Google’s €325M CNIL fine: cookies pushed before real consent (2025)
At a glance
- Brought by
- Regulator: CNIL (France)Regulator
- Company
- Google LLC and Google Ireland
- Sector
- Search and advertising
- Law
- ePrivacy cookie rules (France)
- Amount
- €325M
- Date
- Decided Sep 1, 2025
- Status
- Decided, with compliance order
Summary
On September 1, 2025, France’s data protection regulator, the CNIL, fined Google €325 million total for steering people into personalized-advertising cookies during account creation without clear disclosure, and for placing ads between messages in Gmail inboxes without consent.
What happened
The €325 million is split into €200 million against Google LLC and €125 million against Google Ireland, and the decision came with a compliance order. On the signup finding, the CNIL said Google did not make clear that accepting personalized-advertising cookies was tied to creating the account.
The mechanism
On the cookie side, consent that is nudged rather than freely given is not valid consent under the ePrivacy rules (the EU’s cookie and electronic-communications rules), which is what the CNIL applied here through Article 82 of the French Data Protection Act.

Why it was preventable
How a consent flow steers a user, and what a tag does the moment an account is created, are both testable. So is whether “accept” and “refuse” are presented as genuinely equal choices.
In the regulator’s words
The CNIL stated: “The display of such advertisements required the consent of Gmail users, in accordance with Article L. 34-5 of the French Postal and Electronic Communications Code (CPCE).”
Timeline
- Sep 1, 2025decided (CNIL deliberation SAN-2025-004), with a six-month order to comply.
Source
Questions
Who fined Google, and how much?
France’s data protection regulator, the CNIL, fined Google €325 million total on September 1, 2025: €200 million against Google LLC and €125 million against Google Ireland. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.
What was the cookie problem?
During account creation, users were steered toward accepting personalized-advertising cookies without a clear disclosure that accepting them was tied to the process. Consent that is nudged rather than freely given is not valid consent under the ePrivacy rules.
Was there a second issue?
Yes. Google also placed advertising between messages in Gmail inboxes without the consent that requires, under Article L. 34-5 of the French Postal and Electronic Communications Code.
Related cases
Shein’s €150M CNIL fine
Cookies before the banner; kept after “refuse all”
CNIL’s €750,000 fine against Condé Nast
Cookies on arrival; “reject” did not stop tracking
American Express’s €1.5M CNIL fine
Cookies before, and despite, refusal
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
