CNIL fines 2025: worldwide turnover central to fine calculation

A strategic analysis of the CNIL's recent decisions and their implications for data governance.

The fines issued in 2025 — €325M against Google, €150M against SHEIN, and €900,000 against SOLOCAL — confirm a toughening of the CNIL's enforcement policy.

The most significant development, however, lies in the method of calculating fines: the CNIL now considers the group's worldwide turnover, both for GDPR infringements and those related to ePrivacy regulations. This change significantly alters risk assessment for corporate groups.

Key takeaways:

→ Worldwide turnover is now used to calculate certain fines

→ This approach applies to both GDPR and ePrivacy matters

→ A local failure can have financial consequences at the group level

1. What changes in 2025

1.1. The concept of” venture ” within the meaning of competition law

Recital 150 of the GDPR states that:

When administrative fines are imposed on a business, this term should, in this context, be understood [...] in accordance with Articles 101 and 102 of the TFEU ”.

The EDPS guidelines on administrative fines recall that the concept of enterprise corresponds to:

an economic unit that can be formed by the parent company and all the subsidiaries concerned ”.

The CJEU, in a judgment of December 5, 2023, reaffirmed that the amount of the fine must be calculated according to the real economic capacity of the responsible party, which leads to the economic unit being considered and not the isolated legal entity.

1.2. The practical application by the CNIL in its 2025 sanctions decisions

🔷 First example: Google (SAN-2025-004)

The restricted panel highlights:

When a subsidiary is 100% owned by its parent company, there is a rebuttable presumption of decisive influence. [...] It is necessary to take into account the turnover of the parent company in order for the fine to be effective, proportionate and dissuasive ”.

And it specifies:

ALPHABET Inc. generated more than $350 billion in sales in 2024 ”.

In conclusion, the CNIL takes into account ALPHABET's turnover and not that of Google France or GIL.

🔷 Second example: SHEIN (SAN-2025-005)

The CNIL also upholds the principle of economic unity:

ROADGET BUSINESS PTE LTD wholly owns INFINITE STYLES SERVICES CO LIMITED. [...] The group's parent company's turnover should be used ”.

Again, the CNIL uses the worldwide turnover of the Singaporean company to calculate the fine.

2. Implications for organizations

2.1. Increased financial exposure

The logic is now clear: even if the breach is committed by a local subsidiary, the fine can be calculated based on the group's consolidated turnover.

2.2. The revenue base is not limited to turnover resulting from breaches

The CNIL expressly states this in the Google decision:

No text limits the basis to only turnover resulting from breaches. [...] It is appropriate to rely on total turnover ”.

In other words:
→ the seriousness of the breach is not linked to the revenue generated,
→ economic capacity is the only thing that counts.

3. Operational lessons for groups

🔷 Reassess your financial exposure

Integrate the group's global turnover into your risk analyses, and no longer just that of the French entity or subsidiary concerned. A local failure can now cost tens or even hundreds of millions of euros if you are part of an international group.

🔷 Strengthen group governance

Establish control and supervision mechanisms at the parent company level to ensure the compliance of all subsidiaries. The presumption of decisive influence comes into play when the subsidiary is 100% owned by its parent company.

🔷 Document autonomy (if applicable)

If a subsidiary operates in a truly autonomous manner, document this autonomy in an attempt to overturn the presumption of decisive influence of the parent company. Warning: this presumption is rebuttable but difficult to overturn.

🔷 Treat cookies with the same level of requirement as the GDPR

Cookie breaches now expose them to the same levels of sanctions as GDPR breaches.

Conclusion: a major breakthrough

The sanctions imposed by the CNIL in 2025 mark a breakthrough: the calculation of fines based on the group's turnover, including for ePrivacy breaches (cookies and electronic prospecting), multiplies the financial exposure of international groups.

The era of symbolic sanctions is definitely over. The CNIL now has the legal and methodological tools to impose truly dissuasive sanctions, calibrated to the real economic size of the sanctioned groups.

For international organizations, compliance is becoming a strategic and budgetary imperative. Legal departments, DPOs and general management must integrate this new approach into their governance, risk analyses and compliance budgets.

For an analysis of the CNIL's main enforcement trends, see also our article "The CNIL's targeted enforcement policy: review of the 2025 Sanctions" .

Odoné assists companies facing CNIL investigations and enforcement proceedings, providing strategic support at every stage of the process.

Are you facing a CNIL investigation or enforcement proceeding? Contact us to discuss your situation.

When compliance becomes strategic, The regulator's perspective becomes essential

With over 20 years of experience, Odoné supports leading organisations with rigorous, pragmatic and accessible guidance.

Make an appointment
flèche noire pointant vers la droiteflèche noire pointant vers la droite
Did you like this article?

Share it with colleagues or friends:
Logo bleu FacebookLogo bleu LinkedinLogo bleu X