The French Data Protection Authority (CNIL) fined Criteo €40 million for violating the GDPR, including lack of valid consent, transparency, and failure to respect the right to erasure and access. The enforcement followed complaints filed by noyb and Privacy International in December 2018. The decision was approved by other EU DPAs.
Why it matters: The fine signals strong enforcement against ad‑tech companies that breach data‑subject rights under the GDPR.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.