France’s data protection authority, the CNIL, fined Google LLC €50 million for failing to give users clear information and for relying on invalid consent to personalise advertising. It was the largest GDPR fine issued up to that point.
What happened
- The case followed complaints filed in May 2018 by the privacy groups noyb and La Quadrature du Net.
- The CNIL found that key information about data processing was spread across several documents and required multiple clicks to find.
- Consent for ad personalisation was judged neither specific nor unambiguous, partly because boxes were pre-ticked during Android account set-up.
- Google appealed, but France’s Conseil d’État upheld the fine in June 2020.
Why it mattered
The decision set an early benchmark for GDPR enforcement against big tech and made clear that consent buried in lengthy, fragmented notices would not satisfy regulators. The CNIL also found that Google’s Irish subsidiary did not take the relevant decisions, so the GDPR’s one-stop-shop did not apply and France could act directly.
Lessons for organisations
Review privacy notices and consent flows for clarity and granularity, avoid pre-ticked boxes, and document the lawful basis for each processing activity. Treat transparency as a design requirement, not a legal afterthought.
Sources: CNIL, Help Net Security
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.