Retrospective regulator report for 2025, published in February 2026.
What happened
CNIL’s February 2026 review of its 2025 action records 83 sanctions and €486,839,500 in cumulative fines. It identifies cookies, employee monitoring and data security as major themes. Its activity also included compliance orders, reminders and warnings. Enforcement is therefore broader than the most dramatic fine in a headline.
Source: CNIL — original source ↗
What it means for your website
Use an annual overview to ask whether your own review is too narrow. A business might have a good cookie banner but poor access controls, or a clear privacy notice but no reliable process for requests. Break the work into areas with named owners. Your website developer can address technical tracking behaviour, while management may need to resolve retention decisions and staff processes. Avoid claiming that one plugin or one scan covers all of these topics. A short, maintained action list is more useful than an impressive document nobody owns or updates.
Three useful next steps
- Separate website, security and organisational privacy tasks.
- Give each issue an owner and review date.
- Keep automated findings in their proper scope.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
CNIL — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.