When does consent have to happen? Does a pre-ticked box count? Does Reject have to work? Courts and regulators in the EU and the US have been answering them for cookie banners and tracking pixels, case by case.
Key Takeaways
- 01In the EU, cookie consent must be an active choice. The EU's top court held in Planet49 (2019) that a pre-ticked box is not consent, and Germany's Federal Court of Justice applied it in 2020.
- 02France's CNIL has fined companies where refusing cookies was harder than accepting them, or where cookies kept coming after Refuse all. In September 2025 it fined SHEIN €150 million and Google €325 million, a fine that also covered ads shown in Gmail.
- 03US tracking cases run through wiretap, privacy and video laws. In an unpublished 2022 ruling, the Ninth Circuit predicted that California's wiretap law requires all parties' consent before recording, and in 2025 juries returned verdicts against Meta (Flo Health app) and Google (Web & App Activity).
- 04California's SB 690, signed September 30, 2026, takes effect January 1, 2027. From then, only the Attorney General may bring section 638.51 pen-register or trap-and-trace claims against private actors over website or app conduct. Section 631 and 632 claims and the $5,000-per-violation remedy remain.
- 05Under a strict standard, our EU test observed a request to a third-party tracker before any consent choice on 829 of 912 sites running one of four consent tools, drawn from our sales-lead lists (91%, July 2026).
Here is the short answer, then the long one.
The short answer: in the EU, the top court settled in 2019 that cookie consent has to be an active choice, and France's regulator has since fined companies where refusing was harder than accepting or where cookies kept arriving after a refusal. In the US, the cases run through wiretap, privacy and video laws, and big questions are still open: the flagship healthcare pixel case had no class-certification ruling on the public docket as of October 2, 2026, and the Supreme Court is set to hear argument in a video-privacy case on October 14, 2026.
A record of what courts and regulators decided, built from their own documents. It is not legal advice. Allegations are described as allegations and settlements as settlements. A ruling on a motion to dismiss accepts the complaint's allegations as true, so it is not a finding of fact.
EU: the court rulings that define consent
| Case | Court and date | What it decided |
|---|---|---|
| Fashion ID (C-40/17) | Court of Justice of the EU, July 29, 2019 | A site that embeds a social plugin (here, Facebook's Like button) can be a joint controller for collecting and sending visitors' data to the provider, and must obtain any consent needed for that. |
| Planet49 (C-673/17) | Court of Justice of the EU, October 1, 2019 | A pre-ticked checkbox the user must untick is not valid consent to cookies, whether or not the data is personal. Users must be told how long cookies last and whether third parties can access them. |
| Cookie-Einwilligung II (I ZR 7/16) | German Federal Court of Justice, May 28, 2020 | Cookies used to build profiles for advertising or market research need consent, and a pre-ticked checkbox does not give it. |
| IAB Europe (C-604/22) | Court of Justice of the EU, March 7, 2024 | The TC String, which records a user's consent choices in the IAB's framework, is personal data when it can reasonably be linked to an identifier such as an IP address. |
[Planet49](https://publications.europa.eu/resource/celex/62017CJ0673) began with a 2013 online lottery whose second checkbox arrived already ticked: "I agree to the web analytics service Remintrex being used for me" (in translation). Germany's federation of consumer organizations sued. Germany's Federal Court of Justice referred it to the EU's top court, then decided it in May 2020: no fine, but an injunction and the consumer group's warning costs. Under EU law, a box that arrives ticked is not consent.
[Fashion ID](https://publications.europa.eu/resource/celex/62017CJ0040), decided under the 1995 Data Protection Directive, means a site that embeds another company's plugin can share responsibility for the data that plugin collects and sends.
[IAB Europe](https://publications.europa.eu/resource/celex/62022CJ0604) went back to Belgium, where on May 14, 2025 the Brussels Market Court confirmed the regulator's €250,000 fine.
France: the CNIL on refusing as easily as accepting
The CNIL is France's data protection regulator. Its sanctions can be challenged in court.
| Decided | Organization | Amount | What the CNIL found |
|---|---|---|---|
| December 7, 2020 | Google LLC and Google Ireland | €100 million | Seven cookies, four for advertising, were placed as soon as a visitor reached google.fr, and the banner did not explain their purposes or how to refuse them (Article 82 of the French Data Protection Act), as recounted by the Conseil d'État, which rejected the companies' challenge on January 28, 2022. |
| December 31, 2021 | Two companies, pseudonymized in the published decision | €150 million | Its rapporteur counted one click to accept and at least five actions to refuse; the CNIL held refusing was not as simple as accepting. It ordered a refusal option of equivalent simplicity within three months, then €100,000 for each day of delay. |
| September 1, 2025 | Google LLC and Google Ireland | €325 million | Two breaches: ads shown between Gmail emails, and cookies at account creation, where until October 2023 "it was more difficult to refuse cookies linked to personalised advertising than to accept them". |
| September 1, 2025 | Infinite Styles Services Co. Limited (SHEIN group) | €150 million | Advertising cookies were placed "even before they interacted with the information banner". After "Refuse all", "new cookies were still placed and others, already present, continued to be read". |
Sources: the Conseil d'État decision (No. 449209) and the CNIL's releases on Google and SHEIN, as published by the CNIL on September 3, 2025. The published 2021 decision has since been pseudonymized; the 2025 Google release says they "had previously been sanctioned by the CNIL on two occasions, in 2020 and 2021, for breaches relating to cookies."
Beyond the headline fines, the CNIL's 2024 review says "11 organizations were penalized for not allowing users to refuse cookies as easily as to accept them." Across these decisions, the CNIL looked at three things: whether Refuse was as easy as Accept, whether cookies arrived before any choice, and whether a refusal actually stopped them.
US regulators: settlements over privacy choices
| Matter | Date | Amount | What the regulator alleged | Posture |
|---|---|---|---|---|
| United States v. Google (FTC, Safari) | Announced August 9, 2012 | $22.5 million | Google placed a DoubleClick ad cookie on Safari users' computers, in many cases by getting around Safari's default third-party cookie block, after saying that default "effectively accomplishes the same thing as" opting out. | Court-approved settlement; Google denied liability |
| People v. Sephora (California AG) | August 24, 2022 | $1.2 million | Opt-outs sent through the Global Privacy Control (GPC) were not processed. | Stipulated judgment, no admission |
| In re American Honda (California Privacy Protection Agency) | Announced March 12, 2025 | $632,500 | Ad cookies were on by default. Opting out took two steps; opting back in took one ("Allow All"). | Stipulated order; Honda admits only background facts, not liability |
| People v. Healthline Media (California AG) | Announced July 1, 2025 | $1.55 million | Opt-outs, including GPC, were not honored, and a "consent banner" did not disable tracking cookies when a box was unchecked. | Stipulated judgment, no admission |
Sources: FTC and the court order; Sephora; Honda; Healthline.
Safari is not a banner case: it is where a choice the user had already made, the browser's default block, was alleged to have been overridden. The Honda order speaks to button design directly. A banner offering only "Accept All" and "More Information" or "Preferences" "is not equal or symmetrical," it says. "An equal or symmetrical choice, by contrast, could be between 'Accept All' and 'Decline All.'"
US courts: wiretap and pen-register claims
The Assurance IQ case (Ninth Circuit No. 21-16351, May 31, 2022). A visitor to an insurance-quote site sued under section 631 of the California Invasion of Privacy Act (CIPA), the wiretap section, over a session-recording tool. The Ninth Circuit reversed the dismissal. In an unpublished memorandum, which is not binding precedent, it predicted California would require the prior consent of all parties, so agreeing to a privacy policy after the recording did not defeat the claim at the pleading stage.
Back in the district court, the claim was dismissed as time-barred under CIPA's one-year limitations period, and in June 2023 without leave to amend: the court held the privacy policy had given constructive notice that third-party vendors may monitor site activity, so the claim came too late.
The Kochava ruling (S.D. Cal. No. 22-cv-01327, July 27, 2023). At the motion-to-dismiss stage, the court held that CIPA's pen-register section (638.51) can cover software: "Surely among them is software that identifies consumers, gathers data, and correlates that data through unique 'fingerprinting.'" The allegations concerned a software kit in mobile apps. On whether the statute applies online, the California Assembly's privacy committee later wrote: "Federal courts almost uniformly conclude that it does; state courts mostly conclude the opposite."
Governor Newsom signed SB 690 on September 30, 2026 (Chapter 976, Statutes of 2026). From January 1, 2027, only the Attorney General may bring an action under CIPA's remedy section (637.2) against a private actor for a pen-register or trap-and-trace violation (638.51) alleged to arise from conduct on a website or app. It does not change section 631 or section 632, or the $5,000-per-violation remedy for them. The amendments "apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation."
Sources: the chaptered text and the Governor's signing message, which says "additional work in this area is needed." Our CIPA page covers the statute.
The Converse chat case (Ninth Circuit No. 24-4797, July 9, 2025, unpublished). The claim was that Converse aided a wiretap by Salesforce, which helped run the site's chat. The court affirmed summary judgment for Converse: there was no evidence Salesforce read or tried to read the chats, and evidence that it "could read messages" was not enough.
The Shopify jurisdiction case (Ninth Circuit en banc, No. 22-15815, April 21, 2025). An 11-judge en banc panel held that Shopify was subject to jurisdiction in California. Shopify conceded its geolocation technology let it know the device was in California when it installed cookies, and the complaint alleged it compiled and sold consumer profiles. For an out-of-state company, the ruling turned on what it knew about where the device was.
Healthcare: the hospital-portal pixel case
In re Meta Pixel Healthcare Litigation (N.D. Cal. No. 3:22-cv-03580). Patients allege that the Meta Pixel on hospital patient portals sent Meta health-related information. Meta is the defendant; the hospitals are not defendants. In September 2023 the court granted Meta's motion to dismiss in part and denied it in part, and the federal wiretap, CIPA, contract and unjust-enrichment claims went forward. Class certification was argued on June 12, 2026 ("Written order will follow"), and on July 7, 2026 the court vacated the pretrial conference and jury trial "in light of the time needed for that opinion." The public docket mirror showed no class-certification order as of October 2, 2026.
In another case, a ruling made on the evidence went for the defendant. In the Eating Recovery Center ruling (No. 3:23-cv-05561), the court granted the defendant summary judgment on a Meta Pixel CIPA claim on October 17, 2025, because "the evidence is undisputed that Meta did not read, attempt to read, or attempt to learn the contents" in transit. It added: "The language of CIPA is a total mess." Judgment was entered for the defendant on October 21, 2025. The plaintiff moved to alter it in November 2025, and we found no ruling on that motion.
Two jury verdicts
The Flo Health app case (N.D. Cal. No. 3:21-cv-00757). On August 1, 2025, a jury found that Meta intentionally eavesdropped on or recorded the plaintiffs' communications without the consent of all parties, under CIPA section 632. The case concerned data from a period-tracking app sent through Meta's software kit, not a website pixel. The court denied Meta's post-trial motions in September 2025. No judgment had been entered as of September 30, 2026, and Meta's own SEC filing says the amount of potential damages "is uncertain at this time."
The Google Web & App Activity case (N.D. Cal. No. 3:20-cv-04688). On September 3, 2025, a jury awarded $425,651,947 in compensatory damages for invasion of privacy and intrusion upon seclusion, over app-activity data Google collected from users who had turned off a Web & App Activity setting in their Google accounts (order). Final judgment was entered March 2, 2026, and Google filed a notice of appeal on September 21, 2026.
Video sites: the VPPA split goes to the Supreme Court
Under the federal Video Privacy Protection Act, appeals courts have split over who counts as a "consumer".
| Court | Case | Date | Outcome |
|---|---|---|---|
| 2nd Circuit | The NBA newsletter case, No. 23-1147 | October 15, 2024 | Broad: a free-newsletter signup, given in exchange for personal information, plausibly made the plaintiff a subscriber. |
| 7th Circuit | The Me-TV case, No. 24-1290 | March 28, 2025 | Broad: furnishing valuable data in exchange for benefits makes someone a consumer of a video tape service provider. |
| 6th Circuit | The Paramount Global (247Sports) case, No. 23-5748 | April 3, 2025 | Narrow: the goods or services must be audiovisual. |
| Supreme Court | NBA petition, No. 24-994 | December 8, 2025 | Review denied. |
| Supreme Court | Paramount Global (247Sports), No. 25-459 | Review granted January 26, 2026 | Argument set for October 14, 2026. |
Sources: 2nd Circuit, 7th Circuit, 6th Circuit, Supreme Court docket. The Court agreed to decide which reading of "consumer" is right, in a case where the complaint alleges viewing history was shared with Facebook through its Pixel.
What our scans show about timing
Several rulings above turn on timing: whether consent came before collection. Our scanner asks a narrower, behavioral question on real sites, and it applies no court's or regulator's test. Was a request to a third-party tracker that the scanner classes as needing consent observed before the visitor made any choice?
The standard is strict: a Google Consent Mode "denied" ping without cookies counts, because the request still carries the visitor's IP address.
| Cohort | Scanned | Result |
|---|---|---|
| 912 sites running one of four widely used consent tools, from our sales-lead lists (not a random sample) | July 19 to 20, 2026 | 829 of 912 (91%), the tool's own script excluded |
| 229 sites whose owners ran our free scanner | June 21 to July 14, 2026 | 179 to 189 of 229 (78% to 83%), depending on the counting method |
| 146 of the web's most-visited sites (Tranco list) | July 16, 2026 | 110 of 146 (75%) |
Methods: the consent-tool census and the state of cookie compliance study. A separate Reject All study counted "ghostwritten" tracking cookies: stored under the site's own domain, with a third-party script host in the write stack. Of 6,964 such cookie observations on 791 sites (scanned May 5 to July 30, 2026), all with a Reject option the scanner could click, 3,023 (43.4%) were still in the browser after Reject All, and 97.5% of those survivors existed before the visitor answered the banner. The unit there is cookies, not sites.
How to read these numbers. Every figure above comes from the scanner's EU test: a fresh browser in Frankfurt, Germany, visiting each site for the first time. None comes from the scanner's US visit. It records where each request went and when, not what it contained or why. It cannot see data a site's own servers send to another company (Meta's Conversions API, for example), and it does not count requests to the site's own domain. It does not send a Global Privacy Control signal, so GPC honoring and US opt-out flows are not measured.
These are behavioral measurements. They do not say that any site broke a law or could be sued.
Frequently Asked Questions
On October 1, 2019, the Court of Justice of the EU held (C-673/17) that a pre-ticked checkbox is not valid consent to cookies, whether or not the data is personal, and that users must be told how long cookies last and whether third parties can access them.
Yes, mostly under wiretap, privacy and video laws. In the Meta Pixel healthcare case, a federal court let wiretap and CIPA claims against Meta go forward in 2023, accepting the allegations as true. In 2025 another federal court granted the defendant summary judgment on a Meta Pixel CIPA claim (Eating Recovery Center), and juries returned verdicts against Meta over a period-tracking app (Flo Health) and against Google over app-activity data.
In France, the CNIL has fined companies on that ground. Its 2024 review says "11 organizations were penalized for not allowing users to refuse cookies as easily as to accept them." In California, the privacy agency's Honda order, applying the state's CCPA regulations, says a banner offering only "Accept All" and "More Information" (or "Preferences") "is not equal or symmetrical."
SB 690 takes effect January 1, 2027. From then, only the Attorney General may bring a section 638.51 pen-register or trap-and-trace action against a private actor over website or app conduct. It does not change section 631 or section 632, or the $5,000-per-violation remedy for them.
See what your own site sends
See what your site sends before anyone clicks
The free ConsentStack compliance scanner loads your site in a real browser and shows which third-party requests it observed before a consent choice and after Reject. Full compliance, no compromise.