GDPR cookie banner fines: What websites actually get fined for (2026)

Published 24 August 2026 · 8 min read · GDPR Enforcement Cookies

Most website owners know they need a cookie banner. Far fewer know what actually gets a site fined — and it's usually not "no banner at all". Data protection authorities across the EU consistently penalise a small set of specific, fixable mistakes.

This article walks through real enforcement patterns, the amounts involved, and how to check whether your own setup has the same weaknesses — before an authority or a competitor's complaint does.

💡 Check your own site first: our free compliance scanner tests your cookie banner, HTTPS hardening and privacy policy link on any URL — no sign-up.

What gets websites fined (and what doesn't)

1. Non-compliant banners that are worse than nothing

The single most common trigger is a banner that looks compliant but isn't:

2. No records of consent

GDPR Article 7(1) puts the burden of proof on you. If you can't show when and how each user consented, regulators treat the consent as never having happened. Fines here are common because most small-site consent setups store nothing at all.

3. Missing or buried privacy policy

A cookie banner that doesn't link to a privacy policy explaining cookie purposes, retention periods and third parties fails the "informed" requirement. Several DPAs issue low-level fines and reprimands for this daily — they rarely make headlines but they do land in your inbox.

What typically does not get fined

Strictly necessary cookies without consent (legal under ePrivacy Art. 5(3)), first-party session cookies, and banners that simply use an unusual design as long as consent is freely given, informed and revocable. Design taste isn't regulated; mechanics are.

Typical fine ranges

ViolationTypical rangeNote
No valid consent mechanism€2,000 – €100,000+Scales with traffic and data sensitivity
Tracking before consent€5,000 – €60MMeta/Google cases sit at the extreme end
Missing reject option / dark patterns€40,000 – €150MCNIL 2022 decisions set the benchmark
No privacy policy link / incomplete info€500 – €20,000Most common outcome for SMB sites after complaints
⚠️ The realistic risk for a small business isn't the headline fine. It's the complaint: one user, one email to a DPA, then weeks of correspondence, mandatory documentation and a remediation deadline. Prevention costs minutes; response costs months.

The 5-point self-check

  1. Nothing fires before the click. Open your site in an incognito window with dev tools open. No analytics, marketing or embed cookies may appear before consent.
  2. Reject is one click, equal weight. Same size, same contrast, same number of clicks as accept.
  3. Consent is logged. Your CMP stores timestamp + choices per user.
  4. Banner links to your privacy policy, which names cookie categories, purposes, retention periods and third parties.
  5. Withdrawal works. A visible "cookie settings" path lets users change their mind as easily as they said yes.

Check items 1–3 automatically

Our free scanner checks any URL — WordPress, Shopify, Webflow, Next.js, Squarespace or plain HTML — for consent-banner presence, HTTPS hardening and privacy-policy linking, and tells you exactly what to fix:

Run a free scan →

🛡️ Passed? Show it off — add a free compliance badge to your site (great for client trust and a dofollow backlink).

Want documented proof for clients or auditors? EUComply Pro generates a signed report you can archive, and the document generator drafts the policies themselves.