{"id":27261,"date":"2019-01-22T09:31:02","date_gmt":"2019-01-22T09:31:02","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=27261"},"modified":"2019-01-28T12:19:12","modified_gmt":"2019-01-28T12:19:12","slug":"french-data-protection-regulator-issues-google-with-e50-million-fine","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/01\/22\/french-data-protection-regulator-issues-google-with-e50-million-fine\/","title":{"rendered":"French data protection regulator issues Google with \u20ac50 million fine"},"content":{"rendered":"<p><em>Rules for protecting data stepped up a gear when the EU implemented the General Data Protection Regulation (GDPR) last May. It was introduced to improve the way organisations handled personal data and they were expected to comply with these new rules or risk facing heavy fines. Here, we look at how a French regulator is showing its teeth to ensure its citizens\u2019 privacy and data is protected. <\/em><\/p>\n<p>The General Data Protection Regulation (GDPR) was implemented in May 2018 and at that time, data regulation companies offered guidelines on how to ensure personal data was protected so that companies would be compliant with the new rules.<\/p>\n<p>On the day of the implementation, CNIL, the French data regulator, released an article offering support to public and private bodies to help them understand the changes that would take place and how to make the transition in a methodical way.<\/p>\n<p>Included in the article was a six-step method which highlighted the necessary measures organisations would need to take to ensure GDPR compliance. The CNIL took an early interest in GDPR and has remained actively involved in ensuring it is upheld. <\/p>\n<p>And the regulator showed its teeth to the world when it issued Google with a \u20ac50 million fine, citing the tech giant had demonstrated a \u2018lack of transparency\u2019, provided \u2018unsatisfactory information\u2019 and a \u2018lack of valid consent for the personalisation of advertisements\u2019.<\/p>\n<p>In its decision statement, the CNIL stated that two associations, None Of Your Business (\u2018NOYB\u2019) and La Quadrature du Net (\u2018LQDN\u2019), had filed complaints against Google back in May 2018. The associations criticised Google for failing to have a valid legal basis to process the personal data of the users of its services, in particular for the purpose of personalisation of advertising.  <\/p>\n<p>Investigations carried out by CNIL found two major concerns in connection with GDPR \u2013 that the information provided by Google relating to its use of data is not easily accessible to users. Second was concerning the data used for the personalisation of adverts. The CNIL therefore issued Google with a \u20ac50 million fine and is the first time that the data regulation organisation has applied the new maximum penalties provided by the GPDR. <\/p>\n<p>A spokesperson for Google said the company was studying the decision to determine its next steps, adding: \u201cPeople expect high standards of transparency and control from us. We\u2019re deeply committed to meeting those expectations and the consent requirements of the GDPR.\u201d<\/p>\n<p>Industry experts have had their say on the CNIL\u2019s decision to fine Google, with Matt Lock, Director of Sales Engineering at Varonis, stating that the news should be \u2018hitting companies like a cold shower\u2019.<br \/>\n\u201cThe new fine facing Google will quickly dispel any lingering doubts that the EU would go easy on companies found in violation of the GDPR,\u201d he said.<\/p>\n<p>\u201cIt\u2019s not a stretch to say that a proverbial storm is gathering as privacy groups rally to their cause and seek to uphold major global companies as examples of lax privacy controls. The news should serve as an impetus to organisations that have yet to prioritise their GDPR compliance programmes and hoped to simply fly under the radar \u2013 their luck may be running out soon.\u201d <\/p>\n<p>Meanwhile, Alex Hollis, GRC Practice Director and SureCloud, said the CNIL had certainly \u2018lived up to its reputation\u2019 around matters for data protection in taking action.<\/p>\n<p>He said: \u201cSince last May, we have seen the dip following the initial interest and have been expecting these legal cases to emerge.<\/p>\n<p>\u201cThe scale of the fine for Google is not the 4% which is allowed under the regulation, which must go some way to acknowledging the steps and controls that Google has taken. It should certainly serve as a caution to those who don\u2019t have the legal protection that Google has.\u201d<\/p>\n<p>Fouad Khalil, Vice President of Compliance at SecurityScorecard, highlighted that it was \u2018no surprise\u2019 that the fine had been issued by the French privacy watchdog.<\/p>\n<p>\u201cCNIL is the only regulator that issued any kind of GDPR compliance guidance in an effort to shed light on compliance requirements. Even though Google\u2019s European headquarters is based in Ireland, that did not stop GDPR watchdogs from transitioning the enforcement to France where it is considered to be more effective,\u201d he said.<\/p>\n<p>\u201cThe new year is upon us, as is GDPR enforcement and fines. Companies that have sat back and watched the privacy tidal wave hoping that it will miss them should reconsider. As with any new regulation, most companies scramble to comply once they realise the ramifications are real.<\/p>\n<p>\u201cWe are learning that no one is beyond GDPR reach \u2013 Google was fined \u20ac50 million due to people \u2018not [being] sufficiently informed\u2019 about how Google collected data to personalise advertising.<br \/>\n\u201cThe regulator indicated that Google provided inadequate information to its consumers as well as having had invalid consent for personal data use. This confirms how critical an accurate and up-to-date personal data inventory is. <\/p>\n<p>\u201cOrganisations must ensure all data is properly identified, classified, processed, transmitted, consented for use and much more. Furthermore, point-in-time compliance does not cut it as continuous assurance (monitoring and auditing) is a must to ensure ongoing compliance.<\/p>\n<p>\u201cIn today\u2019s world, managing privacy has become the norm as regulators, auditors and privacy rights groups are keeping a watchful eye. Slapping Google with such a large fine is only possible due to confirmed violations most surely reported by consumers and privacy rights groups. I suspect this will be the first of many to follow in 2019 as GDPR compliance is now in the enforcement phase.\u201d<\/p>\n<p>Ryan Kalember, SVP, Cybersecurity Strategy, Proofpoint: \u201cThis GDPR fine brings to light some vital lessons for other businesses observing this crisis from a distance. By becoming the highest fined company since GDPR came into force, Google is now the black and white case study of \u2018what could happen\u2019 in the event of non-compliance. In a privacy-first world, companies must build a people-centric compliance strategy, which can only start by getting visibility into highly regulated data, the systems that process that data and identifying who within your business has access to that data.<\/p>\n<p>\u201cMany organisations are still unsure whether their GDPR compliance strategy is 100% fit for purpose, but this incident signals that long gone are the days where privacy can be relegated to an IT or compliance effort: the magnitude of this fine clearly shows this is a business issue. Compliance professionals now have a use case to take to the board to secure any funding and resources they need to become GDPR compliant if their organisation isn\u2019t today.\u201d<\/p>\n<p>Paul Farrington, Director of Solutions Architecture (EMEA) at Veracode: \u201cThe fine against Google is an indication of the serious focus on privacy and security by regulators. Global enterprises must take steps to ensure security hygiene and compliance with standards to reduce their risk and protect data.\u201d<\/p>\n<p>Bharat Mistry, Principal Security Strategist at Trend Micro: \u201cThis just goes to show that even the big technology firms are struggling with the tightening regulatory and compliance regimes that the EU has put in place to protect EU citizens\u2019 data. This fine will be a wake-up call for the tech giants and any other company that is collecting and hoarding mass amounts of personal data without applying due care and attention to the protection, retention and safe disposal of the data once it is no longer required.\u201d<\/p>\n<p>Matt Walmsley, EMEA Director at Vectra: \u201cAnd so CNIL, the French supervisory authority, flexes its muscles and Google is the first big scalp for GDPR fines. Others will follow.<\/p>\n<p>\u201cUser experience and clarity in terms and conditions have been used to remind us that data management and use are just as important as data security within GDPR. I\u2019d expect Google to challenge the ruling and we may see the conclusion produce an important test in law that will bring clarity around GDPR implementation for others.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rules for protecting data stepped up a gear when the EU implemented the General Data Protection Regulation (GDPR) last May. It was introduced to improve the way organisations handled personal data and they were expected to comply with these new rules or risk facing heavy fines. Here, we look at how a French regulator is [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":27264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,573,9,497,13,93,24],"tags":[10140,8552,10509,6664,2109,10510,10511,10512,10513,10514,4792,2125,1792,10142,10515,10516,8878,10517,4542,10518,7981,8876,10519],"class_list":["post-27261","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-features","category-france","category-government","category-main-story-newsletter","category-top-stories","category-used","tag-alex-hollis","tag-bharat-mistry","tag-cnil","tag-cybersecurity-strategy","tag-data-security","tag-director-of-sales-engineering-at-varonis","tag-director-of-solutions-architecture-emea-at-veracode","tag-emea-director-at-vectra","tag-fine","tag-fouad-khalil","tag-france","tag-gdpr","tag-google","tag-grc-practice-director","tag-matt-lock","tag-matt-walmsley","tag-paul-farrington","tag-principal-security-strategist-at-trend-micro","tag-proofpoint","tag-ryan-kalember","tag-surecloud","tag-svp","tag-vice-president-of-compliance-at-securityscorecard"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=27261"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27261\/revisions"}],"predecessor-version":[{"id":27303,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27261\/revisions\/27303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/27264"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=27261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=27261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=27261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}