French Regulator Fines Google 50 Million Euros Over GDPR Violations

The CNIL issues a massive 50 million euro penalty against Google for failing to obtain valid user consent for ad personalization.

The French data protection authority, known as the CNIL, imposes a 50 million euro financial penalty on Google LLC for violating the General Data Protection Regulation. This historic fine results from group complaints filed by privacy advocacy groups None Of Your Business and La Quadrature du Net, which represent thousands of users who accuse Google of lacking a valid legal basis for processing personal data for ad personalization.

The CNIL targets Google specifically for a lack of transparency, inadequate information, and a failure to obtain valid consent regarding how it personalizes advertisements. Under the GDPR, companies must clearly inform users about how their data is used and obtain explicit, freely given permission before utilizing their information for targeted advertising, requirements that the regulator finds Google consistently ignores.

Because Google's Irish headquarters do not hold decision-making power over the specific data processing operations involved in Android account creation, the European "one-stop-shop" mechanism does not apply. This technicality allows the French regulator to claim direct jurisdiction and issue the penalty independently, setting a strong precedent for how European authorities enforce strict consent rules under the new privacy framework.

Read More at the original source →