Criteo SA – Court Ruling (Netherlands, 2024)

Court Ruling
DPA RbAmsterdam22 April 2024Netherlands
final
Court Ruling

A Dutch court ruled that Criteo SA placed tracking cookies on users' devices without their consent. This decision is important because it reinforces the need for companies to get permission before tracking users online. Website operators should ensure they have proper consent mechanisms in place to avoid similar issues.

What happened

Criteo SA placed tracking cookies on users' devices without obtaining their consent.

Who was affected

Website visitors whose devices had tracking cookies placed by Criteo SA without their permission.

What the authority found

The court decided that Criteo had no valid legal basis for placing cookies, violating GDPR requirements for user consent.

Why this matters

This ruling highlights that companies must obtain clear consent before tracking users. It sets a precedent for stricter enforcement of consent requirements for tracking technologies.

GDPR Articles Cited

AI-verified

Art. 7(GDPR)
Art. 13(GDPR)
Art. 14(GDPR)
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 6(1) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 11.7a(1) Telecommunicatiewet
Decision AuthorityRechtbank Amsterdam
Source verified 9 April 2026
articles corrected
national law identified
amount discrepancy
authority corrected
Full Legal Summary
Detailed

The controller is Criteo SA, a global technology company operating in media and entertainment that does consultancy, provides software and services in relation to digital marketing, media advertising and real time ads bidding. The controller places tracking cookies for targeted advertising on computers and mobile devices of users visiting certain third party websites. The controller uses the Real Time Bidding (RTB) System to recognise a user within seconds and to show personalised ads. In another case against the controller on 15 June 2023 , the French DPA ("CNIL") fined the controller €40 million for violating various articles of the GDPR, in particular for failing to verify that the persons from whom it processed data had given their consent. On 8 August 2023, the data subject wrote to the controller that the placing of tracking cookies on the data subject’s devices without the data subject’s consent, violates [https://www.google.com/search?client=firefox-b-d&q=telecommunicatiewet+11.7a Article 11.7a(1) Dutch telecommunications law] (“Telecommunicatiewet – TW”) and Articles 5(1)(a), 6(1), 7, 13 and 14 GDPR. The controller responded that it is the responsibility of the third party websites to obtain consent. The data subject filed an urgency procedure (“kort geding”) under Dutch civil law at the Amsterdam District Court (“Rechtbank Amsterdam”) against the controller. The court prohibited the controller from placing tracking cookies on the devices of the data subject and imposed a penalty of €250 for every day they fail to comply with the decision (with a maximum of €25.000). The controller appealed this decision on 30 October 2023. The Court of Amsterdam (“Gerechtshof Amsterdam”) found that tracking cookies were placed by the controller and that the data subject’s personal data was processed in violation of the GDPR. The court therefore prohibited the controller from placing tracking cookies and upheld the imposed penalty of the District Court after the judgem

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Violations (2)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Cases (0)

No other cases found for Criteo SA in NL

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

22 April 2024

Authority

DPA RbAmsterdam

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 100%

Cite as: Cookie Fines. Criteo SA - Netherlands (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: