Facebook Ireland Ltd. – €60,000,000 Fine (France, 2021)

€60,000,000Commission Nationale de l'Informatique et des Libertés31 December 2021France
final
ePrivacy
Fine

France's CNIL fined Facebook Ireland Ltd. EUR 60 million for making it hard for users to refuse cookies. Users could accept cookies with one click but had to go through several steps to reject them. This matters because it shows that companies must make it easy for users to refuse tracking.

What happened

Facebook tracked users through cookies on its website without providing an easy way to reject them.

Who was affected

Internet users in France who visited Facebook's website and were tracked by cookies.

What the authority found

The CNIL found that Facebook's cookie setup violated French data protection laws by making rejection harder than acceptance.

Why this matters

This ruling highlights the importance of user consent and transparency in cookie policies. Other companies should ensure their cookie rejection options are as straightforward as acceptance.

National Law Articles

AI-identified

Art. 82 loi Informatique et Libertés
Source verified 2 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies could be refused on the website of Facebook.com. The CNIL subsequently conducted an online review of the websites and found that, although the websites offered a button to accept cookies immediately, there was no equivalent solution that would allow the Internet user to reject the deposit of cookies just as easily. Rather, several clicks were required to reject all cookies, in contrast to a single click to accept them. From this, the CNIL concluded that users would accept the deposit of cookies out of convenience with more frequency. It considered that the design of the cookie deposit interferes with the freedom of consent of Internet users and constitutes a violation of Art. 82 of the French Law on Informatics and Freedoms. In determining the fine, the fact that a large number of people were affected was taken into account in an aggravating manner. In addition, the CNIL took into account the significant profits that the companies were able to make from the advertising revenue generated indirectly from the data collected through cookies. The CNIL also pointed to the fact that the authority had already alerted the the company to this breach in February 2021. In addition to the fine, the CNIL issued an order requiring the companies to provide Internet users in France with a way to reject cookies as easily as they can accept them, within three months of being notified of the decision. Otherwise, companies would face the payment of a penalty of EUR 100,000 per day of delay.

Violations (3)

No Reject Button
critical

Cookie banner does not provide a clear reject/refuse all button at the same level as the accept button.

Art. 7 GDPR

Reject Harder Than Accept
critical

Refusing cookies requires more clicks or steps than accepting them, or the reject option is less visually prominent.

Art. 7 GDPR

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Facebook Ireland Ltd. in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

31 December 2021

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€60,000,000

Enforcement Tracker ID

ETid-980

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 100%

Cite as: Cookie Fines. Facebook Ireland Ltd. - France (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: