France's data protection regulator, CNIL, fined Google and SHEIN a combined EUR 475 million for cookie and consent violations on 1 September 2025, according to CNIL's own sanction announcements and its 2025 enforcement report, published in February 2026. Those two decisions alone accounted for nearly all of CNIL's EUR 486.84 million in total fines that year, and cookie or tracker complaints drove 21 of its 83 sanctions in 2025.

This is not a one-off spike. CNIL has been the most active cookie regulator in the EU since it launched a dedicated cookie enforcement campaign in 2020, and the case-by-case data below traces exactly which companies got fined, how much, and for which specific banner failure.

CNIL fined Google and SHEIN a combined EUR 475 million for cookies in September 2025 EUR 475M in CNIL cookie fines against Googleand SHEIN, September 2025

How much did CNIL fine companies for cookies in 2025?

CNIL issued two record cookie fines on the same day, 1 September 2025. Google LLC and Google Ireland Limited were fined a combined EUR 325 million (EUR 200 million against Google LLC, EUR 125 million against Google Ireland) after CNIL found that advertising cookies were not consented to properly when users created a Google account, affecting more than 74 million accounts, and that Google displayed promotional emails inside Gmail's "Promotions" and "Social" tabs without consent, reaching about 53 million people. SHEIN's operating entity, Infinite Styles Services Co. Limited, was fined EUR 150 million the same day for placing advertising cookies before visitors interacted with the consent banner at all, for consent interfaces that did not name the third parties receiving cookie data, and for continuing to set cookies even after a user clicked "Refuse all."

Largest CNIL cookie and consent fines, 2020 to 2025 (EUR millions) 0100200300400325Google (2025)150SHEIN (2025)150Google (2021)100Google (2020)40Criteo (2023)35Amazon (2020)

Figure 1: The six largest CNIL cookie and consent fines by amount, 2020 to 2025. Source: CNIL press releases, September 2025 and CNIL's cookie action plan retrospective, June 2023.

Both companies face an additional daily penalty of EUR 100,000 if they do not fix the underlying banner within six months of the decision. CNIL's own 2025 enforcement report, published 9 February 2026, confirms that 21 of its 83 total sanctions that year targeted trackers specifically, a category it defines as "storage without the user's consent, insufficient information of individuals" or "failure to effectively take into account the user's refusal or withdrawal of consent."

CNIL's first cookie fines landed in December 2020, when it fined Google's search engine EUR 100 million and Amazon Europe EUR 35 million for setting advertising cookies without consent. A year later, CNIL added a further EUR 150 million against Google and EUR 60 million against Facebook for making cookie refusal harder than acceptance, the same core defect it would cite again against SHEIN and Google four years later.

Figure 2: Named cookie and consent enforcement decisions, 2020 to 2025. Source: CNIL, Belgian Data Protection Authority.

By its own count, CNIL's dedicated cookie action plan issued 94 orders to comply after 125 site inspections and handed down 8 formal sanctions between 2020 and 2022, worth EUR 421 million combined. Of that total, CNIL names Google (EUR 250 million cumulative), Facebook (EUR 60 million) and Amazon (EUR 35 million); the remaining roughly EUR 76 million spans smaller, unnamed sanctions its own retrospective does not itemize by company.

Adding only the individually named cookie decisions traced in this article, and setting aside that unnamed EUR 76 million balance, produces a running total that more than doubled between 2021 and 2025.

Figure 3: Running total of the individually named CNIL cookie and consent decisions in this article, not an official CNIL aggregate. Source: CNIL press releases, 2020 to 2025.

CNIL is the clearest documented case, but it is not acting alone. A single Belgian data protection authority decision, worth just EUR 250,000, found in February 2022 that IAB Europe's Transparency and Consent Framework, the consent-logging system embedded in most EU cookie banners, itself violated GDPR. Belgium's Market Court largely upheld that finding on appeal in May 2025, confirming both the fine and that the framework's consent record counts as personal data. For the fuller picture of how GDPR penalties compare across every violation type, not just cookies, see our companion post on total GDPR fines since 2018.

Every CNIL decision reviewed for this article traces back to one of the same four defects, applied in sequence.

Figure 4: The four recurring failure points across CNIL's named cookie decisions, 2020 to 2025. Source: CNIL sanction decisions cited in this article.

SHEIN's September 2025 decision hit three of the four points at once: cookies fired before the banner loaded, purposes were left undisclosed, and clicking "Refuse all" did not stop new cookies from being set. TikTok's EUR 5 million fine and the earlier Google and Facebook cases from 2021 centered on the second point, an unbalanced refuse button that took more clicks than accept.

How much of CNIL's total 2025 fine value came from cookies?

CNIL's own 2025 report puts its total sanction value for the year at EUR 486.84 million across 83 decisions covering everything from workplace video surveillance to data-breach failures. The two cookie decisions against Google and SHEIN made up almost the entire figure on their own.

Share of CNIL's 2025 fine total from cookie and tracker cases 47511.8Cookie and tracker cases (2 decisions)475All other 2025 sanctions (81 decisions)11.8EUR 486.8MCNIL total fines, 2025

Figure 5: Share of CNIL's 2025 total fine value from cookie and tracker cases versus every other category combined. Source: CNIL, "Sanctions and Corrective Measures: CNIL's Actions in 2025," 9 February 2026.

That concentration is unusual even for CNIL. In most prior years, its cookie fines sat alongside comparably sized penalties for security failures, data-subject-rights violations, and unlawful video monitoring. 2025 was the year cookies and consent management became, by euro value, almost the entire enforcement story.

CNIL has tracked its own action plan's real-world effect on France's 1,000 most popular websites since 2021, and the direction is measurable. The share of sites dropping 6 or more third-party cookies fell from 24% in January 2021 to 12% by August 2022, while the share dropping no third-party cookies at all rose from 20% to 29% over the same window. A June 2022 CNIL survey of French internet users found 95% understood what a cookie was and 52% were aware of the rule changes, up from 44% in November 2020, with 39% choosing to refuse cookies and 59% accepting when shown a compliant banner. Our companion post on cookie consent acceptance and refusal rates breaks that survey data down further.

Fewer sites are hoarding third-party cookies, but the 2025 fine total shows regulators still find plenty to penalize even at companies with dedicated compliance teams. The practical fix regulators keep pointing to is the same across every decision in this article: a banner that discloses each cookie's purpose, treats refuse and accept as equally easy, and stops setting new cookies when a user withdraws consent. A privacy policy generator built for GDPR and ePrivacy disclosures keeps that purpose language current alongside the rest of a site's data practices, which is the second most common defect CNIL cites after the refuse-button asymmetry.

CaseFineDateCore violation
Google + SHEIN, combinedEUR 475 million1 Sept 2025Two separate decisions on the same day
Google (LLC + Ireland)EUR 325 million1 Sept 2025Cookies without informed consent; ads shown without consent in Gmail
SHEIN (Infinite Styles Services)EUR 150 million1 Sept 2025Cookies set pre-banner; refusal did not stop new cookies
Google (google.fr)EUR 150 million31 Dec 2021Refusing cookies harder than accepting
FacebookEUR 60 million31 Dec 2021Refusing cookies harder than accepting
Google (google.fr)EUR 100 million10 Dec 2020Advertising cookies set without consent
CriteoEUR 40 million15 June 2023Retargeting cookies without valid consent
Amazon EuropeEUR 35 million7 Dec 2020Advertising cookies set without consent
TikTok (UK and Ireland)EUR 5 million12 Jan 2023Refusing cookies harder than accepting

Source: CNIL sanction announcements, 2020 to 2025.

The Bottom Line

CNIL's EUR 475 million in cookie fines against Google and SHEIN in a single day is not an outlier decision, it is the current peak of a five-year enforcement pattern that started with EUR 135 million against Google and Amazon in December 2020. The average GDPR fine across every violation category leveled off around EUR 2.28 million per case in 2026, but cookie and consent decisions against large platforms keep landing far above that average because the same four defects, pre-banner cookie drops, unbalanced refuse buttons, undisclosed purposes, and ignored withdrawals, keep showing up at companies with real compliance budgets. This article is one entry in a broader look at what specific GDPR violations cost: companion breakdowns of fines tied to data-breach failures and to marketing-email violations round out the picture of which mistakes are the most expensive. For any site running cookies or a consent banner, the fix pattern in every decision above is the same one: disclose the purpose, make refusal as easy as acceptance, and honor it when a visitor withdraws.

Frequently Asked Questions

How much has CNIL fined companies for cookies in 2025? EUR 475 million combined, from two decisions on 1 September 2025: EUR 325 million against Google (Google LLC and Google Ireland Limited) and EUR 150 million against SHEIN (Infinite Styles Services), according to CNIL's own press releases. Those two cases made up about 98% of CNIL's EUR 486.84 million total sanction value for the year.

What is the largest fine issued specifically for cookie violations? The EUR 325 million fine CNIL issued against Google on 1 September 2025 is the largest cookie-and-consent-specific penalty on record, ahead of SHEIN's EUR 150 million fine the same day and Google's own earlier EUR 150 million cookie fine from December 2021. It is smaller than GDPR's overall record fine, the EUR 1.2 billion penalty against Meta in 2023, which concerned international data transfers rather than cookies.

What triggers a cookie-consent fine? Four failures recur across the CNIL decisions reviewed for this article: cookies placed before a user interacts with the banner at all, a refuse option that takes more clicks than accept, unclear disclosure of each cookie's purpose, and a refusal or withdrawal that does not stop new cookies from loading, the exact violation CNIL cited against both SHEIN and Google in September 2025.

Has cookie-banner compliance improved since regulators started fining companies? Yes, measurably. Among France's 1,000 most-visited websites, the share dropping 6 or more third-party cookies fell from 24% in January 2021 to 12% by August 2022, and the share dropping no third-party cookies at all rose from 20% to 29% over the same period, according to CNIL's own compliance monitoring.

Where the Numbers Come From

  1. CNIL. (2025). "Cookies and Advertisements Inserted Between Emails: Google Fined EUR325 Million by CNIL." EUR 200 million against Google LLC and EUR 125 million against Google Ireland Limited, decision dated 1 September 2025.
  2. CNIL. (2025). "Cookies Placed Without Consent: SHEIN Fined EUR150 Million by CNIL." Decision against Infinite Styles Services Co. Limited, dated 1 September 2025.
  3. CNIL. (2026). "Sanctions and Corrective Measures: CNIL's Actions in 2025." 83 total decisions, EUR 486,839,500 cumulative fines, 21 sanctions for tracker-related breaches, published 9 February 2026.
  4. CNIL. (2023). "Evolution of Web Practices Regarding Cookies: CNIL Evaluates the Impact of Its Action Plan." 8 sanctions worth EUR 421 million from 2020 to 2022, including Google (EUR 250 million), Facebook (EUR 60 million) and Amazon (EUR 35 million); website compliance and user-survey figures. Published 21 June 2023.
  5. Belgian Data Protection Authority. "The Market Court Rules in the IAB Europe Case." Original decision 21/2022 (2 February 2022) fined IAB Europe EUR 250,000 over its Transparency and Consent Framework; Market Court largely upheld the finding and confirmed the fine on 14 May 2025.
  6. CNIL. TikTok cookie sanction, EUR 5 million, decision dated 29 December 2022, announced 12 January 2023. Note: CNIL removes company-identifying details from sanction pages after a set publication period, so this page's original text is no longer live; the figure is corroborated by contemporaneous press coverage of the decision.
  7. DataGuidance. "France: CNIL Fines Criteo EUR40m for Unlawful Processing, Conseil d'État Upholds." Original CNIL decision issued 15 June 2023 over retargeting-cookie consent failures, upheld on appeal.
  8. CMS Law. (2026). "GDPR Enforcement Tracker Report 2025/2026, Numbers and Figures." Cited for the EUR 2.28 million average GDPR fine across all violation categories, used as a comparison baseline.

Note: All figures verified as of July 2026. CNIL's 2025 sanction totals were published 9 February 2026 and cover decisions through the end of 2025; this article's cumulative cookie-fine running total will be refreshed at least twice a year as new CNIL decisions are published.