Luxembourg's Administrative Court annulled Amazon's record €746 million GDPR fine on March 12, 2026, but not because the underlying violations were wrong. The court found Luxembourg's CNPD skipped a fault analysis that EU case law now requires before any fine issues, and sent the case back to the regulator to redo that step. Everything else the CNPD found in 2021, including that Amazon could not rely on legitimate interest for behavioral advertising and that its transparency notices fell short, was left standing.
If your organization runs ad-targeting or profiling on a legitimate interest basis, the headline "Amazon's fine got thrown out" is not the takeaway you want to carry into your next documentation review. The court agreed with Amazon on how the fine was calculated. It did not agree that Amazon's data practices were lawful.
Key Takeaways
- The Administrative Court's March 12, 2026 judgment (case no. 52757C) annulled the CNPD's July 2021 decision in full, but on procedural grounds only: the regulator never assessed whether Amazon acted with fault (intent or negligence) before fining it, a step the Court of Justice of the EU made mandatory in its December 5, 2023 rulings in Deutsche Wohnen (C-807/21) and the Lithuanian "Nacionalinis" case (C-683/21).
- The court separately confirmed the CNPD's substantive findings: Amazon's reliance on legitimate interest as the legal basis for its behavioral advertising was not justified, and its information practices did not meet GDPR's transparency requirements under Articles 12-14.
- At a January 8, 2026 hearing, both sides told the court that Amazon had already brought its practices into compliance with the CNPD's original order, which is why the coercive daily penalty attached to the case became moot before the ruling even came down.
What actually changed on March 12, 2026
The CNPD opened its investigation into Amazon Europe Core in 2018 after a coordinated complaint campaign by La Quadrature du Net on behalf of roughly 10,000 individuals, and issued its decision in July 2021: a €746 million fine, at the time the largest in GDPR history, plus a coercive penalty of €746,000 per day for continued non-compliance. Amazon appealed to Luxembourg's Administrative Court.
The appeal sat for years while a separate strand of EU law caught up with it. On December 5, 2023, the CJEU ruled in Deutsche Wohnen and the parallel Lithuanian case that GDPR fines cannot be imposed on a strict-liability basis. A regulator has to establish that the controller acted with intent or negligence before a fine is even on the table; a bare finding of infringement is not enough on its own.
That doctrine did not exist when the CNPD wrote its 2021 decision, and the regulator never went back to retrofit it. At the January 8, 2026 hearing, the CNPD's own counsel conceded the point: the fault inquiry required by the 2023 CJEU judgments had not been attempted. The Administrative Court treated that gap as fatal to the fine itself, not fixable by the appellate court patching in a fault finding after the fact, and annulled the decision in full, sending the case back to the CNPD to redo the fault and sanction-selection analysis from scratch.
What the court left standing: legitimate interest and transparency violations
This is the part that gets flattened in headline coverage and in AI-generated summaries of the ruling: annulling the fine is not the same as clearing Amazon.
The Administrative Court reviewed the CNPD's substantive violations on the merits and did not disturb them. It confirmed that Amazon's use of legitimate interest under Article 6(1)(f) to justify behavioral advertising and cross-service profiling did not hold up, the same conclusion the CNPD reached in 2021. It also confirmed the CNPD's finding that Amazon's disclosures to users about how their data was used for ad-targeting did not satisfy the transparency obligations in Articles 12 through 14.
In other words, the court split the case cleanly into two questions and answered them differently. Were the violations real? Yes, mostly. Was the fine issued the right way? No, because the CNPD skipped a procedural step. Amazon won on the second question, not the first, which is exactly why the CNPD's own statement on the ruling describes it as having secured "effective data-processing compliance by Amazon" with its "key findings confirmed," rather than framing the outcome as a loss.
Amazon's own public statement on the case leans on the procedural win rather than disputing the substance: the company said it "worked in good faith to give customers control over whether they see personalised advertising based on their interests" after the 2018 rollout of GDPR left ad-targeting rules unclear. That framing is notably different from arguing the CNPD's legitimate-interest and transparency findings were mistaken, because the court did not find them mistaken.
Annulled vs. upheld, at a glance
| Element of the case | Outcome after the March 2026 ruling |
|---|---|
| €746 million fine | Annulled — CNPD must redo the fault (intent/negligence) analysis before any fine can be reimposed |
| €746,000/day coercive penalty | Moot — both parties confirmed at the January 2026 hearing that Amazon had already complied |
| Legitimate interest for behavioral advertising | Upheld against Amazon — rejected as a valid legal basis, same as the CNPD's original finding |
| Transparency notices (Articles 12-14) | Upheld against Amazon — found deficient, same as the CNPD's original finding |
| Underlying data practices at issue | Still non-compliant as found; Amazon's subsequent remediation is what resolved the compliance order, not the court reversing the finding |
If a table like this one is the first place you're seeing your own legitimate-interest use cases laid out this plainly, that's worth fixing before a regulator does it for you.
Why this is a procedural win, not a substantive one
A narrowing of a regulator's internal process is not a legal theory a defendant can lean on twice. The fault-requirement doctrine from Deutsche Wohnen controls how the CNPD (and every other EU data protection authority) must build the record before issuing a fine going forward. It does not change what counts as a valid legal basis for advertising, and it does not retroactively bless legitimate interest as sufficient for profiling.
That distinction matters directly for anyone using legitimate interest as a lawful basis for marketing or ad-targeting, because the substantive bar the CNPD applied to Amazon, and that the court left untouched, is now a live precedent for how any legitimate interest assessment for advertising gets tested. The EDPB's own October 2024 Guidelines 1/2024 already pushed toward stricter necessity and balancing criteria; this ruling is a concrete enforcement example of that standard being applied to one of the largest ad-tech operations in the world and holding up on appeal.
If your program relies on legitimate interest for any advertising, profiling, or cross-service tracking use case, the operational lesson is not "wait and see if the fine survives." It's to pressure-test the documentation now: does your legitimate interest assessment show a real, specific interest (not "we want to market effectively"), a genuine necessity analysis with alternatives considered, and a balancing test that actually weighs the intrusiveness of the profiling against what a user would reasonably expect? A legitimate interests assessment built on a worked example walks through exactly that three-part test, and it is worth rerunning against your current ad-targeting setup rather than assuming last year's version still clears this bar.
This is also where documentation gaps get expensive twice over: once if a regulator finds the legal basis itself doesn't hold, and again if you can't produce a contemporaneous record showing when and how the assessment was done. Secure Privacy's Data Map & ROPA module ties legal bases, data categories, and retention periods directly to each processing activity in one record, so a legitimate-interest justification for an advertising use case is documented at the point it's relied on rather than reconstructed after a regulator asks. The Assessments module runs LIAs alongside DPIAs and AIAs from the same workflow, with approval routing, so the balancing test itself has a timestamped, audit-ready trail if a DPA ever asks to see it.
What to do before your next audit
Audit every processing activity currently justified on legitimate interest grounds where the underlying purpose is advertising, profiling, or personalization. For each one, confirm the LIA was completed before processing started, not after, and that it names a specific alternative the organization considered and rejected, not a generic "no other option was viable" line. If any of those assessments were written before October 2024, treat them as due for a refresh against the EDPB's current guidance, not just this ruling.
None of that has to live in spreadsheets scattered across legal, marketing, and IT. Secure Privacy's Privacy & AI Governance Platform puts Data Map & ROPA and the Assessments module in one place, so every legitimate-interest basis for advertising is tied to a documented, approved LIA before processing starts, not reconstructed under pressure after a regulator opens a file.
FAQ
Was Amazon's GDPR fine overturned because it did nothing wrong?
No. Luxembourg's Administrative Court confirmed that Amazon's legitimate interest basis for behavioral advertising was invalid and that its transparency notices fell short. The €746 million fine was annulled only because the CNPD failed to first establish that Amazon acted with fault, a step EU case law made mandatory after the CNPD's original decision was issued.
What is the fault requirement that got the fine annulled?
It's a threshold condition from the CJEU's December 5, 2023 judgments in Deutsche Wohnen (C-807/21) and a related Lithuanian case (C-683/21): a data protection authority must show a controller acted with intent or negligence before imposing an administrative fine. Strict liability, fining based on the violation alone, is no longer sufficient.
Does this ruling mean legitimate interest can be used for ad-targeting now?
No. The court upheld the CNPD's finding that legitimate interest did not justify Amazon's behavioral advertising and profiling. That substantive rejection was not part of what got annulled.
What happened to the €746,000-per-day coercive fine?
It became moot before the ruling. At a January 8, 2026 hearing, both Amazon and the CNPD told the court Amazon had already complied with the underlying corrective order, so the coercive penalty tied to non-compliance no longer applied.
Can the CNPD fine Amazon again for the same conduct?
The case was remanded to the CNPD to redo its fault and sanction-selection analysis. If the CNPD completes that analysis and finds fault, it can issue a new fine on the same substantive findings the court already upheld, though it must do so through the corrected procedure this ruling requires.
What should privacy teams take from this if they don't use legitimate interest for advertising?
The fault-requirement doctrine applies to how any DPA builds a fine, not just this case. It's relevant background for any organization under active investigation, but it is a process safeguard for regulators to follow, not a substantive defense a controller can raise to justify its own processing.
How is this different from Amazon's 2020 French fine over cookies?
That was a separate, earlier CNIL enforcement action in France concerning cookie consent practices, unrelated to this CNPD case, which concerns the lawful basis for behavioral advertising and profiling rather than cookie banners specifically.




