The Criteo shockwave: what's concretely changing for AdTech in 2026

The €40 million fine imposed on Criteo by the CNIL — confirmed by the Conseil d'État — sent a clear signal to the entire AdTech ecosystem: the grey areas are over. Pseudonymous data, consent responsibility, the right to be forgotten, Retail Media… this article breaks down what concretely changes for startups and scaleups operating in digital advertising, and the priority projects to undertake immediately.

By
Guillemette Songy
1
Min
Share this article
Digital advertising computer screen

If you closely follow AdTech news, you know that the Criteo case is no longer just a legal saga; it has become a true compass for our industry. As a Privacy Officer at Adequacy, I see a lot of concerns about how a startup or scaleup can still operate serenely in digital advertising after such an upheaval.

The €40 million fine imposed by the CNIL (and confirmed by the Conseil d'État) is not just a financial punishment for a giant. It's a message sent to the entire ecosystem: the grey areas are over.

Here's an analysis of what concretely changes for you, beyond the legal jargon.

The illusion of "anonymous" data has shattered

For a long time, many companies in the sector reassured themselves by saying: "We don't handle names or emails, only technical IDs and cookies, so it's pseudonymous data, we're safe."

The Criteo verdict dashes this hope. From the moment you can isolate a user to offer them a sports shoe rather than a drill, you are processing personal data. It doesn't matter if you don't know their civil identity.

The advice I give our clients: stop looking for semantic loopholes. Assume that 100% of your trackers are subject to GDPR. That prevents building a technical stack on sand.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Consent responsibility: blame can no longer be shifted to the publisher

This is undoubtedly the hardest pill to swallow for programmatic platforms. Criteo explained that as an intermediary, it was up to media sites (publishers) to collect consent. Logical, right?

Not according to the CNIL. As a data controller, it's up to you to prove that consent was given.

Let's consider a practical example: if you are a scale-up running campaigns through a network of 500 partner sites, you must be able to provide proof of consent (the famous CMP logs) if requested. Blind trust in your partners has become a major legal risk.

This is where the Criteo ruling also has a significant impact on Retail Media: the brand (advertiser) and the technical platform are co-responsible. If the platform cannot prove that the user accepted the placement of the third-party cookie on the final publisher's site, the entire chain collapses. If you process data from millions of cardholders, you must be able to provide proof of consent for each advertising transaction.

The right to be forgotten: opt-out is no longer sufficient

Another error identified in the case: when a user requested not to be targeted anymore, Criteo stopped sending them ads, but kept their identifiers in the database 'just in case'.

For the CNIL, this is unacceptable. If a user withdraws their consent, you must delete or irreversibly anonymize everything. Holding onto data in the hope it will be useful later exposes you to immediate sanctions.

How to move forward: three key priorities

Let's be honest, the climate is tense, but it's also an opportunity for market cleansing. To come out on top, there are three key priorities:

  • Transparency by design: your APIs must natively integrate consent management. If your clients feel your solution is "privacy-safe," you gain a huge competitive advantage.
  • The pivot to Retail Media: data captured directly on a merchant's site is much more legally sound than third-party tracking across the entire web.
  • Contractual audit: review your contracts with publishers. Don't settle for a single line stating they comply with GDPR anymore. Demand technical guarantees.

AdTech in 2026 won't be less effective; it will just be cleaner. This might be the best news of the year for those looking to build sustainable businesses.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Retail media under CNIL's scrutiny: three practical examples

For mass market retailers and in-store activation specialists, the challenges are amplified. Here are three scenarios that illustrate the new risks.

Cart targeting (lookalike and upsell)

Imagine a solution that analyzes a customer's shopping cart on a grocery pick-up website to offer them an immediate discount coupon for a competing brand.

The risk: If the consent obtained when signing up for the loyalty program is not explicit about sharing this data with third-party ad networks, the activation is unlawful. The user must know that their purchase of "organic yogurts" will be used to target them elsewhere.

Audience extension (off-site)

A major retail chain wants to retarget its "loyal" customers when they browse cooking or news websites.

The risk: This is where the Criteo case law has a significant impact. The retailer (the advertiser) and the technical platform are jointly responsible. If the platform cannot prove that the user accepted the placement of the third-party cookie on the end publisher's site, the entire chain collapses.

Predictive couponing

A scaleup offers technology that predicts the next purchase based on browsing history.

The risk: The right to be forgotten. If a customer requests the deletion of their "loyalty" data from the retailer, this deletion must be instantly reflected in the scaleup's algorithm. Maintaining a "ghost profile" for AI training is now considered gross negligence.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Contractual checklist: five essential clauses after the Criteo case

The data collection guarantee clause

Don't let the publisher claim they manage consent. Specificity is key:

  • The enhanced duty of care: the publisher must commit to using an IAB-approved CMP (TCF v2.2 or higher) or a solution recognized by the CNIL
  • Detailed purposes: the contract must precisely list the purposes for which consent is collected (e.g., ad retargeting, audience measurement, content personalization). If the publisher misses a checkbox in their banner, your data is illegal

The right to technical audit

This is where Criteo went wrong. You must be able to verify that your partners aren't misleading you:

  • Access to logs: include a clause allowing you to request, upon simple request, proof of consent (the "consent string") for a sample of users
  • Response time: the partner must be able to provide you with this proof within 48 or 72 hours. In the event of a CNIL audit, this is the timeframe you will be given

Opt-out chain management

This is the most technically complex point, but legally essential:

  • Opt-out propagation: if a user withdraws their consent on the publisher's site, how does that information reach you in real-time?
  • Deletion Commitment: the contract must stipulate that in the event of withdrawal, you commit to deleting (and not just "no longer targeting") the data linked to that ID within X timeframe

Joint responsibility

Since the Criteo case, you can no longer truly say "I am only a data processor":

  • The Joint Controllership Agreement: you need to define clearly, in writing, who does what. Who responds to the user if they exercise their right of access? (generally, it's the one who first collects the data, i.e., the publisher, but you must be prepared to act as a backup)

The immediate termination clause

If you realize that a partner has too high a consent error rate or does not respond to your requests for proof:

  • Termination Without Notice: plan to be able to cut off data flows immediately and terminate the contract without compensation if compliance is no longer ensured. Your company's health takes precedence over their inventory

FAQ - GDPR compliance after the Criteo case

What is the Criteo case and why is it important for AdTech?

The CNIL fined Criteo €40 million, a decision upheld by the Conseil d'État (French Council of State), for GDPR violations related to consent collection, processing of pseudonymized data, and failure to respect the right to be forgotten. This ruling sets a legal precedent for the entire digital advertising ecosystem.

Is a cookie or a technical identifier considered personal data under the GDPR?

Yes. The Criteo case confirmed it: as soon as a technical identifier allows a user to be isolated for personalized targeting, it constitutes personal data subject to the GDPR — even in the absence of a name or email address.

Who is responsible for consent collection in a programmatic chain?

Each data controller is required to prove that consent has been properly obtained. As a platform or advertiser, you cannot rely solely on your publisher partners. You must be able to produce proof of consent (CMP logs) at any time.

What should happen when a user withdraws their consent?

Withdrawing consent requires the complete deletion of data related to that user — not just its deactivation. Retaining identifiers "just in case" after an opt-out is a clear violation under the GDPR.

Is Retail Media affected by the Criteo ruling?

Yes, and in a particularly direct way. Retailers, advertisers, and technical platforms are joint data controllers in Retail Media setups. The entire chain must be able to prove the validity of consent, including for off-site activations.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The latest news

They have trusted us for years

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.