Belgian DPA Fines Roularta €50,000 for Unlawful Cookie Practices and GDPR Violations
Roularta Media Group failed to obtain valid prior consent before placing cookies on users' devices, violating both GDPR and the ePrivacy Directive. Key failures included pre-ticked consent boxes (which do not constitute freely given consent), deploying statistical cookies that process IP addresses without explicit opt-in, and maintaining inadequate privacy policies that lacked transparency. This case reinforces that 'consent by default' mechanisms are categorically unlawful and that IP addresses are personal data requiring the same rigorous protection as any other identifier. The €50,000 fine demonstrates that regulators are actively auditing cookie compliance and will penalise organisations that treat consent as a formality rather than a genuine user right.
Tactical Insight
Immediate actions
- Audit your cookie banner implementation to ensure no cookies (including statistical/analytics) fire before explicit, affirmative user consent is recorded.
- Remove all pre-ticked consent boxes and default opt-in mechanisms from consent management platforms (CMPs) immediately.
- Review privacy policies to ensure they clearly describe every cookie category, its purpose, the data processed (including IP addresses), and the legal basis used.
Long-term improvements
- Implement a certified Consent Management Platform (CMP) that enforces granular, per-purpose consent and stores auditable consent records with timestamps.
- Establish a periodic cookie inventory process (at least quarterly) to detect and classify new or undeclared cookies introduced via third-party scripts or tag managers.
- Embed GDPR accountability requirements into the software development lifecycle so privacy impact assessments are completed before new tracking technologies are deployed.
Detection & monitoring measures
- Deploy automated cookie scanning tools to continuously monitor your web properties and alert on any cookies firing outside of consented categories.
- Conduct annual third-party privacy audits covering consent flows, data retention periods, and cross-border data transfers to identify gaps before regulators do.