The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s appeal and confirmed the fine. The ruling affirms that pseudonymous identifiers linked to IP addresses are personal data.
Why it matters: The decision reinforces GDPR enforcement on ad‑tech tracking and clarifies that pseudonymous IDs are personal data.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.