webtracking.org
Analysis ConsentCMPePrivacy published 2026-08-16

What €475M of CNIL cookie fines actually punished — and what your banner audit misses

Impact Moderate — worth knowing, act opportunistically
What changedOn September 1, 2025, France's CNIL fined Google €325M (cookies set during account creation without valid consent, plus ads inserted between Gmail emails) and Shein's Irish subsidiary €150M (advertising cookies placed the moment users arrived, before any accept/reject choice). Both companies had consent UIs. The fines were for what happened before and despite them.
Who's affectedAnyone operating a consent banner for EU/French traffic — and specifically whoever owns the gap between what the CMP records and what the tags actually do. If your compliance evidence is 'we deployed a CMP', this is aimed at you.
ActionAudit firing order, not banner presence: capture a fresh-profile page load and verify no advertising cookie or beacon fires before consent. Then check the banner names its purposes and third parties — incompleteness was part of the findings.

The two decisions

Google — €325M. Following a 2022 NOYB complaint, the CNIL found that creating a Google account set cookies without valid consent of French users, and that ads inserted between Gmail emails ran without the consent that format requires. The account-creation flow — a consent surface almost nobody audits — was the scene of the violation.

Shein — €150M. The CNIL found advertising cookies were placed on visitors’ devices as soon as they arrived at shein.com — before any action to accept or reject, with a banner that understated its purposes and said nothing useful about third parties. The fine landed on the Irish subsidiary operating the site; being incorporated elsewhere did not move the case out of France, because the devices were French.

These are ePrivacy/cookie-rule enforcements under the CNIL’s action plan running since 2019 — not GDPR one-stop-shop cases. There is no lead-authority shield to stand behind.

What enforcement actually tests

Notice what neither fine involved: a missing banner. Both companies had consent UIs. The violations lived in the mechanics around them:

What the CNIL testedGoogleShein
Anything set before a choiceaccount-creation cookiesadvertising cookies on arrival
Consent for the specific format/purposead-in-inbox format lacked itbanner omitted advertising purposes
Third parties disclosedeffectively undisclosed

This maps exactly onto the gap we keep measuring: a consent string is the CMP’s record of a choice, and decoding it tells you nothing about whether tags waited for it. In our crawl data, of 1.95M pages sending a Consent Mode state, 55% reported everything granted — a number that regulators are increasingly in a position to check against what actually fired.

What to do

  1. Audit firing order on a fresh profile. Load your site with a clean browser, capture the requests (Pixel & Tag Scanner takes a HAR), and list everything that fired before the banner was answered. That list is the Shein exposure.
  2. Audit the flows nobody looks at — signup, checkout, account creation. Google’s fine came from onboarding, not the homepage.
  3. Check banner completeness against reality: every purpose actually in use, and the third parties receiving data, named. Reconcile the banner’s claims with the scan results, not with the CMP’s configuration screen.
  4. Map your exposure by jurisdiction — cookie rules differ from GDPR proper, and Compliance Atlas tracks which regime reaches which audience.

Sources

Every claim in this brief traces to a source above or to our own published crawl data. Corrections: contact — applied and dated.

The next brief, in your inbox

One email a week: what changed across the tracking stack, with the same what/who/action structure.

Weekly. Free. One-click unsubscribe. Opens Substack in a new tab — you won't lose your place here.