Oracle and Salesforce are facing class action lawsuits, potentially worth €10B+, in the UK and the Netherlands over using cookie data without consumers' consent
Context & Ripple Effects
This lawsuit did not appear from nowhere: Privacy International's 2018 GDPR complaints against Oracle, Acxiom, Criteo, Quantcast, Tapad, Equifax and Experian already framed adtech's behind-the-scenes data trading as a consent problem, and regulators have had years of that mapping to work from. The new twist is scale and mechanism — consumer-side class actions in the UK and Netherlands claiming €10B+, following the template Meta's $3.1B UK class action established for pricing users' data as a mass claim rather than an individual one.
First-order effects
- Oracle and Salesforce now carry potential ten-figure-plus liabilities on their European books for monetizing cookie-derived behavioral data without valid consent, with both companies' core ad-targeting and CRM data practices subject to discovery.
Second-order effects
- The other firms Privacy International named — Acxiom, Criteo, Quantcast, Equifax, Experian — become obvious next targets for the same claim structure, and any advertiser buying their audiences faces repricing if consent gaps force inventory out of the market. Oracle's later agreement to pay $115M to settle a parallel US privacy suit shows these claims convert into real cash costs even when they settle far below headline value.
Third-order effects
- If collective-redress mechanisms keep scaling, consent becomes a priced liability line for every company whose business model trades on third-party data, pushing the industry toward first-party, explicitly licensed data — the structural shift captured by the idea of a data rights stack where provenance and permission are auditable preconditions for monetization.
The trend: European collective-action litigation is converting cookie-consent violations from a regulatory fine into a balance-sheet-scale business-model risk for adtech and enterprise software giants.