Back to all lessons
Awareness Lessons
3 months ago

Amazon Fined €35M for Unlawful Cookie Tracking Without User Consent

Amazon Europe Core failed to obtain prior informed consent before deploying tracking cookies on its websites, violating Article 82 of the French Data Protection Act and the underlying ePrivacy Directive. This case highlights that consent mechanisms must be affirmative, informed, and freely given before any non-essential data processing occurs — not buried in terms or assumed by default. The €35 million fine, upheld by France's highest administrative court, demonstrates that regulators are actively enforcing cookie compliance at scale. Organizations that treat consent as a checkbox rather than a genuine user right face significant financial and reputational consequences.

Tactical Insight

Immediate Actions

  • Conduct a full audit of all cookies and trackers deployed across your websites to classify them as essential vs. non-essential.
  • Ensure your Consent Management Platform (CMP) blocks non-essential cookies from firing until explicit user consent is recorded.
  • Update privacy notices to clearly describe what data is collected, why, and by whom before any processing occurs.

Long-term Improvements

  • Implement a Privacy by Design process so consent flows are reviewed at the start of every new product or feature development cycle.
  • Establish a recurring cookie compliance review (at minimum quarterly) to catch new third-party scripts or tracking pixels introduced via tag managers.
  • Train marketing, product, and development teams on ePrivacy and GDPR consent requirements to prevent accidental non-compliance.

Detection & Monitoring

  • Deploy automated website scanning tools (e.g., OneTrust, Cookiebot) to continuously detect and flag undeclared or pre-consent cookies.
  • Integrate consent audit logs into your SIEM or compliance dashboard to provide evidence of lawful processing during regulatory investigations.