# Cookies — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/cookies
> Sources are cited per item. Verify against the official texts before relying on them.

Online tracking technologies and consent requirements

## Overview

## Legal Framework

Cookie regulation sits at the intersection of the ePrivacy Directive (2002/58/EC) and the GDPR. Article 5(3) of the ePrivacy Directive requires prior informed consent for storing or accessing information on a user's device — the provision that governs most non-essential cookies and similar tracking technologies. The GDPR supplies the substantive standard for that consent: it must be freely given, specific, informed, and unambiguous under Article 4(11) and [Article 7]((/laws/gdpr/art-7), with Article 6(1)(a) providing the corresponding legal basis. The EDPB has confirmed the linkage between the two instruments:

> "The notion of consent in the draft ePrivacy Regulation remains linked to the notion of consent in the GDPR."
> — [EDPB Guidelines 05/2020 §6](/posts/38053#seg-6)

For tracking that serves advertising or analytics rather than strictly necessary functionality, consent under the ePrivacy instrument is required before the cookie is set or read. The GDPR then governs the downstream processing of any personal data collected through that cookie, including questions of controller responsibility and lawful basis.

## Key Developments

The CJEU's ruling in *Wirtschaftsakademie* established that joint controllership can arise even where one party merely embeds a third-party tracking tool. A fan page administrator who integrates Facebook's social plugin becomes a joint controller because the data collection via cookies is carried out for mutual benefit. The Court emphasised that:

> "the production of those statistics is based on the prior collection, by means of cookies installed by Facebook on the computers or other devices of visitors to that page, and the processing of the personal data of those visitors for such statistical purposes."
> — [Wirtschaftsakademie ¶38](/posts/6135#seg-38)

The Court further noted that the processing was "intended, in particular, to enable Facebook to improve its system of advertising, in order better to target its communications" — confirming that advertising-driven cookie deployment falls squarely within the GDPR's material scope.

On the consent quality front, the EDPB has addressed cookie walls directly. Where a website blocks all content unless the user clicks "Accept cookies," the consent obtained is not valid:

> "Since the data subject is not presented with a genuine choice, its consent is not freely given."
> — [EDPB Guidelines 05/2020 §40](/posts/38053#seg-40)

Enforcement actions reinforce these thresholds. The Italian Garante fined Depac €15,000 for insufficient legal basis for data processing through cookies, and the EDPB's Cookie Banner Taskforce has been coordinating cross-border enforcement against deceptive or manipulative cookie consent interfaces since 2023.

## Status of the Debate

This topic is actively contested in court. The core legal framework — ePrivacy Article 5(3) consent plus GDPR consent standards — is well established, but its application to specific tracking technologies, joint controllership allocation, and the permissibility of cookie walls and equivalent mechanisms remains in flux. The pending ePrivacy Regulation could resolve ambiguities around scope and enforcement, but until its adoption, national courts and DPAs are filling gaps with divergent approaches. The central open question is whether consent obtained through "accept or leave" architectures can ever satisfy the "freely given" requirement, and what constitutes a genuinely equivalent "reject all" option. A CJEU referral on cookie wall validity would settle the debate definitively.

## Practical Guidance

- **Obtain prior opt-in consent before setting non-essential cookies.** Article 5(3) ePrivacy Directive requires it; pre-ticked boxes or implied consent do not satisfy the GDPR standard under Article 4(11).

- **Provide a genuine "reject all" option equivalent to "accept all."** Following the EDPB's guidance, any mechanism that conditions content access on cookie acceptance renders consent invalid as not freely given.

- **Identify all controllers involved in cookie-based processing.** *Wirtschaftsakademie* confirms that embedding third-party tracking tools can create joint controllership — assess whether your organisation exercises influence over the purposes and means of processing.

- **Disclose purposes specifically.** Generic "we use cookies to improve our services" statements are insufficient; users must understand what data is collected, by whom, and for what advertising or analytics purpose before consenting.

- **Audit cookie inventories regularly.** Document every cookie set, its provider, its purpose, and its legal basis — and ensure that consent preferences are enforced technically, not merely recorded.

## Legislation (full text of key provisions)

### EPRIVACY-ART-13

*Source: ePrivacy Directive, eprivacy-art-13, 2025-10-08 — https://overview.legal/posts/3181*

### EPRIVACY-ART-6

*Source: ePrivacy Directive, eprivacy-art-6, 2025-10-08 — https://overview.legal/posts/3180*

### EPRIVACY-ART-5

*Source: ePrivacy Directive, eprivacy-art-5, 2025-10-08 — https://overview.legal/posts/3179*

### EPRIVACY-ART-2

*Source: ePrivacy Directive, eprivacy-art-2, 2025-10-08 — https://overview.legal/posts/3178*

### EPRIVACY-ART-1

*Source: ePrivacy Directive, eprivacy-art-1, 2025-10-08 — https://overview.legal/posts/3177*

### Recital 173 — Relationship with ePrivacy Directive

*Source: GDPR, gdpr-rec-173-en, 2016-04-27 — https://overview.legal/posts/91861*

This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council (18), including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation,

## Case law

### BVwG - W 108 2284491-1

*Source: Federal Administrative Court, 2024-07-31 — https://overview.legal/posts/122850 — original: https://gdprhub.eu/index.php?title=BVwG_-_W_108_2284491-1*

Facts — The data subject visited a website operated by a media company (the controller). Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first layer presented only an option to accept the cookies or to manage the options. The cookie manage option was presented as a link. When the data subject clicked on the accept button, they also agreed to pre-ticked options, visible only within the cookie management link. The reject button was a part of the second layer of the cookie banner (within the cookie management link). The data subject lodged a complaint with the Austrian DPA (DSB), claiming the controller violated, inter alia, Article 5(1)(a) GDPR and Article 6(1)(a) GDPR. The data subject was represented by noyb. The controller argued to the DPA that the website provided access to online newspaper articles. Because of that, the processing activities were carried for journalistic purposes and the DPA was not competent to hear the case. In the meantime the controller updated the settings of the cookie banner and introduced a reject button on its first layer, next to the accept button. Also, the link to manage the cookie settings was redesigned as a button. Moreover, the controller added a floating icon, allowing the website users to withdraw the consent given at any time. If a website user rejected the cookies or withdrew the consent via the floating icon, the controller would interpret such a conduct to be an objection under Article 21 GDPR. Additionally, the controller informed they deleted the data concerning the data subject. In response, the data subject emphasized that due to new settings of the website, the controller wrongly qualified certain cookies to be strictly necessary. In consequence, the controller installed the cookies before the website’s user interacted with the cookie banner, violating Article 5(3) ePrivacy Directive. Although the controller announced that it would implement a completely new cookie banner, they later retracted from that plan. The controller changed the cookie banner and – after improving it initially – removed the reject button again. Eventually, updated cookie banner didn’t include a reject button on the first layer any longer. The DPA issued a decision, ordering the controller to modify the cookie banner so that its first layer offered an option to close the cookie banner without giving consent. This option had to be visually equivalent to the accept button. The DPA rejected the applications of the data subject regarding the deletion of its data, an order to stop unlawful processing and establishing the violation of data confidentiality (“Recht auf Geheimhaltung”). The controller appealed the DPA’s order to introduce an equivalent reject option in the first layer of its cookie banner to the Federal Administrative Court (Bundesverwaltungsgericht – BVwG). After hearing the parties and visiting the website itself the court issued its decision. Holding — The court dismissed the appeal of the controller as unfounded. No exemption from the GDPR through media privilege (“Medienprivileg”) — The controller’s processing activities didn’t fall within the scope of journalistic purposes. The court emphasised that the controller placed the cookies and processed the collected data for analytical and advertising purposes. Need for an equivalent reject option in cookie banners — The court also upheld the interpretation of the DPA that the first layer of the cookie banner needs to contain a visually equivalent option to reject cookies. According to the court Article 7(3) GDPR implies that refusing consent shall be as easy as giving consent. In particular, refusing consent shall not require more interactions than giving consent. In the case at hand consenting required only one click, whereas rejecting consent required two clicks. Therefore no equivalence between the options was given. Furthermore, the different design of the options in the first layer – a button for consent on one hand and a link to access the second layer on the other – equally lead to the conclusion that the options cannot be considered equivalent. A mere explanation in the first layer of the cookie banner on how to reject cookies does not change this assessment. Additionally, the cookie manage link at the bottom of the website is not an equivalent option either, since it is only available after an interaction with the cookie banner. Hence, the DPA order was found to be correct. The court did not find that the controller had complied with this order in the meantime.

### CJEU - C-673/17 - Planet49

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/122861 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-673/17_-_Planet49*

Facts — A German company called Planet49 organized an online lottery hosted on their webpage. In order to participate in the lottery the participant had to enter a name and an address. Underneath the input field there were two checkboxes. The first checkbox required the user to accept being contacted by firms for promotional offers. The second checkbox required the user to consent to cookies being installed on the participants computer. The first checkbox was not pre-ticked, while the second checkbox was. To participate in the lottery the user had to tick, at least, the first checkbox. The Federation of German Consumer Organisations (the “Bundesverband”) initated court proceedings against Planet49, claiming that the declaration of consent did not meet the requirements for a freely given and informed consent. The case reached the Federal Court of Justice (“Bundesgerichtshof”), which referred questions regarding the scope of consent under provisions of the Data Protection Directive 95/46/EC, the ePrivacy Directive 2002/58/EC, and the GDPR to the CJEU. The case was referred to the Court of Justice on 5 October 2017 - before the GDPR became applicable on 25 May 2018. As the Bundesverband sought an injunction to prevent Planet49 from continuing its practices in the future, the Court’s decision takes into account the requirements for consent on the basis of both the Directive 95/46/EC and the GDPR. The decision of the Court — The Court assessed the requirements for a valid consent under both Directive 95/46/EC and the GDPR and found that there were no substantial differences between them, noting however that the GDPR explicitly states requirements that need to be inferred under Directive 95/46/EC. As the Court notes, the notion of consent under the ePrivacy directive should have the same meaning as consent under Directive 95/46/EC and the GDPR. Consent — A key question posed by the referring court in relation to the consent requirement was whether consent could be “passive” or if it had to be “active”. The Court concluded that a key component of a valid consent is that the consent is given by a clear affirmative act. Requiring the user to untick a box to “opt-out” is not sufficient. The Court emphasized that inaction is insufficient to establish whether the consent is a “freely given and informed decision”. The Court concludes on this basis that Planet 49’s consent model was inadequate with regards to securing a compliant consent to place cookies on the user’s device. The Court’s conclusion follows from reading Article 5(3) of the ePrivacy directive in conjunction with Article 2(h) of Directive 95/46/EC, and noting that active consent is now regulated under GDPR. For the consent to be valid, it must be “given” on the basis of “clear and comprehensive information” communicated to the user. The requirement for the information to be “clear and comprehensive” implies that in cases where the cookie aim to collect information for advertising purposes, there should be information about “the duration of the operation of cookies and whether or not third parties may have access to those cookies”. Worth noting here is that the Court explicitly referred to Article 13 GDPR and Article 10 Directive 95/46/EC as the relevant framework for determining which information should be provided to the user. The ePrivacy directive and GDPR — The German law transposing the ePrivacy directive establishes a difference between the collection of “personal data” and other data. The Court referenced the earlier opinion of the AG, noting that the AG correctly interpreted the provision to protect the user from any privacy interference, irrespective of whether that interference concerns personal data or other data. The obligation to secure a valid consent for the placement of cookies is therefore applicable regardless of the legal status of that information. A consequence of this view is that the German incorporation of directive 2002/58 is not fully in line with the directive. It is worth highlighting that Article 5(3) of the ePrivacy directive carves out an exception for the consent requirement for cookies that are “strictly necessary” to provide the service as requested by the user. In broad strokes, this means that so-called “functional cookies” that are essential for browsing and using the website, typically for holding items in the cart while browsing a web shop, are exempt for the consent requirement (most often first-party session cookies).

### CE - 451423

*Source: Supreme Administrative Court, 2022-06-27 — https://overview.legal/posts/108993 — original: https://gdprhub.eu/index.php?title=CE_-_451423*

Facts — The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded this complaint to the Luxembourg DPA under the 'one stop shop' mechanism of Article 56 GDPR. The luxembourg DPA started an investigation regarding Amazon's use of cookies and its compliance with the GDPR and the ePrivacy directive. However, the French DPA started its own investigation into Amazon's compliance with Article 82 of the French Data protection act, a national implementation of Article 5(3) of the ePrivacy directive. (directive 2002/58/EC). This investigation regarding Article 82 had resulted in decision SAN-2020-013. In this decision, the French DPA fined Amazon €35,000,000 for the failure to obtain prior consent and the failure to inform users of their rights with regards to the processing of their data, which was mandatory under Article 82 of the Data Protection Act. The DPA found that when a user visited the "Amazon.fr" site, a large number of cookies with advertising purposes were automatically placed on the data subjects computer. Because this type of cookie was not essential to the service provided by the controller, the DPA considered that the controller had not complied with the obligation to obtain the consent of Internet users before depositing the cookies. Amazon appealed this decision at the Conseil d'Etat, the French Supreme Administrative Court, and requested its annulment. Amazon also asked the Conseil to refer several questions to the CJEU for a preliminary ruling. Among other arguments, Amazon claimed that the French DPA had made an incorrect interpretation of the law regarding its competence and had disregarded its competence by imposing the contested sanction. The controller also stated that the involvement of the French DPA, when the Luxembourg DPA was already involved, constituted a violation of Article 50 of the Charter of Fundamental Rights. According to this article, the same person may not be prosecuted more than once for the same acts. Holding — With regard to the application of the "one-stop shop" mechanism and the CNIL's jurisdiction: The Conseil ruled that the application and enforcement of the ePrivacy directive was the responsibility of national DPAs according to Article 15a of the directive. The "one-stop shop" mechanism did not apply in this case, even when there was a form of a cross-border processing. The Conseil also stated that the absence of a 'one-stop shop' mechanism did not imply any infringement of Article 50 of the Charter of Fundamental Rights, because the DPA only ruled on breaches of national law transposing EU law in the contested decision, and not on GDPR related violations. The Conseil also assessed the compatibility of Article 3 of the French Data protection Act with the ePrivacy Directive. The Conseil determined that Directive 2002/58/EC did not prevent the French DPA to apply the French data protection Act (including Article 82). The Directive would therefore also not prevent the French DPA from penalising the controller for supposed violations of Article 82 of the French data protection Act. Therefore, the Conseil established that the French DPA could enforce the French data protection act against any person or legal entity responsible for the processing of data who had an establishment in France, irrespective of the location of the principal establishment of the responsible entity. This enforcement by the DPA would also not constitute violations of articles 49 (Freedom of establishment) or 56 (Freedom to provide services) of the TFEU. With regard to the sanction imposed by the CNIL: The Conseil deemed that the applicant was sufficiently informed regarding the scope of the DPA's investigations, the facts and the legal grounds on which the sanction was based. Moreover, the Conseil considered that the applicant was given sufficient time to present its defence. The Conseil also ruled that the involvement of the French DPA, while the Luxembourg DPA was the lead supervisory authority, was not enough to constitute a breach of the equality of arms principle. Amazon had argued that the involvement of the French DPA in the procedure had enabled the French DPA to gain access to privileged and confidential information and had used this information as a basis for its own decision. The Conseil determined that Amazon did not provide enough proof for this argument and stated that Amazon was not able to prove that was the procedure contrary to Article 15a(4) of Directive 2002/58/EC. On a possible violation of Article 50 of the Charter of Fundamental Rights: The Conseil explained, based on the CJEU's case law (Aklagaren v Akerberg Fransson C-617/10, Powszechny Zaklad Ubezpieczen na Zycie SA of C-617/17 and bpost SA v Belgian Competition Authority C-117/20), that the principle invoked by the applicant, that the same person may not be the subject of several proceeding in respect of the same facts, was not violated by the French DPA. The Conseil stated that the principle could only be enforced when criminal proceedings had been definitively terminated. This was in particular the case when a criminal penalty had become final. The Conseil held that Amazon was not found to be the subject of a final sanction issued by the Luxembourg DPA for the facts that had resulted in the €35,000,000 fine in the contested decision. The Conseil rejected the applicant's claim for a reference for a preliminary ruling on the matter. Regarding the application of French Data Protection Act by the French DPA, Amazon had argued that the legal framework regarding cookies was not stable and unclear at the time when proceedings against Amazon were started. The Conseil concluded that it had published guidelines detailing obligations for entities under the applicable law, and considered that the fact that other national supervisory authorities had taken divergent positions in interpreting the conditions and procedures applicable to the collection of user consent had no bearing on the application of the French Data Protection Act by the French DPA. On the proportionality of the sanction imposed: Taking into account the elements assessed by the French DPA to calculate the imposed fine, the Conseil ruled that the DPA had not imposed a disproportionate penalty on the controller. Consequently, the Conseil rejected the entirety of controller's claims.

### CE - 449209

*Source: CE, 2022-01-28 — https://overview.legal/posts/122847 — original: https://gdprhub.eu/index.php?title=CE_-_449209*

Facts — On 7 December 2020, the French DPA (CNIL) imposed two fines totaling € 100 million on Google LLC and Google Ireland Ltd for violating Article 82 of the French Data Protection Act (which transposes the ePrivacy Directive). Google (1) had not obtained the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) had lacked to provide information, and (3) had not implemented a mechanism to refuse the cookies. Google did not agree with the CNIL’s decision and brought the issue before court. First, it claimed that, since there is cross-border processing, the Irish DPA (DPC) is the lead supervisory authority since Google’s main establishment in the EU is in Ireland, and the CNIL therefore did not have competence to rule on this matter according to the one-stop-shop mechanism. Second, it found the fine to be disproportionate. Hence, it requested the Council of State to annul the decision, and to refer two preliminary questions to the CJEU, asking: (1) whether the one-stop-shop mechanism provided for in Article 56 GDPR is excluded in the context of cross-border processing that falls within the scope of both the ePrivacy Directive and the GDPR, and (2) whether Article 15a ePrivacy Directive violates the right to data protection because does not provide an obligation, but rather an option, “for the competent national regulatory authorities to adopt measures to ensure effective cross-border cooperation in the enforcement of national laws adopted pursuant to the directive and to create harmonised conditions for the provision of services involving cross-border data flows”. Holding — The Council of State rejected Google’s appeal. First, according to the Council, the ePrivacy Directive, implemented in the French Data Protection Act, does not provide for the application of the one-stop-shop mechanism as mentioned in Article 56 GDPR. Although the requirements for consent are regulated by the GDPR the deposit of cookies is regulated by the ePrivacy Directive. Hence, even if cross-border processing takes place, the CNIL is competent to monitor compliance with the objectives of such Directive. The Council then notes that “it follows that, as regards the control of the operations of access and recording of information in the terminals of users in France of an electronic communications service, even if they are the result of cross-border processing, the measures to monitor the application of the provisions transposing the objectives of Directive 2002/58/EC fall within the competence conferred on the CNIL by the Law of 6 January 1978.” The Council stipulated that there is no need to refer preliminary questions to the CJEU, because it had no doubt as to whether the one-stop-shop mechanism should be excluded in the context of cookies. Second, the Council rejected Google’s argument that their right of defense had been infringed by the CNIL because they did not provide a prior formal notice, since it is not required to provide such a formal notice before imposing a sanction. Third, on the substance of the matter, the Council confirmed the three violations of Article 82 of the Data Protection Act: (1) not obtaining the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) not providing clear information on the deposit of cookies, and (3) not implementing a mechanism to refuse the cookies. Lastly, the Council stated that the fines were not disproportionate in light of the financial capacities of the “two” companies. It considered Google’s market share of more than 90% with (an estimated) 47 million users in France and the large profits that follow from the targeted online advertisement. Moreover, it stated that Google did not genuinely cooperated with the CNIL since it did not provide advertising revenues, and the breaches were serious.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### CE - 449212

*Source: CE, 2021-03-04 — https://overview.legal/posts/125660 — original: https://gdprhub.eu/index.php?title=CE_-_449212*

Facts — On December, 7 2020, the French DPA imposed a financial penalty of 60 Million euros fine against Google LLC and a 40 million euros against Google Ireland Limited in accordance with the General Data Protection Regulation (GDPR) and ePrivacy Directive 2002/58/EC, for lack of transparency, inadequate information and lack of valid consent regarding for violating the regulation on cookies while operating the website google.fr. The sanction was accompanied by an order to comply with article 82 of the French Law on data protection (Law Informatique et Libertés), under three months on penalty of a €100,000 fine per day of delay. The companies appealed to the Conseil d’État in interim procedure against the CNIL's decision, arguing that the French DPA was not the competent authority because it was not the lead supervisory authority for Google LLC or Google Ireland Limited. Dispute — Is the CNIL territorially competent to investigate and sanction a company for violating the information principle when depositing cookies if it is not the lead supervisory authority of the company? The CNIL considered that Google does have EU headquarters in Ireland, but that this Irish entity ‘did not have a decision making power’ in relation to the relevant cross-border data processing activities to which the complaints related. For that reason the CNIL decided that the One Stop Shop mechanism did not apply and that the CNIL, like any other European supervisory authority, was therefore competent to make a decision. Holding — The Conseil d’État rejected the request made by Google and ruled that the French DPA was territorially competent on this matter even though it is not the lead supervisory authority. The court stated that Article 82 of the Law Informatique et Libertés was a transposition of Article 5(3) ePrivacy Directive 2002/58/EC into French Law when dealing with cookies and that the CNIL is charged with enforcing this Directive. As such, the one-stop shop mechanism provided for in Article 56 GDPR does not apply in the present case.

### BGH - I ZR 7/16

*Source: BGH, 2020-05-28 — https://overview.legal/posts/122851 — original: https://gdprhub.eu/index.php?title=BGH_-_I_ZR_7/16*

Facts — See facts at the GDPRhub entry to the "Planet 49 case" (C-637/1/). The second checkbox containing a preselected tick used by the defendant (Planet 49) read as follows: {| class="wikitable" !English translation !German original |- |‘I agree to the web analytics service Remintrex being used for me. This has the consequence that, following registration for the lottery, the lottery organiser, [Planet49], sets cookies, which enables Planet49 to evaluate my surfing and use behaviour on websites of advertising partners and thus enables advertising by Remintrex that is based on my interests. I can delete the cookies at any time. You can read more about this here.’ |"Ich bin einverstanden, dass der Webanalysedienst Remintrex bei mir eingesetzt wird. Das hat zur Folge, dass der Gewinnspielveranstalter, [Planet49], nach Registrierung für das Gewinnspiel Cookies setzt, welches Planet49 eine Auswertung meines Surf- und Nutzungsverhaltens auf Websites von Werbepartnern und damit interessengerichtete Werbung durch Remintrex ermöglicht. Die Cookies kann ich jederzeit wieder löschen. Lesen Sie Näheres hier." |} In the explanation linked to the word "here", it was pointed out that the cookies would receive a specific, randomly generated number (ID) associated with the registration data of the user who entered his/her name and address in the web form provided. If the user with the stored ID would visit the website of an advertising partner registered for Remintrex, this visit should be recorded, as well as which product the user is interested in and whether a contract is concluded. Holding — Following the CJEU's reasoning in its preliminary ruling, the BGH dismissed the defendants' appeal and, on the plaintiff's appeal, overturned the appellate judgment regarding cookie consent and restored the first instance conviction of the defendant: The declaration of consent by the preselected tick box does not constitute an "informed indication of the data subject's wishes" within the meaning of Article 2(h) Directive 95/46/EC or an "informed and unambiguous indication of the data subject's wishes" within the meaning of Article 2(h) GDPR. Therefore there is no legally valid consent for the data processing. The plaintiff is entitled to injunctive relief against the storage of cookies on his device under § 1 UKlaG in connection with § 307 BGB because the request for consent by a preselected tick box constitutes an "unreasonable disadvantage to the user". The request for consent by a preselected tick box further violates § 15 TMG. An interpretation of § 15 TMG in light of Article 5(3) Directive 2002/58/EC leads to the conclusion that there is no effective consent within the meaning of these provision if the storage of cookies is permitted by a present checkbox which the user must uncheck to refuse consent. Pursuant to Article 94 and 95 GDPR the above said fully applies also after 25.05.2018.

### Council of State upholds CNIL cookie banner guidance: refusal via corner link as easy as

*Source: Supreme Administrative Court, 2026-06-19 — https://overview.legal/posts/53908 — original: https://gdprhub.eu/index.php?title=CE_-_N._501417*

Facts — Pour un RGPD Respecté, a French NGO that advocates for GDPR compliance, and three individuals requested the CNIL, the DPA, to partially repeal its 2020 recommendation on cookies and trackers. They challenged Figure 5, which showed a cookie banner where users could refuse cookies through a “continue without accepting” link placed in the upper-right corner. After the DPA rejected the request, the applicants asked the Court to annul that decision. They argued that refusing cookies was not as easy as accepting them and that the banner contradicted the positions of the DPA, the EDPB and the Belgian DPA. Holding — The Court dismissed the action. It held that the DPA’s decision did not require a specific statement of reasons under national administrative law. The Court also found that the refusal option was available on the same screen, was immediately accessible and used clear wording and a comparable font size. Therefore, refusing cookies was as easy as accepting them. The Court further held that the example did not contradict the positions of the DPA, the Belgian DPA or the EDPB. The DPA had therefore not made a manifest error of assessment. The requests for an injunction, periodic penalty payment and legal costs were also rejected. No fine or corrective measure was imposed.

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### Judgment of the Court (Full Court) of 30 April 2024.#La Quadrature du Net and Others v Premier ministre and Ministère de la Culture.#Request for a preliminary ruling from the Conseil d'État (France).#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Confidentiality of electronic communications – Protection – Article 5 and Article 15(1) – Charter of Fundamental Rights of the European Unio

*Source: Court of Justice of the European Union, C-470/21, 2024-04-30 — https://overview.legal/posts/132259 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0470*

In Case C-470/21, the CJEU addressed a preliminary reference from the French Conseil d'État concerning La Quadrature du Net and others v. Premier ministre and Ministre de la Culture, which challenged France's "graduated response" system allowing public authorities to access civil identity data associated with IP addresses retained by ISPs for the purpose of combating online copyright infringement. The Court ruled that while such access may be justified under Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) for intellectual property protection, it requires strict safeguards including prior review by a court or independent administrative body, and must be limited to what is strictly necessary, proportional, and subject to substantive and procedural protections against abuse. No fine was imposed as this was a preliminary ruling.

### CJEU - C‑178/22 - Procura della Repubblica presso il Tribunale di Bolzano

*Source: GDPRhub, 2024-04-30 — https://overview.legal/posts/158447 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑178/22_-_Procura_della_Repubblica_presso_il_Tribunale_di_Bolzano*

Facts — Two complaints were lodged with the Italian Public Prosecutor's office concerning acts of mobile theft. In order to identify the perpetrators, the Public Prosecutor's office requested an authorisation to obtain the telephone records of the stolen telephones from all the telephone companies. These requests concerned all the data in the possession of the telephone companies, with tracking and localisation methods, in particular the users and International Mobile Equipment Identity (IMEI) codes of the devices called or making the calls, the sites visited and reached, the times and durations of the calls and connections, the details of the cells and/or towers concerned, and the users and IMEI code of senders and receivers of SMS and MMS. These requests were made to the judge responsible for preliminary investigations at the District Court, Bolzano (‘Giudice delle indagini preliminari presso il Tribunale di Bolzano’) on the basis of an Italian National law, Article 132(3) of Legislative Decree n°196/2003. The referring court was uncertain whether Article 132(3) of Legislative Decree n°196/2003 is compatible with Article 15(1) of Directive 2002/58 (‘ePrivacy Directive’) as interpreted by CJEU, 2 March 2021, Prokuratuur, C-746/18. First, according to paragraph 45 of that judgement, national provisions that allow public authorities to access telephone records containing a set of traffic or location data are justifiable if those provisions are intended for the prosecution of serious offences such as threats to public security and other serious crimes. Second, Article 132(3) of Legislative Decree n°196/2003 establishes that if there is sufficient evidence of the commission of an offence for which the penalty is a maximum term of imprisonment of at least three years, the Public Prosecutor may acquire data relevant to the facts, with the prior authorization of the court. According to the referring court, the Italian courts have a very limited margin of discretion to refuse authorisation to obtain telephone records as the authorization must be granted when there is ‘sufficient evidence of the commission of an offence’ and the data requested are ‘relevant to establishing the facts’. The Giudice delle indagini preliminari presso il Tribunale di Bolzano decided to stay the proceedings and referred the following question to the CJEU: Does Article 15(1) of the ePrivacy Directive preclude a national provision which requires a national court to authorise access to a set of traffic or location data for the purposes of investigating a criminal offence with a penalty of a maximum term of imprisonment of at least 3 years, provided that there is sufficient evidence and that those data are relevant to establishing the facts? Holding — Firstly, the CJEU indicated that access to traffic and location data retained by providers of electronic communications services may be granted to public authorities for the purposes of the prevention, investigation, detection and prosecution of criminal offences pursuant to a national law adopted under Article 15(1) ePrivacy Directive. However, a legislative measure cannot allow the general and indiscriminate retention of traffic and location data as a preventative measure (§35 of the Judgement). The CJEU also held that only the objectives of combating serious crime or preventing serious threats to public security are capable of justifying a serious interference with the fundamental rights of Articles 7 and 8 of the Charter (§36 of the Judgement). Secondly, the CJEU assessed the question of whether access to the traffic and location data in the present case may be classified as a serious interference with the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Access to the set of traffic or location data requested in the present case may allow precise conclusions to be drawn concerning the private lives of the persons whose data have been retained, for example the habits of their everyday life, their permanent or temporary places of residence, their daily movements, the activities they carried out, their social relationships and social environments frequented by them. The CJEU found that in such a case, the interference with the fundamental rights guaranteed in Articles 7 and 8 of the Charter would likely to be classified as serious (§39 of the Judgement). The Court considered that for the purposes of assessing the existence of a serious interference with the fundamental rights, it was irrelevant that the access may not concern the data of the owners of the phones, but the data of the persons who communicated with each other after the theft. Indeed, Article 5(1) ePrivacy Directive establishes that the obligation to ensure confidentiality of the traffic data covers communications made by the ‘users’ of that network. The ‘users’ are defined as any natural person using a publicly available electronic communications service, without necessarily having subscribed to that service (§41 of the Judgement). Thirdly, the CJEU added that national law determines the conditions under which providers of electronic communications services grant access to the data in the provider's possession. However, the legislation must lay down clear and precise rules governing the scope and conditions for the application of such access. As a general rule, the CJEU noted that access can be granted in relation to the objective of fighting crime, only for the data of individuals suspected of being implicated in a serious crime. The Court also pointed out that in order to ensure that the interference is limited to what is strictly necessary, the access must be subject to a prior review carried out by a court or an independent administrative body. This does not apply in cases of duly justified emergency (§43 of the Judgement). Regarding the definition of the concept of 'serious offence', the EU has not legislated in that field. This concept reflects social realities and legal traditions, which vary between the Member States and over time. Therefore, it is up to the Member States to define 'serious offences’ for the purposes of applying Article 15(1) ePrivacy Directive (§46 of the Judgement). The CJEU recalled that Article 15(1) ePrivacy Directive is an exception to the obligation to ensure the confidentiality of electronic communications and data and must not become the rule (§48 of the Judgement). Furthermore, the national measures taken by Member States under this provision must comply with the general principles of EU law, in particular the principle of proportionality and ensuring respect for the fundamental rights enshrined in Articles 7, 8 and 11 of the Charter (§49 of the Judgement). Therefore, the Court considered that Member States must not distort the concept of ‘serious offence’ and ‘serious crime’ by including within it, offences which are manifestly not serious offences. In the present case, the CJEU pointed out that Article 132(3) Legislative Decree n°196/2003 defines the offences for which access to data retained by providers of electronic communications services may be granted, by reference to a maximum term of imprisonment of at least three years. Additionally, there must be sufficient evidence to the commission of an offence and the data must be relevant to establishing the facts (§52 of the Judgement). The CJEU held that the definition of ‘serious offence’ cannot cover the vast majority of criminal offences, which would be the case if the maximum term of imprisonment was sent at an excessively low level. The Court considered that a maximum term of imprisonment of three years does not appear excessively low (CJEU, 21 June 2022, Ligue des droits humains, C-817/19, §150). Lastly, the CJEU found that setting a maximum term of imprisonment may create a situation in which the access would be requested for the purposes of prosecuting offences which do not constitute a serious crime. However, the Court held that setting a minimum period above which the maximum term of imprisonment for an offence justifies the classification of that offence as a serious offence is not necessarily contrary to the principle of proportionality (§58 of the Judgement). Thus, the CJEU concluded that Article 15(1) ePrivacy Directive does not preclude a national provision which requires a national court, acting in the context of a prior review, to authorise access to traffic or location data for the purposes of investigating criminal offences punishable under national law by minimum 3 years imprisonment. However, the court must be entitled to refuse such access in the context of investigating an offence which is manifestly not a serious offence in the light of the societal conditions prevailing in the Member State concerned.

## Guidance

### Report of the work undertaken by the Cookie Banner Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-cookie-banner-taskforce-en, 2023-01-18 — https://overview.legal/posts/125875 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-cookie-banner-taskforce_en*

Adopted 1 Report of the work undertaken by the Cookie Banner Taskforce Adopted on 17 January 2023 Adopted 2 Adopted 3 DISCLAIMER The positions presented in this document result from the coordination of the members of the TF with a view to handling the “cookies banner” complaints received from NOYB. They reflect the common denominator agreed by the SAs in their interpretation of the applicable provisions of the ePrivacy Directive, and of the applicable provisions of the GDPR, for the analysis to…

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB

*Source: EDPB, statement-on-the-eprivacy-regulation-and-the-future-role-en, 2020-11-19 — https://overview.legal/posts/126113 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-eprivacy-regulation-and-the-future-role_en*

1 Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB Adopted on 19 November 2020 The European Data Protection Board has adopted the following statement: Firstly, the EDPB wants to stress that this statement is without prejudice to its previous positions , including s tatement 3/2019 1 and its statement of 25 May 2018 2 . The ePrivacy Regulation must under no circumstances lower the level of protection offered by the curren t ePrivacy Directive…

### Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities

*Source: EDPB, opinion-52019-on-the-interplay-between-the-eprivacy-directive-en, 2019-03-12 — https://overview.legal/posts/126232 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52019-on-the-interplay-between-the-eprivacy-directive_en*

adopted 1 Opinion 5 / 2019 on the i nterplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities Adopted on 12 March 2019 adopted 2 adopted 3 The European Data Protection Board Having regard to article 63 and article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications

*Source: EDPB, statement-of-the-edpb-on-the-revision-of-the-eprivacy-en, 2018-05-25 — https://overview.legal/posts/126329 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-of-the-edpb-on-the-revision-of-the-eprivacy_en*

Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications The Data Protection Authorities of the European Union, united in the European Data Protection Board, consider that the revision of the current ePrivacy Directive (2002/58/EC, amended by 2009/136/EC) is an important and necessary step that has to be concluded rapidly. The use of IP based communication services has…

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### Statement 3/2019 on an ePrivacy regulation

*Source: EDPB, statement-32019-on-an-eprivacy-regulation-en, 2019-03-13 — https://overview.legal/posts/126229 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32019-on-an-eprivacy-regulation_en*

1 Statement 3 / 2019 on an ePrivacy r egulation Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: The EDPB calls on the EU legislators to intensify efforts towards the adoption of a n ePrivacy Regulation , which is necessary to complete the EU’s framework for data protection and confidentiality of communications. The EDPB wishes to reiterate the positions previously adopted by data protection authorities in the EU, including the Opinion 1/2017 of…

## Enforcement decisions

### APD/GBA (Belgium) - 113/2024

*Source: APD/GBA (Belgium), 2024-09-06 — https://overview.legal/posts/122855 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_113/2024*

Facts — A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie banner which: Didn’t contain a reject button within its first layer;Buttons colours were misleading; It was not as easy to withdraw consent as it was to give it; Contained a reference to the legal basis of legitimate interest. The data subject filed four complaints referring to abovementioned cookie banners with the Belgian DPA (ADP/GBA). noyb was appointed by the data subject as their representative under Article 80(1) GDPR. MediaHuis was assigned the role of data controller. According to the controller, the law, especially Article 7(3) GDPR or Article 4(11) GDPR, didn’t prescribe the controller to implement reject button within the first layer of the cookie banner or to use different colours for the buttons or to implement consent withdrawal option in a particular way. The fact that the cookie banners were not in line with the guidelines of different data protection authorities and the EDPB, as mentioned by the data subject, did not amount to violation of the GDPR. Moreover, the data subject gave their consent for processing activities of the controller and, for that reason, they had no interest to bring a case before the DPA. Holding — The DPA found the controller violated the Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7(3) GDPR. Firstly, the DPA clarified that for the consent to be freely and unambiguously given under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive, the reject button had to be presented alongside the accept button. Otherwise, the data subject would have no real alternative to consenting for placing and processing cookies. Secondly, the buttons’ colours used by the controller were of deceptive nature. They inclined a data subject to give a consent for the cookies processing. Because of that, the controller was in breach of Article 5(1)(a) GDPR. Since the cookie banner was lacking of the reject button within its first layer, and the colours used were misleading, the DPA order the controller to bring the cookie banner into compliance with the GDPR within 45 days. The order was combined with a penalty of €25,000 per day and per each website concerned, due if the controller fails to implement the ordered changes. The maximum amount of total penalty was set on €10,000,000. Thirdly, the controller violated Article 7(3) GDPR. To withdraw the consent given, a data subject had to perform more actions - “click more” – whilst to give a consent only one click sufficed. Nevertheless, the controller updated their websites by adding the reject button to the first layer of cookie banner and the option to withdraw the consent, using the manage link at the bottom of each website. The violation was remedied, accordingly the DPA reprimanded the controller. Fourthly, the legitimate interest called upon by the controller covered placing and processing of the cookies, which were not “strictly necessary”. The controller’s cookies were of different kind, including the analytical cookies. Especially for the latter, the application of Article 6(1)(f) GDPR is per se excluded and the consent needed to be obtained. Furthermore, by adding the legitimate interest to be a “back-up” legal basis for the cookies related processing, the controller mislead the data subject. The controller violated then Article 6(1)(a) GDPR. Nonetheless, the DPA reprimanded the controller that the legal basis for placing and processing of analytical cookies and other cookies that were not “strictly necessary cookies only was a consent under Article 6(1)(a) GDPR. In answer to the controller’s claims, the DPA emphasised that: the fact that the data subject gave a consent didn’t deprive them from starting the case before the DPA; the guidelines of the EDPB were not legally binding, as pointed by the controller, but they played important role regarding the interpretation of the GDPR. In addition, the DPA excluded alleged pressure put on the data subject by noyb to initiate the proceedings. The controller argued the relationship between the data subject, being a trainee at noyb, was instructed to lodge the complaints with the DPA. Hence there was no legal interest of the data subject in the case at hand. However, for the DPA statements of that kind were unfounded, bearing in mind the facts of the case. In particular, the outcome of the data subject’s hearing before the DPA that proved the data subject’s interest being involved.

### CNIL (France) - SAN-2023-012

*Source: CNIL (France), 2023-07-13 — https://overview.legal/posts/125588 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2023-012*

Facts — This decision follows from a previous decision of the French DPA (SAN 2021-023 of 31 December 2021), in which said DPA fined Google LLC €90,000,000 and Google Ireland Limited €60,000,000 for violating Article 82 French Data Protection Act. This Act transposes the ePrivacy Directive into domestic French law. Article 82 of the French Data Protection Act is the national equivalent to Article 5(3) ePrivacy Directive 2002/58/EC, which stipulates that the storing of user information or the gaining of access to information already stored, is only permitted on the condition that the user has already given their informed consent. The French DPA had fined Google LLC and Google Ireland Limited in decision SAN 2021-023 for failing to offer users a way of rejecting cookies. It ordered Google to bring its processing activities into compliance and imposed an additional periodic fine of €100,000 per day if Google failed to bring its processing activities into compliance within 3 months. On 24 April 2022, Google sent the French DPA its proposed cookie amendments, which included a button titled "reject all." Between April and June 2022, Google sent further information to the French DPA, and on 5 August 2022, the French DPA re-investigated the matter to ensure that the updated cookie system was compliant. On 25 January 2023 the French DPA requested further information from Google on their system, which Google provided on 28 April 2023. Holding — The French DPA held that Google's updated cookie system was compliant, as the implementation of the "reject all" button offered a means of users refusing the storage of and access to their information, pursuant to Article 82 French Data Protection Act. Consequently, the French DPA decided to dismiss the periodic fine of €100,000 per day in the case of non-compliance, as the updated cookie banner was lawful.

### Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates

*Source: APD/GBA (Belgium), 2024-10-11 — https://overview.legal/posts/122846 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_131/2024*

Facts — On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data subject noticed that the cookie banner of this website had an “Accept all” and a “Know more” button. The data subject believed that this cookie banner was unlawful under the GDPR. Therefore, under Article 80(1) GDPR, she mandated noyb to file a complaint with the DPA on her behalf. More specifically, the data subject pointed out the following violations: the fact that the cookie banner did not have a “Reject all” button violates Articles 5(1)(a), 6(1)(a) and 7(1) GDPR and Article 5(3) ePrivacy Directive 2002/58/EC as implemented by Article 10/2 of the Belgian Data Protection Code (Loi relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel - Loi-cadre); the usage of a vivid colour for the “Accept all” button misleads data subjects and violates Articles 5(1)(a), 6(1)(a) and 7(1) GDPR and Article 5(3) ePrivacy Directive 2002/58/EC as implemented by Article 10/2 Loi-cadre; the fact that the banner does not allow to withdraw consent as easily as it is possible to give that consent is a violation of Articles 5(1)(a) and 17(1)(b) GDPR and Article 5(3) ePrivacy Directive 2002/58/EC as implemented by Article 10/2 Loi-cadre. First of all, the controller argued that noyb cannot represent the data subject since, when she filed the complaint, she was volunteering as a trainee for that organisation. Furthermore, the controller noted that the GDPR does not require websites to have a “Reject all” button, nor the “Accept” button to have a specific colour. Holding — On the representation agreement under Article 80(1) GDPR First, the DPA held that noyb can represent the data subject. It pointed out that the representation agreement between the former and the latter is valid under Article 80(1) GDPR. Moreover, it noted that the data subject decided on her own to visit the website and that nothing opposes to the fact that an organisation under Article 80 GDPR can represent one of its employees or volunteers. Furthermore, the DPA held that the fact that noyb has provide technical and legal assistance to the data subject is not a problem. On the contrary, according to the DPA, this represent a good practice. On the merits On the merits, the DPA noted that, according to Article 4(11) GDPR, consent must be freely given. In a cookie banner, this means that accepting should be as easy as refusing the installation of the cookies. Therefore, the cookie banner should have, all on the first layer, both an “Accept all” and a “Refuse all” button. On these grounds, the DPA found a violation of Article 6(1)(a) GDPR and of Article 10/2 Loi-cadre. As for the button colours, the DPA is of the opinion that the colours used by the controller are able to manifestly induce the data subject to click on the “accept all” button, since the latter, having a bright colour, stands out from the resto of the banner. Therefore, the DPA found a violation of Articles 5(1)(a) and 6(1)(a) GDPR and Article 10/2 Loi-cadre. Finally, as for the options to withdraw consent, the DPA noted that the controller placed a button that allows to manage the cookies at the bottom of each page of its website. The DPA considered this solution enough to comply with the requirement set by Article 7(3) GDPR and, therefore, rejected this point of the complaint. On these grounds, the DPA reprimanded the controller and ordered it to implement a GDPR-compliant cookie banner.

### DSB Austria: No fine imposed on COVID mask shop for cookie consent failure

*Source: DSB (Austria), 2026-01-16 — https://overview.legal/posts/144040 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2026-0.043.390*

Facts — Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop within a few days and made it publicly accessible to its customers on 28 March 2020. On 1 April 2020, a customer (the data subject) visited the controller’s online shop. They discovered that it had placed 14 cookies on their device without displaying any cookie consent banner. The customer lodged a complaint with the North Rhine-Westphalian DPA, arguing that the cookies had been stored on their device without prior opportunity for refusal. The German authority transmitted the complaint to the Austrian DPA (DSB). The controller acknowledged that, because the online shop had been set-up rapidly, it did not yet meet all technical requirements at the time of the customer’s visit, including the absence of a cookie consent pop-up. It further admitted that although a privacy policy had already been drafted, it was not publicly accessible to the users when the data subject visited the site. The controller explained that the online shop had been established as a matter of urgency due to the shortage of protective masks. It claimed it had not previously offered any business-to-consumer sales, and given the closure of physical stores and the absence of other direct sales channels, online sales were the best option under the circumstances. The controller stated during proceedings that the deficiencies had subsequently been remedied. The website was no longer accessible on 24 November 2025. Holding — The DPA found that, when the data subject accessed the online shop, the controller processed the data subject’s IP address in connection with the 14 cookies placed on their device. The cookies contained a unique user identifier and were processed for purposes including user recognition, advertising, marketing and the creation of a digital shopping cart. It acknowledged that the website had been created at short notice, that the deficiencies existed only for a brief period and that the controller had subsequently implemented a cookie banner and made a privacy policy available. The DPA held that the controller failed to transparently inform any user about the cookies that were placed, whether the cookies were technically necessary or not, since neither a cookie banner nor a publicly accessible privacy policy was available at the relevant time. The DPA emphasised that the principle of transparency requires data subjects to be able to understand which personal data concerning them are processed, for which purposes and to what extent, as well as the associated risks, rights and safeguards. This enables data subjects to exercise their rights against the controller and to demand processing that is fair and consistent with their reasonable expectations. Moreover, the DPA noted that the principle of transparency constitutes an integral part of numerous GDPR provisions, including the controller's obligation to inform data subjects about the processing of their personal data where personal data are collected directly from the data subjects pursuant to Article 13 GDPR as well as the communications standards under Article 12 GDPR. It concluded that the controller had therefore infringed Article 13 GDPR by failing to provide the required information in a concise, transparent, intelligible and easily accessible form, as required by Article 12 GDPR. The DPA considered unnecessary to further examine whether the processing was based on a valid legal basis under Article 6 GDPR, as the processing already infringed the principles laid down in Article 5 GDPR. The DPA upheld the complaint and found that the controller had infringed the principle of transparency under Article 5(1)(a) GDPR and the data subject’s right to information under Article 13 GDPR. However, it did not issue an order under Article 58(2) GDPR as it took into account that the controller had remedied the deficiencies shortly after the incident and that the website was no longer accessible.

### Belgian DPA settles with Mediafin: De Tijd cookie banner must add equal "refuse all"

*Source: APD/GBA (Belgium), 2023-11-24 — https://overview.legal/posts/122845 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_159/2023*

Facts — On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The complaint concerned the practices of the setting of cookies on the website of the Belgian newspaper De Tijd, owned by Mediafin (the controller). The data subject first complained about a missing "decline" option next to the "consent" option at the first level of the cookie banner. Second, it stated that the cookie banner used misleading button colours and third, that it was not as easy to withdraw consent as it was to give it. On 20 October 2023, a settlement proposal was sent to the parties. The data subject responded on 30 October 2023 demanding a few modifications to the proposed settlement, which the DPA denied on 6 November 2023. Meanwhile, the controller accepted the proposal on 24 November 2023. Holding — In its settlement decision, the Belgian DPA held that the controller should comply with three conditions. Firstly, the DPA stated that the controller should provide the cookie-setting banner on De Tijd with a "refuse all" option at the same level as the "agree and close" option within one month of the decision. Secondly, it pointed out that the "refuse all" option should be displayed no less (visually) attractive than the "agree and close" option. The data subject requested to modify this condition. Instead, it requested that both options be identical in size, colour, shape, contrast and location. This demand was, however, rejected. The DPA stated that the controller was free to display the "refuse all" option in an even more appealing manner than the "agree and close" option. Lastly, the DPA noted that the controller should, within one month of the decision, ensure that it does not take more clicks to withdraw than to give consent on the website in question. The clicks should be counted from the moment the data subject reaches the cookie setting page, and this page should be accessible on every page of the litigious website. The DPA mentioned that this change should be done to meet the requirements of collecting valid consent under the GDPR and Article 5(3) ePrivacy Directive 2002/58/EC, as well as the following three additional cumulative requirements: (i) the ability to withdraw consent, (ii) the ability to withdraw consent at any time and (iii) withdrawal of consent must be as easy as giving consent. The DPA decided to not impose a fine because it did not feel the need for a sanction.

### CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case

*Source: CNIL (France), 2021-12-31 — https://overview.legal/posts/125662 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2021-023*

Facts — Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out an online inspection of the website "google.fr" in the context of a previous procedure against Google LLC and GIL. The purpose of this inspection was to verify their compliance with the Loi 'Informatique et Libertés', and in particular with Article 82 thereof. This resulted in this decision, that Google appealed. Following this decision, the CNIL received more complaints about the methods of refusing cookies from the website "google.fr". It therefore reopened the case and launched a new investigation. Holding — On the request for a stay of proceedings — First, the companies requested that per Article 66 of the CNIL's rules of procedure, the CNIL stay these proceedings pending the decision to be handed down by the Council of State in the appeal against its first decision against Google and pending the conclusions of the new EDPB working group on cookies. The CNIL rejected this request, as it considered that there were no acceptable grounds for staying the proceedings. On the complaint alleging breach of the ne bis in idem principle — Second, the companies argued that the restricted formation cannot rule again on the same facts as those concerned by deliberations No. SAN-2020-012 and No. SAN-2021-004, without violating the ne bis in idem principle, as it considered the parties and material facts in those case to be identical. The CNIL responded that the two procedures do not concern the same facts, as these cases included an injunction relating to the information of users on the purposes of cookies subject to consent and on the means available to refuse cookies, whereas the one at hand concerned the refusal methods themselves, and not only the information. It also highlighted that this procedure concerned both the websites "google.fr" and "youtube.com", whereas the previous procedure concerned only the website "google.fr". As such, the CNIL rejected the complaint based on the violation of the ne bis in idem principle. On the competence of the CNIL — The material competence of the CNIL and the non-application of the "one-stop shop" mechanism provided for by the GDPR — The processing operations investigated by the CNIL in this case were carried out in the context of the provision of publicly available electronic communications services via a public electronic communications network offered within the European Union. As such, it considered they fell within the material scope of the ePrivacy Directive. Article 5(3) of that directive was transposed into domestic law through Article 82 of the French Data Protection Act. The CNIL therefore considered itself materially competent under these provisions to monitor and sanction the access or registration of information by companies in the terminals of users of the "google.fr" and "youtube.com" websites in France. The companies contested the jurisdiction of the CNIL. They argued they should be subject to the procedural framework provided for by the GDPR, or the 'one-stop shop' mechanism, under which the Irish DPA (DPC) would be the lead supervisory authority (LSA). They considered that the absence of specific rules on determining the competence of the supervisory authority in the case of cross-border processing operations falling within the scope of the ePrivacy Directive should be replaced by the application of the procedural framework provided for by the GDPR. Interestingly, the companies further argued that the EDPB's announcement regarding the creation of a working group on cookie banners in response to the significant number of complaints recently filed with supervisory authorities by noyb was evidence that the EDPB considers that cookie-related breaches fall directly within the scope of the GDPR and, therefore, the 'one-stop shop' mechanism. First, the CNIL responded that a distinction should be made between, on the one hand, the operations consisting in depositing and reading a cookie on a user's terminal and, on the other hand, the subsequent use that is made of the data generated by these cookies ("subsequent/further processing"). The former are governed by special rules, set by the ePrivacy Directive - in this case, by its Article 5(3) - and transposed into national law, the latter is governed by the GDPR and, as such, may be subject to the "one-stop-shop" mechanism in the event that they are cross-border. This case only concerned the read and write operations carried out on the terminal of the user located in France visiting the Google Search and YouTube search engines. Second, it held that where a processing operation may fall within both the material scope of the ePrivacy Directive and the material scope of the GDPR, reference should be made to the relevant provisions of the two texts which provide for their articulation. The rule laid down in Article 5(3) of the ePrivacy Directive, according to which reading and/or writing operations must systematically be subject to the prior consent of the user, after having been informed, constitutes a special rule with regard to the GDPR, since it prohibits the legal bases mentioned in Article 6 GDPR from being invoked in order to be able to lawfully carry them out. The control of this rule is therefore a matter for the special control and sanction mechanism provided for by the ePrivacy Directive, and not for the data protection authorities and the EDPB under the GDPR. It stated that the French legislator entrusted this task to the CNIL. Thus, the "one-stop shop" mechanism provided for by the GDPR could not be applied to the processing operations covered by the Directive, as the companies claimed. Third, the CNIL confirmed that the 'one-stop-shop' mechanism is not applicable to facts that are materially covered by the ePrivacy Directive, by referring to the Opinion No 5/2019 of the EDPB and the CJEU decision C-645/19 (Facebook Belgium) upholding this opinion. Finally, the CNIL stated that the creation of a working group on cookies in response to the large number of complaints filed by noyb did not mean that the EDPB considered that all violations related to cookies necessarily fall within the scope of the GDPR. Furthermore, pursuant to Article 70(1)(u) GDPR, one of the EDPS's tasks is to promote cooperation and the effective bilateral and multilateral exchange of information and best practices between supervisory authorities. The purpose of the working party was thus only to exchange views on the analysis of the numerous complaints lodged by noyb . Thus, the CNIL held that the "one-stop shop" mechanism provided for by the GDPR was not applicable to the present procedure and that it was competent to control and sanction processing operations consisting of reading and/or writing information in the terminal of users located in France implemented by companies falling within the scope of the "ePrivacy" Directive, provided that they fall within its territorial jurisdiction. On the territorial jurisdiction of the CNIL — The CNIL considered it was territorially competent under Article 3 GDPR since the processing that was the subject of the present procedure, namely consisting of accessing or recording information on the terminals of users residing in France when using the Google Search engine and YouTube, in particular for advertising purposes, was carried out within the "framework of the activities" of the company Google France, which constituted the "establishment" of the Google group in France. In response, Google argued that its establishment in the EU was located in Ireland. The CNIL considered a range of CJEU case law (included but not limited to Google Spain C-131/12, Weltimmo C-230/14) and its findings in the previous decision SAN-2020-012, which pointed towards a broad interpretation of 'establishment' and 'in the context of the activities' and rejected this argument. As such, it held that French law was applicable and that it was materially and territorially competent to exercise its powers, including the power to impose sanctions on processing operations falling within the scope of the ePrivacy Directive. The determination of the controller — The CNIL held that Google LLC and Google Ireland Limited jointly determined the purposes and means of the processing consisting of accessing or recording information in the terminal of users residing in France when using the Google Search engine and YouTube. On the failure to comply with the obligations relating to cookies — The CNIL finally assessed whether the companies had complied with Article 82 of the French Data Protection Act. It noted that, in order to give consent to the reading and/or writing of information on their terminal, users visiting the home page of the sites "google.fr" and "youtube.com" only had to click on the "I accept" button on the pop-up window, which made the window disappear and allowed them to continue browsing. On the other hand, the users going to these same home pages and wishing to refuse cookies had to click on the "Personalise" button of this first window, which took them to an interface on both the "google.fr" and "youtube.com" sites, offering them the choice of activating or deactivating cookies, on which they had the possibility of carrying out various actions. The investigator for the CNIL considered that making the mechanism for refusing cookies more complex than the one for accepting them amounted to discouraging users from refusing cookies and encouraging them to opt for the "I accept" button. This led to their conclusion that the methods of refusing cookies implemented by the companies on the sites "google.fr" and "youtube.com" did not comply with the provisions of Article 82 of the French Data Protection Act, as clarified by the enhanced consent requirements set out in the GDPR. In response, the companies argued that neither the ePrivacy Directive, nor the RGPD, nor Article 82 of the Data Protection Act provided that the action of refusing cookies should be as simple as accepting them. "They [also added] that, for many years, the CNIL itself had not deduced this principle even though the regulations in question had remained unchanged since the RGPD came into force. They point out that the CNIL cannot, through its guidelines and recommendations, introduce new requirements relating to the refusal of consent and consider that it is up to each data controller to choose the most appropriate method of obtaining consent." The CNIL rejected this, restating its powers, which include drawing up and publishing guidelines, recommendations or benchmarks intended to facilitate the compliance of personal data processing with the texts relating to the protection of personal data. It was in this context the DPA had issued its previous deliberations which provided guidance to stakeholders on the implementation of concrete measures to ensure compliance with these provisions, so that they implemented these measures or measures of equivalent effect. Indeed, the guidelines' main purpose "is to recall and clarify the law applicable to the reading and/or writing of information [...] in the subscriber's or user's electronic communications terminal equipment, and in particular to the use of cookies". It thus considered that it had not created any new obligations for the actors in its recommendation, but has limited itself to illustrating in concrete terms how Article 82 of the law should be applied. The position according to which it must be as simple for users to refuse cookies as to consent to them was even endorsed by the French Council of State in CE, 19 June 2020, No. 434684, pt 15. Further, the CNIL highlighted that users residing in France who visit the Google Search engine and/or YouTube had to perform a single action to accept cookies, whereas they had to perform five to refuse them. It was therefore not as simple to refuse cookies as to accept them. It referred to studies that showed that having a "refuse all" button on the first-level consent interface led to a decrease in the rate of consent to accept cookies. It therefore considered that making the mechanism for refusing cookies more complex than the one for accepting them actually discourages users from refusing cookies and encourages them to prefer the ease of the "accept all" button. "In view of the above, the [CNIL held] that there [had] been a breach of the provisions of Article 82 of the [French] Data Protection Act, interpreted in the light of the GDPR, insofar as the companies [did] not provide users located in France, on the websites "google.fr" and "youtube.com", with a means of refusing to read and/or write information to their terminal that is as simple as the one provided for accepting its use. Thus, the CNIL: imposed a fine of €90,000,000 on Google LLC for failing to comply with Article 82 of the French Data Protection Act, imposed a fine of €60,000,000 on Google Ireland Limited for failing to comply with Article 82 of the French Data Protection Act, ordered Google LLC and Google Ireland Limited to modify, on the websites "google.fr" and "youtube.com", the methods for obtaining the consent of users located in France to the reading and/or writing of information in their terminal, by offering them a means of refusing these operations that is as simple as the mechanism provided for their acceptance, in order to guarantee the freedom of their consent; attached to the injunction a penalty of 100,000 euros (one hundred thousand euros) per day of delay at the end of a period of three months following notification of this decision, with proof of compliance to be sent to the restricted panel within this period; made its decision public on the CNIL website and on the Légifrance website, which will no longer identify the companies by name at the end of a two-year period from the date of its publication.

### ANSPDCP (Romania) - Fine against There's an AI for that S.R.L

*Source: ANSPDCP (Romania), 2026-07-24 — https://overview.legal/posts/158433 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_There's_an_AI_for_that_S.R.L*

Facts — In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP) concluded an investigation into THERE’S AN AI FOR THAT S.R.L., a company operating a website that used cookies. The investigation began after a data subject submitted a complaint alleging a possible breach of data protection rules. Holding — The ANSPDCP found that the controller’s website stored cookies that were not technically necessary on users’ devices. The authority also found that users were not provided with clear and complete information about these cookies and that their explicit consent had not been obtained before such cookies were placed. The ANSPDCP held that the controller violated Article 4(5)(a) and Article 4(5)(b) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector (implementing ePrivacy Directive). As a result, the authority imposed an administrative fine of RON 30,000 (€6,000) on the controller for processing data through non-essential cookies without proper information or consent.

### AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent

*Source: AEPD (Spain), 2025-11-14 — https://overview.legal/posts/158452 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00480-2025*

Facts — Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting publishers offering advertising space with advertisers seeking to display ads on those websites. Through this platform, the controller processed personal data of users visiting publishers’ websites where its ads were displayed. This included IP addresses, device and browser information, website URLs, referral URLs, clicks, impressions and cookie identifiers. According to the controller, the data were processed for ad delivery, fraud prevention, frequency capping, performance measurement and service improvement. The controller argued that it did not carry out behavioural advertising or profiling. It claimed that any targeting was limited to contextual factors, such as country and language. The controller relied mainly on legitimate interest as a legal basis and argued that publishers, as independent controllers of their own websites, were responsible for obtaining any consent required for cookies. The DPA investigated the controller’s platform and several Spanish websites using it. It found that cookies linked to the controller’s platform were installed on users’ devices without prior consent. These cookies were used for advertising-related purposes, including measuring ad performance, improving ad relevance, limiting frequency and detecting fraud. The AEPD also noted that the controller was not established in the EU. Although the controller stated that it had appointed a representative in Northern Ireland and was in the process of changing representative, the DPA considered that it did not have a valid representative established in the Union. Holding — The AEPD held that the controller violated Article 6 GDPR by processing personal data without a valid legal basis. The DPA emphasised that the LSSI, the Spanish law implementing the ePrivacy Directive require prior consent for storing or accessing information on a user’s device through cookies, unless an exemption applies. The DPA distinguished between the placement or reading of cookies, which is governed by the cookie rules, and the subsequent processing of personal data obtained through those cookies, which must comply with the GDPR. Since the cookies were installed without consent, the subsequent processing of the data collected through them could not be considered lawful. The AEPD rejected the controller’s reliance on legitimate interest under Article 6(1)(f) GDPR. It found that users had not received clear information and had not consented to the use of cookies. Moreover, users of the affected websites did not have a reasonable expectation that their browsing-related data would be processed by a third-party advertising network for advertising purposes. Therefore, the processing did not pass the balancing test required under Article 6(1)(f) GDPR. The DPA also held that the controller violated Article 27 GDPR. Since the controller was not established in the EU but processed personal data of users in Spain in connection with its advertising services, it was required to appoint a representative established in an EU Member State. A representative in Northern Ireland did not meet this requirement. The AEPD fined the controller €120,000 in total: €70,000 for the violation of Article 6 GDPR and €50,000 for the violation of Article 27 GDPR. Pursuant to Article 85 of the Spanish administrative Law 39/2015, the notice of initiation informed the controller of the possibility of acknowledging liability and making a voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the final penalty was set at €72,000, and its payment resulted in the termination of the proceedings. The AEPD also ordered the controller to adopt corrective measures within three months. In particular, the controller had to ensure compliance with Article 6 GDPR, ensure compliance with the Spanish cookie rules by the service providers using its cookies, appoint an EU representative and notify the AEPD of the measures adopted.

## Recent developments

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

*Source: European Data Protection Board, 2026-07-14 — https://overview.legal/posts/96831 — original: https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en*

Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium.The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT.The Belgian DPA,

### EU Member States (and Google) suddenly want to keep cookie banners!

*Source: noyb - European Center for Digital Rights, 2026-06-23 — https://overview.legal/posts/53123 — original: https://noyb.eu/en/eu-member-states-and-google-suddenly-want-keep-cookie-banners*

GDPR Policy For years, users and many companies have been complaining about cookie banners. Even though this understandable frustration is mostly caused by misleading dark patterns used by the industry, these banners have become the symbol of what is perceived as excessive EU regulation. As part of the ‘Digital Omnibus’, the European Commission now finally wanted to get rid of cookie banners and replace them with an automated signal. However, Google and some of the very EU Member States that are

### noyb success: ORF.at must correct misleading cookie banner

*Source: noyb - European Center for Digital Rights, 2026-05-21 — https://overview.legal/posts/53126 — original: https://noyb.eu/en/noyb-success-orfat-must-correct-misleading-cookie-banner*

Cookie Banners The Austrian Broadcasting Corporation (ORF) must amend its cookie banner on ORF.at to bring it into line with the GDPR. This has now been decided by the Federal Administrative Court (BVwG), thereby upholding a decision made by the Austrian Data Protection Authority in 2024. Specifically, the ORF must ensure that the buttons to ‘accept’ or ‘reject’ tracking cookies are designed equally so that visitors are not tricked into agreeing. Currently, the ‘Accept’ option is misleadingly hi

### Conseil d'État upholds Criteo's €40M GDPR fine

*Source: noyb - European Center for Digital Rights, 2026-03-13 — https://overview.legal/posts/53130 — original: https://noyb.eu/en/conseil-detat-upholds-criteos-eu40m-gdpr-fine*

Data Subject Rights The French Data Protection Authority (CNIL) fined Criteo, a major online advertisement and tracking company in Europe, €40 million for violating the GDPR. This decision is based on complaints filed by noyb and Privacy International in December 2018. The CNIL found that the company failed to comply with data subject rights under the GDPR and could not prove that they obtained valid consent. The Conseil d’Etat rejected CRITEO's appeal and upheld the fine. Original Press Release

## Literature

### Cookies, privacidade e proteção de dados

*Source: J², 2026-04-04 — https://overview.legal/posts/53837 — original: https://doi.org/10.29073/j2.v8i1.1124*

This paper aims to analyze issues related to cookies, privacy, and data protection, providing a critical overview of relevant literature and regulatory frameworks. It examines the implications of cookie usage in the context of the General Data Protection Regulation (GDPR), highlights current challenges, and discusses emerging trends such as the decline of third-party cookies and the rise of alternative tracking technologies. The paper concludes by proposing measures that organizations should ado

### Can the GPC standard eliminate consent banners in the EU?

*Source: Computer law & security review, 2025-12-10 — https://overview.legal/posts/53850 — original: https://doi.org/10.1016/j.clsr.2026.106332*

In the EU, the General Data Protection Regulation and the ePrivacy Directive mandate informed consent for behavioural advertising and use of tracking technologies. However, the ubiquity of consent banners and popups has led to widespread consent fatigue and questions regarding the effectiveness of these mechanisms in protecting users' data. In contrast, users in California and other US jurisdictions can utilize Global Privacy Control (GPC), a browser-based privacy signal that automatically broad

### European Union ∙ New EDPB Guidance Expands the Technical Scope of Article 5(3) ePrivacy Directive to Many Standard Tracking Technologies

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132452 — original: https://doi.org/10.21552/edpl/2024/4/8*

### Effective Regulation through Design – Aligning the ePrivacy Regulation with the EU General Data Protection Regulation (GDPR): Tracking Technologies in Personalised Internet Content and the Data Protection by Design Approach

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132422 — original: https://doi.org/10.2139/ssrn.3945471*

### La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non-Serious Crime

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132457 — original: https://doi.org/10.21552/edpl/2025/2/17*

La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive Citation for published version (APA): Elisabeth Dekhuijzen, A. (2025). La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non- Serious Crime. European Data Protection Law Review , 11 (2), 253-258. https://doi.org/10.21552/edpl/2025/2/17 Document status and date: Published: 01/01/2025 DOI: 10.21552/edpl/2025/2/17 Document Version: Publisher's PDF, also known as Version of record Document license: Taverne Please check the document version of this publication: • A submitted manuscript is the version of the article upon submission and before peer-review. There can be important differences between the submitted version and the official published version of record. People interested in the research are advised to contact the author for the final version of the publication, or visit the DOI to the publisher's website. • The final author version and the galley proof are versions of the publication after peer review. • The final published version features the final layout of the paper including

## Tools

### EDPS Website Evidence Collector

*Source: EDPS, 2026-07-04 — https://overview.legal/posts/53809 — original: https://github.com/EU-EDPS/website-evidence-collector*

Open-source tool by the European Data Protection Supervisor that automatically collects evidence of personal data processing by websites: cookies, local storage, third-party requests and beacons. Used by DPAs and DPOs for cookie-compliance inspections.

### CookieViz — visualise web tracking (CNIL)

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125634 — original: https://github.com/LINCnil/CookieViz*

Open-source tool by the French DPA's innovation lab that visualises in real time which third parties are notified while you browse: cookies set, trackers loaded and the network of data flows between sites — useful for demonstrations and cookie audits.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Telecommunications** — https://overview.legal/topics/telecommunications
  Processing by telecom providers and eprivacy
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/cookies · 2026-08-22
