Key takeaways

European regulators have issued substantial sanctions where websites placed or read non-essential cookies without the required consent, made refusal harder than acceptance, or could not demonstrate consent. The French decisions against Amazon, Microsoft, and TikTok concern France's cookie rules, which implement the ePrivacy framework. The CNIL's €40 million Criteo decision was a GDPR decision about, among other things, demonstrating consent obtained through partners.

Last reviewed: 29 August 2026

The headline amounts reflect the facts, scale, and legal framework of each case. They are not a prediction of what a small business would face. The useful lesson is more ordinary: test your own site before a visitor chooses. Then make accepting, refusing, and changing a choice straightforward, and keep evidence of the choice.

Enforcement themes, translated into calm site checks

  1. 01

    Before choice

    Open a clean session and inspect cookies, storage, and network requests before interacting with the banner.

  2. 02

    Equal, easy choices

    Compare the visibility, wording, prominence, and number of actions for accept, reject, and manage.

  3. 03

    Preference effect

    Reject or choose one category, refresh and navigate, then confirm the browser and tags reflect that choice.

  4. 04

    Evidence & review

    Record the banner version, vendors, purposes, date, and owner; revisit after releases or new integrations.

Use the map as a review rhythm. It turns public enforcement themes into observable implementation questions without predicting an outcome.

These checks are practical review prompts drawn from recurring themes in official decisions. Passing them does not guarantee compliance or resolve every legal question.

Cookie enforcement can sound remote when the examples involve global platforms. It is not useful to turn those decisions into a scare story for a local shop, consultant, or growing SaaS business. Regulators assess cases individually, and a large-company sanction does not establish a standard fine for every site.

It is useful, however, to read the decisions closely. The same operational problems recur: a marketing tag runs before a choice, the “reject” route takes more effort, the information is too vague, or a business relying on partners cannot show that consent was collected properly. Those are problems a small team can identify and address.

This article uses a short list of primary-source decisions rather than an unverified league table. It also separates cookie-law sanctions from GDPR enforcement, because the distinction matters. The linked notices and decision report the decisions; this article does not claim that any decision is final or describe any later appeal unless the cited record establishes it.

People often use “GDPR cookie fine” as shorthand. In Europe, cookies and similar technologies commonly sit at the intersection of two rule sets:

Question Main framework Plain-English point
May a site store or read non-essential information on a visitor's device? The ePrivacy Directive, as implemented in national law Consent is generally the starting point, subject to a narrow “strictly necessary” exception.
What makes consent valid where personal data is processed? GDPR Consent must meet the GDPR standard: freely given, specific, informed, and unambiguous.
Can the organisation prove the consent it relies on? GDPR and accountability obligations Records and the collection flow matter, especially where multiple parties are involved.

For example, the French CNIL can enforce the French cookie provision in Article 82 of the Data Protection Act. Its Google, Amazon, Microsoft, and TikTok cookie decisions below were issued under that national provision, not as GDPR administrative fines. Criteo's €40 million sanction was issued under the GDPR.

That does not make the cookie decisions less relevant. A site owner still needs to know what loads before a choice and whether the visitor can make a real choice. For a practical explanation of the underlying rule, see the ePrivacy Directive and cookie law.

Verified enforcement examples

Amazon Europe Core: €35 million in France (2020)

On 7 December 2020, the CNIL fined Amazon Europe Core €35 million under Article 82 of the French Data Protection Act. According to the CNIL, when users visited amazon.fr, advertising cookies were placed without prior consent. The authority also found that the information provided to users was not sufficiently clear or complete.

This is a useful reminder that timing is part of the implementation, not an afterthought. A banner can be visible while tags, pixels, or cookies have already run. In that situation, the banner does not change what happened at page load.

What to take from it: Review the first page request in a fresh browser session. Do not click the banner first. If non-essential services initialise before the visitor decides, investigate the tag configuration and any third-party embeds. Our guide to blocking cookies before consent explains the technical question to ask your developer or agency.

Primary notice: CNIL, 7 December 2020.

Microsoft Ireland: €60 million in France (2022)

On 22 December 2022, the CNIL fined Microsoft Ireland Operations Limited €60 million under Article 82. The decision concerned cookies placed when users visited bing.com. The CNIL said that users could accept cookies immediately, but there was no equally simple control to refuse them, and that advertising cookies were placed without consent.

The CNIL's public notice also describes an injunction, backed by a daily penalty if not complied with within three months, to obtain consent before placing advertising cookies and to provide a means to refuse them as simply as accepting.

What to take from it: Treat “reject” as a core user choice, not as a settings-page feature. A visitor should not have to search for it or complete a more burdensome journey merely to decline non-essential tracking.

Primary notice: CNIL, 22 December 2022.

TikTok Technology: €5 million in France (2022)

On 29 December 2022, the CNIL fined TikTok Technology Limited €5 million under Article 82. The CNIL reported that users of tiktok.com could accept cookies with one click, while refusing them required several clicks. It also found shortcomings in the information supplied to users about the purposes of cookies.

The case is narrower in scale than the large-platform decisions above, but the design lesson is the same. Small friction choices in a banner can change whether a visitor has an equally accessible way to say no.

What to take from it: Compare the actions, not just the labels. Check the number of steps, visual prominence, and plain-language explanation for both choices. Avoid wording that implies a visitor must accept tracking to continue unless that restriction has been assessed for the specific service and jurisdiction.

Primary notice: CNIL, 29 December 2022.

Criteo: €40 million GDPR sanction in France (2023)

On 15 June 2023, the CNIL fined Criteo €40 million under the GDPR. The authority's public notice says that Criteo collected browsing data through its business partners for targeted advertising. Among several GDPR findings, the CNIL found that Criteo did not sufficiently verify that partners obtained consent from people whose data it processed and did not adequately demonstrate that consent.

This is not an Article 82 cookie fine. It is included because it illustrates a common website-owner problem: a business may depend on a consent flow operated by a publisher, tag manager, agency, or other partner, but it remains important to understand what evidence exists and what the parties have agreed to do.

What to take from it: If another party supplies a tag or collects consent, do not assume the paperwork and configuration are settled. Identify the parties, purposes, technical signals, and records involved. Keep the consent journey and vendor list understandable enough that you can explain them.

Primary decision: CNIL restricted committee decision SAN-2023-009, 15 June 2023.

The recurring failures, translated into website checks

The examples are not identical, and the legal provisions differ. Still, they point to a useful review sequence.

Recurring issue What it can look like on a site A practical check
Non-essential tracking before a choice Analytics, advertising, or social tags load on the first page view Use a clean browser profile and inspect cookies and network requests before responding to the banner.
Refusal is harder than acceptance “Accept all” is immediate; “reject” is hidden in several settings screens Time both routes and count the actions. Review mobile as well as desktop.
Information does not explain the choice Generic text such as “we use cookies to improve your experience” with no purposes or meaningful detail Read the first layer and the detailed settings as a visitor would. Can you tell why each category is used?
Consent cannot be demonstrated No retained record, unclear vendor list, or uncertainty over which system collected the choice Ask who can retrieve the record, what it contains, and how it is linked to the version of the notice shown.

None of these checks decides every legal question. Exemptions, national rules, the technologies in use, and the processing that follows all matter. But they provide a much better starting point than judging a banner by its appearance alone.

A 20-minute review for a small-business website

Use this as an operational checklist after a redesign, marketing campaign, plugin installation, or tag-manager change.

1. List what can store or read data on the device

Start with more than named cookies. The ePrivacy rule can cover similar technologies, including local storage and tracking pixels. Make a list of:

  • analytics and advertising tags;
  • embedded video, maps, chat, and social widgets;
  • A/B testing and session-recording tools;
  • tag-manager containers and the tags they can publish; and
  • essential functions such as login, basket, security, and consent-preference storage.

If you do not know what the site loads, begin with a cookie scan. Treat the result as an inventory and a prompt for technical investigation, not as a legal verdict.

2. Test the page before touching the banner

Open a private browsing window or a new browser profile. Visit the home page and one high-traffic landing page without choosing anything. Look for non-essential cookies, storage entries, and requests to known analytics or advertising services.

Test more than the home page. A campaign page may use a different template, and an embedded video can behave differently from the main banner. If a third party loads before consent, ask the person responsible for the site to confirm whether it is strictly necessary and, if not, how it is prevented from loading before a choice.

3. Test both choices fairly

On the first layer, find the route to accept and the route to reject non-essential options. Then test:

  • whether both are visible and understandable;
  • how many actions each takes;
  • whether the layout makes one choice conspicuously easier;
  • whether individual categories can be adjusted where offered; and
  • whether the same experience works on a narrow mobile screen.

The aim is not to make every button identical in every detail. The aim is to avoid designing refusal as an obstacle course.

4. Confirm that the decision takes effect

Choose rejection, refresh the page, and move between a few pages. Repeat the browser inspection. Then accept only a category, if your banner offers granular controls, and check that the site behaves in line with that choice.

This step often finds implementation gaps. A banner interface may correctly store a preference while a hard-coded tag, a plugin, or a second tag-manager container keeps running.

5. Check the evidence and the change process

Record the banner version, the categories and vendors shown, the date of review, and any findings. If you rely on consent, establish who can retrieve evidence of the choice and what happens when the banner text, vendor list, or purposes change.

Also assign ownership. Marketing may add a new pixel; a developer may add an embed; an agency may change a container. A lightweight release check prevents cookie issues from returning after a clean-up.

For a broader implementation checklist, read cookie consent best practices and how to audit website cookies.

How enforcement can begin

A regulator does not need a major data breach to become aware of a cookie issue. Authorities receive complaints, conduct investigations, and publish guidance and enforcement priorities. The exact methods and priorities vary by country and change over time.

For a business owner, the practical point is simple: public pages are easy to inspect. A visitor, journalist, competitor, regulator, or customer can see a banner and can observe what their browser receives. That is why a basic pre-consent test is worth repeating whenever the site changes.

Do not assume that a small audience or a modest marketing budget answers the legal question. At the same time, do not infer from a €150 million decision that a small firm faces the same outcome. Enforcement and sanctions depend on the facts, applicable law, seriousness, duration, cooperation, and other factors considered by the authority.

What to do if your review finds a problem

Prioritise by what happens first:

  1. Stop unintended non-essential loading before a choice. Identify the tag, template, or embed responsible and have it gated or removed.
  2. Simplify the first-layer choice. Make the route to refuse clear and avoid unnecessary extra steps.
  3. Improve the explanation. Describe categories and purposes in language a normal visitor can understand; keep the detailed information current.
  4. Validate the rejected state. Do not stop once the banner looks right. Test what the browser actually receives.
  5. Document the fix and re-test after releases. A short record helps your team keep track of what changed and why.

Where the decision is difficult—for example, an analytics exemption, a cookie wall, a cross-border site, or a complex ad-tech setup—obtain advice suited to your circumstances and the countries you serve. This article is general information, not legal advice.

Build a calmer, repeatable process

Cookie controls work best when they are part of ordinary site maintenance rather than a one-time design project. Keep an inventory, review new vendors before publishing them, test the site in a clean session, and make one person responsible for signing off changes.

If you serve several markets, start with the shared European baseline, then review local differences. Our cookie consent guide by country is a useful planning reference. It is better to ask targeted questions about your site now than to discover an unexpected tag after a campaign is live.

Sources