Cookie Consent Fines: What Regulators Actually Punish
€325 million to Google, 37 million kronor to Apoteket. Six years of enforcement decisions come down to four mistakes — and the most expensive Swedish one happened to a company whose consent banner was working correctly.
Most articles about GDPR fines quote the headline number — 4% of global turnover — and stop there. That number is not what has actually been happening. What has been happening is a steady run of decisions, many of them over things a developer could have seen in DevTools in under a minute.
Here is what regulators have actually fined companies for, what the pattern is, and how to check whether your own site has the same problem.
The international cases
France's CNIL has been the most active regulator on cookies specifically, because the French implementation of the ePrivacy Directive lets it act without going through the one-stop-shop mechanism. That is why so many of the big numbers are French.
| Company | Fine | What went wrong |
|---|---|---|
| €325m (Sept 2025) | Ads placed in Gmail's Promotions and Social tabs without prior consent; consent options presented unevenly | |
| SHEIN | €150m (Sept 2025) | Cookies placed without the user's consent |
| €150m (Jan 2022) | Refusing cookies took more clicks than accepting them | |
| Facebook Ireland | €60m (Jan 2022) | Same — no equivalent refuse button on the first layer |
| Microsoft Ireland | €60m (Dec 2022) | Tracers on bing.com set before consent |
| €100m (Dec 2020) | Advertising cookies placed on arrival, before any consent | |
| Amazon | €35m (Dec 2020) | Same, on amazon.fr |
| Yahoo EMEA | €10m (2023) | Cookies without valid consent, plus friction designed to discourage withdrawing consent |
| TikTok | €5m (Dec 2022) | Users could not refuse cookies as easily as accept them |
Read that column again. Almost none of these are exotic legal theories. They are: cookies before consent, and refusing being harder than accepting.
Sweden: IMY has been busy too
It would be comfortable to treat this as something that happens to American platforms in France. It is not. Sweden's Integritetsskyddsmyndigheten has issued its own decisions against well-known Swedish companies.
Bonnier News — 13 million kronor
In June 2023, IMY fined Bonnier News 13 million kronor for profiling customers and site visitors without consent. The company combined browsing behaviour with purchase data from across the group, and in some cases enriched it with externally purchased data — gender, household car ownership, postal code, area statistics — then used the resulting profiles for targeted advertising, direct mail and telephone sales.
Bonnier News had relied on legitimate interest under Article 6(1)(f). IMY disagreed, in a sentence worth pinning above a desk:
Kunderna kan inte förvänta sig att deras beteendedata samlas in för marknadsföringssyfte.
Customers cannot expect their behavioural data to be collected for marketing purposes.
Bonnier appealed. The Administrative Court upheld the decision in February 2025.
Apoteket — 37 million kronor, and Apohem — 8 million kronor
This one is different, and it is the most instructive case on this page.
In July 2025, IMY fined Apoteket AB 37 million kronor and Apohem AB 8 million. Both had the Meta Pixel on their sites, and both transferred far more to Meta than anyone intended: customer contact details — name, address, telephone number — alongside what those customers had bought. At Apoteket that included over-the-counter medicines for specific conditions, self-tests, treatments for sexually transmitted infections and sex toys.
The consent banner was not the problem. This case is widely described as data going to Facebook without consent. Read the decisions and that is not what happened, and the truth is more uncomfortable. From Apoteket's:
Apoteket har inte fört över uppgifter om kunder som nekat till marknadsföringskakor.
Apoteket did not transfer data about customers who refused marketing cookies. The consent gate worked. Customers who said no were correctly excluded. The transfers happened to customers who had said yes to marketing cookies — and then got far more collected about them than that yes ever covered.
The cause was Meta Pixel's Automatic Advanced Matching. Neither company deliberately turned it on. IMY's finding against both is a single article:
...har behandlat personuppgifter i strid med artikel 32.1 i dataskyddsförordningen genom att inte ha vidtagit lämpliga tekniska och organisatoriska åtgärder...
Article 32(1): inadequate technical and organisational security measures. Not Article 6, not consent. IMY even records that the Swedish ePrivacy cookie rule did not apply here, because the data was what customers typed into the site's own forms, not something read off their devices.
Apoteket's exposure ran from January 2020 to April 2022. Neither company found it on their own — Apohem learned of it from an external source, shut the pixel off and self-reported.
So: a working consent manager, a correctly configured banner, users who had genuinely consented, and two years of names, addresses and pharmacy purchases going to Meta anyway. Nobody chose that. A feature inside somebody else's tag did, and the site kept working perfectly the whole time.
The four mistakes
Across every case above, the failures reduce to four:
1. Trackers fire before consent. Google 2020, Amazon, Microsoft, SHEIN. The banner is present and correct, and the cookies are already set behind it.
2. Refusing is harder than accepting. Google 2022, Facebook, TikTok, Yahoo. One click to accept, two or three to refuse. This is now the single most-cited failure in European cookie enforcement.
3. Consent is assumed for things that need it. Bonnier News. Legitimate interest is a real legal basis, but behavioural profiling for marketing is generally not what it covers.
4. A tag does something you never authorised. Apoteket and Apohem. You cannot design your way out of this one in a banner. You find it by looking at what actually leaves the browser.
Checking your own site
The first three are visible in a browser in about a minute, and you do not need an account to do it:
- Open your site in a private window, open DevTools → Application → Cookies, and look before you touch the banner. Anything there that is not strictly necessary is mistake #1.
- Count the clicks to refuse versus accept, on the first layer. If refusing needs a trip into a settings panel, that is mistake #2.
- Open the Network tab, filter by your ad and analytics domains, and watch what goes out before you click anything.
Our cookie checker and Consent Mode checker automate the first and third of those for a single URL. No account, no email.
Where Katla fits
Being straight about this: no consent tool makes a site compliant, and anyone selling you that is selling you the thing regulators have been fining people for. What a tool can do is make the mechanics hard to get wrong.
- The cookie guard blocks writes before consent. Katla overrides
document.cookieand drops anything not in an allowed category, so a tag added by a marketer next quarter does not quietly reintroduce mistake #1. - Refuse is on the first layer, always. Accept, Reject and Customise sit in the same row at the same level. On narrow screens they stack full-width and equal — the reject button never becomes the small one.
- Scans look for pixels, not just cookies. Every scan renders your pages in a real browser and records tracking requests as well as stored cookies, with the endpoint each one called. That is the category the Apoteket case falls into.
- The guard is verified, not assumed. Each scan checks the guard is actually installed and running on the live site, because the most common way to be non-compliant is to be confident you are not.
None of that substitutes for knowing what your own tags do. It does mean the four mistakes above are visible to you before they are visible to anyone else.
This post summarises published enforcement decisions and is not legal advice. Every case links to the regulator's own announcement — if any of this is load-bearing for a decision you are making, read the original.
Sources: CNIL — Google €325m and SHEIN €150m · CNIL — Google €150m and Facebook €60m · CNIL — Google €100m (2020) · CNIL — Microsoft €60m · CNIL — Yahoo €10m · IMY — Bonnier News · IMY — Apoteket and Apohem · IMY — Apoteket decision (PDF) · IMY — Apohem decision (PDF)