[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjuZ1-D_sg54X44J1LXK614jMG8-8d_vHNYC6T6Ap8xI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"63756ec1-b4f1-4ff3-9172-102bf8edee8b","google-fined-150m-for-making-cookie-rejection-harder-than-acceptance","90d1980a-6e41-44c2-b723-6346941349fc","Google Fined €150M for Making Cookie Rejection Harder Than Acceptance","CNIL found that Google's cookie consent interfaces were deliberately asymmetric — users could accept cookies in one click but required multiple steps to refuse them, violating the principle of freely given, informed, and unambiguous consent under French data protection law (Article 82). This 'dark pattern' design effectively coerced users into consenting to tracking by making refusal unnecessarily burdensome. The case illustrates that compliance is not just about having a consent mechanism, but ensuring it is genuinely fair and balanced. Regulators across the EU are increasingly scrutinizing UX design as a data protection issue, meaning technical and legal teams must collaborate on interface decisions. Fines of this magnitude signal that consent management is a board-level risk, not merely a legal checkbox.","**Immediate actions:**\n- Audit all cookie consent banners and consent management platforms (CMPs) to verify that 'reject all' is as prominent and accessible as 'accept all'.\n- Remove dark patterns such as pre-ticked boxes, hidden reject options, or multi-layer refusal flows from all user-facing interfaces.\n\n**Long-term improvements:**\n- Establish a formal privacy-by-design review process that includes UX designers, legal counsel, and data protection officers before any consent interface is deployed.\n- Maintain a consent management inventory documenting the purpose, legal basis, and UI design of every cookie or tracker across all company domains.\n- Conduct annual third-party audits of consent flows against evolving regulatory guidance (e.g., CNIL, ICO, EDPB guidelines).\n\n**Governance & monitoring measures:**\n- Implement automated CMP monitoring tools to detect configuration drift that could re-introduce non-compliant consent flows after updates.\n- Define clear accountability (e.g., a named DPO or privacy lead) for approving changes to consent mechanisms before production deployment.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 7 (Conditions for consent)","GDPR Article 13 (Information to be provided)","GDPR Recital 32 (Freely given consent)","French Data Protection Act Article 82","EDPB Guidelines 05\u002F2020 on Consent","EDPB Guidelines 03\u002F2022 on Dark Patterns","CNIL Cookie Guidelines (2020)","NIST Privacy Framework PR.CP-1 (Consent management)","ISO\u002FIEC 29184 (Online privacy notices and consent)","CIS Control 3 (Data Protection)","published","2026-07-17T12:20:55.76428+00:00","2026-07-17T12:20:55.63+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CNIL_(France)_-_SAN-2021-023&diff=52371&oldid=25131","cnil-france-san-2021-023-9e5cbf","CNIL (France) - SAN-2021-023",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]