Belgian court rules Facebook is illegally collecting user data via cookies on third party sites, must remove data, threatens €250K/day fines for non-compliance
Fine of up to 250,000 euros a day if company doesn't comply — Social network to appeal, says cookies are industry standard
Context & Ripple Effects
This ruling is the second act of a fight Belgium started years ago: the country's privacy watchdog sued Facebook over what it called "flagrant and massive" privacy violations in June 2015, and a Belgian court followed with an order to stop tracking non-registered users within 48 hours or face roughly $269K a day in fines — an order Facebook appealed. When Facebook instead required Belgian users to log in to view pages, it treated the dispute as a product-design problem rather than a legal one.
The 2018 decision escalates matters: the court now finds the third-party cookie collection itself illegal, orders deletion of the data, and attaches a €250K-per-day penalty for non-compliance. The stakes extend beyond one case — the related coverage shows the same enforcement logic later reaching the ad-tech layer itself, with Belgium fining IAB Europe over its GDPR-violating targeting tool, and the EU's top court confirming in 2021 that Facebook cannot escape EU-wide privacy orders by pointing to its Irish regulator.
First-order effects
- Facebook must delete data collected via cookies on third-party sites and faces up to €250K per day if it does not comply; it is appealing on the grounds that such cookies are an industry standard.
- The ruling directly targets Facebook's off-platform tracking — the mechanism behind its social-graph-driven ad targeting — not just its handling of registered users.
Second-order effects
- Facebook's "industry standard" defense puts every company running similar third-party cookie tracking on notice: if the argument fails in Belgium, the same playbook can be turned on other platforms and ad networks.
- Belgian regulators have already applied this template beyond Facebook, fining IAB Europe €250K and ordering remedies for its ad-targeting tool — signaling that the enforcement target is the ad-targeting ecosystem, not one company.
Third-order effects
- With the EU's top court ruling that Facebook cannot avoid EU-wide privacy orders from authorities outside Ireland, national watchdogs gain leverage to enforce against a single lead regulator's jurisdiction — fragmenting compliance into a patchwork of national orders rather than one Irish gatekeeper.
- If courts keep treating behavioral tracking as presumptively unlawful without valid consent, the structural endpoint is an ad market rebuilt around logged-in, first-party consent — which is effectively where Facebook's own login-wall response to the earlier Belgian order was heading.
The trend: European national courts and regulators are dismantling third-party behavioral tracking piece by piece, moving from single-company rulings like Facebook's toward system-wide challenges to the ad-targeting ecosystem itself.