Facebook Ireland Ltd. – €60,000,000 Fine (France, 2021)
France's CNIL fined Facebook Ireland Ltd. EUR 60 million for making it hard for users to refuse cookies. Users could accept cookies with one click but had to go through several steps to reject them. This matters because it shows that companies must make it easy for users to refuse tracking.
What happened
Facebook tracked users through cookies on its website without providing an easy way to reject them.
Who was affected
Internet users in France who visited Facebook's website and were tracked by cookies.
What the authority found
The CNIL found that Facebook's cookie setup violated French data protection laws by making rejection harder than acceptance.
Why this matters
This ruling highlights the importance of user consent and transparency in cookie policies. Other companies should ensure their cookie rejection options are as straightforward as acceptance.
National Law Articles
On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies could be refused on the website of Facebook.com. The CNIL subsequently conducted an online review of the websites and found that, although the websites offered a button to accept cookies immediately, there was no equivalent solution that would allow the Internet user to reject the deposit of cookies just as easily. Rather, several clicks were required to reject all cookies, in contrast to a single click to accept them. From this, the CNIL concluded that users would accept the deposit of cookies out of convenience with more frequency. It considered that the design of the cookie deposit interferes with the freedom of consent of Internet users and constitutes a violation of Art. 82 of the French Law on Informatics and Freedoms. In determining the fine, the fact that a large number of people were affected was taken into account in an aggravating manner. In addition, the CNIL took into account the significant profits that the companies were able to make from the advertising revenue generated indirectly from the data collected through cookies. The CNIL also pointed to the fact that the authority had already alerted the the company to this breach in February 2021. In addition to the fine, the CNIL issued an order requiring the companies to provide Internet users in France with a way to reject cookies as easily as they can accept them, within three months of being notified of the decision. Otherwise, companies would face the payment of a penalty of EUR 100,000 per day of delay.
Violations (3)
Cookie banner does not provide a clear reject/refuse all button at the same level as the accept button.
Art. 7 GDPR
Refusing cookies requires more clicks or steps than accepting them, or the reject option is less visually prominent.
Art. 7 GDPR
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Facebook Ireland Ltd. in FR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
31 December 2021
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€60,000,000
Enforcement Tracker ID
ETid-980
About this data
Cite as: Cookie Fines. Facebook Ireland Ltd. - France (2021). Retrieved from cookiefines.eu
Last updated: