Conseil d'État upholds Criteo's €40M GDPR fine
France's highest administrative court has upheld a €40 million GDPR fine against ad-tracking company Criteo, originally imposed by the CNIL. The regulator found that Criteo could not demonstrate it had obtained valid consent from users and had failed to respect data subject rights.
Why this matters: Criteo's business runs on tracking people across the web to serve targeted ads. The core finding here is that it could not prove people actually agreed to that tracking. That is not a technicality. Consent is supposed to be the legal foundation for this entire model. If a major ad-tech company cannot show valid consent after years of complaints, it suggests the industry built its infrastructure on assumptions rather than permission. This ruling took six years to land. That gap is part of the story too.
Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.