Don’t do SECURITY. Do business SECURELY.

French regulator fines Google €50 million over consent and transparency

France's CNIL fines Google €50 million, then the largest GDPR penalty, for unclear information and invalid consent for ad personalisation.

France’s data protection authority, the CNIL, fined Google LLC €50 million for failing to give users clear information and for relying on invalid consent to personalise advertising. It was the largest GDPR fine issued up to that point.

What happened

  • The case followed complaints filed in May 2018 by the privacy groups noyb and La Quadrature du Net.
  • The CNIL found that key information about data processing was spread across several documents and required multiple clicks to find.
  • Consent for ad personalisation was judged neither specific nor unambiguous, partly because boxes were pre-ticked during Android account set-up.
  • Google appealed, but France’s Conseil d’État upheld the fine in June 2020.

Why it mattered

The decision set an early benchmark for GDPR enforcement against big tech and made clear that consent buried in lengthy, fragmented notices would not satisfy regulators. The CNIL also found that Google’s Irish subsidiary did not take the relevant decisions, so the GDPR’s one-stop-shop did not apply and France could act directly.

Lessons for organisations

Review privacy notices and consent flows for clarity and granularity, avoid pre-ticked boxes, and document the lawful basis for each processing activity. Treat transparency as a design requirement, not a legal afterthought.

Sources: CNIL, Help Net Security

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights