American Express’s €1.5M CNIL fine: ad cookies placed before, and despite, refusal (2025)
At a glance
- Brought by
- Regulator: CNIL (France)Regulator
- Company
- American Express Carte France
- Sector
- Finance
- Law
- ePrivacy cookie rules (France)
- Amount
- €1.5M
- Date
- Decided Nov 27, 2025
- Status
- Decided
Summary
On November 27, 2025, France’s data protection regulator, the CNIL, fined American Express Carte France €1.5 million for placing advertising cookies on americanexpress.fr before any choice, dropping them despite a refusal, and continuing to read them after a visitor withdrew consent.
What happened
The CNIL’s findings go further than advertising cookies on arrival: other cookies were set before any choice too. And the cookies still read after a withdrawal were ones the visitor had agreed to earlier, so taking consent back did not stop them.
The mechanism
This is the same pattern as the larger CNIL cases, at a different scale. The consent record and the actual tag behavior did not match.

Why it was preventable
Set the state to “refused,” then to “withdrawn,” and read what still fires. That is the check.
In the regulator’s words
The CNIL found: “As soon as the user arrived on the website … and even before interacting with the window allowing them to express a choice, several cookies were placed on their device, particularly for advertising purposes.”
Timeline
- Nov 27, 2025decided.
Source
Questions
Who fined American Express, and how much?
France’s data protection regulator, the CNIL, fined American Express Carte France €1.5 million on November 27, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.
What was the failure?
Advertising cookies were placed on arrival before any choice, dropped despite a refusal, and still read after a visitor withdrew consent they had given earlier.
How do you test cookies “after withdrawal”?
Give consent, then withdraw it, and read what still fires. Under the ePrivacy rules, withdrawal has to actually stop the tags.
Related cases
Shein’s €150M CNIL fine
Cookies before the banner; kept after “refuse all”
CNIL’s €750,000 fine against Condé Nast
Cookies on arrival; “reject” did not stop tracking
Google’s €325M CNIL fine
Cookies steered during signup; Gmail inbox ads
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
