What CNIL enforced in 2025

Cookie compliance, security and employee monitoring all featured in the regulator’s annual review.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 9 February 2026

Retrospective regulator report for 2025, published in February 2026.

What happened

CNIL’s February 2026 review of its 2025 action records 83 sanctions and €486,839,500 in cumulative fines. It identifies cookies, employee monitoring and data security as major themes. Its activity also included compliance orders, reminders and warnings. Enforcement is therefore broader than the most dramatic fine in a headline.

Source: CNIL — original source ↗

What it means for your website

Use an annual overview to ask whether your own review is too narrow. A business might have a good cookie banner but poor access controls, or a clear privacy notice but no reliable process for requests. Break the work into areas with named owners. Your website developer can address technical tracking behaviour, while management may need to resolve retention decisions and staff processes. Avoid claiming that one plugin or one scan covers all of these topics. A short, maintained action list is more useful than an impressive document nobody owns or updates.

Three useful next steps

  1. Separate website, security and organisational privacy tasks.
  2. Give each issue an owner and review date.
  3. Keep automated findings in their proper scope.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

CNIL — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading