CNIL 2025: record-breaking fines signal new era of GDPR enforcement

In 2025, the CNIL imposed record penalties and an unprecedented level of requirements. An analysis of this stricter enforcement and strategic recommendations for companies.

With nearly 500 million euros in fines issued in 2025, the CNIL marks a turning point. Beyond the amounts, these decisions reveal a methodical toughening of its enforcement policy, characterized by higher penalties, a focus on specific infringements, and a more assertive application of European case law.

Key takeaways:

→ Increase in fine amounts

→ Penalties focused on specific areas

→ Consideration of the group's global turnover

1. Unprecedented Amounts

The figures speak for themselves: the CNIL no longer hesitates to impose penalties on an unprecedented scale.

Some of the most significant decisions of 2025 include:

•     325 million euros against GOOGLE, divided between Google LLC (200 million euros) and Google Ireland Limited (125 million euros

•    150 million euros against SHEIN

•    1.7 million euros against NEXPUBLICA

•     1.5 million euros against AMERICAN EXPRESS

•     1 million euros against MOBIUS SOLUTIONS LTD

•     900 000 against SOLOCAL MARKETING SERVICES

•     750,000 euros against CONDÉ NAST publications

In 2025, the average amount of sanctions issued by the CNIL under ordinary procedure reached approximately 44 million euros, compared to 4 million in 2024: in other words, on average, the sanction amounts increased tenfold between 2024 and 2025.

These amounts reflect the authority's clear desire to strengthen the deterrent effect of sanctions and to remind all economic players of the importance of complying with data protection rules.

Another significant development: for the first time, some of the sanctions imposed by the restricted committee exceed the amount initially proposed by the rapporteur (CONDÉ NAST and MOBIUS SOLUTION sanctions).

The CNIL's strengthened position was confirmed in 2026, as demonstrated by the CNIL's sanctions issued on January 14, 2026, which fined FREE MOBILE and FREE 27 million euros and 15 million euros respectively.

In short, in 2025, the CNIL demonstrated unprecedented firmness, reflecting a sanctions policy that was much more severe than in previous years.

2. Unprecedented level of requirements

Beyond the record amounts, it is the stringent requirements imposed by the CNIL that mark a significant shift. The authority is now adopting a particularly rigorous, even inflexible, approach that is evident at several levels.

🔷 Remediation is no longer enough to avoid heavy sanctions

The sanctions imposed in 2025 also demonstrate that the remediation of breaches is no longer a significant factor in mitigating the penalty.

For example, the CNIL imposed relatively heavy sanctions against AMERICAN EXPRESS and PUBLICATIONS CONDÉ NAST, despite the complete correction of the breaches identified during the procedure.

The authority considers the breach a past issue and imposes firm sanctions, despite the rapid adoption of corrective measures.

Although the Conseil d'État acknowledged, in the Optical Center case, that the speed with which the company implemented corrective measures could justify a reduction in the amount of the fine imposed by the CNIL, this assessment remains discretionary and, based on recent decisions, the amounts imposed reflect a very limited, even marginal, consideration of corrective actions, indicating a now greatly reduced tolerance.

🔷 Towards a zero tolerance GDPR compliance standard

The CNIL's strengthened requirements are also evident in its extensive interpretation of GDPR obligations, revealing a maximalist stance.

The clearest illustration concerns the security obligation under Article 32 of the GDPR, which, despite being qualified as an obligation of means, the CNIL tends to interpret as a virtual obligation of result.

The CNIL relies on the principle of “defense in depth”, which involves multiplying and superimposing independent security mechanisms, distributed at different levels of a system, in order to reduce the probability that a failure or an attack will compromise the entire system. Thus, if one layer is bypassed, subsequent layers should make it possible to detect, slow down, contain, or block the attack.

In practice, this requirement is particularly difficult, if not impossible, to meet, in a context where data breaches are increasing and no security measure is infallible.

This CNIL requirement reveals a desire to impose a maximum standard of compliance: compliance efforts are now insufficient. The authority imposes zero tolerance and expects exemplary, immediate, and complete compliance.

🔷 An ambitious but unpredictable law enforcement strategy

The dramatic tightening of sanctions imposed by the CNIL in 2025, which undeniably demonstrates a strong desire to make the GDPR a truly binding text, is reflected in practice by a worrying unpredictability for economic actors.

The CNIL is clearly seeking to establish itself as a leading enforcement authority, imposing fines of hundreds of millions of euros.

However, unlike the Autorité de la Concurrence (Competition Authority), which relies on a detailed calculation grid and a proven methodology for calculating fines, the CNIL operates within a much less structured framework: the 04/2022 guidelines of the European Data Protection Board (EDPB) on the calculation of fines are not explicitly applied in deliberations, the justification of the amounts used in accordance with the criteria of Article 83 of the GDPR is not required by the Council of State (EC, 10th/9th, 19 June 2020, no. 430810), and the reasons for the deliberations are sometimes very brief given the amounts involved.

This situation creates significant legal uncertainty: while the amounts of sanctions are reaching unprecedented levels, the criteria for anticipating their quantum remain largely opaque. As a result, businesses are unable to accurately calibrate their legal and financial risk, even when they are making significant compliance efforts.

In short, the CNIL's enforcement regime in 2025 is characterized by an unprecedented combination of maximum severity and legal uncertainty regarding the methodology for calculating fines.

Conclusion: anticipate the new paradigm of CNIL sanctions

Businesses must now incorporate a high risk of sanctions into their GDPR compliance management. The CNIL reached a decisive milestone in 2025, imposing fines of an unprecedented scale and applying a maximum level of requirements.

In light of the CNIL’s increasingly strict enforcement policy, an appropriate strategy can be crucial, both during an inspection and in the context of sanction proceedings. Odoné assists companies in CNIL litigation and enforcement matters.

Are you facing a CNIL investigation or enforcement proceedings? Contact us to discuss your situation.

Key Recommendations to navigate stricter CNIL sanctions

🔷 Rethink risk governance : raise GDPR risk to the level of strategic business risks by involving senior management and by systematically integrating GDPR issues into strategic and operational decisions.

🔷 Increase the level of data security : adopt a defence in depth approach and strengthen your security arrangements.

🔷 Strengthen the internal skills and resources of the DPO : Equip your data protection officer with sufficient resources and train your teams to create a true data protection culture at all levels of the organization, especially when it comes to data security.

🔷 Provision for high financial risk : the amounts of sanctions were multiplied by 10 on average between 2024 and 2025. Reassess your provisions and cyber insurance accordingly.

When compliance becomes strategic, The regulator's perspective becomes essential

With over 20 years of experience, Odoné supports leading organisations with rigorous, pragmatic and accessible guidance.

Make an appointment
flèche noire pointant vers la droiteflèche noire pointant vers la droite
Did you like this article?

Share it with colleagues or friends:
Logo bleu FacebookLogo bleu LinkedinLogo bleu X