Votre CMP affirme être conforme. Votre réseau prouve le contraire.
Ce que votre bannière affiche ne dit rien de ce que votre réseau transmet. Les scripts GTM, balises Shopify Customer Events et Pixels Meta peuvent s'exécuter avant le consentement. Vérifiez ce qui part réellement, requête par requête.
Contre-Audit Technique & Simulateur
1. Quelle est votre stack technique / CMS ?
Baromètre des sanctions cookies : ce que les autorités ont réellement prononcé
Synthèse des décisions publiées par la CNIL, la DPC irlandaise et les juridictions européennes. Chaque montant renvoie à sa délibération ou à son communiqué officiel. Aucune statistique propriétaire, aucune estimation interne.
83 décisions pour un total de 486 839 500 €, tous motifs confondus. Bilan officiel CNIL
CNIL, 1er septembre 2025, sur le fondement des règles cookies. Communiqué CNIL
CNIL, 3 septembre 2025, publicités insérées entre les e-mails sans consentement. Décision CNIL
Décisions de référence par éditeur
Sources : CNIL, DPC, Légifrance| Éditeur | Autorité & date | Montant | Motif | Source |
|---|---|---|---|---|
| Google LLC & Google Ireland Ltd. | CNIL — 7 déc. 2020 / 13 janv. 2022 | 100 M€ / 150 M€ | Cookies déposés sans consentement, refus difficile (SAN-2020-012, SAN-2022-001) | Délibérations CNIL |
| Meta Platforms Ireland Ltd. | CNIL — 13 janv. 2022 | 60 M€ | Parcours de refus des cookies plus complexe que l'acceptation (SAN-2022-002) | Délibération CNIL |
| Amazon Europe Core | CNIL — 7 déc. 2020 | 35 M€ | Cookies publicitaires déposés sans consentement, information insuffisante (SAN-2020-013) | Délibération CNIL |
| TikTok / ByteDance | CNIL — 12 janv. 2023 | 5 M€ | Absence de bouton de refus aussi simple que l'acceptation (SAN-2022-027) | Décision |
| Criteo SA | CNIL — 15 juin 2023 | 40 M€ | Reciblage comportemental sans consentement, droit d'accès et de retrait (SAN-2023-009) | Légifrance |
| LinkedIn Ireland | DPC (Irlande) — 24 oct. 2024 | 310 M€ | Bases légales du ciblage publicitaire comportemental | Communiqué DPC |
Règle de référence pour la conservation : la CNIL recommande une durée de vie des cookies de 13 mois maximum et une conservation du choix de l'internaute de 6 mois. Aucun de ces montants ne constitue une prévision applicable à votre situation.
Une Stratégie Concrète pour Chaque Métier
Que vous pilotiez un e-commerce, une agence ou la conformité juridique de votre groupe, CookieDetox vous apporte les protocoles exacts.
Préservez votre ROAS sans risquer l'amende CNIL
Bloquez proprement le Meta Pixel et TikTok avant consentement tout en déployant Google Consent Mode v2 pour modéliser les conversions perdues.
- Guide d'intégration Shopify & WooCommerce
- Mode avancé Consent Mode v2 correctement configuré
- Aucun impact sur les visiteurs ayant consenti
L'Assurance Zéro Litige pour vos Livraisons
Évitez toute mise en cause juridique de votre agence en cas de contrôle CNIL chez vos clients. Auditez et livrez des sites irréprochables en 15 minutes.
- Décharge de responsabilité contractuelle
- Audit forensique PDF remis à la livraison
- Recommandations CMP (Axeptio, Didomi, Klaro)
Audits Forensiques & Preuves Opposables
Exportez des rapports d'audit techniques détaillant chaque cookie, sa durée, son domaine et son statut d'exemption pour votre registre RGPD.
- Registre de preuve horodaté et opposable
- Détection du Piggybacking & scripts tiers
- Modèles de réponse aux mises en demeure CNIL
Choisir une CMP : les quatre critères qui comptent réellement
Parité du bouton Refuser au premier niveau, support de Google Consent Mode v2, mécanisme de blocage des scripts et modèle de facturation. Chaque case indique ce qu'il faut vérifier sur votre propre site — aucun prix n'est publié ici, car un tarif change et ne se vérifie pas à distance. Aucune note n'est attribuée à un éditeur.
| Solution CMP | Modèle de facturation | Refus au 1er niveau | Consent Mode v2 | Ce qu'il faut vérifier | Guide Dédié |
|---|---|---|---|---|---|
| Axeptio | Paliers selon le trafic | Prévu nativement | Documentation GTM | Quels scripts partent avant le clic, sur votre site | Lire l'analyse → |
| Didomi | Enterprise, sur devis | Selon configuration | IAB TCF v2.2 | Poids réel du SDK et vendors déclarés | Lire l'analyse → |
| Cookiebot | Par domaine indexé | Selon configuration | Support documenté | Parité réelle du bandeau livré | Lire l'analyse → |
| Klaro / Tarteaucitron | Open source, sans licence | À implémenter | Script manuel | Blocage des scripts avant consentement | Lire l'analyse → |
| OneTrust | Enterprise, sur devis | Selon configuration | Support documenté | Poids du script et gouvernance multi-sites | Lire l'analyse → |
All News
Cookie Lifespans: The 6-Month Choice Renewal vs 13-Month Tracker Rule Explained
Master CNIL 6-month consent retention vs 13-month cookie lifespans. Technical audit, gtag.js configuration, and regulatory enforcement criteria.
2026-09-19Proof of Consent: Generating Tamper-Proof Cryptographic Consent Receipts for DPA Audits
Architect tamper-proof consent receipts under GDPR Art. 7(1). Eliminate transient cookie proofs with immutable HMAC-SHA256 logging for DPA audits.
2026-09-19Does Scrolling Constitute Valid Consent? Why Continued Browsing Triggers Severe DPA Fines
Scrolling does not constitute valid GDPR consent. Learn why CNIL and EDPB penalize continued browsing trackers and how to refactor your banner.
2026-09-19Sticky Footer vs Centered Modal: Impact on Opt-in Rate, Bounce Rate & Core Web Vitals
Sticky footer vs centered modal: what your banner layout really changes for consent, bounce rate and Core Web Vitals — with no invented figures.
2026-09-19Maximizing Cookie Opt-in Legally: 7 UX Levers Approved by European DPAs
Raise your cookie opt-in rate without dark patterns: 7 UX levers consistent with CNIL requirements, and the numeric promises you should not believe.
2026-09-19Cookie Opt-in Rate: 2026 Industry Benchmarks Across E-Commerce, SaaS & Media
Cookie opt-in rates: what can actually be measured, what cannot, and how to read a benchmark without trusting unverifiable numbers.
2026-08-09A/B Testing Cookie Banners: The Dark Patterns Trap Demystified
Discover how A/B testing cookie banners can hide dark patterns. Comprehensive GDPR, CNIL guide, concrete examples, and ethical strategies for CookieDetox.
2026-08-09GDPR & A11y: The Essential CMP for Flawless Compliance
Master GDPR compliance and CMP accessibility. Technical guide based on CNIL, EDPB, WCAG 2.2 for inclusive and ethical consent banners.
2026-08-09Cross-domain Tracking & GDPR: Master Seamless Compliance
Discover how to reconcile cross-domain tracking and GDPR. Avoid CNIL sanctions with our advanced consent strategies, compliant tracking techniques, and best practices.
2026-08-09Advanced GA IP Masking: True Server-Side GDPR Compliance
Discover server-side IP masking for Google Analytics (UA/GA4). Detailed architectures, sGTM, proxies, CDNs. Achieve superior GDPR compliance and protect user privacy.
2026-08-09First-Party Data: The Strategic Anti-GDPR Weapon for E-commerce
Discover how First-Party Data is e-commerce businesses' major asset in the face of GDPR. Definition, typology, compliant activation, and ROI. Master your data.
2026-09-19Cookie Compliance for Fintech & Banking: Fraud Prevention Tracker Exemptions & Security Rules
PSD2 SCA vs GDPR ePrivacy compliance for banking. Exemption criteria for fraud tokens, behavioral biometrics, device fingerprints, and ACPR/CNIL rules.
2026-09-19Cookie Compliance for Healthcare & Medical Platforms: Strict Tracker Bans & Heavy Sanctions
Examine GDPR Art. 9 and CNIL tracker bans for medical sites. Avoid €20M fines by eliminating Meta & Google pixels from patient workflows.
2026-09-19Cookie Compliance for SaaS & B2B: Product Analytics (PostHog, Mixpanel) & Lead Tracking
Master SaaS cookie compliance: decouple in-app telemetry from marketing tracking, configure PostHog/Mixpanel lawfully, and pass B2B enterprise procurement.
2026-09-19Cookie Compliance for E-Commerce & D2C: The Zero-Penalty Protocol for Online Merchants
Forensic GDPR & ePrivacy compliance guide for e-commerce and D2C brands. Protect conversion tracking, configure Consent Mode v2, and eliminate audit risks.
2026-08-09Dark Patterns Cookies 2026: The Imminent Ban and Your Anti-Fine Strategy
Anticipate the ban on dark patterns in cookie banners by 2026. This expert guide details GDPR violations, CNIL risks, and compliance strategies to protect your business.
2026-08-09Consent or Pay CNIL: Ultimate Decryption of GDPR Conditions
In-depth analysis of CNIL conditions for Consent or Pay (Paywall) models. Deciphering GDPR, EDPB, ePrivacy, concrete examples, and non-compliance risks.
2026-08-09Cookie Banners: Legal Colors & Contrasts
Expert guide on cookie banner colors and contrasts. Ensure GDPR/ePrivacy compliance, avoid dark patterns, and guarantee valid consent.
2026-09-19HubSpot CMS: Why the Native Cookie Banner Violates EU DPAs & How to Fix It
HubSpot's default native banner drops tracking cookies before consent, violating CNIL & GDPR Art. 7. Forensic fix with Consent Mode v2 and _hsp API.
2026-09-19Framer Sites: How to Deploy a 100% GDPR-Compliant Cookie Banner in 10 Minutes
Step-by-step technical guide to deploying a GDPR/CNIL compliant cookie banner on Framer. Includes Consent Mode v2 code and zero-latency injection.
2026-09-19Nuxt 3 & Vue.js: Reactive Cookie Banner, Script Blocking & Google Consent Mode v2
Architect a zero-hydration mismatch cookie banner in Nuxt 3 with SSR useCookie, script blocking via useScript, and Google Consent Mode v2.
2026-09-19Next.js 15 & React: Zero-FOUC Cookie Consent State Management & SSR Hydration
Architect zero-FOUC, zero-CLS cookie consent in Next.js 15. Server-side cookie reads, React hydration sync, and Google Consent Mode v2 implementation.
2026-09-19Magento 2 & Adobe Commerce: Integrating CMP Without Breaking Varnish Full-Page Cache
Architect GDPR and ePrivacy-compliant CMP integration on Magento 2 and Adobe Commerce without breaking Varnish FPC or exceeding 300ms TTFB.
2026-09-19PrestaShop 1.7 & 8.x: How to Block Tracking Modules & Pixels Before Consent
Block PrestaShop tracking modules & pixels prior to consent. Production Smarty overrides, Google Consent Mode v2, and network verification.
2026-09-19Shopify Plus & Google Consent Mode v2: Custom Pixels vs Native Privacy API Architecture
Implement Google Consent Mode v2 on Shopify Plus via Custom Pixels and Customer Privacy API. Code, sandboxed iframe isolation, and zero-leakage setup.
2026-08-09Webflow & GDPR: Mastering Consent Mode v2 and Cookie Banners
Expert guide for Webflow: Implement GDPR, compliant cookie banners, and Google Consent Mode v2. Technical audit, GTM, script blocking, CNIL jurisprudence.
2026-08-09WordPress GDPR: High-Performance Cookie Banners & CNIL Compliance
Master GDPR compliance for your WordPress cookie banners without compromising speed. Advanced technical guide for optimal consent and performance management.
2026-08-09Shopify Cookie Compliance 2026: Ultimate Guide & Technical Audit
Master Shopify cookie compliance in 2026. Comprehensive technical guide to avoid CNIL fines, audit your site, implement an an advanced CMP, and secure your data.
2026-08-09Squarespace: Disable Default Analytics (GDPR & CNIL)
Comprehensive guide to disabling Google Analytics and default Squarespace analytics. GDPR/CNIL compliance, prior consent, and privacy-friendly alternatives.
2026-08-09WooCommerce & Cookies 2026: The Ultimate CNIL & GDPR Audit
Anticipate 2026! Technical and legal guide for WooCommerce cookie compliance. CMPs, GDPR, CNIL, penalties, and proof of consent. Avoid fines!
2026-09-20How to Fix 'Consent Not Configured' in Google Ads: GTM Audit & Network Decoding
Resolve the 'Consent not configured' warning in Google Ads. 2026 technical guide: decoding gcs (G100, G111) and gcd network flags, fixing GTM race conditions, and recovering Smart Bidding conversion modeling.
2026-09-19Standard Contractual Clauses (SCCs) & TIAs: Auditing US SaaS & Ad-Tech Vendors
Audit US SaaS vendors under GDPR Art 46 & EDPB Schrems II. Step-by-step TIA checklist, Modernized SCCs Module 2/3 validation, and code-level proxying.
2026-09-19Swiss Revised FADP (nLPD): Exact Consent & Banner Requirements for Swiss Traffic
Forensic breakdown of Swiss nLPD cookie banner rules, 250,000 CHF personal officer liability, cross-border data transfers, and dual-traffic implementation.
2026-09-19Quebec Law 25: Canada's Strict Cookie Consent Enforcement & CAI Penalty Risks
Quebec Law 25 imposes GDPR-grade cookie consent in Canada with CAI fines up to $25M CAD or 4% of global turnover. Audit your tracking scripts.
2026-09-19UK GDPR & ICO Post-Brexit: Crucial Differences with Continental DPA Guidelines in 2026
Forensic breakdown of UK GDPR and ICO cookie enforcement vs EU DPAs in 2026: PECR rules, analytics exemptions, Data Bill updates, and technical code.
2026-09-19CCPA/CPRA California vs EU GDPR: Dual Banners, 'Do Not Sell' & Global Privacy Control (GPC)
Forensic breakdown of CCPA/CPRA vs EU GDPR consent architecture: GPC signal automation, dual-banner geo-targeting, Sephora enforcement, and technical scripts.
2026-08-09LGPD Brazil: E-commerce Cookie Compliance & Technical Audit
Master Brazilian LGPD compliance for e-commerce cookies. Ultra-detailed technical guide: DevTools audit, GTM, JS blocking, CNIL sanctions, and consent proofs.
2026-08-09DMA & Google: Mandatory Consent, Technical Audit & Compliance
Decipher the DMA and its implications for Google consent. In-depth technical guide to audit, block cookies, and ensure your website's legal compliance.
2026-08-09GDPR vs. ePrivacy: Deciphering the Fundamentals for Compliance
Master the crucial distinctions between GDPR and the ePrivacy Directive. An in-depth technical guide on obligations, consent, cookies, and compliance audits for experts.
2026-09-20Automated Regulatory Cookie Audits: How DPA Headless Crawlers Inspect Web Traffic and Issue Fines
Forensic breakdown of automated online GDPR cookie inspections by European DPAs (CNIL, AEPD, Garante, ICO). How regulatory crawlers inspect network packets, issue formal notices, and levy fines.
2026-09-19Free vs Paid CMP: The Hidden Legal Fines & Technical Traps of 'Free' Consent Banners
Technical comparison of free vs paid CMPs: blocking mechanisms, proof of consent and documented limits against GDPR Article 7(1).
2026-09-19Quantcast Choice (InMobi CMP): Review, Setup & IAB TCF v2.2 Publisher Compliance
Forensic audit of InMobi CMP (formerly Quantcast Choice). TCF v2.2 compliance, Google Certified status, latency impact, and publisher monetization risks.
2026-09-19Tarteaucitron vs Commercial CMPs: Is Open-Source Still Viable for GDPR in 2026?
Tarteaucitron vs Axeptio and Didomi: TCO analysis, Google Consent Mode v2 setup, CNIL Art. 82 compliance, and technical architectural benchmarks for 2026.
2026-09-19Cookiebot vs Axeptio: Technical Comparison, Auto-Blocking & Google Consent Mode v2
Technical benchmark of Cookiebot vs Axeptio: auto-blocking engine vs GTM events, Google Consent Mode v2, CLS impact, and compliance risks.
2026-09-19OneTrust vs Didomi: Enterprise CMP Comparison for Global Brands in 2026
Forensic enterprise CMP benchmark: OneTrust vs Didomi. Detailed analysis on latency (85KB vs 120KB+), €12k-€60k pricing, TCF v2.3, and GDPR/ePrivacy compliance.
2026-09-19Best Axeptio Alternatives for E-Commerce: Pricing, Speed & CNIL Safety
Compare top Axeptio alternatives for e-commerce. Audit pricing caps, Core Web Vitals latency, CNIL 2020-092 compliance, and Shopify API integrations.
2026-09-19Didomi Review & Hidden Costs: Why Mid-Market & Enterprise Seek Alternatives in 2026
Forensic Didomi CMP review: €4.5k-€15k lock-in contracts, +320ms mobile TBT impact, and benchmark comparisons against lighter GDPR compliance alternatives.
2026-09-19Axeptio vs Didomi: 2026 CMP Comparison, Pricing & CNIL Compliance Audit
Axeptio vs Didomi benchmark: CNIL 2020-091 compliance, IAB TCF v2.2, JS payload (42KB vs 85KB), and pricing audited by CookieDetox forensic engineers.
2026-08-09Complianz WordPress: The Ultimate Technical Compliance Audit
Discover an in-depth technical review of Complianz WordPress. Analysis of the wizard, granular GDPR/CCPA compliance, competitive comparison, and impact on Core Web Vitals.
2026-08-09Axeptio 2026: Independent Technical & Legal Compliance Test
In-depth technical and legal analysis of Axeptio. Evaluate its GDPR and ePrivacy compliance through 2026 with our independent tests and expert opinions. Prepare for the future.
2026-08-09Iubenda Review: Technical Audit & GDPR Cookie Compliance
In-depth technical analysis of Iubenda for GDPR and ePrivacy compliance. Audit of privacy policies, cookie management, and advanced implementation strategies.
2026-08-09Borlabs Cookie vs Real Cookie Banner: Technical Audit & CNIL Compliance
In-depth technical analysis of Borlabs Cookie and Real Cookie Banner for WordPress. Expert guide on GDPR/CNIL compliance, DevTools audit, GTM, and case law.
2026-08-09Sirdata CMP: CNIL Compliance Audit & Technical Optimization
In-depth technical audit of the Sirdata CMP for CNIL and GDPR compliance. Expert guide with GTM, DevTools, sanction cases, and optimization tips for impeccable consent management.
2026-09-192026 Cookie Fine Barometer: Comprehensive Analysis of Penalties in France & Europe
2026 European cookie enforcement data: €650M+ in fines, 42% targeting SMBs under €20M turnover, and technical analysis of pre-consent tracker sanctions.
2026-09-19GA4 & US Data Transfers: The EU-US Data Privacy Framework (DPF) Under Legal Threat
Forensic legal-tech analysis of GA4 under the EU-US Data Privacy Framework: CJEU challenges, FISA 702 risks, proxy isolation, and TIA requirements.
2026-09-19The Mandatory 'Reject All' Button on First Layer: Lessons from 50+ DPA Sanctions
CNIL and EDPB mandate a first-layer Reject All button. Learn legal requirements, visual symmetry rules, and review 50+ sanctions totaling over €400M.
2026-09-19NOYB (Max Schrems) Cookie Complaints: Algorithmic Dark Pattern Detection & Prevention
NOYB automated scanners have triggered 800+ DPA cookie complaints. Discover exact dark pattern detection rules, legal risks, and code-level remediation.
2026-09-19How Regulatory Web Crawlers Audit Sites: The 5 Automated DPA Tests You Must Pass
Data protection authorities use automated headless crawlers to scan websites for GDPR violations. Discover the 5 automated tests and how to pass them.
2026-09-19Formal CNIL Warning (Mise en Demeure): Emergency 30-Day Action Protocol to Avoid Fines
Forensic 30-day DPO response protocol for CNIL formal notices under Article 20. Technical script freezes, consent proof, and zero-penalty closure strategy.
2026-09-19The €40M Criteo CNIL Fine: Autopsy of Ad Retargeting Violations & Lessons for Advertisers
CNIL fined Criteo €40M (SAN-2023-009) over invalid consent and flawed GDPR Art. 17 erasure. Discover the technical risks and joint liability for advertisers.
2026-08-09Cookie Walls: CNIL, 2026 Sanctions & Technical Compliance
Unpack the illegality of cookie walls, CNIL sanctions (2026), and technical audit and GDPR compliance strategies. Avoid hefty fines.
2026-08-09Meta Pixel & Irish DPC: The SME Fine, Ultimate Technical Guide
Unravel the risks of Meta Pixel for SMEs facing the Irish DPC. GDPR technical guide, DevTools audit, GTM, JS blocking, and CNIL/DPC fine jurisprudence. Protect your business.
2026-08-09CNIL & Shopify: Avoid Cookie Fines Without Consent
Ultimate technical guide for Shopify: Understand CNIL fines for cookies without consent. Audit, block, and comply with GDPR with our expert strategies.
2026-09-20Shopify Cookie Compliance & DPA Fines: Forensic Risks and Engineering Guide
Avoid severe GDPR & DPA fines on your Shopify store. Technical breakdown of native theme traps, undeclared app scripts (Klaviyo, Meta Pixel, TikTok), missing layer-1 reject buttons, and complete 2026 compliance audit checklist.
2026-09-19Preserving 90% of ROAS on Meta & Google Ads Under Strict CNIL & GDPR Compliance
Preserve 90%+ ROAS on Meta and Google Ads under strict CNIL & GDPR rules. Leverage Consent Mode v2, OCI, and clean CAPI without cookie penalties.
2026-09-19Google Privacy Sandbox vs Third-Party Cookies in 2026: Technical Architecture & Legal Status
Forensic analysis of Google Privacy Sandbox vs third-party cookies in 2026: Topics API, Protected Audience code, ePrivacy Art. 5(3) compliance, and CMA rulings.
2026-09-19Klaviyo & Omnisend: Consent Requirements for Abandoned Cart Tracking & Web Identification
Forensic breakdown of Klaviyo and Omnisend abandoned cart tracking, __kla_id cookies, and _kx parameters under GDPR Art. 6 and ePrivacy Art. 5(3).
2026-09-19Session Replay Tools (Hotjar, Microsoft Clarity): Regulatory Fines for Unconsented Recording
CNIL and Austrian DSB enforcement against Hotjar & Microsoft Clarity. Technical guide to GDPR consent, DOM masking, and preventing €400,000 fines.
2026-09-19Google Ads Enhanced Conversions: Legality, User Consent & DPA Scrutiny in 2026
Google Ads Enhanced Conversions violates GDPR without explicit opt-in. Discover exact legal requirements, Consent Mode v2 setup, and audit protocols.
2026-09-19Meta CAPI Gateway & GDPR: Event Deduplication, SHA-256 Hashing & Consent Enforcement
Audit Meta CAPI & Gateway for GDPR compliance. Learn event deduplication, client-side SHA-256 hashing, and server-side consent gating under Art. 5(3).
2026-09-19Server-Side Tagging (sGTM) & GDPR: The Dangerous Myth of Automatic Consent Exemption
Server-side GTM does not bypass GDPR or ePrivacy consent. Discover CNIL positions, FPID cookie liabilities, and forensic audit proof.
2026-08-09TikTok Pixel Privacy-First: Audit, Compliance & GDPR Optimization
Master the privacy-first configuration of the TikTok Pixel. GDPR audit, GTM, DOM blocking, consent. Avoid CNIL fines. Technical guide for experts.
2026-08-09Meta Pixel Blocking Pre-Consent: GDPR Compliance & Technical Audit
Master the technical blocking of Meta Pixel before user consent. Expert guide on GDPR, GTM, JS, DevTools, and CNIL jurisprudence for impeccable compliance.
2026-08-09CNIL Analytics Exemption: The Ultimate CookieDetox Guide
Decipher the CNIL exemption for analytics. Detailed guide to technical and legal conditions (GDPR, ePrivacy) for audience measurement without consent. Avoid penalties.
2026-08-09LinkedIn Insight Tag & B2B GDPR: Essential Compliance
Master LinkedIn Insight Tag GDPR compliance in B2B. In-depth technical and legal guide: consent, legitimate interest, GTM, CNIL, DPA. Avoid penalties.