The new regulations will unify the legal provisions that have so far functioned in the 28 member states of the European Union.

Most Common Questions About GDPR

At the same time, Criteo Academy admits that in conversations with clients, concerns still arise from a misunderstanding of the new regulations – particularly regarding how GDPR defines the issues of 'giving consent' and 'data confidentiality.'

Here are the most popular questions about GDPR that companies have encountered in recent months:

What is the purpose of GDPR?

In general terms, GDPR unifies the regulations currently in force in individual member states of the European Union (EU), while ensuring consistency in their implementation and subsequent enforcement – which falls under the competence of local Data Protection Authorities (DPA).

The main objectives of the new regulations are:

  • Modernizing the existing legal system so that it better protects personal data in the era of globalization and technological innovation;
  • Strengthening individual rights while reducing administrative obstacles by ensuring the free/unrestricted flow of personal data within the European Union;
  • Introducing clarity and consistency to personal data protection rules, in order to ensure their uniform application and effective implementation by EU countries.

What type of consent under the new legal provisions is needed by companies such as Criteo to collect personal data?

What Type of Consent Is Needed?

The biggest challenge for digital marketers is understanding the essence of unambiguous consent, which is not necessarily the same as explicitly expressed consent.

'Explicitly expressed' consent means that the user must clearly declare their willingness to share their data. This principle applies to special categories of personal data, such as race, religion, sexual orientation, political affiliation, or health status.

On the other side are the so-called non-special categories of personal data, for example, browsing history. In this case, GDPR regulations require companies to obtain 'unambiguous' consent from users. Since online identifiers (e.g., cookies) have been categorized as non-special categories of personal data, opt-in consent (explicitly expressed) is not required.

Consent must be 'freely given, specific, informed, and unambiguous.' What does this mean?

What Does Freely Given and Informed Consent Mean?

'Freely given' – consent is valid only when the data subject has the ability to make a genuine decision, and there is no risk of fraud, intimidation, coercion, or significant negative consequences if they refuse consent. Users can opt out of Criteo's services directly from the cookie message, without any negative consequences.

'Specific' and 'informed' means that for consent to be valid, it must be precise and based on appropriate information. In other words, general consent, without specifying a particular reason for processing, is not acceptable. The purpose of our message is to inform users that by clicking any link on the site, they agree to Criteo's 'cross-site tracking' technology.

'Unambiguous' means that consent must result from activity indicating its actual expression. For example, when a person does not interrupt their browsing of a website and thereby accepts the use of cookies.

Summary

GDPR unifies data protection rules in the EU, but it raises concerns mainly due to confusion of terms. Criteo explains that for non-personal data, such as browsing history, 'unambiguous' consent is sufficient (e.g., not interrupting the session), rather than 'explicitly expressed' opt-in, which is required only for sensitive data. What is key is the user's informed, freely given, and specific consent.

Companies must precisely inform about processing purposes, as Criteo does with cross-site tracking technology. It is worth remembering that enforcement of the regulations falls to local DPA authorities, which is meant to ensure consistency across the entire EU.