Most lists of "biggest GDPR fines" are padded with data breaches, dodgy transfers, and HR mishaps. Useful for trivia night, useless if your actual question is: what does a cookie banner have to do wrong to get fined?
So this is a different kind of list. Every fine below was issued specifically for cookies, trackers, or consent/opt-out mechanics — and for each one, we break down what the banner (or the opt-out flow behind it) actually did wrong. Every amount and date is verified against the regulator's own press release or an authoritative legal source.
Two things will jump out: France's CNIL has turned cookie enforcement into a production line, and since 2022 California has built a parallel track where the magic words aren't "consent" but "opt-out" and "symmetry."
What are the biggest cookie consent fines?
The largest cookie-related fine to date is the CNIL's €325 million sanction against Google (September 1, 2025), followed by €150 million fines against SHEIN (2025) and Google (2021), and €100 million against Google in 2020 — all issued by France's CNIL under ePrivacy cookie rules. In the US, the biggest tracker-related penalties are Disney's $2.75 million CCPA settlement (February 2026) and Healthline's $1.55 million (July 2025).
Here's the full ledger.
The cookie fine ledger
Sorted by amount. EU fines are mostly CNIL decisions under Article 82 of the French Data Protection Act (the ePrivacy cookie rule); US entries are CCPA enforcement by the California Attorney General or the California Privacy Protection Agency (CPPA).
| Company | Regulator | Date | Amount | What went wrong |
|---|---|---|---|---|
| CNIL (FR) | Sep 2025 | €325M | Ads inserted between Gmail emails without consent; ad cookies nudged at account creation | |
| SHEIN | CNIL (FR) | Sep 2025 | €150M | Cookies set before any choice; "Reject all" didn't actually stop tracking |
| CNIL (FR) | Dec 2021* | €150M | 1 click to accept, ~5 to refuse on google.fr and YouTube | |
| CNIL (FR) | Dec 2020 | €100M | Ad cookies placed on google.fr without prior consent | |
| Microsoft (Bing) | CNIL (FR) | Dec 2022 | €60M | Cookies set without consent; refusing took two clicks, accepting one |
| Facebook (Meta) | CNIL (FR) | Dec 2021* | €60M | Refusal flow ended on a button labeled "Accept cookies" |
| Criteo | CNIL (FR) | Jun 2023 | €40M | Couldn't prove users had consented to retargeting cookies |
| Amazon | CNIL (FR) | Dec 2020 | €35M | Ad cookies dropped on arrival at amazon.fr, no consent |
| Yahoo | CNIL (FR) | Dec 2023 | €10M | ~20 ad cookies set despite refusal; withdrawing consent meant losing Yahoo Mail |
| TikTok | CNIL (FR) | Dec 2022* | €5M | Accept button with no equally easy "Refuse all"; vague purpose info |
| Disney | California AG | Feb 2026 | $2.75M | Opt-outs only applied per device/service, not account-wide; GPC handled per device |
| Healthline | California AG | Jul 2025 | $1.55M | Cookies and pixels kept sharing data (incl. health-revealing article titles) after opt-out |
| Tractor Supply | CPPA | Sep 2025 | $1.35M | Opt-out webform didn't stop third-party trackers; GPC signals ignored |
| Sephora | California AG | Aug 2022 | $1.2M | Sold data via third-party trackers without disclosure; ignored GPC signals |
| PlayOn Sports | CPPA | Feb 2026* | $1.1M | Banner had only "Agree" — no way to close or refuse, especially on mobile |
| Honda | CPPA | Mar 2025 | $632.5k | Cookie tool: two steps to opt out, one click to "Allow All" |
| Doctissimo | CNIL (FR) | May 2023 | €380k | €100k of the fine for cookies set without valid consent on a health site |
| IAB Europe | Belgian DPA | Feb 2022 | €250k | The TCF consent framework itself found to breach GDPR |
*The Google/Facebook decisions are dated 31 December 2021, announced 6 January 2022; TikTok's was announced 12 January 2023; PlayOn's order was adopted 27 February 2026, announced in March.
Now the teardowns, grouped by the five patterns regulators keep punishing.
Pattern 1: Cookies fire before (or despite) the user's choice
This is the cardinal sin, and it's behind the two biggest pure cookie fines ever.
SHEIN (€150M, 2025). The CNIL found advertising cookies were placed the moment users landed on shein.com — before any banner interaction. Worse: clicking "Reject all" didn't stop trackers from being set and read. A reject button that doesn't reject is arguably worse than no button at all, because it manufactures evidence of bad faith. The CNIL also weighted the scale: ~12 million French visitors per month.
Yahoo (€10M, 2023). Around twenty advertising cookies were deposited despite users refusing. Second twist: users who tried to withdraw consent were warned they'd lose access to Yahoo Mail. The CNIL called that coercion — consent you can't freely withdraw was never valid.
Google (€100M) and Amazon (€35M), December 2020. The fines that started the CNIL's cookie campaign: ad cookies set automatically on google.fr and amazon.fr with no prior consent and inadequate information.
The lesson: your CMP must actually block tags until consent exists, not just display a banner over the top of tags that already fired. This is exactly what automatic cookie scanning is for — finding the trackers that fire before consent.
Pattern 2: Rejecting is harder than accepting
The CNIL invented the "reject parity" doctrine, and California codified its own version as "symmetry in choice."
Google (€150M) and Facebook (€60M), decisions Dec 2021. One click to accept everything; five clicks (Google) or a click-scroll-click maze ending at a button literally labeled "Accept cookies" (Facebook) to refuse. The CNIL ruled this biases consent and ordered a one-click refusal within three months, on pain of €100,000/day. This pair of fines is why "Reject all" buttons appeared across the European web in 2022.
Microsoft Bing (€60M, Dec 2022) and TikTok (€5M, decision Dec 2022). Same doctrine: one click to accept, two or more to refuse, plus (for TikTok) vague information about what the cookies were for.
Google again (€325M, September 2025). Worth characterizing carefully, because headlines flattened it into "biggest cookie fine ever." It's really two violations: ads disguised as emails inside Gmail's Promotions and Social tabs without consent (an ePrivacy direct-marketing breach), and a cookie flow during Google account creation that nudged users toward accepting personalized ads — accepting was easy, refusing wasn't, and users weren't told the trade-off. So: partly an email-ads fine, partly a consent-asymmetry fine. Either way, €325M and a six-month compliance deadline backed by €100k/day penalties.
Honda ($632,500, March 2025) — the CPPA's first enforcement action. Honda's third-party cookie tool was configured so opting out took two steps (toggle off, then "Confirm My Choices") while opting in took one click on "Allow All." The CPPA called this a failure of "symmetry in choice" and required a "Reject All" button. A cookie tool's configuration, left on defaults, was the violation.
The lesson: count the clicks. If accept-all is one click, reject-all must be one click — in the first layer, same size, same prominence. Our cookie banner UI/UX checklist covers the details.
Pattern 3: The banner with only one button
PlayOn Sports ($1.1M, order adopted Feb 2026). PlayOn's digital ticketing sites for high-school sports showed a cookie banner that couldn't be closed without clicking "Agree" — on mobile, you had to click it just to use your ticket — while its trackers sold and shared data with advertising and analytics partners. The CPPA's first case involving students and schools, and a clean illustration that under the CCPA you don't need consent, but you absolutely need a working way to say no.
Pattern 4: The opt-out that doesn't opt anything out
California's signature pattern. The CCPA doesn't require an EU-style consent banner, but if you sell or share personal info through trackers, the opt-out must work — including Global Privacy Control signals.
Sephora ($1.2M, August 2022). The first public CCPA enforcement: third-party trackers monitoring shoppers amounted to a "sale," which Sephora neither disclosed nor let users opt out of via GPC.
Healthline ($1.55M, July 2025). Even after users opted out, cookies and pixels kept sending data to ad partners — including article titles that could reveal a medical diagnosis.
Tractor Supply ($1.35M, September 2025). A "Do Not Sell" link led to a webform that, when submitted, did not actually stop tracker-based selling and sharing; GPC signals went unprocessed until mid-2024. The CPPA's then-largest fine, triggered by a single consumer complaint.
Disney ($2.75M, February 2026). The largest CCPA settlement at the time: opt-out toggles applied only to one service on one device, the webform didn't cover third-party ad-tech embedded in apps, and GPC was honored per device even for logged-in users. The imposed fix: account-wide, frictionless opt-outs.
The lesson: regulators test. They opt out, then watch the network tab. If pixels keep firing, your opt-out is a decoration. (Pixels and SDKs your blind spot? See do pixels and fingerprinting require consent.)
Pattern 5: No proof, no defense
Criteo (€40M, June 2023). The adtech firm never set cookies via its own banner — its publisher partners collected consent. The CNIL fined it anyway, because Criteo couldn't prove consent existed for the people it was retargeting, and its partner contracts didn't require proof. Upheld by France's highest administrative court. If consent is collected on your behalf, the receipts are still your problem.
IAB Europe (€250k, February 2022). The Belgian DPA found the Transparency & Consent Framework — the consent-string plumbing behind thousands of EU banners — itself breached the GDPR. After a CJEU detour confirming TC Strings can be personal data, the Brussels Market Court upheld the fine in May 2025. Small number, enormous blast radius.
Doctissimo (€380k, May 2023). A health publisher fined under both the GDPR and the cookie rules (€100k for the cookie part) — proof the CNIL doesn't only hunt whales.
How to stay off this list
- Block first, ask second. No non-essential cookie, pixel, or SDK fires until a choice is made. Verify in the network tab, not your CMP's dashboard.
- Make "Reject all" a first-layer, one-click button with the same prominence as "Accept all."
- Test your reject button. Click it, reload, confirm trackers stay silent. SHEIN's €150M says this is not paranoia.
- Honor GPC and make opt-outs propagate to every third-party tag, device, and connected service — and to the ad partners downstream.
- Keep consent receipts. Timestamped logs of who consented to what. Criteo's €40M was for missing paperwork, not missing banners.
- State purposes plainly in the first layer ("advertising," not "enhancing your experience").
- Never bundle consent with access to a service users already paid for (Yahoo, PlayOn).
- Re-audit quarterly. Marketing adds tags; tags drift. Enforcement in 2026 is accelerating on both continents.
Where CookieChimp fits
Every pattern above is a tooling failure before it's a legal one. CookieChimp is a simple yet powerful CMP built around exactly these failure modes: automatic cookie scanning catches tags that fire before consent, banners ship with symmetric Accept/Reject buttons by default, geo-targeting serves opt-in banners in the EU and GPC-respecting opt-out flows in California, and every choice is logged as an auditable consent record. The boring stuff, done correctly — which is precisely what regulators check.
FAQ
What is the biggest cookie consent fine ever issued?
The CNIL's €325 million fine against Google (September 1, 2025) is the largest sanction involving cookie consent, though it also covered ads inserted between Gmail emails. The largest pure cookie-banner fine is SHEIN's €150 million, issued the same day, for setting cookies before and despite users' choices.
Which regulator issues the most cookie fines?
France's CNIL, by a wide margin. It enforces cookie rules under Article 82 of the French Data Protection Act (implementing the ePrivacy Directive), which lets it sanction companies directly without the GDPR's slow cross-border one-stop-shop process. Google, Amazon, Meta, Microsoft, TikTok, Yahoo, Criteo, and SHEIN have all been fined this way.
Can you be fined in the US for a cookie banner?
Yes — not for lacking consent, but for blocking the right to opt out. The CPPA fined Honda $632,500 partly because its cookie tool took two steps to opt out versus one to opt in, and fined PlayOn Sports $1.1 million for a banner that only offered "Agree." The Sephora, Healthline, and Disney settlements all involved trackers that kept selling or sharing data after users opted out.
Do small websites get cookie consent fines?
Enforcement mostly targets large audiences, but not exclusively: Doctissimo took a €100,000 cookie penalty, IAB Europe was fined €250,000, and the CPPA opened its Tractor Supply investigation from a single consumer complaint. CNIL and California sweeps routinely catch mid-size sites; the fines are smaller but the remediation orders are just as binding.
Is a "Reject all" button legally required?
In the EU, effectively yes: the CNIL's Google/Facebook decisions established that refusing cookies must be as easy as accepting them, and €275M+ in follow-on fines (Microsoft, TikTok, and others) cemented it. In California, the CPPA's Honda order requires "symmetry in choice" — if accepting takes one click, declining must too.
What happens after a cookie fine — is paying it the end?
No. CNIL decisions typically include compliance orders with daily penalties (€100,000/day in the Google and Facebook cases) until the banner is fixed. California settlements impose multi-year injunctive terms: opt-out testing, contract overhauls, UX reviews, and regular reports to the regulator.
References
- CNIL, "Cookies placed without consent: SHEIN fined 150 million euros by the CNIL": cnil.fr
- CNIL, "Cookies and advertisements inserted between emails: GOOGLE fined 325 million euros by the CNIL": cnil.fr
- TechCrunch, "France spanks Google $170M, Facebook $68M over cookie consent dark patterns": techcrunch.com
- Hunton, "CNIL Fines Google and Amazon 135 Million Euros for Alleged Cookie Violations": hunton.com
- Infosecurity Magazine, "France Fines Microsoft $64m for Imposing Ad Cookies to its Bing Users": infosecurity-magazine.com
- TechCrunch, "TikTok fined in France for manipulative cookie-consent flow": techcrunch.com
- EDPB, "Personalised advertising: French SA fined CRITEO EUR 40,000,000": edpb.europa.eu
- Gerrish Legal, "CNIL Fines Yahoo! €10 Million for Cookie Breaches": gerrishlegal.com
- EDPB, "Health data and use of cookies: French SA fines DOCTISSIMO": edpb.europa.eu
- Belgian Data Protection Authority, "IAB Europe held responsible for a mechanism that infringes the GDPR": dataprotectionauthority.be
- California Attorney General, "Attorney General Bonta Announces Settlement with Sephora": oag.ca.gov
- California Attorney General, "Attorney General Bonta Announces Largest CCPA Settlement to Date, Secures $1.55 Million from Healthline.com": oag.ca.gov
- California Attorney General, "Attorney General Bonta Announces $2.75 Million Settlement with Disney": oag.ca.gov
- California Privacy Protection Agency, "Honda Settles With CPPA Over Privacy Violations": cppa.ca.gov
- California Privacy Protection Agency, "Tractor Supply decision and announcement": cppa.ca.gov
- CalPrivacy, "Youth Sports Media Company to Pay $1.10 Million Fine, Change Practices Over Privacy Violations": privacy.ca.gov
Don't wait for a regulator to test your reject button for you. Get started with CookieChimp and ship a banner that blocks first, asks second, and keeps the receipts.