CNIL’s 750,000 euro fine against Condé Nast: cookies before consent, and a “reject” that didn’t work (2025)
At a glance
- Brought by
- Regulator: CNIL (France)Regulator
- Company
- Condé Nast (vanityfair.fr)
- Sector
- Digital publishing
- Law
- ePrivacy cookie rules (France)
- Amount
- €750,000
- Date
- Decided Nov 20, 2025
- Status
- Decided
Summary
On November 20, 2025, France’s data protection regulator, the CNIL, fined Les Publications Condé Nast 750,000 euros over cookie practices on vanityfair.fr: cookies set the moment a visitor arrived, some cookies presented as “strictly necessary” without useful information about their purposes, and a “reject” after which cookies were still placed and read.
What happened
The cookies set on arrival were ones that required consent, placed before the visitor touched the banner. The CNIL’s finding on “reject” covered withdrawing consent too. After either, new cookies that needed consent were still placed, and cookies already on the device kept being read.
The mechanism
Each of the three failures is testable. The reject failure is the quiet, common one: a banner that records the refusal but doesn’t gate the tags.

Why it was preventable
Each of these is something a scan checks directly. Load the page and see what’s set before consent. Click “reject all” and see what fires anyway. The gap between what the banner claims and what the tags do is exactly what monitoring measures.
In the CNIL’s words
The regulator found that cookies subject to consent “were placed on the devices of users visiting the ‘vanityfair.fr’ website as soon as they arrived on the site, even before they interacted with the information banner to express a choice.”
Timeline
- Nov 20, 2025decision.
- Nov 27, 2025announced.
Source
Questions
Who fined Condé Nast, and how much?
France’s data protection regulator, the CNIL, fined Les Publications Condé Nast 750,000 euros on November 20, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.
What was wrong with the cookie banner?
Cookies were set before the visitor made any choice, some cookies appeared as “strictly necessary” without useful information about their purposes, and clicking “reject all” did not stop new cookies from being placed or existing ones from being read.
Why does a “reject” button often fail?
A banner can record the refusal without actually gating the tags. The choice is stored, and the trackers keep running, which is only visible if you test what fires after you click reject.
Related cases
Shein’s €150M CNIL fine
Cookies before the banner; kept after “refuse all”
Google’s €325M CNIL fine
Cookies steered during signup; Gmail inbox ads
American Express’s €1.5M CNIL fine
Cookies before, and despite, refusal
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
