GDPR: the CNIL imposes a fine of 10 million on Yahoo for non-compliance with consent


Benoit Bayle

January 20, 2024 at 6:02 p.m.

5

CNIL © © Stephane de Sakutin / AFP

The CNIL has decided © Stephane de Sakutin / AFP

In a press release released on January 19, the National Commission for Information Technology and Liberties (CNIL) was able to indicate that it had sanctioned Yahoo! a fine of up to 10 million euros, for not having respected the consent of its users regarding the use of cookies.

This is not the first time that the CNIL has sanctioned a large foreign tech company: Microsoft was fined 60 million euros, while TikTok got away with 5 million. Yahoo! is the new target of the commission, for a reason in all respects similar: Microsoft had been condemned for lacking a mechanism allowing cookies to be refused as easily as accepting them on Bing, TikTok had not respected the necessary obligations in relation to the choice to accept or not cookies. The same goes for Yahoo!.

A fine of 10 million euros for non-compliance with consent

The 27 complainants as part of the investigation carried out by the CNIL mainly concerned the Yahoo.com portal, but also the Yahoo Mail messaging service. During the investigation, which took place during 2020 and 2021, investigators noted the downloading of around twenty cookies, despite the fact that the sites had not obtained user consent. . The main purpose of this illegal practice was to resell data obtained on Yahoo from advertisers, for advertising purposes. This is a direct violation of article 82 of the Data Protection Act: advertising cookies can only be placed in a specific case, namely if the user has given explicit consent.

That’s not all: Yahoo! also stood out for its encouragement not to withdraw consent.
Thus, in its press release, the CNIL indicates:
the restricted training noted that when a user of the “Yahoo! Mail” wanted to withdraw the consent he had given to the deposit of cookies, the company informed him that his action would have the consequences that he would no longer be able to access the services offered by the company and that he would lose access to his messaging “. The CNIL thus notes that the withdrawal of consent could not be exercised freely.

yahoo-new-logo-siege.png © Yahoo

Yahoo ordered to pay a very large fine © Yahoo

Yahoo’s long descent into hell

The CNIL’s sanction comes after the commission noted this breach for several years, and repeatedly. In doing so, the fine can reach up to 2% of the company’s turnover, which allows it to reach 10 million euros. This high figure is in turn considered disproportionate by the targeted company: it could for its part appeal the decision.

This is not the first hard blow for Yahoo: the company has suffered a real descent into hell since the beginning of the 2010s, with revenues in free fall for a few years, notably in 2016 when the company announced a drop in its profits by more than 20%. Moreover, the same year, Yahoo! reported that 500 million of its user accounts had been hacked (or about half of the accounts in total). There is no doubt that this new condemnation by the CNIL of the American company will not help it restore its image.

Yahoo!  Email

See the offer

Yahoo! Email

  • 1 TB of storage space
  • Very simple handling

With a very simplified interface and handling, Yahoo!Mail messaging is suitable for users looking for a service focused solely on sending and receiving emails.

With a very simplified interface and handling, Yahoo!Mail messaging is suitable for users looking for a service focused solely on sending and receiving emails.

Source : CNIL



Source link -99