Criteo Fine Warns Swedish Tech Firms
Based on research by NOYB
The French highest administrative court has upheld a €40 million GDPR fine against ad-tech giant Criteo, rejecting its final appeal. This ruling is a stark warning for Swedish technology firms and developers: if you are building systems that rely on tracking user behavior or pseudonymous identifiers, you are on the hook for compliance. The decision confirms that data protection authorities will not tolerate vague interpretations of consent or data classification, regardless of how sophisticated your technical architecture claims to be.
The core issue was Criteo’s attempt to classify pseudonymous identifiers as non-personal data. The court ruled that data is only anonymized if re-identification is practically impossible. Since Criteo could cross-reference browsing data and IP addresses to identify users for targeted advertising, the identifiers remained personal data. This means any company processing data for behavioral profiling must ensure they can prove users have given valid, specific consent. The CNIL also found failures in transparency and the right to erasure, showing that consent is just one part of a broader compliance obligation.
For Swedish CTOs and CISOs, the risk is immediate and financial. If your LLM APIs or data pipelines process user data without clear, verifiable consent mechanisms, you face similar regulatory scrutiny. The fine amount signals that authorities are willing to levy substantial penalties for systemic violations. You must audit your data flows to ensure that pseudonymization does not become a loophole for ignoring GDPR obligations. Compliance gaps in data subject rights, such as access and deletion, can trigger investigations that expand far beyond the initial complaint, as seen with Criteo.
This reinforces the critical case for processing data locally within the EU and Sweden. When you keep data onshore, you maintain tighter control over consent management and data classification, reducing the risk of cross-border regulatory friction. Local processing ensures that your anonymization techniques are robust and defensible, preventing identifiers from being re-linked to individuals through external data sources. It is not just about privacy; it is about operational resilience and avoiding the catastrophic fines that come from misinterpreting what constitutes personal data.