Earlier this week, France’s data protection agency known as CNIL fined Alphabet’s Google 50 million euros ($57 million) for breaching the European Union’s new online privacy rules – the biggest such penalty levied against a U.S. tech company so far. 

The penalty was issues for alleged violations of the EU’s General Data Protection Regulation (GDPR), which went into force in May 2018.    It allows users to better control their personal data and gives regulators the power to impose fines of up to 4 percent of global revenue for violations.

“GDPR represents a seismic shift in data privacy rules, requiring tech companies to be more transparent about data use, and giving individuals much more power over the collection and use of their data,”  says Jim Chester, a global business and technology attorney and partner in Dallas-based technology boutique Klemchuk LLP.

“Although the industry has been aware of GDPR, it is such a fundamental and comprehensive change in how companies need to think about data privacy that many companies have struggled to adapt their policies – there is no clear ‘best practices’ blueprint for compliance,” Chester adds.  

US companies have also been uncertain the extent to which they’d be subject to the EU’s rules.  According to Chester, once penalties and enforcement actions start to happen, a clearer picture of what’s expected will begin to develop.

In this case, the French regulator claimed Google lacked transparency and clarity in the way it informs users about its handling of personal data and failed to properly obtain their consent for personalized ads. In a statement, CNIL said “The amount decided, and the publicity of the fine, are justified by the severity of the infringements observed regarding the essential principles of the GDPR: transparency, information and consent.”

The penalty will likely be the first of many enforcement actions under the GDPR, and U.S. Internet companies are scrambling to comply.  

But GDPR is not limited to tech titans like Google.  To avoid penalties all companies operating online need to be aware of the GDPR’s requirements and must ensure they don’t run afoul of the data privacy rules. 

For more information, see this article from Reuters (a source of much of this article’s content):

https://www.reuters.com/article/us-google-privacy-france/france-fines-google-57-million-for-european-privacy-rule-breach-idUSKCN1PF208