Key takeaways:
The sanctions issued in 2025 show that the CNIL is now focusing its enforcement activity on three main categories of non-compliance:
→ Cookies: technical inspections of network traffic and verification of the effectiveness of users' consent.
→ Data security: heightened expectations regarding the implementation of appropriate technical and organisational measures.
→ Direct marketing: increased scrutiny of data collection and data-sharing practices throughout the marketing chain.
Taken together, these three areas account for nearly €500 million in fines imposed by the CNIL in 2025.

1. Cookies, security, direct marketing at the core of enforcement
🔷 Cookies and consent: reinforced technical control
Sanctions relating to cookies have targeted major players:
• Google (€325M)
• Shein (€150M)
• Condé Nast publications (€750,000)
• American Express (€1.5M)
These decisions reflect a significant evolution in the CNIL's control methodology, which is now conducting an in-depth technical analysis of the effectiveness of user choices.
Concretely, the CNIL examines the HTTP requests exchanged between the user's browser and the servers (of the publisher or third parties), which allows it to establish factually:
• the deposit of cookies before consent,
• the automatic reading and transmission of cookies,
• the ineffectiveness of refusal mechanisms.
This approach turns the assessment of consent into a factual and binary control : either cookies are blocked before consent, or they are not. Either the refusal is effective instantly, or it is not.
In practice, non-compliance with the CNIL's cookie guidelines and recommendation has become one of the simplest breaches for the authority to establish — and one of the most costly for businesses.
Through technical audits of consent interfaces, default settings, and data flows, the CNIL can document infringements that are extremely difficult to challenge on substantive grounds.
Businesses are thus confronted with deficiencies evidenced by screenshots, HTTP request logs, and interface audits, which leave little room for legal debate on the interpretation of obligations.
🔷 Data security: towards an almost results-based obligation
The company Free and Free Mobile (€42M) — examined by the restricted group in December 2025 with decisions published in January 2026 — illustrate an increasingly broad interpretation of the security obligation provided for in Article 32 of GDPR.
This approach is based on the requirement of a ”defense in depth” which, in fact, is similar to a strict liability obligation. To avoid sanctions, it is necessary to establish a particularly high and well-documented level of protection.
The emerging trend is concerning for data controllers: the mere occurrence of a data breach tends to be treated as evidence that security measures were insufficient.
Although the CNIL regularly states that a breach does not automatically constitute a violation of Article 32, in practice breaches almost systematically lead to sanctions, as inspections triggered by incidents nearly always uncover shortcomings when assessed against the CNIL’s very high standards.
🔷 Direct Marketing : data brokerage and data sharing in the spotlight
Sanctions aimed at SoLocal Marketing Services (€900,000) and Caloga (€80,000) have targeted direct marketing practices, particularly in the data brokerage sector.
These sanctions are part of the CNIL's priority control areas on direct marketing launched in 2022, which focused on the practices of professionals in the sector, in particular those who resell data and the numerous intermediaries in this ecosystem.
The sanctioned pattern :
1. Data collected via online competitions by primo-collecting companies
2. Transmitted to brokers who integrate them into their databases
3. To carry out marketing purpose operations or resell them to their advertising customers
The CNIL has sanctioned a double lack of consent :
• No valid consent to canvass prospects : the competition forms did not allow free and unequivocal consent to be obtained (acceptance buttons highlighted, refusal drowned in small print).
• No valid consent to transmit data to partners : the CNIL reiterates that, in the data brokerage ecosystem, all processing must be based on consent, not legitimate interest.
Key point : In the Canal+ case (CE, 5 May 2025, No. 490202), the French Conseil d’État referred to the CJEU the question of “cascade consent”: can consent given to a primary collector for transmission to a “category” of partners be sufficient, or must each recipient obtain separate consent?
This unresolved issue highlights that the legal framework governing data brokerage is far less clear-cut than CNIL decisions may suggest.
2. CNIL's enforcement strategy: focusing on breaches that are straightforward to establish, based on online-accessible technical evidence
The concentration of CNIL sanctions in these three areas reveals a pragmatic logic: to prioritize breaches that are relatively simple to characterize from both a technical and legal standpoint.
Unlike concepts such as the proportionality of processing or legal basis assessments — which require contextual legal analysis — breaches related to cookies, security, or direct marketing lend themselves to factual demonstration.
The French Conseil d'État recently illustrated this distinction by reducing Amazon's fine by half (from €32 million to €15 million), holding that the processing based on legitimate interests was not disproportionate (Conseil d'État, 23 December 2025, No. 492830).
This approach reflects a form of rationalization of control methods: faced with the magnitude of the challenges and the multiplicity of actors, the authority focuses its resources on the breaches that are most simply characterized and most likely to set a precedent.
Practical difficulty for businesses : to characterize these breaches, the CNIL relies heavily on soft law — its own guidelines and recommendations (particularly regarding cookies), but also very specialized technical references, such as some recommendations from ANSSI concerning security.
However, these texts, which have no binding value in the strict sense, are particularly numerous, evolving, and dense.
The use of evolving technical standards raises a practical difficulty: businesses, even mature and structured, struggle to benefit from a consolidated vision of the expected technical measures.
However, at the operational level, this strategy is extremely effective : by relying on precise and documented standards, the CNIL makes its decisions difficult to challenge from a factual point of view.
Businesses are thus faced with the following choice: challenge these requirements at the risk of a long and expensive litigation or comply with them as a precautionary principle. In fact, the second option is most often required, making soft law from the CNIL quasi-hard law in practice.
3. GDPR 2026 compliance: three priority areas for businesses
Faced with the CNIL's repressive strategy, it would be relevant for companies to focus their efforts on technical and documented compliance in three high-risk areas.
🔷 First task : technical governance of cookies and consent
Compliance with cookies can no longer be limited to the display of a standardized cookie banner.
Concrete actions :
→ Identify and map all cookies comprehensively deposited, read or transmitted, via an audit of HTTP flows, including third-party trackers that are not actively exploited.
→ Guarantee immediate effectiveness Choices Of the user: the refusal or withdrawal of consent must result in the instantaneous blocking of all reading or writing of non-essential cookies, as well as the stopping of associated transmissions.
→ Conform the interfaces To obtain consent to the guidelines of the CNIL: refusal as simple as acceptance, granular consent by purpose, clear information on recipients.
→ Document each cookie in detail (purpose, duration, recipients, legal basis) in order to demonstrate compliance in the event of verification by the supervisory authority.
Key point : the use of the IAB TCF does not exempt from strict control of the quality and effectiveness of the information provided.
For a detailed analysis of the latest cookie-related sanctions, see also our article on the decisions concerning Google, SHEIN, Condé Nast and American Express.
🔷 Second task: “defence in depth” and security documentation
The almost absolute safety requirement imposes a multi-layered strategy And a full traceability of the measures deployed.
Concrete actions :
→ Deploy a defense in depth combining multiple independent security mechanisms, distributed at different levels of a system and designed as additional bulwarks in the event of a failure of another security layer.
→ Compile comprehensive technical documentation on the security measures implemented, their level of protection and their compliance with state-of-the-art standards (ANSSI recommendations, ISO27001 standards, etc.).
→ Formalize a procedure for managing data breaches allowing for rapid detection, risk assessment, notification within regulatory deadlines (72 hours), and comprehensive documentation of the incident and corrective actions.
Key point : this documentation will be crucial in the event of a data breach to demonstrate the appropriateness of the measures taken.
🔷 Third task: validity and traceability of consents for direct marketing
Marketing operations, particularly in the context of data pooling or brokerage, require a increased vigilance regarding legality and transparency.
Concrete actions :
→ Map all customer data flows, by precisely identifying the sources, recipients, purposes, and legal bases of each marketing operation. This map must be updated regularly, especially in the event of new commercial partnerships.
→ Systematically check the legality of each marketing campaign : explicit consent for direct marketing via electronic means (email, SMS), legitimate interest with a documented balance of interests for direct marketing by post or telephone, and respect for the right to object.
→ For data brokers and recipients, concretely verify the validity of the consents invoked at each link in the chain : the data controller cannot rely on simple contractual commitments from its partners, but must ensure that the individuals concerned have validly consented, both to be prospected and, where applicable, to the transmission of their data to identified or clearly identifiable third parties. This involves auditing the forms used by initial data collectors, ensuring the conformity of consent collection interfaces, and documenting these verifications.
→ Secure collection forms and information interfaces, by ensuring that the choices offered are not ambiguous or misleading, that the purposes of direct marketing and the categories of recipients are clearly stated at the time of collection, and that the presentation of options does not bias the expression of consent through inductive or unbalanced design mechanisms.
These decisions should not be analyzed in isolation. They reflect a coherent enforcement strategy, focused on three categories of infringements that are particularly easy to identify during CNIL inspections.
4. Anticipating 2026: an operational compliance imperative
These priorities help guide compliance actions. Companies that focus their compliance efforts on these three areas significantly reduce their exposure to the risk of audits and sanctions.
However, in the event of an audit, how the company responds to the CNIL is just as crucial. Find our recommendations in our article "CNIL Audit: 6 Mistakes That Raise the Risk of Sanctions".
These developments highlight the importance of anticipating CNIL investigations and defining an appropriate strategy if enforcement proceedings arise. Odoné assists companies throughout CNIL investigations and enforcement actions.
Would you like to assess your level of regulatory exposure or are you currently involved in CNIL proceedings? Contact us.
