The CNIL issues 23 new sanctions since January 2026 under the simplified procedure
Facts and context
The National Commission on Informatics and Liberty (CNIL) published on July 6, 2026, a report of 23 new sanctions issued since January 2026 under the simplified procedure, for a total amount of fines of €133,750, mainly concerning video surveillance, cookies, and respect for data subject rights.
These procedures were mostly initiated following complaints, which are the origin of 19 of the 23 decisions.
Grounds for the decision
The authority identified several categories of breaches:
- Lawfulness obligation of processing (Article 5(1)(a) of the GDPR): The authority sanctioned companies for operating video surveillance systems without the prefectural authorization required by national legislation, which rendered the data processing unlawful from the outset.
- Data minimization obligation (Article 5(1)(c) of the GDPR): Breaches were found against organizations that continuously filmed their employees without particular justification, which the authority deemed excessive and disproportionate regarding the pursued purposes, thus contrary to the minimization principle.
- Obligation to obtain consent and prior information before depositing cookies (Article 82 of the French Data Protection Act): The authority found that several sites deposited non-essential cookies before any user action or displayed incomplete information banners. Moreover, the refusal mechanism was not as simple as acceptance, requiring multiple clicks to refuse while only one was needed to accept, violating the requirement for refusal to be as easy as consent.
- Obligation to respect data subject rights (Articles 12, 15 and 17 of the GDPR): Several organizations were sanctioned for failing to respond or responding late to access or erasure requests made by data subjects.
- Obligation to cooperate with the supervisory authority (Article 31 of the GDPR): The authority sanctioned organizations, including lawyers and doctors, for failing to respond to its requests during complaint investigations, constituting an independent breach of their duty to cooperate.
Authority's decision
Consequently, the authority imposed fines totaling €133,750.
Furthermore, the authority ordered certain organizations to comply, accompanied by financial penalties enforceable in case of persistent non-compliance.
Lessons learned
This series of decisions reminds that:
- Continuous video surveillance of employees at their workstation is deemed excessive and contrary to the minimization principle, except in duly justified exceptional circumstances.
- The refusal mechanism for cookies must be as simple as acceptance; a user journey requiring more clicks to refuse than to accept is non-compliant.
- Failure to respond or late response to a data subject rights request constitutes a sanctionable breach, regardless of the initial request's validity.
- Failure to cooperate with the supervisory authority during complaint investigation constitutes a separate violation and may lead to a specific sanction, in addition to the breaches subject to the complaint.
- The simplified sanction procedure is an effective and swift tool used by the authority to address common and proven breaches of fundamental data protection obligations.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire