Google

Google’s €325M CNIL fine: cookies pushed before real consent (2025)

Regulator: CNIL (France)Last updated

At a glance

Brought by
Regulator: CNIL (France)Regulator
Company
Google LLC and Google Ireland
Sector
Search and advertising
Law
ePrivacy cookie rules (France)
Amount
€325M
Date
Decided Sep 1, 2025
Status
Decided, with compliance order

Summary

On September 1, 2025, France’s data protection regulator, the CNIL, fined Google €325 million total for steering people into personalized-advertising cookies during account creation without clear disclosure, and for placing ads between messages in Gmail inboxes without consent.

What happened

The €325 million is split into €200 million against Google LLC and €125 million against Google Ireland, and the decision came with a compliance order. On the signup finding, the CNIL said Google did not make clear that accepting personalized-advertising cookies was tied to creating the account.

The mechanism

On the cookie side, consent that is nudged rather than freely given is not valid consent under the ePrivacy rules (the EU’s cookie and electronic-communications rules), which is what the CNIL applied here through Article 82 of the French Data Protection Act.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

How a consent flow steers a user, and what a tag does the moment an account is created, are both testable. So is whether “accept” and “refuse” are presented as genuinely equal choices.

In the regulator’s words

The CNIL stated: “The display of such advertisements required the consent of Gmail users, in accordance with Article L. 34-5 of the French Postal and Electronic Communications Code (CPCE).”

Timeline

  1. Sep 1, 2025decided (CNIL deliberation SAN-2025-004), with a six-month order to comply.

Source

cnil.fr.

cnil.fr

Questions

Who fined Google, and how much?

France’s data protection regulator, the CNIL, fined Google €325 million total on September 1, 2025: €200 million against Google LLC and €125 million against Google Ireland. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.

What was the cookie problem?

During account creation, users were steered toward accepting personalized-advertising cookies without a clear disclosure that accepting them was tied to the process. Consent that is nudged rather than freely given is not valid consent under the ePrivacy rules.

Was there a second issue?

Yes. Google also placed advertising between messages in Gmail inboxes without the consent that requires, under Article L. 34-5 of the French Postal and Electronic Communications Code.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue