American Express

American Express’s €1.5M CNIL fine: ad cookies placed before, and despite, refusal (2025)

Regulator: CNIL (France)Last updated

At a glance

Brought by
Regulator: CNIL (France)Regulator
Company
American Express Carte France
Sector
Finance
Law
ePrivacy cookie rules (France)
Amount
€1.5M
Date
Decided Nov 27, 2025
Status
Decided

Summary

On November 27, 2025, France’s data protection regulator, the CNIL, fined American Express Carte France €1.5 million for placing advertising cookies on americanexpress.fr before any choice, dropping them despite a refusal, and continuing to read them after a visitor withdrew consent.

What happened

The CNIL’s findings go further than advertising cookies on arrival: other cookies were set before any choice too. And the cookies still read after a withdrawal were ones the visitor had agreed to earlier, so taking consent back did not stop them.

The mechanism

This is the same pattern as the larger CNIL cases, at a different scale. The consent record and the actual tag behavior did not match.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

Set the state to “refused,” then to “withdrawn,” and read what still fires. That is the check.

In the regulator’s words

The CNIL found: “As soon as the user arrived on the website … and even before interacting with the window allowing them to express a choice, several cookies were placed on their device, particularly for advertising purposes.”

Timeline

  1. Nov 27, 2025decided.

Source

cnil.fr.

cnil.fr

Questions

Who fined American Express, and how much?

France’s data protection regulator, the CNIL, fined American Express Carte France €1.5 million on November 27, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.

What was the failure?

Advertising cookies were placed on arrival before any choice, dropped despite a refusal, and still read after a visitor withdrew consent they had given earlier.

How do you test cookies “after withdrawal”?

Give consent, then withdraw it, and read what still fires. Under the ePrivacy rules, withdrawal has to actually stop the tags.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue