Back to all lessons
Awareness Lessons
3 months ago

Tiger Media Fined €72K for Unlawful Advertising Cookies and Missing EU Representative

Tiger Media Inc. placed advertising cookies on users' devices without obtaining prior consent, incorrectly invoking 'legitimate interest' as a legal basis — a justification explicitly prohibited for non-essential tracking cookies under the ePrivacy Directive. This violation compounds GDPR Article 7 requirements, which demand freely given, specific, informed, and unambiguous consent before processing personal data via cookies. Further, as a non-EU-established company targeting EU users, Tiger Media failed to appoint a designated EU representative as required by GDPR Article 27, a structural compliance gap that impedes regulatory accountability. This case highlights that ad networks, regardless of their geographic location, face full GDPR and ePrivacy obligations when processing EU residents' data. Regulators are increasingly scrutinizing cookie consent mechanisms and the accountability structures of non-EU companies.

Tactical Insight

Immediate actions

  • Audit all cookies deployed on your platforms and classify them as essential or non-essential before any further deployment.
  • Remove or block all non-essential advertising or tracking cookies until a valid, explicit consent mechanism (e.g., a compliant Consent Management Platform) is in place.
  • If your organization is not established in the EU but targets EU users, appoint a named EU representative as required by GDPR Article 27 without delay.

Long-term improvements

  • Implement a documented cookie governance policy that maps each cookie to its legal basis, vendor, purpose, and retention period.
  • Conduct annual GDPR and ePrivacy compliance reviews with legal counsel, specifically covering lawful basis assessments for all data processing activities.
  • Establish a third-party vendor management process to ensure all ad network partners meet EU privacy requirements before integration.

Detection & monitoring measures

  • Deploy automated cookie scanning tools to continuously detect unauthorized or undisclosed cookies appearing on your web properties.
  • Set up regulatory monitoring alerts (e.g., DPA press releases, enforcement databases) to stay informed of enforcement trends relevant to your industry.
  • Maintain consent audit logs to demonstrate compliance and provide evidence in the event of a regulatory inquiry.