Consent is often treated as a document problem: publish a notice, keep a policy link, and preserve a record that a person clicked something. In a large digital service, the more consequential question can be architectural. What does a person see at the moment a choice has commercial effect, and how many layers must they cross before the actual purpose becomes clear?
Fact
Source record. CNIL’s decision concerned how relevant information and personalized-advertising consent were presented in the mobile operating system ecosystem. The authority imposed a monetary sanction of EUR50 million. France’s highest administrative court upheld that outcome.
The sequence matters because it joins a regulator decision to later court treatment. It would be inaccurate to describe the sanction only as an allegation or to describe the court decision as a new fine. The source material records an administrative sanction first and judicial confirmation later.
Signal
PARAVEILUX inference. Consent is not only a checkbox. It is a path through screens, settings, explanations, defaults, and records. A path that is technically available can still be hard for a person to understand at the point where a choice is made.
What happened
The CNIL decision addressed inadequate transparency, information, and consent connected with personalized advertising. The authority imposed EUR50 million. The official decision is in French, with a related translated court document; translation and summary should not be stretched beyond what the underlying decision says.
The Conseil d’Etat later upheld the sanction. That later result limits a common shortcut: calling the 2019 decision merely a provisional complaint or assuming it was overturned because the subject was a global technology platform. The publicly available materials instead show the regulator outcome and its subsequent judicial status.
The turn
The turn is that interface design can become the legal record. An organization may have a detailed privacy notice, a governance committee, and product documentation. If the relevant explanation is scattered across layers at the decisive moment, the design itself can become central to a regulator’s assessment.
This does not mean that all layered design is defective. It means that a notice library and an on-screen journey answer different questions. One documents what the organization can say. The other shows what a person could realistically learn before a data use is activated.
The hidden variable
The hidden variable is consent architecture and layered notices. Product, marketing, privacy, and engineering teams can each see a complete slice of the system while no one can reproduce the whole decision path as a user would experience it.
PARAVEILUX inference. The missing evidence is often a versioned journey: screen order, default state, precise language, links, language setting, and the data use that follows. Without it, an organization may only be able to describe what the intended design was, not what a person actually encountered.
What this source does not prove
CNIL’s decision and the Conseil d’Etat’s ruling do not establish the same duty, fine, consent outcome, or damages exposure for another service, country, product, or time period. They do not decide a particular organization’s GDPR position or the adequacy of a particular user interface.
Owner Q&A
What should a consent review be able to replay?
It should be able to show the relevant journey as it existed for a defined audience: what was visible, what required another click, what the default was, and what processing followed the choice. The objective is a factual record of the experience, not a retrospective description of intent.
Why keep product changes with the privacy record?
Small interface changes can alter sequencing, wording, and defaults even when the formal policy has not changed. A shared record helps distinguish a current screen from a historical screen and a design hypothesis from what was actually released.
Action boundary
Use this as a neutral review prompt: “Is consent understandable at the exact point of collection, not merely documented somewhere?” The cited source does not prescribe an answer for another organization; current facts and appropriate specialist advice govern any action.
Next verification
Verify the current governing law, implementation, languages, user populations, and source materials before relying on this French enforcement record for another decision.
Limitations
The source set is CNIL’s SAN-2019-001 decision and the Conseil d’Etat decision. The primary decision is French-language material, and this article does not add facts beyond the bounded enforcement and later-status point.
This is general risk education, not legal, privacy, product, or professional advice. Verify the current sources, actual interface, and applicable rules before acting.