France's data protection authority, the Commission Nationale de l'Informatique et des Libertes (CNIL), issued 23 sanctions under its simplified procedure between January and early July 2026, for a combined EUR 133,750 in fines. Several of them punished cookie banners that let visitors accept everything in one click but made them open a settings panel to refuse.
The regulator published the figures in its 6 July 2026 round-up of simplified sanctions (in French). Nineteen of the 23 cases began with a complaint from an individual. The decisions fall into three groups: cameras filming staff all day, cookie consent failures, and organisations that ignored requests to access or delete personal data, four of which had also failed to cooperate with the CNIL.
Key takeaways
The CNIL issued 23 simplified-procedure sanctions from January to early July 2026, totalling EUR 133,750, and 19 of them started with a complaint.
Simplified sanctions are decided by a single member of the CNIL's sanctions committee, are capped at EUR 20,000, and never name the organisation.
The 2026 cookie cases involved incomplete banner information, advertising cookies set before any click, and refuse options hidden behind a "Customise" button.
In 2025, 13 of the CNIL's 21 cookie sanctions went through the simplified procedure, with fines between EUR 2,000 and EUR 20,000.
Failing to answer the CNIL is a separate breach, and an ignored injunction can cost up to EUR 100 for each day of delay.
What Is the CNIL's Simplified Sanction Procedure?
The simplified sanction procedure is a fast-track enforcement route the CNIL has used since 2022 for cases that raise no particular legal difficulty. A single member of its sanctioning body decides the case through a mostly written process, fines can't exceed EUR 20,000, and the organisation's name is never made public.
It covers breaches of both the General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertes), and its legal basis is Article 22-1 of that Act. According to the CNIL's guidance on the simplified sanction procedure, a case qualifies when settled case law exists, when the restricted committee (the CNIL body that imposes sanctions) has already ruled on similar facts, or when the questions of fact and law are simple. A CNIL staff member acts as rapporteur, and the chair of the restricted committee either takes the case personally or assigns it to another member.
The whole process runs in writing. You have one month from receiving the rapporteur's report to send written observations, the rapporteur can reply within a further month, and an oral hearing happens only if you ask for one.
Three measures are available, alone or combined: a call to order, an injunction to bring the processing into line with a penalty of up to EUR 100 per day of delay, and a fine of up to EUR 20,000. The chair can refuse the fast track or move a case back to the ordinary procedure at any stage, and every document already in the file carries over. So the EUR 20,000 ceiling protects you only for as long as the CNIL treats your case as simple.
Here's how the two routes compare, using the 2025 figures from the CNIL's public register of sanctions (in French).
| Feature | Simplified procedure | Ordinary procedure |
|---|---|---|
| Who decides | The chair of the restricted committee, or a member they designate, alone | The restricted committee sitting as a panel |
| Which cases | No particular legal difficulty: settled case law, earlier decisions on similar facts, simple questions | All other cases, including those raising legal difficulty |
| Maximum fine | EUR 20,000 | Up to EUR 20 million or 4% of worldwide annual turnover for GDPR breaches |
| Other measures | Call to order; injunction with a penalty of up to EUR 100 per day of delay | Call to order; injunction with a penalty payment |
| Format | Written, with a hearing only on request | Written exchanges, then a hearing before the committee |
| Organisation named? | Never | Possible, depending on the seriousness of the case |
| Sanctions in 2025 | 67 | 16 |
| Cookie sanctions in 2025 | 13, fined EUR 2,000 to EUR 20,000 | 8, fined EUR 270,000 to EUR 325 million |
What Did the CNIL Sanction Between January and July 2026?
The 23 decisions announced on 6 July 2026 cover three areas: workplace video surveillance, cookie consent, and ignored requests to access or erase personal data, four of them combined with a failure to cooperate with the CNIL. The fines total EUR 133,750, which works out at roughly EUR 5,800 per decision.
The video cases involved fast-food businesses, an urban transport operator, and companies running shops in railway stations. Some had installed cameras without the authorisation required from the local prefect, which breaches the lawfulness principle in Article 5(1)(a) GDPR. Others filmed employees continuously with no exceptional circumstance to justify it, a breach of the data minimisation principle in Article 5(1)(c).
Eight decisions concerned people who asked a company for a copy of their data, or for its deletion, and either heard nothing or got an answer too late.
Don't read the round-ups as a complete count. The CNIL's two 2025 round-ups described 10 and 16 decisions, yet its register lists 67 simplified sanctions for the whole of 2025. What the round-ups do show is where cases come from: 19 of the 23 in 2026 started as complaints, as did 14 of the 16 in the October 2025 round-up.
Which Cookie Banner Failures Led to Fines?
The CNIL fined sites whose banners left out required information, set advertising cookies before the visitor did anything, or offered "Accept all" in one click while hiding refusal behind a "Customise" button. All three breach Article 82 of the French Data Protection Act, which transposes Article 5(3) of the ePrivacy Directive into French law.
These findings came from online inspections, which the CNIL carries out remotely when a breach can be observed from outside and records in an official report. The regulator identifies the sites only by sector, citing online ticket sellers and telemarketing companies among them. Loading a homepage in a clean browser is enough to spot all three problems.
Banners that left out required information
Some banners didn't explain what the cookies were for, didn't identify the organisation responsible for the processing, or didn't tell visitors how to refuse or later withdraw consent. Consent given without that information isn't informed, so it isn't valid. A banner that only promises to "improve your experience" has the same gap. Good banner copy names each purpose, such as audience measurement or targeted advertising, in plain terms.
Advertising cookies set before any click
Other sites placed cookies that need consent, with advertising cookies as the CNIL's example, before the visitor had taken any action. A banner displayed over trackers that are already firing is decoration. A common cause is a tag hard-coded into the page template, or loaded through a tag manager outside the consent logic, that drops cookies such as _fbp, _gcl_au or IDE on the first page view.
A refuse option hidden behind "Customise"
This is the failure the CNIL described in most detail. The banners offered an "Accept all" button that worked immediately, but refusing meant clicking "Personnaliser" (Customise) and then using a separate interface to switch cookies on or off. The CNIL's position is plain: if a site lets visitors accept all cookies in one click, it must let them refuse all cookies in one click too. Renaming the button "Manage preferences" or "Settings" changes nothing.
The rule has appeared in the CNIL's cookie guidelines since 2020, and the CNIL's 2025 enforcement review said the organisations it sanctioned for cookie breaches couldn't have been unaware of it, given how widely the regulator had publicised its cookie rules.
One decision in the register shows how these problems stack up. On 26 March 2026, a company that organises events and sells tickets was fined EUR 15,000 and ordered to put things right for cookie consent and cookie information failures, alongside a failure to honour an erasure request, keeping data too long, unlawful processing and incomplete privacy information. The banner was one line in a longer list.
How Much Does a Simplified Cookie Fine Cost?
Usually a few thousand euros: the CNIL register lists 13 simplified-procedure cookie sanctions in 2025, ranging from EUR 2,000 to EUR 20,000, with ten of them between EUR 3,000 and EUR 5,000 and five accompanied by an injunction. Eight other cookie cases went through the ordinary procedure that year, with fines starting at EUR 270,000.
Here are all 13 simplified cookie decisions from 2025, as the register describes them.
| Date | Organisation (as the CNIL describes it) | Cookie breach | Outcome |
|---|---|---|---|
| 18 Jun 2025 | Distance seller (general catalogue) | Consent | EUR 3,000 |
| 9 Oct 2025 | Distance seller (general catalogue) | Consent, information | EUR 4,000 |
| 16 Oct 2025 | Distance seller (specialist catalogue) | Consent | EUR 3,000 |
| 16 Oct 2025 | Magazine and periodical publisher | Consent, information | EUR 4,000 + injunction |
| 16 Oct 2025 | Sports and leisure centre operator | Consent, plus security and information failures | EUR 20,000 + injunction |
| 4 Nov 2025 | Local authority | Information | EUR 4,000 |
| 4 Nov 2025 | Consultancy for scuba-diving clubs | Consent, information | EUR 4,000 |
| 13 Nov 2025 | Shoe retailer | Consent, information | EUR 5,000 |
| 13 Nov 2025 | Company-information web portal | Consent, information | EUR 5,000 |
| 11 Dec 2025 | Performing arts company | Information, consent | EUR 5,000 + injunction |
| 18 Dec 2025 | Travel agency | Information, consent | EUR 2,000 + injunction |
| 29 Dec 2025 | Newspaper publisher | Consent | EUR 5,000 |
| 29 Dec 2025 | Newspaper publisher | Consent | EUR 7,000 + injunction |
Look at the sectors. A local authority, a travel agency, a consultancy for scuba-diving clubs and two newspaper publishers appear alongside online retailers, so the fast track is clearly used well beyond large e-commerce. Twelve of the 13 decisions date from October 2025 onwards, which suggests the CNIL began pushing cookie cases through the simplified procedure in earnest in late 2025, and the July 2026 round-up shows the practice has continued.
Compare that with the ordinary track. In the same year it produced the widely reported EUR 325 million and EUR 150 million fines against Google and Shein, plus mid-sized penalties such as EUR 750,000 for a magazine publisher and EUR 1.5 million for a payment card issuer. Both tracks dealt with the same two categories in the register, cookie consent and cookie information. What decides the route is whether a case raises any legal difficulty, and a banner with no refuse button raises none.
The cost can also grow after the decision. An injunction can carry a penalty of up to EUR 100 for each day of delay, and the CNIL does collect: in the first quarter of 2026 the register records penalty liquidations of EUR 1,000 each against a doctor and a lawyer, EUR 850 against a performing arts company, and EUR 5,100 against an association defending fundamental rights. As of September 2026, the register's 2026 list ran only to early April, so recent decisions take a while to appear there.
What Happens If You Ignore a Data Request or the CNIL?
Both are sanctionable on their own. Eight of the 23 decisions announced in July 2026 involved access or erasure requests that went unanswered or were answered too slowly, and in four of those the organisation also failed to respond to the CNIL, which is a separate breach under Article 18 of the French Data Protection Act.
The CNIL singled out lawyers and doctors who didn't reply to its questions while it investigated complaints about their handling of rights requests. They were fined and ordered to answer the complainants. When they ignored that injunction too, the CNIL liquidated the penalty, meaning they had to pay a sum once the deadline to comply had passed.
Non-cooperation isn't a rare charge. The CNIL's 2025 enforcement review counted 14 organisations sanctioned under the simplified procedure for failing to answer the regulator, and 14 decisions over ignored erasure, objection or access requests.
For website owners, the overlap with cookies is real: the ticketing company fined in March 2026 was sanctioned for the erasure request in the same decision as its banner. Under Article 12(3) GDPR, you have one month to act on an access request or an erasure request, extendable by two further months for complex or numerous requests, provided you tell the person within the first month. If the CNIL writes to you about a complaint, reply by the deadline it sets, even when the answer is simply that the problem has been fixed.
How Can You Keep Your Site Out of the Simplified Procedure?
Fix the three banner failures the CNIL keeps finding, and be ready to respond when someone complains. That means a "Refuse all" button on the first layer that's as easy to use as "Accept all", no consent-requiring cookies before a choice, a banner that names purposes and the organisation responsible, and a routine for answering data requests and regulator letters on time.
Look at the first layer in a clean browser profile. If accepting takes one click, refusing must take one click too, on the same screen. Watch for dark patterns such as a refuse link styled as faint grey text.
Check what loads before consent. Clear site data, reload the page, and inspect the Application tab in your browser's developer tools before clicking anything. A session cookie such as
PHPSESSIDcan be there; advertising cookies such as_fbpor_gcl_aucan't.Rewrite the banner text. State each purpose, name the organisation responsible, and explain how to refuse now and how to withdraw consent later, for example through a persistent footer link.
Test refusal as carefully as acceptance. After clicking "Refuse all", reload and confirm that no new advertising cookies appear and that none set earlier are still being read.
Put data requests on a clock. Log every access or erasure request with its date, answer within one month, and keep a copy of what you sent.
Keep evidence. Dated consent records and scan reports show what visitors saw and when, which helps if a complaint turns into a CNIL investigation.
A consent management platform handles most of the technical side. Kukie.io's banner shows "Reject all" alongside "Accept all" by default, and its script blocking holds known trackers back until the visitor makes a choice.
Reform in Brussels won't rescue a non-compliant banner any time soon. The Digital Omnibus proposal published in November 2025 would move cookie rules into the GDPR, but as of September 2026 it hadn't been adopted, and the CNIL keeps applying Article 82 as it stands. Every sanction in the July round-up was decided under today's rules.
Frequently Asked Questions
What is the maximum fine under the CNIL's simplified procedure?
EUR 20,000. The decision-maker can also issue a call to order or an injunction with a penalty of up to EUR 100 per day of delay, and can move a case to the ordinary procedure, where that ceiling no longer applies.
Does the CNIL publish the names of organisations fined under the simplified procedure?
No. The CNIL isn't allowed to disclose the name of an organisation sanctioned this way, and its public register describes each one only by sector, such as a travel agency or a newspaper publisher.
Can a small business be fined by the CNIL for its cookie banner?
Yes. The 2025 register includes simplified cookie fines of EUR 2,000 for a travel agency, EUR 4,000 for a local authority and EUR 5,000 for a shoe retailer, so size offers no protection.
Is a "Customise" button enough to let visitors refuse cookies in France?
No. If your banner offers "Accept all" in one click, the CNIL requires a way to refuse all cookies in one click as well, and in 2026 it fined banners that sent visitors through a "Customise" panel to refuse.
How do CNIL cookie investigations usually start?
Most simplified cases start with a complaint, as 19 of the 23 decisions announced in July 2026 did. The CNIL also runs online inspections of websites, which is how the 2026 cookie breaches were found.
What happens if you ignore a CNIL injunction?
The CNIL can liquidate the penalty attached to the injunction, meaning you pay a sum once the compliance deadline passes. In early 2026 it liquidated penalties of between EUR 850 and EUR 5,100 against organisations that failed to comply.
Check Your Banner Before Someone Complains
If you're not sure whether your site sets advertising cookies before a visitor clicks, or whether refusing takes as few clicks as accepting, a scan will tell you. Kukie.io flags cookies that load before consent, so you can fix them before a complainant or an inspector finds them.
