What €475M of CNIL cookie fines actually punished — and what your banner audit misses
The two decisions
Google — €325M. Following a 2022 NOYB complaint, the CNIL found that creating a Google account set cookies without valid consent of French users, and that ads inserted between Gmail emails ran without the consent that format requires. The account-creation flow — a consent surface almost nobody audits — was the scene of the violation.
Shein — €150M. The CNIL found advertising cookies were placed on visitors’ devices as soon as they arrived at shein.com — before any action to accept or reject, with a banner that understated its purposes and said nothing useful about third parties. The fine landed on the Irish subsidiary operating the site; being incorporated elsewhere did not move the case out of France, because the devices were French.
These are ePrivacy/cookie-rule enforcements under the CNIL’s action plan running since 2019 — not GDPR one-stop-shop cases. There is no lead-authority shield to stand behind.
What enforcement actually tests
Notice what neither fine involved: a missing banner. Both companies had consent UIs. The violations lived in the mechanics around them:
| What the CNIL tested | Shein | |
|---|---|---|
| Anything set before a choice | account-creation cookies | advertising cookies on arrival |
| Consent for the specific format/purpose | ad-in-inbox format lacked it | banner omitted advertising purposes |
| Third parties disclosed | — | effectively undisclosed |
This maps exactly onto the gap we keep measuring: a consent string is the CMP’s record of a choice, and decoding it tells you nothing about whether tags waited for it. In our crawl data, of 1.95M pages sending a Consent Mode state, 55% reported everything granted — a number that regulators are increasingly in a position to check against what actually fired.
What to do
- Audit firing order on a fresh profile. Load your site with a clean browser, capture the requests (Pixel & Tag Scanner takes a HAR), and list everything that fired before the banner was answered. That list is the Shein exposure.
- Audit the flows nobody looks at — signup, checkout, account creation. Google’s fine came from onboarding, not the homepage.
- Check banner completeness against reality: every purpose actually in use, and the third parties receiving data, named. Reconcile the banner’s claims with the scan results, not with the CMP’s configuration screen.
- Map your exposure by jurisdiction — cookie rules differ from GDPR proper, and Compliance Atlas tracks which regime reaches which audience.
Sources
- CNIL — GOOGLE fined 325 million euros (official English release) — 2025-09-01
- CNIL — SHEIN fined 150 million euros (official English release) — 2025-09-01
- CNIL — cookie action plan continuation (both fines in context) — 2025-09-01
Every claim in this brief traces to a source above or to our own published crawl data. Corrections: contact — applied and dated.
One email a week: what changed across the tracking stack, with the same what/who/action structure.
Weekly. Free. One-click unsubscribe. Opens Substack in a new tab — you won't lose your place here.