Violations of the cookie consent requirement aren't a theoretical risk — data protection authorities across several EU countries have repeatedly issued substantial fines in recent years. The legal framework comes from Article 83(5) GDPR: serious violations can carry fines of up to €20 million or up to 4% of worldwide annual turnover, whichever is higher — even though, as described in the earlier posts in this series, the actual trigger formally comes from the ePrivacy Directive or its national implementation.
One of the best-known examples comes from France's data protection authority, the CNIL: in December 2020, it fined Google a total of €100 million and Amazon €35 million because both companies had set advertising cookies before users had given their consent. In January 2022, a further fine followed against Google — €150 million — along with one against Facebook (now Meta) of €60 million, this time because rejecting cookies on their respective websites was made noticeably more cumbersome than accepting them: accepting took one click, while rejecting required navigating through several menus. The CNIL treated this as a violation of the requirement that consent be as easy to refuse as to give.
Other data protection authorities acted too, generally with smaller sums against small and medium-sized businesses: missing cookie categorisation, third-party scripts that loaded before any interaction with the banner at all, or a "reject" button that simply didn't exist, forcing visitors into accepting because there was no genuine alternative. That last point in particular — a banner without an equally weighted reject option — is among the most common findings in audits, because it directly contradicts the requirement for a free decision that the Planet49 ruling confirmed.
What data protection authorities actually want to verify during an audit can be pieced together from these cases and from published regulatory guidance: were non-essential cookies set only AFTER active consent, not before? Was there a genuine, equally presented way to reject? Were the categories and purposes described with enough specificity? And — often the decisive point in an actual dispute — can the website operator still prove, after the fact, that a particular consent was genuinely given at a particular time?
That last point is frequently underestimated in practice. A technically flawless banner is of limited use if, in a dispute — following a complaint, say, or a spot-check — no record survives showing that and exactly how consent was given. The accountability obligation under Article 5(2) GDPR sits with the website operator, not the visitor: in case of doubt, the operator has to prove it, not the user disprove it.
For most small and medium-sized websites, fines on the scale of the cases above are unlikely — in practice, authorities focus on large reach, repeated violations, or targeted complaints. That doesn't change the underlying principle, though: informed, active, logged consent isn't a formality. It's the only basis on which a cookie banner actually serves its purpose at all.
