Your CMP claims compliance. Your network proves otherwise.
What your banner displays says nothing about what your network transmits. Les scripts GTM, balises Shopify Customer Events et Pixels Meta peuvent s'exécuter avant le consentement. Vérifiez ce qui part réellement, requête par requête.
Technical Counter-Audit & Simulator
1. What is your technical stack / CMS?
Cookie enforcement barometer: what authorities actually decided
A synthesis of decisions published by the CNIL, the Irish DPC and European courts. Every amount links to its official decision or press release. No proprietary statistics, no internal estimates.
83 decisions totalling €486,839,500 across all subject matters. Official CNIL report
CNIL, 3 September 2025, ads inserted between emails without consent. CNIL decision
Reference decisions by vendor
Sources: CNIL, DPC, Légifrance| Vendor | Authority & date | Amount | Reason | Source |
|---|---|---|---|---|
| Google LLC & Google Ireland Ltd. | CNIL — 7 déc. 2020 / 13 janv. 2022 | 100 M€ / 150 M€ | Cookies set without consent, refusal made difficult (SAN-2020-012, SAN-2022-001) | CNIL decisions |
| Meta Platforms Ireland Ltd. | CNIL — 13 janv. 2022 | 60 M€ | Cookie refusal path more complex than acceptance (SAN-2022-002) | CNIL decision |
| Amazon Europe Core | CNIL — 7 déc. 2020 | 35 M€ | Advertising cookies set without consent, insufficient information (SAN-2020-013) | CNIL decision |
| TikTok / ByteDance | CNIL — 12 janv. 2023 | 5 M€ | No refusal button as simple as acceptance (SAN-2022-027) | Décision |
| Criteo SA | CNIL — 15 juin 2023 | 40 M€ | Behavioural retargeting without consent, access and withdrawal rights (SAN-2023-009) | Légifrance |
| LinkedIn Ireland | DPC (Irlande) — 24 oct. 2024 | 310 M€ | Legal bases for behavioural advertising | DPC press release |
Retention reference rule: the CNIL recommends a maximum cookie lifespan of 13 months and keeping the user's choice for 6 months. None of these amounts is a forecast for your own situation.
Concrete Strategies for Every Professional
Whether you manage an e-commerce brand, a web agency, or group data governance, CookieDetox provides clear, actionable protocols.
Safeguard Your ROAS Without DPA Sanctions
Properly block Meta Pixel and TikTok prior to opt-in while implementing Google Consent Mode v2 to model unconsented conversions.
- Shopify & WooCommerce compliance SOPs
- Advanced Consent Mode v2 correctly configured
- No impact on visitors who consented
Zero-Liability Assurance for Client Delivery
Prevent contract disputes and agency liability in case of DPA audits on client websites. Audit and ship 100% compliant stacks in 15 minutes.
- Contractual liability protection clauses
- Forensic PDF audit report upon project handover
- Verified CMP templates (Axeptio, Didomi, Klaro)
Forensic Audits & Court-Ready Evidence
Export technical reports detailing each cookie, its lifespan, domain provenance, and exemption status for your official GDPR records.
- Cryptographic timestamped proof logs
- Piggybacking & third-party script mapping
- Standard response templates for DPA inquiries
Choosing a CMP: the four criteria that actually matter
First-layer refusal parity, Google Consent Mode v2 support, script-blocking mechanism and billing model. Each cell states what to verify on your own site — no prices are published here, because a price changes and cannot be verified remotely. No rating is assigned to any vendor.
| CMP Platform | Billing model | First-layer refusal | Consent Mode v2 | What to verify | Dedicated Review |
|---|---|---|---|---|---|
| Axeptio | Traffic-based tiers | Supported natively | Documentation GTM | Which scripts fire before the click, on your site | Read the analysis → |
| Didomi | Enterprise, quote-based | Configuration-dependent | IAB TCF v2.2 | Actual SDK weight and declared vendors | Lire l'analyse → |
| Cookiebot | Per indexed domain | Selon configuration | Documented support | Actual parity of the shipped banner | Lire l'analyse → |
| Klaro / Tarteaucitron | Open source, no licence fee | To be implemented | Manual script | Script blocking before consent | Lire l'analyse → |
| OneTrust | Enterprise, sur devis | Selon configuration | Support documenté | Script weight and multi-site governance | Lire l'analyse → |
Latest Investigations & Case Law
Proof of Consent: Generating Tamper-Proof Cryptographic Consent Receipts for DPA Audits
Architect tamper-proof consent receipts under GDPR Art. 7(1). Eliminate transient cookie proofs with immutable HMAC-SHA256 logging for DPA audits.
2026-09-19Does Scrolling Constitute Valid Consent? Why Continued Browsing Triggers Severe DPA Fines
Scrolling does not constitute valid GDPR consent. Learn why CNIL and EDPB penalize continued browsing trackers and how to refactor your banner.
2026-09-19Sticky Footer vs Centered Modal: Impact on Opt-in Rate, Bounce Rate & Core Web Vitals
Sticky footer vs centered modal: what your banner layout really changes for consent, bounce rate and Core Web Vitals — with no invented figures.
2026-09-19Maximizing Cookie Opt-in Legally: 7 UX Levers Approved by European DPAs
Raise your cookie opt-in rate without dark patterns: 7 UX levers consistent with CNIL requirements, and the numeric promises you should not believe.
2026-09-19Cookie Opt-in Rate: 2026 Industry Benchmarks Across E-Commerce, SaaS & Media
Cookie opt-in rates: what can actually be measured, what cannot, and how to read a benchmark without trusting unverifiable numbers.
2026-08-09A/B Testing Cookie Banners: The Dark Patterns Trap Demystified
Discover how A/B testing cookie banners can hide dark patterns. Comprehensive GDPR, CNIL guide, concrete examples, and ethical strategies for CookieDetox.
2026-08-09GDPR & A11y: The Essential CMP for Flawless Compliance
Master GDPR compliance and CMP accessibility. Technical guide based on CNIL, EDPB, WCAG 2.2 for inclusive and ethical consent banners.
2026-08-09Cross-domain Tracking & GDPR: Master Seamless Compliance
Discover how to reconcile cross-domain tracking and GDPR. Avoid CNIL sanctions with our advanced consent strategies, compliant tracking techniques, and best practices.
2026-08-09Advanced GA IP Masking: True Server-Side GDPR Compliance
Discover server-side IP masking for Google Analytics (UA/GA4). Detailed architectures, sGTM, proxies, CDNs. Achieve superior GDPR compliance and protect user privacy.
2026-08-09First-Party Data: The Strategic Anti-GDPR Weapon for E-commerce
Discover how First-Party Data is e-commerce businesses' major asset in the face of GDPR. Definition, typology, compliant activation, and ROI. Master your data.
2026-09-19Cookie Compliance for Fintech & Banking: Fraud Prevention Tracker Exemptions & Security Rules
PSD2 SCA vs GDPR ePrivacy compliance for banking. Exemption criteria for fraud tokens, behavioral biometrics, device fingerprints, and ACPR/CNIL rules.
2026-09-19Cookie Compliance for Healthcare & Medical Platforms: Strict Tracker Bans & Heavy Sanctions
Examine GDPR Art. 9 and CNIL tracker bans for medical sites. Avoid €20M fines by eliminating Meta & Google pixels from patient workflows.
2026-09-19Cookie Compliance for SaaS & B2B: Product Analytics (PostHog, Mixpanel) & Lead Tracking
Master SaaS cookie compliance: decouple in-app telemetry from marketing tracking, configure PostHog/Mixpanel lawfully, and pass B2B enterprise procurement.
2026-09-19Cookie Compliance for E-Commerce & D2C: The Zero-Penalty Protocol for Online Merchants
Forensic GDPR & ePrivacy compliance guide for e-commerce and D2C brands. Protect conversion tracking, configure Consent Mode v2, and eliminate audit risks.