GDPR and Cookies: The New CNIL Recommendations for 2026
A theoretical €375,000 fine for cookie non-compliance is enough to send a chill down your spine. Take a breath: that figure almost never applies to a good-faith small business. That said, CNIL, France’s data protection authority, has genuinely tightened things up in 2026, with new multi-device consent recommendations published January 16 and finalized February 25, plus permanent automated monitoring of cookie banners. Here’s what actually changed and what to fix.
What Actually Changed in 2026
- CNIL published a multi-device consent recommendation (cross-device) in January 2026, governing the practice of applying a choice made on one device to all others (CNIL, January-February 2026)
- An automated crawler now continuously checks the compliance of cookie banners displayed on French websites
- Cookies remain the top reason for sanctions in France, accounting for 35% of CNIL’s cases
- 32% of companies checked by CNIL in 2025 were small or micro businesses
Forget the eye-watering figures you’ve seen floating around (up to €375,000 for a company, even higher in theory). In reality, of the 23 simplified sanctions CNIL has issued since January 2026 for cookie issues, the real average amount is €5,815, capped at €20,000 under this simplified procedure. The theoretical maximum amounts are rarely applied to a good-faith small business that fixes the issue quickly after a formal notice.
The 5 Requirements to Check on Your Banner
1. Two Buttons at the Same Level
“Accept” and “Reject” must be equally visible and equally easy to click, with no hidden path to reject.
2. Real Script Blocking Before Consent
No non-essential cookie (including Google Analytics) should fire before the user has made a choice.
3. A Permanently Visible Settings Link
Users must be able to change their choices at any time via a link accessible in the footer.
4. A Maximum Retention Period of 13 Months
This is the recommended maximum duration for advertising and analytics cookies that aren’t strictly necessary.
5. Clear Information from the First Level
If you enable multi-device consent, users must be informed as soon as the banner first appears, before they even click.
A small business running WordPress discovers, through a manual check, that its cookie banner plugin did show two buttons, but Google Analytics was firing as soon as the page loaded, before any consent. The fix took under an hour: configuring the plugin to block the script until the click. That’s exactly the kind of mistake that’s both the most common and the fastest to fix, rather than requiring a full site overhaul.
Frequently Asked Questions
Does the ePrivacy Regulation replace GDPR for cookies?
No, the European ePrivacy Regulation was formally withdrawn in February 2025. A “Digital Omnibus” proposal from November 2025 aims to fold cookie rules into GDPR, but it hasn’t been adopted yet.
Is multi-device consent mandatory?
No, it remains optional. CNIL only regulates it for companies that choose to implement it.
Does being logged into an account waive cookie consent?
No, authentication doesn’t waive the need to collect consent for non-essential cookies.
What’s the real risk for a small business?
In practice, a formal notice followed by a quick fix, rather than a financial penalty. The real average cookie sanction amount in 2026 is €5,815, far below the theoretical maximums.
