This post lists the cookie, tracker and pixel fines we could find from January 2024 to October 1, 2026, taken from regulators' own decisions, sanctions lists and press releases, and from court records.
Key Takeaways
- 01Two CNIL decisions on September 1, 2025, Google (EUR 325 million) and SHEIN (EUR 150 million), make up EUR 475 million of the roughly EUR 482 million in 2025 CNIL sanctions that included a tracker breach.
- 02Elsewhere in Europe cookie fines are mostly small. All but two of Spain's 21 came to EUR 1,000 to EUR 12,000, and Romania's 13 total RON 237,000.
- 03Italy's Garante, the UK's ICO and the German authorities whose reports we read issued no cookie fine we could find. They used warnings, letters and orders.
- 04In the 72 fines we itemized, the most common findings are trackers before any choice (34), missing or misleading information (27) and tracking after Reject or withdrawal (21), mostly in Europe. Every California penalty concerns how opt-outs worked, including GPC.
- 05Our scanner measures behavior, not legality. Under a strict standard, our July 2026 EU test observed a tracker request before any choice on 829 of 912 consent-tool sites from our sales-lead lists. It does not measure the US failure types.
We found at least 95 fines, penalties and settlements from 13 regulators. That is a floor, not a census.
The short answer: most of the money is in France
In 2025 the CNIL issued 21 sanctions that included a tracker breach, worth about EUR 482 million. Two decisions of September 1, 2025 make up EUR 475 million of it: Google (EUR 325 million) and SHEIN (EUR 150 million).
Outside France, most cookie fines are small. All but two of the 21 Spanish fines we could read came to EUR 1,000 to EUR 12,000. Romania's 13 total RON 237,000, and Croatia's six total EUR 85,500.
In the US, most penalties came from California: five worth USD 4,407,678 in 2025, and three more in 2026, the largest USD 2.75 million from Disney. The FTC's two 2024 health-data orders were mostly refunds or suspended penalties, and Connecticut added one pixel settlement.
What regulators fined for
Grouped by what went wrong (one decision often names several):
- Trackers before any choice. The CNIL found SHEIN placed advertising cookies "as soon as they arrived on the site, even before they interacted with the information banner". Twelve of Romania's 13 fines are for this.
- Tracking after Reject or withdrawal. The CNIL found that at Orange, cookies "continued to be read" after users withdrew consent, and that American Express placed advertising cookies "despite their expressed refusal".
- Refusing harder than accepting, or impossible. The CNIL found that at Google account creation, until October 2023, "it was more difficult to refuse cookies linked to personalised advertising than to accept them".
- Pre-ticked boxes and assumed consent. The two Dutch fines, on Kruidvat's operator and Coolblue.
- Consent-or-pay. Four Spanish resolutions tie refusing to paying.
- Missing or misleading information. For example, cookies presented as "strictly necessary" on vanityfair.fr without useful information (CNIL).
- US opt-outs and GPC. The CPPA alleged that opting out at Honda took two steps and opting back in took one. All five GPC cases are Californian.
Named actions, January 2024 to October 2026
| Date | Regulator | Organization, as named | Amount | Main finding |
|---|---|---|---|---|
| Feb 13, 2024 | AEPD (ES) | LA VANGUARDIA EDICIONES, S.L. | EUR 10,000 proposed, 8,000 paid | Before consent; kept after refusal |
| Feb 22, 2024 | AEPD (ES) | PRENSA IBÉRICA MEDIA, S.L. | EUR 5,000 proposed, 4,000 paid | Before consent; after Reject All |
| Mar 22, 2024 | AEPD (ES) | NH HOTEL GROUP S.A. | EUR 10,000 proposed, 8,000 paid | Accept-only; before consent; refusal ineffective |
| Apr 11, 2024 (ann.) | FTC | Monument, Inc. | USD 2,500,000 penalty, suspended | Alleged: pixels sent health events |
| Apr 15, 2024 (ann.) | FTC | Cerebral, Inc. | Over USD 7 million, mostly cancellation refunds | Alleged: trackers sent health data |
| May 3, 2024 | AP (NL) | AS Watson (Health & Beauty Continental Europe) B.V. (Kruidvat) | EUR 600,000, cut to 50,000 | Pre-ticked; refusing took many steps |
| Jun 25, 2024 | IMY (SE) | Avanza Bank AB | SEK 15,000,000 | Pixel sent account and ID numbers |
| Aug 29, 2024 | IMY (SE) | Apoteket AB | SEK 37,000,000 | Pixel sent sensitive purchase data |
| Aug 29, 2024 | IMY (SE) | Apohem AB | SEK 8,000,000 | Same; on appeal |
| Oct 8, 2024 | AEPD (ES) | SEAT, S.A. | EUR 20,000 proposed, 12,000 paid | Tracking after consent revoked |
| Nov 14, 2024 | CNIL (FR) | ORANGE SA | EUR 50,000,000 | Read after withdrawal; email ads |
| Dec 24, 2024 (ann.) | AP (NL) | Coolblue | EUR 40,000 | Consent assumed; pre-checked |
| Mar 7, 2025 | CPPA | American Honda Motor Co., Inc. | USD 632,500 | Alleged: opt-out harder than opt-in |
| Apr 29, 2025 (pub.) | IMY (SE) | Diskrimineringsombudsmannen | SEK 100,000 | Web-form data reached analytics |
| May 1, 2025 | CPPA | Todd Snyder, Inc. | USD 345,178 | Alleged: banner vanished; GPC |
| Jun 10, 2025 | Datatilsynet (NO) | Kristiansand kommune | NOK 250,000 | Pixels on a children's helpline |
| Jul 1, 2025 (ann.) | California AG | Healthline Media LLC | USD 1,550,000 | Alleged: tracking after opt-out; GPC |
| Jul 3, 2025 | AEPD (ES) | WALLAPOP, S.L. | EUR 5,000 proposed, 3,000 paid | Reject All had no effect |
| Sep 1, 2025 | CNIL (FR) | GOOGLE LLC; GOOGLE IRELAND LIMITED | EUR 325,000,000 | Harder to refuse; Gmail ads |
| Sep 1, 2025 | CNIL (FR) | INFINITE STYLES SERVICES CO. LIMITED (SHEIN) | EUR 150,000,000 | Before consent; after Refuse all |
| Sep 26, 2025 | CPPA | Tractor Supply Company | USD 1,350,000 | Alleged: opt-out form did not stop trackers; GPC |
| Oct 30, 2025 (ann.) | California AG | Sling TV L.L.C.; Dish Media Sales L.L.C. | USD 530,000 | Alleged: cookie settings did not opt out |
| Nov 20, 2025 | CNIL (FR) | LES PUBLICATIONS CONDE NAST | EUR 750,000 | Before consent; after refusal |
| Nov 27, 2025 | CNIL (FR) | AMERICAN EXPRESS CARTE FRANCE | EUR 1,500,000 | Before consent; despite refusal |
| Feb 11, 2026 (ann.) | California AG | Disney DTC, LLC; ABC Enterprises, Inc. | USD 2,750,000 | Alleged: opt-outs per device; GPC |
| Feb 27, 2026 | CPPA | Ford Motor Company | USD 375,703 | Alleged: email check before opt-out |
| Feb 27, 2026 | CPPA | 2080 Media, Inc. d/b/a PlayOn Sports | USD 1,100,000 | Alleged: forced "agree"; GPC |
| Mar 24, 2026 | AEPD (ES) | CONECTA5 TELECINCO, S.A.U. | EUR 5,000 imposed | Before consent; consent-or-pay |
| Aug 19, 2026 (ann.) | Connecticut AG | TaxAct | USD 275,000 | AG: tracking sent tax details |
Dates are decision or order dates, except "ann." (announced) and "pub." (published). AEPD dates are the latest dated step in the resolution, usually payment. Spanish amounts show the proposed fine, then the amount paid after early-payment reductions or, without early payment, the fine imposed; in early-payment cases the finding is what the AEPD recorded on opening the case. The US matters are settlements, so their facts are allegations (Honda and PlayOn admitted only background facts, not liability), and the TaxAct findings are the Connecticut AG's. We count, but do not name, the small businesses and individuals some regulators name.
Sources: CNIL on Orange, Google, SHEIN, Condé Nast and American Express; AEPD on La Vanguardia, Prensa Ibérica, NH Hotel Group, Wallapop and Conecta5 Telecinco (SEAT is PS/00284/2024); the AP on Kruidvat, its objection decision and Coolblue; IMY's decision pages on imy.se; Datatilsynet's pixel inspection; CPPA orders for Honda, Todd Snyder, Tractor Supply, Ford and PlayOn; the California AG on Healthline, Sling TV and Disney; the FTC on Monument and Cerebral; the Connecticut AG on TaxAct.
Totals by regulator and year
| Regulator | 2024 | 2025 | 2026 (to Oct 1) |
|---|---|---|---|
| CNIL (France) | 12 decisions, EUR 50,133,000 | 21 decisions, EUR 482,191,000 | 1 listed, EUR 15,000 (list ends April 2) |
| AEPD (Spain) | 12 or 13, EUR 160,600 to 162,600 paid or imposed | 6, EUR 84,200 paid or imposed | 2, EUR 8,000 paid or imposed |
| ANSPDCP (Romania) | 2, RON 20,000 | 9, RON 182,000 | 2, RON 35,000 |
| AZOP (Croatia) | 6, EUR 85,500 | none | none |
| AP (Netherlands) | 2, EUR 640,000 as imposed | none new (one cut to EUR 50,000) | none found |
| IMY (Sweden) | 3, SEK 60,000,000 | 1, SEK 100,000 | none found |
| Datatilsynet (Norway) | none | 1, NOK 250,000 | none found |
| DSB (Austria) | none | 1, EUR 6,200 (a second, EUR 11,500, was annulled) | none new |
| NAIH (Hungary) | none found | none found | 3 fines for missing information, HUF 27,000,000 |
| CPPA (California) | none | 3, USD 2,327,678 | 2, USD 1,475,703 |
| California AG | none in scope | 2, USD 2,080,000 | 1, USD 2,750,000 |
| Connecticut AG | none | none | 1, USD 275,000 |
| FTC | 2 proposed health-data orders | none | none (one complaint filed) |
The CNIL 2025 figure is our sum of the 21 tracker sanctions on its sanctions list. Several also covered other breaches, so read it as decisions that included a cookie breach. The CNIL's own 2025 total, all topics, was EUR 486,839,500, and its July 6, 2026 note implies at least one more 2026 cookie case than the list shows. One Spanish 2024 resolution may date from late 2023, and the Spanish 2025 figure includes EUR 50,000 (proposed) that was not for cookies.
Others acted without fining. The ICO says 979 of the UK's top 1,000 sites passed its cookie checks by December 2025, after 564 improved their practices following letters and, in 17 cases, preliminary enforcement notices. The Dutch AP warned more than 200 sites by November 2025. Hamburg's authority wrote to 185 of 1,000 sites it found accessing devices on first load without consent, and no German report we read records a cookie fine. New York's attorney general found 13 high-traffic sites whose privacy controls "did not work as described" (guide). We found 18 cookie warnings from Italy's Garante (one example), and no fines.
Healthcare and pixel-data cases
Several of the larger amounts outside France are about what a pixel carried, not when it fired.
- IMY fined Apoteket and Apohem for inadequate security measures (GDPR Article 32) after sensitive purchase data, including self-tests and treatment for sexually transmitted infections, and sex toys, reached Meta through the Meta Pixel.
- Datatilsynet fined Kristiansand kommune because pixels on a helpline site for children at risk sent visitor data to third parties without legal basis or information.
- The FTC alleged that Monument, an alcohol-addiction treatment company, sent events such as "Paid: Weekly Therapy" to Meta and Google, and that Cerebral, a telehealth company, passed data on nearly 3.2 million consumers to LinkedIn, Snapchat, TikTok and others.
- Not a fine: on July 29, 2026 the FTC, Utah and California sued Hims & Hers. The complaint, as filed on August 18, alleges that registration and purchase events carrying identifiers and treatment details reached Meta through the Meta Pixel and Conversions API about 8 million times. The case is pending.
Fines changed on appeal
- The Dutch AP cut Kruidvat's fine from EUR 600,000 to EUR 50,000 on objection (May 27, 2025). It kept its finding and gave four reasons for the cut: the long procedure, the company's acknowledgment of the infringement, "de geringe ernst van de overtreding" (the low seriousness of the infringement) and a comparable case.
- Austria's Federal Administrative Court annulled a EUR 11,500 fine on May 1, 2026. Google Analytics cookies had been set before any choice for 13 days after the consent tool's auto-blocking script was misconfigured; the fix came within the compliance period of an earlier order.
- Sweden's Administrative Court upheld Apohem's fine on May 15, 2026. A further appeal is pending.
What our scanner measures, by failure type
The comparison below is by failure type only. None of the organizations named above was scanned for this post, and nothing here describes how any of them behaves. None of these figures says that any site broke a law or would be fined.
The figures come from four separate cohorts: the per-consent-tool census (912 sites running one of four consent tools, from our sales-lead lists and not a random sample, scanned July 19 and 20, 2026); the state census (229 sites whose owners ran our free scanner, June 21 to July 14, 2026); 146 of the most-visited sites (July 16, 2026); and the Reject All cookie study (6,964 observations of tracking cookies stored under the site's own domain with a third-party script host in the write stack, on 791 sites).
Every "before consent" and "after Reject" figure comes from the scanner's EU test: a fresh browser in Frankfurt, Germany, visiting each site for the first time. "No banner" means the scanner detected no banner from either of its two locations. "Before consent" counts any third-party tracker request observed before the visitor chose, including Google Consent Mode "denied" pings, which still reach Google. That is a strict standard.
| Failure type | Fines with this finding (of 72 itemized) | What our scanner observed |
|---|---|---|
| Trackers before any choice | 34 | A tracker request before any choice on 829 of 912 consent-tool sites (91%), 179 to 189 of 229 state-census sites (78% to 83%), and 110 of 146 most-visited sites (75%) |
| Tracking after Reject or withdrawal | 21 | A tracker request after Reject on 178 of 741 consent-tool sites where Reject was clickable (24%) and 30 of 70 state-census sites (43%, wider tracker definition). 3,023 of 6,964 tracking-cookie observations (43.4%) were still present after Reject All. Three of the 21 were US opt-outs, a different act |
| Of which, withdrawal of an earlier Accept | 6 | Not measured: every scan is a first visit |
| No way to refuse at all | 5 | Not reported: below our five-site floor |
| Refusing harder than accepting | 4 | Not measured: the scanner does not count clicks or judge banner design |
| Pre-ticked boxes | 2 | Not measured |
| Consent-or-pay | 4 | Not measured |
| Missing or misleading information | 27 | Not measured, except no banner at all while tracking before consent: 124 of 229 state-census sites (54%), 67 of 146 most-visited sites (46%), at most 83 of 912 consent-tool sites (9%) |
| US opt-out friction | 6 | Not measured |
| GPC not fully honored | 5 | Not measured |
| What a pixel sent | 8 | Not measured |
The 72 leave out the CNIL's 24 simplified-procedure decisions of 2024 and 2025. Its 2024 review says "11 organizations were penalized for not allowing users to refuse cookies as easily as to accept them."
Our scanner records the network requests a real browser makes while it visits one page. It cannot see data a website's own servers send to another company, such as events sent through Meta's Conversions API, and it does not count requests to the website's own domain, so tracking relayed through the site's own server is not in these figures. It records where each request went and when, not what the request contained or why it was made. It does not send a Global Privacy Control signal, so GPC honoring and US opt-out flows are not measured.
How we built this list
Law-firm summaries, news, the CMS enforcement tracker and GDPRhub only pointed us to cases. Each was read on the regulator's or court's own site.
Europe: the CNIL, AEPD, Garante, Dutch AP, Belgian APD, ICO, Irish DPC, IMY, Datatilsynet in Norway and Denmark, Finland's Traficom, Romania's ANSPDCP, Croatia's AZOP, Austria's DSB and courts, Hungary's NAIH, ten reports from Germany's federal authority and 7 of its 17 state authorities, and the authorities of Luxembourg, Czechia, Latvia, Lithuania, Greece, Portugal and Poland. US: the CPPA, the FTC (its whole press archive from January 2025) and the attorneys general of California, Connecticut, New York, Texas, Florida and Oregon.
Gaps: about 150 AEPD resolutions would not open, and the Garante's search cannot be queried by machine. Ten German state authorities, and the telecom regulators that enforce cookie rules in some countries, were not read. Other EEA countries and other US attorneys general got only finding-aid or site searches, so we make no claim about them.
Left out by design: California's mobile-app cases (Jam City, Tilting Point), the Irish DPC's EUR 310 million LinkedIn decision (GDPR advertising consent, with a pixel as one data source, under appeal) and the FTC's Avast order (browser software). We name only what a live regulator or court record names, because the CNIL removes names when a decision's publication period ends.
Frequently Asked Questions
The CNIL's EUR 325 million against Google LLC (EUR 200 million) and Google Ireland Limited (EUR 125 million), decided on September 1, 2025. It covered cookies at Google account creation and ads in Gmail, and the CNIL did not split the amount between the two. SHEIN's EUR 150 million, decided the same day, was for cookies alone.
In the records we read, the CNIL, by count and by amount: 34 decisions with a cookie breach from January 2024 to early April 2026, 25 of them under its simplified procedure. Spain's AEPD follows with 21, then Romania's ANSPDCP with 13.
Yes, in the records we read. The AEPD fined two private individuals over their own websites, EUR 1,000 and EUR 2,000 under its cookie rule, and Romania's ANSPDCP fined online shops, a law office and two individuals, starting at RON 5,000.
Not always. Spain's AEPD fines cookie breaches under Article 22.2 of its LSSI law, and Romania's ANSPDCP under Article 4(5) of Law 506/2004, its ePrivacy law. Croatia's AZOP fines under the GDPR, and the Dutch AP fined Kruidvat's operator under GDPR Article 6(1). The California penalties came under the CCPA.
Yes. California's privacy agency and attorney general announced eight penalties in 2025 and 2026, from USD 345,178 to USD 2.75 million, all settlements. Connecticut's attorney general settled with TaxAct for USD 275,000.
Check your own site
See what your site sends before consent
The free compliance scanner visits your site from the EU and the US, clicks Reject, and reports the third-party requests it observed before and after the choice. Full compliance, no compromise.