Regulatory Watch  /  France  /  Fine
Moderate impactFineIn effect

French CNIL fines Criteo €40 million for GDPR violations

The French Data Protection Authority (CNIL) fined Criteo €40 million for violating the GDPR, including lack of valid consent, transparency, and failure to respect the right to erasure and access. The enforcement followed complaints filed by noyb and Privacy International in December 2018. The decision was approved by other EU DPAs.

Why it matters: The fine signals strong enforcement against ad‑tech companies that breach data‑subject rights under the GDPR.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Advertising Company CRITEO fined €40 Mio
noyb · primary source · Jun 22, 2023
Advertising Company CRITEO fined €40 Mio
noyb · Jun 22, 2023
Details
JurisdictionFrance
RegulatorCNIL
LawGeneral Data Protection Regulation
StatusIn effect
PublishedJune 22, 2023
Effectivenot stated
Penalty€40 million
OrganisationsCriteo
Topicsconsent, transparency, access, deletion, tracking, targeted advertising
Datapersonal