Explore real-world investigations and rulings related to GDPR compliance and server-side tracking. Learn from actual cases how proper implementation of server-side tracking can help maintain both marketing capabilities and regulatory compliance.
The Swedish Authority for Privacy Protection (IMY) has criticized three major companies for improper cookie banner design and inadequate consent management, highlighting the importance of maintaining control over data processing once consent is given.
The Swedish Authority for Privacy Protection (IMY) has imposed significant fines on Apoteket and Apohem for transferring sensitive personal data to Meta through the Meta Pixel, emphasizing the need for server-side tracking solutions.
The Norwegian Data Protection Authority (Datatilsynet) has issued a reprimand to Telenor ASA for illegally transferring personal data to the United States through Google Analytics, emphasizing the ongoing challenges with transatlantic data transfers following the Schrems II judgment.
The Swedish Authority for Privacy Protection (IMY) has ordered four companies to cease their use of Google Analytics due to improper data transfer to the USA, highlighting the importance of server-side tracking solutions.
The Danish Data Protection Authority (Datatilsynet) has ruled that the use of Google Analytics violates GDPR due to improper transfer of personal data to the United States, joining other EU authorities in establishing a consistent approach to US-based analytics services.
The Italian Data Protection Authority (Garante) has ruled that the use of Google Analytics violates GDPR due to improper transfer of personal data to the United States, reinforcing the growing European consensus against using US-based analytics services without adequate safeguards.
The French Data Protection Authority (CNIL) has ruled that transfers of personal data to the United States through Google Analytics violate the GDPR, reinforcing the need for EU-based analytics solutions and proper anonymization techniques.
The Austrian Data Protection Authority (DSB) has ruled that the use of Google Analytics violates the GDPR due to inadequate protection of personal data transferred to the US, setting a precedent for similar decisions across the EU.
The European Data Protection Supervisor (EDPS) has reprimanded the European Parliament for transferring personal data to the United States through Google Analytics on its COVID-19 testing website, marking the first major institutional application of the Schrems II ruling.