Condé Nast

CNIL’s 750,000 euro fine against Condé Nast: cookies before consent, and a “reject” that didn’t work (2025)

Regulator: CNIL (France)Last updated

At a glance

Brought by
Regulator: CNIL (France)Regulator
Company
Condé Nast (vanityfair.fr)
Sector
Digital publishing
Law
ePrivacy cookie rules (France)
Amount
€750,000
Date
Decided Nov 20, 2025
Status
Decided

Summary

On November 20, 2025, France’s data protection regulator, the CNIL, fined Les Publications Condé Nast 750,000 euros over cookie practices on vanityfair.fr: cookies set the moment a visitor arrived, some cookies presented as “strictly necessary” without useful information about their purposes, and a “reject” after which cookies were still placed and read.

What happened

The cookies set on arrival were ones that required consent, placed before the visitor touched the banner. The CNIL’s finding on “reject” covered withdrawing consent too. After either, new cookies that needed consent were still placed, and cookies already on the device kept being read.

The mechanism

Each of the three failures is testable. The reject failure is the quiet, common one: a banner that records the refusal but doesn’t gate the tags.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

Each of these is something a scan checks directly. Load the page and see what’s set before consent. Click “reject all” and see what fires anyway. The gap between what the banner claims and what the tags do is exactly what monitoring measures.

In the CNIL’s words

The regulator found that cookies subject to consent “were placed on the devices of users visiting the ‘vanityfair.fr’ website as soon as they arrived on the site, even before they interacted with the information banner to express a choice.”

Timeline

  1. Nov 20, 2025decision.
  2. Nov 27, 2025announced.

Source

Questions

Who fined Condé Nast, and how much?

France’s data protection regulator, the CNIL, fined Les Publications Condé Nast 750,000 euros on November 20, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.

What was wrong with the cookie banner?

Cookies were set before the visitor made any choice, some cookies appeared as “strictly necessary” without useful information about their purposes, and clicking “reject all” did not stop new cookies from being placed or existing ones from being read.

Why does a “reject” button often fail?

A banner can record the refusal without actually gating the tags. The choice is stored, and the trackers keep running, which is only visible if you test what fires after you click reject.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue