, update data processing agreements, review consent management platforms, and consider privacy-first advertising alternatives.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free