Knowledge Base โ Channels & domains โ ๐ช Website Privacy โ Cookies, Consent & Tracking
๐ช Website Privacy โ Cookies, Consent & Tracking
Website privacy โ cookies & consent (CMPs), trackers/pixels, fingerprinting, ePrivacy / PECR / TTDSG-TDDDG, web scraping and analytics โ including enforcement (cookie-banner decisions, Google-Analytics/transfer cases, dark-pattern actions).
Key resources (24)
- EDPB Guidelines 05/2020 on consent
- EDPB Cookie Banner Taskforce โ report
- ePrivacy Directive 2002/58/EC (EUR-Lex)
- CJEU C-673/17 Planet49 โ cookie consent
- ICO โ Cookies and similar technologies
- noyb โ Cookie banner project
- Germany TTDSG / TDDDG (gesetze-im-internet)
- Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks โ Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
- Edpb adopts guidelines on anonymous data web scr โ EDPB Adopts DRAFT Guidelines on Anonymous Data, Web Scraping, and Blockchain
- What do the european data protection boards web
- COMUNICATO STAMPA - Intelligenza artificiale: il Garante privacy sanziona… - Garante Privacy โ Italy’s data protection authority, the Garante, issued a 158,000 euro fine to Character.AI over the U.S.-based company’s alleged age verification issues and delay in implementing a data protection impact assessment. The Garante also raised concerns about the company’s services being easily accessible to minors. Character.AI must ensure its age verification systems are compliant with privacy regulations and automatically set underage users’ accounts to private.
- Provvedimento del 12 marzo 2026 - Garante Privacy โ Case: Unlawful processing and profiling of over 2.4 million customers during their transfer from Intesa Sanpaolo to the digital-only bank, Isybank. Violations Unlawful Profiling: Customers were profiled and moved to a new controller (Isybank) without proper consent or a valid legal basis. Inadequate Communication: Information regarding the transfer was sent without proper push alerts, often buried in the app’s archive during the summer period.
- Google Chrome macht Cookie Klau unter Windows si โ DBSC - Device Bound Session Cookies
- Is the privacy pro role dead hardly but it s com โ Almost 20 years ago, in 2007, the IAPP ran a contest among its nascent membership to define a “privacy pro” in 75 words or less. The submission from Orrie Dinstein, co-author of this article, won and was memorialized on the back of shirts that were handed out. It stated a privacy pro is “a leader who understands the technical, legal and operational aspects of gathering, handling, and securing personal data, and who can establish and maintain a comprehensive strategic vision for handling all personal data of employees, customers and suppliers of an organization in a manner that is legal, secure and ethical, from the point of acquisition through the point of disposition, thereby gaining public trust in the organization’s role as custodian of such data.”
- Cookies et autres traceurs quelles conditions co โ ๐จIf you can give your consent once for all your devices, you should also be able to refuse or withdraw it with the same simplicity and scope. ๐จ โถ๏ธ Multi-device consent should never make it more difficult to exercise your rights: accepting, refusing or changing your mind should have the same effects on all your devices.
- Deletion of personal data not possible
- Cookies la cnil sanctionne american express dune โ On November 27, 2025, the CNIL fined AMERICAN EXPRESS CARTE FRANCE, the French subsidiary of the AMERICAN EXPRESS group, 1.5 million euros for failing to comply with applicable rules regarding trackers ( cookies ). The CNIL has sanctioned several of the company’s practices that violated Article 82 of the French Data Protection Act Depositing trackers without user consent : the CNIL noted that, as soon as the user arrived on the website “www.americanexpress.frfr” and even before he interacted with the window allowing him to express a choice, several trackers, including those for advertising purposes, were deposited on his terminal. Tracking cookies despite user refusal : the CNIL also noted that advertising tracking cookies were being placed on the user’s terminal despite their expressed refusal. Reading of trackers despite withdrawal of consent : finally, the CNIL noted that when a user accepted the deposit and reading of trackers, then withdrew their consent, the previously deposited trackers continued to be read by the company.
- Cookies deposes sans consentement la cnil sancti โ Cookies placed without consent: the CNIL fines the company that publishes the website “vanityfair.fr” 750,000 euros
- European commission gdpr modification to kill co
- EDOEB update of cookie guidelines per se ban
- Achieving privacy excellence understanding the p โ GE Healthcare: Achieving privacy excellence: Understanding the privacy maturity model
- e.g. Medtronic settled for $ 475,000 in a class action involving “Google Analytics, Crashyltics, Firebase Authentication and related tools (“Tracking Tools”) - installed on its website and/or mobile
- OAIC guidance on tracking pixels and privacy obligations (4 November 2024) โ Report: Your life, pixelated: how tracking pixels watch your every click OAIC guidance on tracking pixels and privacy obligations (4 November 2024)
- Report: Your life, pixelated: how tracking pixels watch your every click โ Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026) - external site
โ๏ธ Notable enforcement & decisions
- 2025-09-01 CNIL fines SHEIN โฌ150M โ cookies set before consent, ineffective โRefuse allโ (CNIL)
- 2025-09 CNIL fines Google โฌ150M over cookies (CNIL)
- 2025 CNIL cookie action plan โ two fines (SHEIN & Google) (CNIL)
- 2025 Conseil dโรtat upholds CNILโs cookie sanction against Amazon (CNIL)
- 2024โ Dutch DPA (AP): active cookie-banner supervision since 2024 (AP)
- โ Dutch DPA fines Coolblue for unsolicited cookies (AP)
๐ Case law (curated)
- CJEU C-40/17 Fashion ID โ social-plugin (Like button) joint controllership.
๐ Recent additions (auto)
- 2026-09-07 CJEU Preview: Preliminary questions regarding non-material damages claims through collective actions โ The Hanseatic Court of Appeals Hamburg refers preliminary questions to the CJEU that arise in a proceeding by vzbv against Meta. In addition to local jurisdiction questions, the main issue is whether a consumer protection organization in a collective action can assert users’ damages claims following a data scraping incident, or whether such a collective action would be compatible with the GDPR (Datenzirkus (BvD))
- 2026-08-04 The โChat Control 1.0โ saga: Big Tech can scan our private messages again โ but Parliament sent a strong signal against mass surveillance (European Digital Rights (EDRi))
Curated + auto-enriched.