Société du Figaro – €50,000 Fine (France, 2021)
Société du Figaro was fined for placing cookies on users' devices without their consent. This matters because it highlights the importance of getting user permission before tracking their online activity. Website owners need to ensure they have clear consent mechanisms in place for cookies.
What happened
Société du Figaro installed cookies on users' devices before they could give consent.
Who was affected
Website visitors to Société du Figaro's site whose browsing was tracked by cookies without their permission.
What the authority found
The French data protection authority found that Société du Figaro violated data protection rules by not obtaining valid consent for cookie placement.
Why this matters
This case emphasizes that companies must actively seek user consent for cookies. It sets a precedent that companies can be held accountable for their partners' tracking practices.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
This decision follows a complaint received by the French DPA (CNIL) on 16 August 2018 from a user of the Société du Figaro's website, a publisher, in which was reported the installation of cookies on their terminal without their consent and prior to any action. The DPA therefore conducted five online inspections of the website between 14 January 2020 and 1 June 2021. During the first two operations, the DPA carried out a verification on: * The nature of the cookies; * The purpose of each of the cookie; * The information provided to users; * The system put in place so that the user can refuse the installation when browsing on the home page of the website. Then, the DPA also verified the consequences for the user of navigating to another page of the website after having refused the installation of cookies on arrival on the website. First, the DPA stated that the scope of responsibility of the controller regarding cookies on its website exists in the form of an obligation of means to ensure that its partners do not, via its website, install cookies in violation of the applicable law. In addition, the DPA found out that cookies were installed on a user's terminal as soon as they arrived on the website's home page, before they could express their choice, and even if they had expressed a refusal in the event of navigation to another page of the site. Consequently, the DPA held that the controller had breached its obligations regarding consent and information about cookies on its website by: * allowing cookies to be installed on users' terminals before any action on their part; * making their refusal ineffective; * failing to ensure that its partners do not emit, via its site, cookies that do not comply with the applicable regulations; * failing to take the necessary steps to put an end to the breach observed. The DPA fined the controller €50,000.
Violations (3)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Tracking cookies remain active or are re-placed even after the user explicitly rejects them.
Art. 6(1) GDPR
The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.
Art. 12, 13 GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Société du Figaro in FR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
27 July 2021
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€50,000
GDPRhub ID
gdprhub-3696About this data
Cite as: Cookie Fines. Société du Figaro - France (2021). Retrieved from cookiefines.eu
Last updated: