Regulatory Watch  /  France  /  Fine
Moderate impactFineIn effect

French court upholds €40M GDPR fine against Criteo

The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s appeal and confirmed the fine. The ruling affirms that pseudonymous identifiers linked to IP addresses are personal data.

Why it matters: The decision reinforces GDPR enforcement on ad‑tech tracking and clarifies that pseudonymous IDs are personal data.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Conseil d'État upholds Criteo's €40M GDPR fine
noyb · primary source · Mar 13, 2026
Conseil d'État upholds Criteo's €40M GDPR fine
noyb · Mar 13, 2026
Details
JurisdictionFrance
RegulatorCNIL
CourtConseil d’État
LawGeneral Data Protection Regulation
StatusIn effect
PublishedMarch 13, 2026
Effectivenot stated
Penalty€40 million
OrganisationsCriteo
Topicsconsent, transparency, profiling, targeted advertising, deletion, access, privacy
Datapersonal