Home Privacy Google Loses Its Appeal On 50 Million Euro GDPR Fine

Google Loses Its Appeal On 50 Million Euro GDPR Fine

SHARE:

Remember that 50 million euro fine that Google got slapped with in France for failing to comply with the General Data Protection Regulation last year?

Looks like Google is going to have to pay up.

On Friday, the Conseil d’État (translates to Council of State), a division of the French government that serves as the supreme court of administrative justice, sided with France’s data protection authority, the CNIL (Commission nationale de l’informatique et des libertés), which levied the fine against Google in January 2019.

(Fun fact: Napoleon Bonaparte founded the Conseil d’État in 1799.)

The CNIL’s sanctions focused mainly on two specific GDPR infringements: having a non-transparent consent gathering process that doesn’t give users enough info to make an informed decision and – the bigger issue – the lack of a legal basis for processing personal data for advertising purposes.

At the time, Google’s fine (which translates to just over $56 million) was the largest issued under GDPR. Today, that dubious honor goes to British Airways in the United Kingdom, which was fined more than 204 million euros (roughly $229 million) in July 2019 for a massive 2018 data breach.

Google immediately announced its intention to appeal the CNIL’s decision. In a January statement, Google defended its consent process for serving personalized ads and said it was “concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond.”

Google appealed on the grounds that the French DPA doesn’t have jurisdiction over Google’s European headquarters. Google claimed that the Irish data protection authority should be leading any cases or investigations into its practices.

But the argument apparently didn’t fly, and the Conseil d’État is expected to issue its final judgement next week.

The CNIL’s original ruling in January followed a series of complaints filed by two nonprofit groups, La Quadrature du Net and None Of Your Business, both of which accused Google of lacking a legal basis for processing the personal data of its users.

None Of Your Business is led by Max Schrems, the Austrian lawyer and privacy campaigner responsible for bringing the 2013 legal challenge against Facebook’s international data-sharing practices that ultimately overturned the Safe Harbor agreement.

Must Read

Forget ROAS? The New Retail Metrics Game

Unfortunately, we seem stuck with our longtime measurement standards, like the trusty old CPM and ROAS. But for change to happen, it must come from within.

clickbait

Perion Shutters Content IQ, Its Made-For-Advertising Division

Laptop fans can rest a little easier. A network of well-known MFA sites operated by Perion-owned Content IQ have been taken offline.

‘Incrementality’ Is The Buzzword That Stole Prog IO

Well, that’s a wrap on Programmatic IO Las Vegas 2024! The AdExchanger editorial hopped on stage for a live recording of The Big Story to round up all the moments that made us go “a-ha” this week, including observations on commerce media, CTV and generative AI.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Paramount And Shopsense Add Programmatic Demand To Their Shoppable Ad Network

What if the new storefront is a person sitting on their couch and scrolling their phone?

Scott’s Miracle-Gro Is Seeing Green With Retail Media

It’s lawn season – and you know what that means. Scott’s Miracle-Gro commercials, of course. Except this time, spots for Scott’s will be brought to you by The Home Depot’s retail media network.

Walled Garden Platforms Are Drowning Marketers In Self-Attributed Sales

Sales are way up; ROAS is through the roof across search, social and ecommerce. At least, that’s what the ad platforms say.