Fino

Explainer No. 1 · Websites and marketing · Updated 6 Oct 2026 · 3 min read

Our cookie banner has no “reject” button. How big are the fines?

Potentially very big. European regulators expect refusing cookies to be as easy as accepting them. In December 2021 the French regulator, the CNIL, fined Google €150 million and Facebook €60 million because accepting took one click and refusing took several. Smaller cases end in fines of tens of thousands of euros, or in a reprimand (a formal warning without a fine).

The rule

Cookies are mainly governed by the ePrivacy Directive, not the GDPR. Its Article 5(3) says that storing or reading information on a visitor’s device

“is only allowed on condition that the subscriber or user concerned has given his or her consent”

The only exception is what is strictly necessary for a service the visitor asked for, such as remembering the items in a shopping basket. Analytics and advertising cookies need consent.

The Directive works through each country’s own law, which is why the decisions cite national laws: in France, Article 82 of the Loi Informatique et Libertés; in Spain, Article 22(2) of the LSSI. Read the Directive on EUR-Lex ↗

For the meaning of consent, the Directive uses the GDPR. Article 4(11) says consent must be “freely given, specific, informed and unambiguous”. Three more lines decide most banner cases:

  • Article 7(3): “It shall be as easy to withdraw as to give consent.”
  • Recital 42: consent is not free if the person is “unable to refuse or withdraw consent without detriment”.
  • Recital 32: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent.”

Regulators read these together. If saying no takes more effort than saying yes, the consent is not valid, and every non-essential cookie placed on the strength of it is unlawful.

Why the biggest fines come from France

Under the GDPR, a complaint about a company whose EU base is in Ireland normally goes to the Irish regulator. This is called the “one-stop shop”. Cookie rules come from the ePrivacy Directive, where the one-stop shop does not apply. So the CNIL could fine Google and Facebook directly for the cookies they placed on French visitors’ devices, and most of the large cookie fines in Fino come from France.

What regulators decided

The closest decisions in Fino, biggest fine first. Each line opens the decision with its source.

Decided the other way

See every decision in Fino and search for “cookie”.

Check your own banner

  1. Is “Reject all” on the first screen, next to “Accept all”?
  2. Do both buttons stand out equally: same size, similar colours, same number of clicks?
  3. Are any non-essential cookies placed before the visitor chooses? Open the site in a private window and look.
  4. Does “Reject” really stop them? Test it after clicking.
  5. Can visitors change their mind later just as easily, for example through a link in the footer?

Related explainers

Sources. ePrivacy Directive 2002/58/EC (consolidated text, EUR-Lex). GDPR text on Fino. Decisions from GDPRhub (noyb) and the CMS Enforcement Tracker, CC BY-NC-SA 4.0; descriptions rewritten in plain words by Fino.

Not legal advice. National rules can add to what is described here.