[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7k8oRP4bz8B6DYk9mKrQKMmrelMBVzt5lb7Rdrf6EKA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"055bdc39-4661-4fa8-a153-86d0a5386064","belgian-dpa-fines-roularta-50000-for-unlawful-cookie-practices-and-gdpr-violations","a16f58ee-68ee-438b-892e-a93b0da588f8","Belgian DPA Fines Roularta €50,000 for Unlawful Cookie Practices and GDPR Violations","Roularta Media Group failed to obtain valid prior consent before placing cookies on users' devices, violating both GDPR and the ePrivacy Directive. Key failures included pre-ticked consent boxes (which do not constitute freely given consent), deploying statistical cookies that process IP addresses without explicit opt-in, and maintaining inadequate privacy policies that lacked transparency. This case reinforces that 'consent by default' mechanisms are categorically unlawful and that IP addresses are personal data requiring the same rigorous protection as any other identifier. The €50,000 fine demonstrates that regulators are actively auditing cookie compliance and will penalise organisations that treat consent as a formality rather than a genuine user right.","**Immediate actions:**\n- Audit your cookie banner implementation to ensure no cookies (including statistical\u002Fanalytics) fire before explicit, affirmative user consent is recorded.\n- Remove all pre-ticked consent boxes and default opt-in mechanisms from consent management platforms (CMPs) immediately.\n- Review privacy policies to ensure they clearly describe every cookie category, its purpose, the data processed (including IP addresses), and the legal basis used.\n\n**Long-term improvements:**\n- Implement a certified Consent Management Platform (CMP) that enforces granular, per-purpose consent and stores auditable consent records with timestamps.\n- Establish a periodic cookie inventory process (at least quarterly) to detect and classify new or undeclared cookies introduced via third-party scripts or tag managers.\n- Embed GDPR accountability requirements into the software development lifecycle so privacy impact assessments are completed before new tracking technologies are deployed.\n\n**Detection & monitoring measures:**\n- Deploy automated cookie scanning tools to continuously monitor your web properties and alert on any cookies firing outside of consented categories.\n- Conduct annual third-party privacy audits covering consent flows, data retention periods, and cross-border data transfers to identify gaps before regulators do.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(e) – Storage limitation","GDPR Article 7 – Conditions for consent","GDPR Article 5(2) – Accountability principle","ePrivacy Directive 2002\u002F58\u002FEC Article 5(3) – Cookie consent requirement","NIST Privacy Framework PR.CO-P1 – Policies and procedures for data processing","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","NIST SP 800-53 PT-5 – Privacy Notice","CIS Control 3 – Data Protection (Data Classification and Handling)","ISO\u002FIEC 27701:2019 Section 7.2.3 – Determining a lawful basis for processing PII","ITIL Service Design – Information Security and Data Governance Policies","published","2026-07-16T16:21:00.596348+00:00","2026-07-16T16:21:00.463+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=APD\u002FGBA_(Belgium)_-_85\u002F2022&diff=52289&oldid=26425","apd-gba-belgium-85-2022-76e0f9","APD\u002FGBA (Belgium) - 85\u002F2022",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]