News

πŸ‘‰ Non-compliant practices

Cookies & Trackers, Legal basis | 10/09/2025

πŸ›‘οΈ CNIL: €325M for Google & €150M for SHEIN — Enforcement on cookies & consent

Regulator: CNIL
Decision, Google: SAN 2025-004
Decision, SHEIN: SAN 2025-005

⚠️ The CNIL has just severely sanctioned two giants for non-compliant practices on cookies and marketing communications.
πŸ” Clear message: no trackers and no “disguised” ads without prior consent (freely given, informed, specific, unambiguous).

🧾 What the CNIL founds
βœ‰οΈ Google (€325M): insertion of ads between Gmail emails (Promotions/Social tabs) without prior consent, plus πŸͺ cookies set without valid consent during account creation.
βš–οΈ Injunction: ⏳ 6 months to comply, then πŸ’Έ €100,000/day penalty payment (astreinte). (Source: CNIL)
πŸ›οΈ SHEIN (€150M): πŸͺ cookies placed without the user’s consent, 🧩 incomplete banner, ❌ ineffective refusal (“Reject all” did not prevent some trackers), insufficient information about third parties. (Source: CNIL)

πŸ“š Key takeaways (GDPR / ePrivacy)
🧭 Legal framework applied: ePrivacy (Article 82 of the French Data Protection Act) and French Electronic Communications Code L.34-5, complementing the GDPR.
βœ… Consent must be clear, and refusal as easy as acceptance.
Consent was not informed in the account-creation journey, because nothing indicated that access to Google group services was conditioned on placing advertising-related trackers. (Source: CNIL)

πŸ› οΈ To do now
πŸ§ͺ Test your CMP: πŸ™…‍♂️ one-click refusal; 🚫πŸͺ no cookies before consent, except strictly necessary ones.
 πŸ”Ž Verify choices are respected: 🚫 no setting/reading after “Reject all.”
🧾 Document evidence: πŸ—‚οΈ consent logs.

Back to news list

Explore all our areas of expertise:

]]>