FineMeFine Intelligence
🇫🇷
EUFR

France

Europe's most aggressive privacy enforcer — the CNIL sets the continental standard

Commission Nationale de l'Informatique et des Libertés·CNIL

GDPRePrivacyLoi Informatique et LibertésNIS2
Eiffel Tower
5/5
Enforcement
3–6%
Penalty basis
14 mo
Avg investigation
124
Cases tracked
€312M
Total fines

Enforcement profile

The CNIL is the most aggressive DPA in the EU for cookie consent and adtech enforcement. It systematically investigates major platforms using its LINC unit and publishes detailed technical guidelines. Non-compliance with those guidelines is treated as aggravating. Early voluntary compliance during an investigation can reduce the final fine by 20–40%.

CNIL has a dedicated cookie enforcement unit (LINC) — the most active in Europe
Non-compliance with CNIL's published cookie guidelines is treated as an aggravating factor
CNIL can issue injunctions and compliance orders in addition to fines

Notable enforcement decisions

Google LLCePrivacy — cookie consent2022

Cookie refusal mechanism made more difficult than acceptance, violating French ePrivacy rules.

€150M
Facebook Inc.ePrivacy — cookie consent2022

Same cookie refusal mechanism violation issued simultaneously with the Google decision.

€60M
Amazon France LogistiqueGDPR Art. 52023

Disproportionate employee surveillance system tracking productivity in real-time.

€32M
Clearview AIGDPR Art. 6, 92022

Unlawful processing of biometric data of French residents without legal basis.

€20M

Active regulations

GDPR
ePrivacy
Loi Informatique et Libertés
NIS2
Eiffel Tower

The 330-meter iron lattice tower on the Champ de Mars is the world's most-visited paid monument and Paris's defining skyline element.

Enforcement data is based on publicly available decisions and may not reflect every action, appeal, reduction, or subsequent court ruling. Fine amounts are shown as reported at the time of the decision. This information is for intelligence purposes and does not constitute legal advice.