French data protection agency CNIL fines Google $120M and Amazon $42M for placing tracking cookies without consent
France's data protection agency, the CNIL, has slapped Google and Amazon with fines for dropping tracking cookies without consent. — Google has been hit with a total …
Context & Ripple Effects
This 2020 action sits at the start of a repeat-offender arc: a year earlier, the CNIL had already fined Google €50M under GDPR over Android's ads-personalization onboarding, and this cookie-consent case extends the same enforcement logic from app flows to the web's most basic tracking mechanism.
The pattern only intensified afterward — the regulator later penalized Google and Meta for making it hard to reject trackers as easily as accept them, and by 2025 had escalated to €325M against Google alongside Shein for ad cookies without consent. The 2020 fines established that consent banners alone don't satisfy French law.
First-order effects
- Google ($120M) and Amazon ($42M) face direct financial penalties and must rework how french-language sites under their control present cookie choices before any further visits are tracked.
Second-order effects
- Every large ad-funded platform serving French users now has to treat pre-ticked or default-on tracking as a compliance liability, pushing consent-management vendors and publishers toward explicit opt-in flows rather than dark-pattern defaults.
Third-order effects
- If the CNIL's escalating fine cadence holds — from €50M in 2019 to triple-digit millions by 2025 — cookie consent becomes a recurring cost of doing business in France rather than a one-time fix, strengthening the EU-wide model of national regulators enforcing data rules against US platforms.
The trend: European data regulators are converting cookie consent from a checkbox formality into an escalating, repeat-penalty enforcement regime aimed at ad-tracking business models.