EUComply

GDPR cookie banner fines: What websites actually get fined for (2026)

Published 24 August 2026 · 8 min read · GDPR Enforcement Cookies

Most website owners know they need a cookie banner. Far fewer know what actually gets a site fined — and it's usually not "no banner at all". Data protection authorities across the EU consistently penalise a small set of specific, fixable mistakes.

This article walks through real enforcement patterns, the amounts involved, and how to check whether your own setup has the same weaknesses — before an authority or a competitor's complaint does.

Check your own site first: our free compliance scanner tests your cookie banner, HTTPS hardening and privacy policy link on any URL — no sign-up.

What gets websites fined (and what doesn't)

1. Non-compliant banners that are worse than nothing

The single most common trigger is a banner that looks compliant but isn't:

2. No records of consent

GDPR Article 7(1) puts the burden of proof on you. If you can't show when and how each user consented, regulators treat the consent as never having happened. Fines here are common because most small-site consent setups store nothing at all.

3. Missing or buried privacy policy

A cookie banner that doesn't link to a privacy policy explaining cookie purposes, retention periods and third parties fails the "informed" requirement. Several DPAs issue low-level fines and reprimands for this daily — they rarely make headlines but they do land in your inbox.

What typically does not get fined

Strictly necessary cookies without consent (legal under ePrivacy Art. 5(3)), first-party session cookies, and banners that simply use an unusual design as long as consent is freely given, informed and revocable. Design taste isn't regulated; mechanics are.

Typical fine ranges

ViolationTypical rangeNote
No valid consent mechanism€2,000 – €100,000+Scales with traffic and data sensitivity
Tracking before consent€5,000 – €60MMeta/Google cases sit at the extreme end
Missing reject option / dark patterns€40,000 – €150MCNIL 2022 decisions set the benchmark
No privacy policy link / incomplete info€500 – €20,000Most common outcome for SMB sites after complaints
The realistic risk for a small business isn't the headline fine. It's the complaint: one user, one email to a DPA, then weeks of correspondence, mandatory documentation and a remediation deadline. Prevention costs minutes; response costs months.

Recent enforcement: what regulators actually did

These are real decisions from 2024–2026, each verified against the authority's own announcement:

WhenWhoFine / actionWhat went wrong
Sep 2025Google (France, CNIL)€325MAds in Gmail without valid consent; coercive cookie practices. Third CNIL fine for Google's cookies (after €100M in 2020 and €150M in 2021).
Sep 2025SHEIN (France, CNIL)€150MAdvertising cookies placed before any user choice; reject/withdrawal mechanisms ineffective; incomplete banner information.
Dec 2025UK top-1,000 sites (ICO)Enforcement sweep564 of the UK's 1,000 biggest websites failed initial checks and only complied after ICO letters, investigations and 17 preliminary enforcement notices; 21 still failing.
2024Kruidvat / AS Watson (Netherlands)€600,000Tracking cookies without valid consent; pre-ticked-style consent mechanics.
Apr 2025Warner Music Sweden, Aller Media et al. (Sweden, IMY)Formal warningsBanners designed to favour "Accept" over "Reject".

Sources: CNIL press releases (cnil.fr, 1 & 3 Sep 2025), EDPB case register, ICO news release (4 Dec 2025), Dutch DPA decision on AS Watson, Swedish IMY supervisory notices.

The pattern across every case is the same three failures: cookies before consent, a harder-to-find reject option, and incomplete information. None of these require enterprise budgets to fix — they are implementation mistakes.

The 5-point self-check

  1. Nothing fires before the click. Open your site in an incognito window with dev tools open. No analytics, marketing or embed cookies may appear before consent.
  2. Reject is one click, equal weight. Same size, same contrast, same number of clicks as accept.
  3. Consent is logged. Your CMP stores timestamp + choices per user.
  4. Banner links to your privacy policy, which names cookie categories, purposes, retention periods and third parties.
  5. Withdrawal works. A visible "cookie settings" path lets users change their mind as easily as they said yes.

Check items 1–3 automatically

Our free scanner checks any URL — WordPress, Shopify, Webflow, Next.js, Squarespace or plain HTML — for consent-banner presence, HTTPS hardening and privacy-policy linking, and tells you exactly what to fix:

Run a free scan →

Passed? Show it off — add a free compliance badge to your site (great for client trust and a dofollow backlink).

Want documented proof for clients or auditors? EUComply Pro ($79/yr) monitors your site daily and generates a signed report you can archive, and the compliance checklist drafts the policies themselves.

Further reading