Blog

Cookie and Tracker Fines, 2024 to 2026: Who Was Fined, for What, and How Much

This post lists the cookie, tracker and pixel fines we could find from January 2024 to October 1, 2026, taken from regulators' own decisions, sanctions lists and press releases, and from court records.

Key Takeaways

  • 01Two CNIL decisions on September 1, 2025, Google (EUR 325 million) and SHEIN (EUR 150 million), make up EUR 475 million of the roughly EUR 482 million in 2025 CNIL sanctions that included a tracker breach.
  • 02Elsewhere in Europe cookie fines are mostly small. All but two of Spain's 21 came to EUR 1,000 to EUR 12,000, and Romania's 13 total RON 237,000.
  • 03Italy's Garante, the UK's ICO and the German authorities whose reports we read issued no cookie fine we could find. They used warnings, letters and orders.
  • 04In the 72 fines we itemized, the most common findings are trackers before any choice (34), missing or misleading information (27) and tracking after Reject or withdrawal (21), mostly in Europe. Every California penalty concerns how opt-outs worked, including GPC.
  • 05Our scanner measures behavior, not legality. Under a strict standard, our July 2026 EU test observed a tracker request before any choice on 829 of 912 consent-tool sites from our sales-lead lists. It does not measure the US failure types.

We found at least 95 fines, penalties and settlements from 13 regulators. That is a floor, not a census.

The short answer: most of the money is in France

In 2025 the CNIL issued 21 sanctions that included a tracker breach, worth about EUR 482 million. Two decisions of September 1, 2025 make up EUR 475 million of it: Google (EUR 325 million) and SHEIN (EUR 150 million).

Outside France, most cookie fines are small. All but two of the 21 Spanish fines we could read came to EUR 1,000 to EUR 12,000. Romania's 13 total RON 237,000, and Croatia's six total EUR 85,500.

In the US, most penalties came from California: five worth USD 4,407,678 in 2025, and three more in 2026, the largest USD 2.75 million from Disney. The FTC's two 2024 health-data orders were mostly refunds or suspended penalties, and Connecticut added one pixel settlement.

What regulators fined for

Grouped by what went wrong (one decision often names several):

  • Trackers before any choice. The CNIL found SHEIN placed advertising cookies "as soon as they arrived on the site, even before they interacted with the information banner". Twelve of Romania's 13 fines are for this.
  • Tracking after Reject or withdrawal. The CNIL found that at Orange, cookies "continued to be read" after users withdrew consent, and that American Express placed advertising cookies "despite their expressed refusal".
  • Refusing harder than accepting, or impossible. The CNIL found that at Google account creation, until October 2023, "it was more difficult to refuse cookies linked to personalised advertising than to accept them".
  • Pre-ticked boxes and assumed consent. The two Dutch fines, on Kruidvat's operator and Coolblue.
  • Consent-or-pay. Four Spanish resolutions tie refusing to paying.
  • Missing or misleading information. For example, cookies presented as "strictly necessary" on vanityfair.fr without useful information (CNIL).
  • US opt-outs and GPC. The CPPA alleged that opting out at Honda took two steps and opting back in took one. All five GPC cases are Californian.

Named actions, January 2024 to October 2026

Named cookie, tracker and pixel actions, January 2024 to October 1, 2026 (original currencies)
DateRegulatorOrganization, as namedAmountMain finding
Feb 13, 2024AEPD (ES)LA VANGUARDIA EDICIONES, S.L.EUR 10,000 proposed, 8,000 paidBefore consent; kept after refusal
Feb 22, 2024AEPD (ES)PRENSA IBÉRICA MEDIA, S.L.EUR 5,000 proposed, 4,000 paidBefore consent; after Reject All
Mar 22, 2024AEPD (ES)NH HOTEL GROUP S.A.EUR 10,000 proposed, 8,000 paidAccept-only; before consent; refusal ineffective
Apr 11, 2024 (ann.)FTCMonument, Inc.USD 2,500,000 penalty, suspendedAlleged: pixels sent health events
Apr 15, 2024 (ann.)FTCCerebral, Inc.Over USD 7 million, mostly cancellation refundsAlleged: trackers sent health data
May 3, 2024AP (NL)AS Watson (Health & Beauty Continental Europe) B.V. (Kruidvat)EUR 600,000, cut to 50,000Pre-ticked; refusing took many steps
Jun 25, 2024IMY (SE)Avanza Bank ABSEK 15,000,000Pixel sent account and ID numbers
Aug 29, 2024IMY (SE)Apoteket ABSEK 37,000,000Pixel sent sensitive purchase data
Aug 29, 2024IMY (SE)Apohem ABSEK 8,000,000Same; on appeal
Oct 8, 2024AEPD (ES)SEAT, S.A.EUR 20,000 proposed, 12,000 paidTracking after consent revoked
Nov 14, 2024CNIL (FR)ORANGE SAEUR 50,000,000Read after withdrawal; email ads
Dec 24, 2024 (ann.)AP (NL)CoolblueEUR 40,000Consent assumed; pre-checked
Mar 7, 2025CPPAAmerican Honda Motor Co., Inc.USD 632,500Alleged: opt-out harder than opt-in
Apr 29, 2025 (pub.)IMY (SE)DiskrimineringsombudsmannenSEK 100,000Web-form data reached analytics
May 1, 2025CPPATodd Snyder, Inc.USD 345,178Alleged: banner vanished; GPC
Jun 10, 2025Datatilsynet (NO)Kristiansand kommuneNOK 250,000Pixels on a children's helpline
Jul 1, 2025 (ann.)California AGHealthline Media LLCUSD 1,550,000Alleged: tracking after opt-out; GPC
Jul 3, 2025AEPD (ES)WALLAPOP, S.L.EUR 5,000 proposed, 3,000 paidReject All had no effect
Sep 1, 2025CNIL (FR)GOOGLE LLC; GOOGLE IRELAND LIMITEDEUR 325,000,000Harder to refuse; Gmail ads
Sep 1, 2025CNIL (FR)INFINITE STYLES SERVICES CO. LIMITED (SHEIN)EUR 150,000,000Before consent; after Refuse all
Sep 26, 2025CPPATractor Supply CompanyUSD 1,350,000Alleged: opt-out form did not stop trackers; GPC
Oct 30, 2025 (ann.)California AGSling TV L.L.C.; Dish Media Sales L.L.C.USD 530,000Alleged: cookie settings did not opt out
Nov 20, 2025CNIL (FR)LES PUBLICATIONS CONDE NASTEUR 750,000Before consent; after refusal
Nov 27, 2025CNIL (FR)AMERICAN EXPRESS CARTE FRANCEEUR 1,500,000Before consent; despite refusal
Feb 11, 2026 (ann.)California AGDisney DTC, LLC; ABC Enterprises, Inc.USD 2,750,000Alleged: opt-outs per device; GPC
Feb 27, 2026CPPAFord Motor CompanyUSD 375,703Alleged: email check before opt-out
Feb 27, 2026CPPA2080 Media, Inc. d/b/a PlayOn SportsUSD 1,100,000Alleged: forced "agree"; GPC
Mar 24, 2026AEPD (ES)CONECTA5 TELECINCO, S.A.U.EUR 5,000 imposedBefore consent; consent-or-pay
Aug 19, 2026 (ann.)Connecticut AGTaxActUSD 275,000AG: tracking sent tax details

Dates are decision or order dates, except "ann." (announced) and "pub." (published). AEPD dates are the latest dated step in the resolution, usually payment. Spanish amounts show the proposed fine, then the amount paid after early-payment reductions or, without early payment, the fine imposed; in early-payment cases the finding is what the AEPD recorded on opening the case. The US matters are settlements, so their facts are allegations (Honda and PlayOn admitted only background facts, not liability), and the TaxAct findings are the Connecticut AG's. We count, but do not name, the small businesses and individuals some regulators name.

Sources: CNIL on Orange, Google, SHEIN, Condé Nast and American Express; AEPD on La Vanguardia, Prensa Ibérica, NH Hotel Group, Wallapop and Conecta5 Telecinco (SEAT is PS/00284/2024); the AP on Kruidvat, its objection decision and Coolblue; IMY's decision pages on imy.se; Datatilsynet's pixel inspection; CPPA orders for Honda, Todd Snyder, Tractor Supply, Ford and PlayOn; the California AG on Healthline, Sling TV and Disney; the FTC on Monument and Cerebral; the Connecticut AG on TaxAct.

Totals by regulator and year

Cookie, tracker and pixel money by regulator and year (original currencies; counts are a floor)
Regulator202420252026 (to Oct 1)
CNIL (France)12 decisions, EUR 50,133,00021 decisions, EUR 482,191,0001 listed, EUR 15,000 (list ends April 2)
AEPD (Spain)12 or 13, EUR 160,600 to 162,600 paid or imposed6, EUR 84,200 paid or imposed2, EUR 8,000 paid or imposed
ANSPDCP (Romania)2, RON 20,0009, RON 182,0002, RON 35,000
AZOP (Croatia)6, EUR 85,500nonenone
AP (Netherlands)2, EUR 640,000 as imposednone new (one cut to EUR 50,000)none found
IMY (Sweden)3, SEK 60,000,0001, SEK 100,000none found
Datatilsynet (Norway)none1, NOK 250,000none found
DSB (Austria)none1, EUR 6,200 (a second, EUR 11,500, was annulled)none new
NAIH (Hungary)none foundnone found3 fines for missing information, HUF 27,000,000
CPPA (California)none3, USD 2,327,6782, USD 1,475,703
California AGnone in scope2, USD 2,080,0001, USD 2,750,000
Connecticut AGnonenone1, USD 275,000
FTC2 proposed health-data ordersnonenone (one complaint filed)

The CNIL 2025 figure is our sum of the 21 tracker sanctions on its sanctions list. Several also covered other breaches, so read it as decisions that included a cookie breach. The CNIL's own 2025 total, all topics, was EUR 486,839,500, and its July 6, 2026 note implies at least one more 2026 cookie case than the list shows. One Spanish 2024 resolution may date from late 2023, and the Spanish 2025 figure includes EUR 50,000 (proposed) that was not for cookies.

Others acted without fining. The ICO says 979 of the UK's top 1,000 sites passed its cookie checks by December 2025, after 564 improved their practices following letters and, in 17 cases, preliminary enforcement notices. The Dutch AP warned more than 200 sites by November 2025. Hamburg's authority wrote to 185 of 1,000 sites it found accessing devices on first load without consent, and no German report we read records a cookie fine. New York's attorney general found 13 high-traffic sites whose privacy controls "did not work as described" (guide). We found 18 cookie warnings from Italy's Garante (one example), and no fines.

Healthcare and pixel-data cases

Several of the larger amounts outside France are about what a pixel carried, not when it fired.

  • IMY fined Apoteket and Apohem for inadequate security measures (GDPR Article 32) after sensitive purchase data, including self-tests and treatment for sexually transmitted infections, and sex toys, reached Meta through the Meta Pixel.
  • Datatilsynet fined Kristiansand kommune because pixels on a helpline site for children at risk sent visitor data to third parties without legal basis or information.
  • The FTC alleged that Monument, an alcohol-addiction treatment company, sent events such as "Paid: Weekly Therapy" to Meta and Google, and that Cerebral, a telehealth company, passed data on nearly 3.2 million consumers to LinkedIn, Snapchat, TikTok and others.
  • Not a fine: on July 29, 2026 the FTC, Utah and California sued Hims & Hers. The complaint, as filed on August 18, alleges that registration and purchase events carrying identifiers and treatment details reached Meta through the Meta Pixel and Conversions API about 8 million times. The case is pending.

Fines changed on appeal

  • The Dutch AP cut Kruidvat's fine from EUR 600,000 to EUR 50,000 on objection (May 27, 2025). It kept its finding and gave four reasons for the cut: the long procedure, the company's acknowledgment of the infringement, "de geringe ernst van de overtreding" (the low seriousness of the infringement) and a comparable case.
  • Austria's Federal Administrative Court annulled a EUR 11,500 fine on May 1, 2026. Google Analytics cookies had been set before any choice for 13 days after the consent tool's auto-blocking script was misconfigured; the fix came within the compliance period of an earlier order.
  • Sweden's Administrative Court upheld Apohem's fine on May 15, 2026. A further appeal is pending.

What our scanner measures, by failure type

The comparison below is by failure type only. None of the organizations named above was scanned for this post, and nothing here describes how any of them behaves. None of these figures says that any site broke a law or would be fined.

The figures come from four separate cohorts: the per-consent-tool census (912 sites running one of four consent tools, from our sales-lead lists and not a random sample, scanned July 19 and 20, 2026); the state census (229 sites whose owners ran our free scanner, June 21 to July 14, 2026); 146 of the most-visited sites (July 16, 2026); and the Reject All cookie study (6,964 observations of tracking cookies stored under the site's own domain with a third-party script host in the write stack, on 791 sites).

Every "before consent" and "after Reject" figure comes from the scanner's EU test: a fresh browser in Frankfurt, Germany, visiting each site for the first time. "No banner" means the scanner detected no banner from either of its two locations. "Before consent" counts any third-party tracker request observed before the visitor chose, including Google Consent Mode "denied" pings, which still reach Google. That is a strict standard.

Failure types in the fines, and the closest behavior our scanner measures
Failure typeFines with this finding (of 72 itemized)What our scanner observed
Trackers before any choice34A tracker request before any choice on 829 of 912 consent-tool sites (91%), 179 to 189 of 229 state-census sites (78% to 83%), and 110 of 146 most-visited sites (75%)
Tracking after Reject or withdrawal21A tracker request after Reject on 178 of 741 consent-tool sites where Reject was clickable (24%) and 30 of 70 state-census sites (43%, wider tracker definition). 3,023 of 6,964 tracking-cookie observations (43.4%) were still present after Reject All. Three of the 21 were US opt-outs, a different act
Of which, withdrawal of an earlier Accept6Not measured: every scan is a first visit
No way to refuse at all5Not reported: below our five-site floor
Refusing harder than accepting4Not measured: the scanner does not count clicks or judge banner design
Pre-ticked boxes2Not measured
Consent-or-pay4Not measured
Missing or misleading information27Not measured, except no banner at all while tracking before consent: 124 of 229 state-census sites (54%), 67 of 146 most-visited sites (46%), at most 83 of 912 consent-tool sites (9%)
US opt-out friction6Not measured
GPC not fully honored5Not measured
What a pixel sent8Not measured

The 72 leave out the CNIL's 24 simplified-procedure decisions of 2024 and 2025. Its 2024 review says "11 organizations were penalized for not allowing users to refuse cookies as easily as to accept them."

Our scanner records the network requests a real browser makes while it visits one page. It cannot see data a website's own servers send to another company, such as events sent through Meta's Conversions API, and it does not count requests to the website's own domain, so tracking relayed through the site's own server is not in these figures. It records where each request went and when, not what the request contained or why it was made. It does not send a Global Privacy Control signal, so GPC honoring and US opt-out flows are not measured.

How we built this list

Law-firm summaries, news, the CMS enforcement tracker and GDPRhub only pointed us to cases. Each was read on the regulator's or court's own site.

Europe: the CNIL, AEPD, Garante, Dutch AP, Belgian APD, ICO, Irish DPC, IMY, Datatilsynet in Norway and Denmark, Finland's Traficom, Romania's ANSPDCP, Croatia's AZOP, Austria's DSB and courts, Hungary's NAIH, ten reports from Germany's federal authority and 7 of its 17 state authorities, and the authorities of Luxembourg, Czechia, Latvia, Lithuania, Greece, Portugal and Poland. US: the CPPA, the FTC (its whole press archive from January 2025) and the attorneys general of California, Connecticut, New York, Texas, Florida and Oregon.

Gaps: about 150 AEPD resolutions would not open, and the Garante's search cannot be queried by machine. Ten German state authorities, and the telecom regulators that enforce cookie rules in some countries, were not read. Other EEA countries and other US attorneys general got only finding-aid or site searches, so we make no claim about them.

Left out by design: California's mobile-app cases (Jam City, Tilting Point), the Irish DPC's EUR 310 million LinkedIn decision (GDPR advertising consent, with a pixel as one data source, under appeal) and the FTC's Avast order (browser software). We name only what a live regulator or court record names, because the CNIL removes names when a decision's publication period ends.

Frequently Asked Questions

Check your own site

See what your site sends before consent

The free compliance scanner visits your site from the EU and the US, clicks Reject, and reports the third-party requests it observed before and after the choice. Full compliance, no compromise.