Most website owners know they need a cookie banner. Far fewer know what actually gets a site fined — and it's usually not "no banner at all". Data protection authorities across the EU consistently penalise a small set of specific, fixable mistakes.
This article walks through real enforcement patterns, the amounts involved, and how to check whether your own setup has the same weaknesses — before an authority or a competitor's complaint does.
The single most common trigger is a banner that looks compliant but isn't:
GDPR Article 7(1) puts the burden of proof on you. If you can't show when and how each user consented, regulators treat the consent as never having happened. Fines here are common because most small-site consent setups store nothing at all.
A cookie banner that doesn't link to a privacy policy explaining cookie purposes, retention periods and third parties fails the "informed" requirement. Several DPAs issue low-level fines and reprimands for this daily — they rarely make headlines but they do land in your inbox.
Strictly necessary cookies without consent (legal under ePrivacy Art. 5(3)), first-party session cookies, and banners that simply use an unusual design as long as consent is freely given, informed and revocable. Design taste isn't regulated; mechanics are.
| Violation | Typical range | Note |
|---|---|---|
| No valid consent mechanism | €2,000 – €100,000+ | Scales with traffic and data sensitivity |
| Tracking before consent | €5,000 – €60M | Meta/Google cases sit at the extreme end |
| Missing reject option / dark patterns | €40,000 – €150M | CNIL 2022 decisions set the benchmark |
| No privacy policy link / incomplete info | €500 – €20,000 | Most common outcome for SMB sites after complaints |
These are real decisions from 2024–2026, each verified against the authority's own announcement:
| When | Who | Fine / action | What went wrong |
|---|---|---|---|
| Sep 2025 | Google (France, CNIL) | €325M | Ads in Gmail without valid consent; coercive cookie practices. Third CNIL fine for Google's cookies (after €100M in 2020 and €150M in 2021). |
| Sep 2025 | SHEIN (France, CNIL) | €150M | Advertising cookies placed before any user choice; reject/withdrawal mechanisms ineffective; incomplete banner information. |
| Dec 2025 | UK top-1,000 sites (ICO) | Enforcement sweep | 564 of the UK's 1,000 biggest websites failed initial checks and only complied after ICO letters, investigations and 17 preliminary enforcement notices; 21 still failing. |
| 2024 | Kruidvat / AS Watson (Netherlands) | €600,000 | Tracking cookies without valid consent; pre-ticked-style consent mechanics. |
| Apr 2025 | Warner Music Sweden, Aller Media et al. (Sweden, IMY) | Formal warnings | Banners designed to favour "Accept" over "Reject". |
Sources: CNIL press releases (cnil.fr, 1 & 3 Sep 2025), EDPB case register, ICO news release (4 Dec 2025), Dutch DPA decision on AS Watson, Swedish IMY supervisory notices.
The pattern across every case is the same three failures: cookies before consent, a harder-to-find reject option, and incomplete information. None of these require enterprise budgets to fix — they are implementation mistakes.
Our free scanner checks any URL — WordPress, Shopify, Webflow, Next.js, Squarespace or plain HTML — for consent-banner presence, HTTPS hardening and privacy-policy linking, and tells you exactly what to fix:
Passed? Show it off — add a free compliance badge to your site (great for client trust and a dofollow backlink).
Want documented proof for clients or auditors? EUComply Pro ($79/yr) monitors your site daily and generates a signed report you can archive, and the compliance checklist drafts the policies themselves.