GDPR: What You Need to Know | Criteo

Meet Criteo GO: now with access to emerging advertising opportunities inside ChatGPT.

Learn more

GDPR: What You Need to Know

Confused about GDPR? If you still have questions, you may find the answers you need in the following FAQ’s.

Updated on May 20, 2026

From the Criteo Privacy Team: This article does not constitute legal advice, nor is this information intended to create or rise to the level of an attorney-client relationship. You should seek professional legal advice where appropriate.

In 1995, the EU implemented the Data Protection Directive. That directive permitted broad discretion as to how it would be implemented and sometimes resulted in dissimilar or even inconsistent rules.

Now, 23 years later, the directive is being replaced by the General Data Protection Regulation (GDPR). The GDPR will harmonize the various data privacy laws that exist across the European Union (EU), including the U.K. This harmonization will increase certainty and predictability producing a win-win for businesses and the consumers they serve.

In previous blog posts, we’ve addressed the six bases for collecting personal data [1] as set forth by the GDPR, as well as the crucial differences between sensitive and non-sensitive personal data, of which we only collect the latter.

What is the role of Criteo, as defined by GDPR?

Criteo acts as co-data controller, together with our clients.

A Data Controller means the natural or legal person, public authority, agency or any other body which alone or jointly with others, determines the purposes and means of the processing of personal data.

Criteo cannot be considered a “Data Processor”, since Data Processor means a natural or legal person, public authority, agency or any other body, which processes personal data on behalf of the controller. Data protection authorities in Europe consider that Criteo cannot be qualified as Data Processor and shall be qualified Data Controller, as defined in the Directive 94/46/EC.

What does it mean to be co-data controllers?

Being co-data controllers does not necessarily mean that each party is liable for everything. Article 26 of GDPR imposes on the joint controllers to determine the scope of their respective liability in their agreement.

In this regard, our standard terms and conditions that we have in place today are already clear on this:

According to GDPR, what are Criteo’s obligations?

To comply with GDPR we:

What is “Personal Data” as defined by GDPR?

Personal data means any information relating to an identified or identifiable natural person (or ‘data subject’). An identifiable natural person is an individual who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data that is considered personal data under the scope of GDPR includes but is not limited to:

However, GDPR establishes a distinction between two different categories of personal data:

Directly identifying information: a subcategory of personal data that allows to directly identify the individual (e.g. name, surname, social security number…)

Pseudonymous data: a subcategory of personal data that allows the singling out of individual behaviors without identifying the data subject directly (e.g. cookie ID, hashed email, device ID…)

What kind of Personal Data does Criteo Collect?

Criteo already acknowledges that the data collected for the purpose of its services is personal data, and only collects pseudonymous data linked to browsing events. For instance, Criteo can notably collect the following data on its advertiser clients’ websites or on their mobile applications:

Criteo uses state-of-the-art data hashing algorithms to pseudonymize the data and ensure that no directly identifying information is willingly stored in plain form, such as name, surname or email address. The pseudonymization of personal data is considered a best practice to reduce the risks for the data subjects concerned and helps companies meet their data protection obligations.

Does Criteo collect anonymous data?

No. Criteo collects pseudonymous data, which is a sub category of personal data that allows us to single out individual behaviors and serve relevant ads to relevant users without directly identifying them.

Anonymous data is the only category of data that falls out of the scope of the GDPR. However, it must be understood as highly aggregated information about a vast group of person and limited to information which does not relate to an identified or identifiable natural person and therefore does not allow singling out individual behaviors. When you aim to personalize content, you have to single out individual behaviors and should make sure you don’t say to your user you only collect anonymous data.

What is “Sensitive Data” as defined by GDPR?

The GDPR law defines sensitive data as any data that reveals:

By nature, the data that Criteo collects and processes for the purpose of its services does not qualify as sensitive data as defined by the GDPR.

Criteo gathers several data about users that may allow Criteo to build an ultimate “identity” of these users. Could the sum of all pseudonymous data somehow result in a PII (Personally Identifiable Information)?

We commit to respect and apply data minimization principle, making sure that we don’t collect more information than what is strictly necessary for the purpose of our services.

Since the data collected in the first place is only pseudonymous and cannot lead to the personal identification, Criteo is not able to build any identity of the user.

Is Criteo Compliant with GDPR?

In our standard terms with clients and partners, Criteo already undertakes to comply with all applicable laws and regulations. This will of course cover the GDPR when it comes into force. We already have a strong foundation and legacy of following several industry best practices, standards and regulations and applying high levels of security and data privacy across our portfolio of products, technologies and services.