← Enforcement
GDPR EU 2016/679 France

CNIL fines: the EU's cookie-enforcement powerhouse, case by case

A registry of the biggest fines issued by France's CNIL — Google €150M and €100M, Facebook €60M, Microsoft €60M, Orange €50M, Criteo €40M and more. Why most of them are about cookies rather than the GDPR, why the CNIL can fine Big Tech directly when Ireland normally would, and which fines France's top court has upheld — every amount sourced to the regulator.

If you want to understand how Europe actually polices web tracking, you read the CNIL’s fine list. France’s data protection authority is the most aggressive cookie enforcer in the EU — and that word matters, because most of its largest penalties are not classic GDPR fines at all. They are cookie fines, issued under a different law, through a route that lets France fine Google, Facebook and Microsoft directly even though those companies normally answer to Ireland.

This post is the registry of the CNIL’s headline penalties: the exact amounts, the legal basis, what each company actually did, and which fines France’s highest court has since upheld. Every figure links to the regulator or the EU mirror of its decision.

Why most CNIL mega-fines are about cookies, not the GDPR

There are two separate legal tracks here, and the CNIL uses both — but its biggest, most frequent fines run on the cookie track.

  • The GDPR track governs the processing of personal data generally. For cross-border cases it is subject to the one-stop-shop, which sends Big Tech cases to Ireland’s DPC (because that is where their EU headquarters sit — explained in the Big Tech GDPR fines registry).
  • The cookie track is Article 82 of the French Data Protection Act, which transposes the EU’s ePrivacy Directive — the rules on storing or reading information (cookies, trackers) on a user’s device. Crucially, the ePrivacy regime is not subject to the GDPR one-stop-shop. France’s highest administrative court, the Conseil d’État, confirmed that the CNIL can act against any company that drops cookies on French users’ devices — regardless of where that company’s GDPR lead authority is.

That second point is the whole story. It is why the CNIL — not Ireland — fined Google, Amazon, Facebook and Microsoft for cookies. On cookies, every national regulator keeps its own teeth.

The doctrine: “refusing must be as easy as accepting”

Almost every CNIL cookie fine turns on one simple principle, which the regulator has now made into hard law: rejecting cookies must be as easy as accepting them. A banner with a single “Accept all” button but no equally easy “Reject all” — forcing the user to click through layers of menus to say no — is an invalid consent design. In the Google/Facebook decisions, accepting took one click while refusing took five (Google) or three (Facebook). That asymmetry, by itself, was the violation.

This is the cookie-banner standard the rest of the EU now points to.

The scale

The CNIL is not just a big-fine regulator; it is a high-volume one. Over 2022–2024 it issued 495 formal notices (mises en demeure) and 150 sanctions, for more than €245 million in fines combined (CNIL Rapport annuel 2024). A simplified sanction procedure — for straightforward cases, capped at €20,000 — let the number of sanctions jump from 21 in 2022 to 87 in 2024, sharply increasing how fast the CNIL can punish routine complaints.

Sanctions are decided not by the CNIL’s president but by its formation restreinte — a restricted, sanctions-only chamber separated from the members who investigate.

Quick guide to the legal bases below:

  • Article 82, French Data Protection Act — the cookie rule: you must get free, informed prior consent before storing or reading non-essential cookies/trackers on someone’s device. This transposes the ePrivacy Directive and sits outside the GDPR one-stop-shop.
  • GDPR Article 6 — the six lawful bases for processing personal data; you need one. Used in the non-cookie cases (Criteo, Google 2019).
  • GDPR Articles 12–13 — transparency: clear, accessible information about what you do with data.
  • Conseil d’État — France’s highest administrative court; it hears appeals against CNIL fines in first and last instance, so when it confirms a fine, the fine is final.

The registry — by amount

1. Google — €150,000,000 — 31 December 2021 (cookies)

The largest CNIL fine. Google made refusing cookies on google.fr and youtube.com far harder than accepting them — five clicks to reject, one to accept. The €150 million was split €90 million on Google LLC and €60 million on Google Ireland, plus an order to fix the banner within three months on pain of €100,000 per day. Announced in early January 2022.

Basis. Article 82, French Data Protection Act (cookies).

Source: DLA Piper — CNIL fines Google €150M and Facebook €60M.


2. Google — €100,000,000 — 7 December 2020 (cookies)

The CNIL’s first big cookie strike. Google set advertising cookies on google.fr users’ devices without prior consent, gave inadequate information, and ran a broken opt-out. €100 million across Google LLC and Google Ireland, with a three-month injunction at €100,000 per day.

Basis. Article 82, French Data Protection Act (cookies).

Source: Hunton — CNIL fines Google and Amazon €135 million.


3. Facebook (Meta) — €60,000,000 — 31 December 2021 (cookies)

Same decision day as the €150M Google cookie fine. On facebook.com, refusing cookies took three clicks against one to accept. €60 million plus the same three-month banner-fix injunction.

Basis. Article 82, French Data Protection Act (cookies).

Source: DLA Piper — Facebook Ireland €60 million.


4. Microsoft — €60,000,000 — 22 December 2022 (cookies)

Microsoft’s search engine Bing set advertising cookies without consent and offered an “accept all” button but no equally easy “refuse all” — two clicks were needed to reject. €60 million.

Basis. Article 82, French Data Protection Act (cookies).

Source: CPO Magazine — French regulator hits Microsoft with €60M.


5. Google LLC — €50,000,000 — 21 January 2019 (GDPR)

The CNIL’s landmark — the first multi-million-euro GDPR fine in the EU — for lack of transparency, poor information and no valid consent for ad personalisation during Android setup. Issued before Google had an EU main establishment, so the one-stop-shop did not apply. The Conseil d’État upheld it in full on 19 June 2020, making it final. (Detailed entry in the Big Tech GDPR fines registry.)

Basis. GDPR — transparency and consent for ad personalisation.

Source: EDPB / CNIL — €50 million against Google LLC.


6. Orange — €50,000,000 — 14 November 2024 (mixed)

France’s leading telecoms operator inserted advertisements disguised as emails among real messages in its webmail inboxes, without consent, and kept reading cookies after users had withdrawn consent. Over 7.8 million people had seen the in-inbox ads. €50 million, plus a three-month order at €100,000 per day. Recorded in the CNIL Rapport annuel 2024.

Basis. Direct-marketing rules and Article 82 (cookies).

Source: CNIL — Orange fined €50 million; EDPB mirror.


7. Criteo — €40,000,000 — 22 June 2023 (GDPR)

The Paris-based adtech giant could not prove it had valid consent for the behavioural-advertising data it processed on millions of people, and failed several data-subject-rights duties. The case began with complaints from noyb and Privacy International in 2018. The Conseil d’État later upheld the €40 million fine.

Basis. GDPR — legal basis (consent) and data-subject rights.

Source: EDPB — French SA fined Criteo €40,000,000.


8. Amazon Europe Core — €35,000,000 — 7 December 2020 (cookies)

Part of the same December 2020 decision as the €100M Google cookie fine. amazon.fr set advertising cookies without consent or adequate information. €35 million. The Conseil d’État confirmed the sanction.

Basis. Article 82, French Data Protection Act (cookies).

Source: CNIL — Council of State confirms the 2020 Amazon sanction.


9. Clearview AI — €20,000,000 — 17 October 2022 (GDPR)

For scraping facial images of French residents without a legal basis. This sits in the broader cross-regulator story of how four EU authorities hit the same US firm — full detail in the Clearview AI fines registry.

Basis. GDPR — no legal basis, data-subject rights.

Source: Clearview AI fines registry.


10. Yahoo — €10,000,000 — 29 December 2023 (cookies)

YAHOO EMEA LIMITED was fined €10 million (decision SAN-2023-024): visitors to yahoo.com who clicked to refuse cookies still got at least 20 advertising cookies dropped on their devices, and Yahoo! Mail users could not withdraw consent without losing access to the service.

Basis. Article 82, French Data Protection Act (cookies).

Source: CNIL — Yahoo! fined €10 million.


11. Apple — €8,000,000 — 29 December 2022 (cookies/targeting)

The CNIL fined Apple €8 million (decision SAN-2022-025) over the App Store: the identifier for advertising (IDFA) was read and written on iPhones for targeted advertising without properly collected prior consent — the advertising setting was pre-ticked by default and too buried to count as a real choice.

Basis. Article 82, French Data Protection Act (device identifiers / targeting).

Source: CNIL — Apple Distribution International fined €8 million.


12. TikTok — €5,000,000 — 29 December 2022 (cookies)

On tiktok.com, users could accept cookies with one click but had no equally simple way to refuse them, and the information given was inadequate. €5 million.

Basis. Article 82, French Data Protection Act (cookies).

Source: CNIL — TikTok fined €5 million over cookies.


The Conseil d’État backstop

A recurring fear about big regulators is that the fines are theatre — announced, appealed, quietly cut. The CNIL’s record cuts against that. France’s highest administrative court has upheld the landmark Google €50 million GDPR fine (2020), the Amazon €35 million cookie sanction, and the Criteo €40 million fine. Because the Conseil d’État sits as both first and last instance for CNIL decisions, these confirmations are final. The CNIL’s cookie doctrine — reject must be as easy as accept — has survived judicial review, which is exactly why it now functions as the de-facto EU standard.

What this means if you run a website or product

The CNIL’s fine list is, in practice, a cookie-banner spec:

  • Your “Reject all” must be as prominent and as few clicks as “Accept all.” No buried refusal, no pre-ticked boxes, no “Accept” highlighted while “Refuse” hides in a sub-menu. This single rule produced Google €150 million, Facebook €60 million, Microsoft €60 million and TikTok €5 million.
  • “Refuse” must actually stop the tracking. Yahoo was fined because cookies kept dropping after a refusal, and Orange because tracking continued after consent was withdrawn. The button has to do what it says.
  • You are responsible for consent even when a partner collects it. Criteo was fined €40 million for not verifying that the publishers in its adtech chain had real consent. “Our partner handles consent” is not a defence.
  • Cookies are enforced by the regulator of the country whose users you track — not by your EU headquarters’ regulator. Being established in Ireland or Luxembourg does not move you out of the CNIL’s reach on cookies. If French users load your site, French rules apply directly.

The structural way out is the same one that keeps you off every other regulator’s list: don’t set non-essential trackers before consent, make refusal genuinely one-click, and prefer analytics that don’t drop identifiers at all. A site built that way has nothing for the CNIL’s cookie chamber to find.

Sources for independent verification

Short conclusion

The CNIL is where the EU decides what a lawful cookie banner looks like. Its biggest fines — Google, Facebook, Microsoft, Amazon, Orange, TikTok — are overwhelmingly about cookies under Article 82, a track that escapes the one-stop-shop and lets France police trackers on its own users directly. The doctrine is now settled and court-tested: refusing must be as easy as accepting, and “refuse” must actually stop the tracking. Build to that, and the most active sanctions chamber in Europe has nothing to write up.