France's data regulator, the CNIL, fines Google €150M and Meta €60M for failing to let French users easily reject cookie trackers
says France, Waving $240M Fines CNIL : Cookies: FACEBOOK IRELAND LIMITED fined 60 million euros Ravie Lakshmanan / The Hacker News : France Fines Google, Facebook €210 Million Over Privacy Violating Tracking Cookies Katie Collins / CNET : Google and Meta fined $237M over user tracking in France James Vincent / The Verge : France fines Google and Facebook for pushing tracking cookies on users with dark patterns Kelvin Chan / Associated Press : France fines Google, Facebook millions over tracking consent Pierluigi Paganini / Security Affairs : France hits Google, Facebook with fines over ‘Cookies’ management Joseph Gobran / International Business Times : Why France Imposed Fines On Google And Facebook Over Privacy Issues Steve Dent / Engadget : French regulator fines Google and Facebook a combined $238 million over cookies PYMNTS.com : Europe Crackdown on Big Tech Continues as Facebook, Google Fined Over Cookies in France Chethan Rao / Android Headlines : French Regulator CNIL Slaps Google & Meta With $238 Million Fine Martin Coulter / Insider : France fines Google a record $170 million for making it too difficult to opt out of cookies Tweets: Mark Di Stefano / @markdistef : In order to refuse cookies, Facebook makes users click a button titled “Accept Cookies”. You have to laugh. https://twitter.com/... Mark Di Stefano / @markdistef : France is fining Facebook and Google a combined *€210 million* for... and I quote.... https://twitter.com/... Adam Levin / @adam_k_levin : A combined $235 million fine for two of the largest data mining companies on the planet is unlikely to hurt their bottom lines or alter their behavior, unfortunately. It's more likely to be viewed as the cost of doing business. https://www.zdnet.com/... Mike Masnick / @mmasnick : So... if I understand this properly, Google and Facebook have been fined because people are too lazy to understand how to use their own browsers with regards to cookies? https://www.cnil.fr/... @technology : Google and Facebook have been fined by the French privacy watchdog over the way they manage cookies https://www.bloomberg.com/... Talia Ringer / @taliaringer : My favorite Google consent anti-pattern is when you figure out how to disable targeted ads, and the UI tells you that you might also want to disable targeted ads from all of their competitors, then gives you a link to do so. I mean, yes, but also, really? https://twitter.com/...
Context & Ripple Effects
CNIL had already penalized Google over ad-personalization transparency in Android onboarding and later fined Google and Amazon for placing tracking cookies without consent. The new action extends that enforcement record from whether consent is obtained to whether refusing tracking is practically accessible.
The sanctions put Meta alongside Google in CNIL's cookie-consent campaign, while Google's subsequent failed appeal of an earlier cookie fine reinforced the regulator's enforcement position.
First-order effects
- Google faces a €150M penalty and Meta a €60M penalty for cookie-rejection flows that CNIL found difficult for French users to use.
- French users are the immediate beneficiaries of pressure on both platforms to make refusal of tracking easier, rather than steering consent through asymmetric interface design.
Second-order effects
- Amazon, previously fined by CNIL over non-consensual cookies in the related coverage, has a clear incentive to scrutinize its own consent flows as enforcement broadens beyond Google.
- For ad-funded platforms, consent-interface design becomes a compliance and revenue issue: easier rejection can reduce the pool of users available for tracking-based advertising.
Third-order effects
- Repeated CNIL actions—from Google's Android transparency fine to the earlier Google and Amazon cookie penalties—point toward privacy enforcement that evaluates the usability of consent, not merely the presence of a consent notice.
- If this approach holds, European platforms will have to treat equal-access refusal paths as a durable product requirement, raising the compliance burden for tracking-dependent services.
The trend: European privacy enforcement is moving from policing nominal consent toward testing whether users can meaningfully refuse tracking in the interface.