CRITEO

€40,000,000

Insufficient fulfilment of data subjects rights

결정 날짜

2023년 6월 15일

권한

French Data Protection Authority (CNIL)

FR

섹터

Media, Telecoms and Broadcasting

국가

FR

법률

GDPR

상태

FINAL

설명

The French DPA has imposed a fine of EUR 40 million on CRITEO. The controller is specialized in 'retargeting advertising'. This involves the company tracking the surfing behavior of Internet users via so-called Criteo trackers (cookies) in order to show them personalized advertising. In the course of its investigation, the DPA found numerous deficiencies in data processing. First, the DPA found that the controller failed to prove that Internet users had given their consent to be tracked using the Criteo trackers. Also, the controller failed to ensure that its partners obtained consent from the Internet users of whose data it was processing. The DPA further found that the controller's privacy policy was not complete, as it did not list all the purposes for which it was processing data. In addition, some of the purposes were not clearly defined. In addition, the controller failed to adequately respond to a data subject's requests for information regarding their personal data. The DPA also found that when data subjects requested withdrawal of their consent or deletion of their data, the controller merely ensured that users were no longer shown personalized advertising. However, the controller did not delete the personal data of the data subjects. Finally, the DPA found that the agreement between the controller and a joint controller was incomplete. In determining the amount of the fine, the DPA considered the fact that a large number of individuals were affected as an aggravating factor.

법적 인용

Art. 7 (1)Art. 12Art. 13Art. 15 (1)Art. 17 (1)Art. 26

문제 및 위반 사항

Insufficient fulfilment of data subjects rights

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.