France's CNIL fines Google €325M and Shein €150M for using ad cookies without users' consent; Google says it is reviewing the decision, which involves Gmail
France's data protection authority on Wednesday issued record fines against search giant Google and fast-fashion platform Shein …
Context & Ripple Effects
CNIL has repeatedly targeted Google’s consent practices: it previously fined Google over tracking cookies and later penalized the difficulty of rejecting them in France. This decision escalates that enforcement history by pairing Google with Shein and putting Gmail in scope.
The case makes consent design—not simply the presence of a cookie notice—the operative compliance issue. It follows CNIL’s earlier action over pre-consent tracking cookies and its later penalty for making rejection harder than acceptance.
First-order effects
- Google faces a €325M CNIL penalty tied to ad cookies and Gmail, while Shein faces a separate €150M penalty; Google says it is reviewing the decision.
- Both companies must contend with heightened scrutiny of whether users gave valid consent before advertising cookies were used in France.
Second-order effects
- Large consumer platforms and retailers with French audiences will have reason to re-check cookie flows, especially whether refusal is as usable as acceptance—the issue behind CNIL’s prior Google and Meta fines.
- Consent-management and advertising teams may need to prioritize demonstrable consent controls, because enforcement is reaching both a major platform and a fast-fashion seller rather than a single business model.
Third-order effects
- If this enforcement pattern persists, consent interfaces may become a more consequential competitive and compliance layer for ad-funded and commerce platforms, not a peripheral legal banner.
- Repeated CNIL action suggests that regulators can treat ineffective consent mechanisms as a recurring operational issue; the eventual impact on ad-data practices depends on the final resolution of challenges and subsequent enforcement.
The trend: European privacy enforcement is increasingly testing whether digital services’ consent architecture gives users a practical, not merely nominal, choice over advertising tracking.