ePrivacy Directive + GDPR
Cookie Consent Fine Calculator
Estimate your cookie-consent enforcement exposure and get a prioritized fix list based on CNIL practice.
How this is calculated
- Each issue you tick has a weight: 3 for cookies set before consent; 2 for no first-layer reject button, pre-ticked boxes, cookie walls or undisclosed third-party trackers; 1 for no granular choice or no consent records. The weights add up to a score.
- Two multipliers apply: supervisory risk (0.5 low, 1 medium, 2 high) and audience (1 under 10,000 monthly EU visitors, 2 from 10,000, 4 from 100,000, 8 from 1,000,000).
- Low end = EUR 2,000 x score x risk x audience, rounded to the nearest EUR 100, with a floor of EUR 1,000. High end = 25 x the low end, capped at EUR 20 million.
- Fixes are listed heaviest-weight first, so the top of the list is where risk falls fastest.
Constants the tool uses
Unless a value names a study, it is VITI Security's working estimate for budgeting - not taken from a statute or a dated study - so treat it as an adjustable assumption.
- Issue weights
- 3 / 2 / 1 as described above
- Base amount per score point
- EUR 2,000
- Supervisory risk multiplier
- 0.5 / 1 / 2
- Audience multiplier
- 1 / 2 / 4 / 8
- High end
- 25x the low end, capped at EUR 20 million
- Floor
- EUR 1,000
Worked example
The calculator run on its default inputs:
- Monthly EU visitors
- 50,000 visitors
- Consent issues found on your site (select all that apply)
- Non-essential cookies set before consent
- Supervisory attention risk
- Medium - active market, some complaints possible
Indicative exposure band
€12,000 - €300,000
- Issues selected
- 1
- Exposure band (indicative)
- €12,000 - €300,000
- Fix #1
- Block all non-essential cookies and tags until consent is given (prior-consent requirement, ePrivacy Art. 5(3)).
One issue (non-essential cookies before consent, weight 3), medium supervisory risk (x1) and 50,000 monthly EU visitors (x2) give EUR 2,000 x 3 x 1 x 2 = EUR 12,000 at the low end, and 25 times that, EUR 300,000, at the high end.
Sources
- ePrivacy Directive 2002/58/EC, Art. 5(3) (EUR-Lex) - prior consent before storing or reading non-essential information on a device (as amended by Directive 2009/136/EC)
- GDPR Art. 4(11), 7 and 83 (EUR-Lex) - what valid consent is, proof of consent, and the EUR 20 million / 4% ceiling
- EDPB Guidelines 05/2020 on consent - cookie walls and freely given consent
- CNIL decision SAN-2020-013, Amazon Europe Core (Legifrance) - EUR 35 million, December 2020
- CNIL decision SAN-2021-024, Facebook Ireland (Legifrance) - EUR 60 million, December 2021
- CNIL decision SAN-2022-023, Microsoft Ireland (Legifrance) - EUR 60 million, December 2022
- CNIL - Shein fined EUR 150 million - September 2025
- CNIL decision SAN-2025-004, Google (CNIL) - EUR 325 million, September 2025
- CNIL - American Express fined EUR 1.5 million - November 2025
- CNIL - simplified sanction procedure - fines capped at EUR 20,000, or EUR 100,000 above EUR 50 million worldwide turnover
Sources last checked September 2026.
Limitations
The band is a heuristic, not a prediction: cookie rules are enforced under each country’s ePrivacy law, with its own ceilings and procedures, and the reference fines above involved very large companies. The EUR 20 million cap is a modelling choice - fines on large companies have gone well above it (Google, EUR 325 million in 2025). This is an indicative estimate for education and planning, not legal advice. Laws and published figures change, and regulators and courts apply discretion no calculator can model - confirm with a qualified legal or compliance professional before acting on a result.
