Cookie-consent enforcement has moved from warnings to nine-figure fines. Regulators now use automated scanning tools to find non-compliant banners at scale, and the companies being fined are not obscure — they are some of the most visited sites in Europe.
This page tracks the major public decisions, what each company actually did wrong, and — more usefully for you — the small set of patterns behind nearly every fine. Most of them are detectable on any website in seconds.
| Company | Fine | When | What went wrong |
|---|---|---|---|
| €325M | Sep 2025 | Ads personalisation without prior consent in Gmail; misleading banner interface that made refusal harder than acceptance | |
| SHEIN | €150M | Sep 2025 | Advertising cookies placed before any interaction with the banner; "Reject all" failed to actually stop cookies |
| Free Mobile | €27M | Jan 2026 | Broader data protection failures including consent handling |
| Free | €15M | Jan 2026 | Data protection failures including consent mechanisms |
| Les Publications Condé Nast (vanityfair.fr) | €750k | Nov 2025 | Cookies placed on the vanityfair.fr site without the user's prior consent — proof that media brands of every size are in scope |
| American Express (France) | €1.5M | Jan 2026 | Cookies placed before the user's choice — and continuing even after explicit refusal |
| Meta (benchmark) | €150M+ | 2022 CNIL | "Reject" required more clicks than "Accept"; the dark-pattern benchmark DPAs still cite |
| Google & Meta (benchmark) | €150M / €60M | 2022 CNIL | Same refusal asymmetry — the decisions that defined today's enforcement standard |
Amounts as publicly reported by data protection authorities and press coverage of the decisions. Sources: CNIL press releases (Sep 2025 Google & SHEIN, Nov 2025 Condé Nast, Jan 2026 American Express). This article is general information, not legal advice.
The SHEIN and American Express decisions share one core failure: tracking scripts ran before the visitor made any choice. This is called pre-consent tracking, and it is technically detectable by anyone who opens browser dev tools — which is exactly how many complaints start. Privacy advocacy groups now publish automated reports naming thousands of offending sites, so the complaint often arrives before the regulator's own scan does.
The CNIL's landmark decisions established that a banner where "Reject all" is smaller, greyed out, hidden behind a second menu, or simply missing is a dark pattern — even if a reject option technically exists somewhere. The 2026 standard is strict: equal prominence, equal number of clicks, first layer of the banner.
The most expensive lesson from the SHEIN decision: having a CMP installed is not compliance. If cookies continue after rejection — through misconfigured tag managers, server-side tagging, or scripts outside the CMP's control — regulators treat it as knowing violation. CMP misconfiguration is now itself an audit finding that exposes every downstream client.
Steps 1–2 are exactly what the free scanner automates — plus HTTPS hardening, security headers and privacy-policy linking: