Ce qui bouge du côté des autorités, de la jurisprudence et des outils. Chaque entrée renvoie à sa source officielle, et dit ce qu'il faut en retenir.
Europe
The European Board requires the Belgian authority to examine a cookie banner complaint on the merits
The Belgian authority wanted to set aside a complaint from the association noyb targeting the cookie banner of public broadcaster VRT, invoking an abuse of rights. In a binding decision of 28 May 2026, published on 14 July, the European Data Protection Board requires it to rule on the merits and to submit a new draft decision.
A complaint brought by an association can no longer be set aside on that procedural ground alone. If your consent banner is the subject of a complaint, expect it to be examined on the merits.
The European Board adopts guidelines on anonymisation
The European Data Protection Board has adopted guidelines on anonymisation and on automated data collection for generative AI. Data is considered anonymous if it allows neither singling out, nor linkability, nor inference. The text incorporates the Court of Justice ruling of 4 September 2025 and remains open for public consultation until 30 October 2026.
Anonymity is assessed case by case, entity by entity. If you present your statistics as anonymous, document this three-criteria test rather than relying on a vendor label.
Twenty-three simplified sanctions from the CNIL since January 2026, several of them on cookies
The CNIL has issued 23 sanctions under the simplified procedure since January 2026, for a total of 133,750 euros. Nineteen of them follow complaints from individuals. The breaches identified concern in particular banners with no refusal mechanism as simple as acceptance, and advertising cookies set before any consent.
The simplified procedure targets sites of every size, not only the large platforms. Check that refusing takes a single click, exactly like accepting, and that no advertising tracker fires before the choice is made.
The Swiss federal commissioner publishes his 33rd activity report
The 2025/26 report of the Federal Data Protection and Information Commissioner records more than 2,000 notifications of potential data breaches, 156 interventions with controllers and 9 investigations. It also notes the first final ruling handed down under the new act, on 6 October 2025, which confirms the authority's decision-making practice.
The new Swiss act is now applied and confirmed in court. If you process data on Swiss residents, your record of processing activities and your breach notification procedure must be operational.
Google Analytics: the consent signal becomes the only control over advertising data
Since 15 June 2026, the Google Signals setting in Google Analytics only drives the association of data with signed-in users, for behavioural reports. Data sharing with Google Ads now depends on the Ads settings and on the advertising consent signal. Google has announced a second step on ad personalisation later in 2026.
If you use Google Analytics, the configuration you validated with your legal adviser may no longer produce the same effect. Run the test again: refuse everything in your banner and check what actually goes out.
The CNIL publishes its recommendation on tracking pixels in emails
Adopted on 12 March 2026 (deliberation no. 2026-042) and published on 14 April, the recommendation classifies tracking pixels present in emails as trackers within the meaning of Article 82 of the French Data Protection Act. Their use is therefore in principle subject to the prior consent of the recipient. Individual deliverability measurement of transactional emails is among the cases discussed as exempt.
The open rates of your campaigns rely on these pixels. For addresses collected before 14 April 2026, the CNIL asks you to inform recipients clearly and to offer a simple way to object within three months.
The Swiss federal commissioner warns against fake emails sent in his name
The FDPIC is warning about a campaign of fraudulent messages impersonating it. These emails target website operators and accuse them of breaching the Swiss data protection act, with a demand for payment or for the transfer of data. The authority has reported the matter to the competent authorities.
A data protection authority never demands payment by email. Check the sender domain, do not open the attachments and contact the authority through its official channels.
European coordinated enforcement action 2026: transparency and information of individuals
The European Data Protection Board launched its annual coordinated action on 19 March 2026. Twenty-five national authorities are examining compliance with the transparency and information obligations set out in Articles 12, 13 and 14 of the GDPR. The results will be aggregated in the second half of 2026.
Your privacy policy and your information notices are on this year's audit programme. Go through them point by point: purposes, legal bases, retention periods, recipients.
The Luxembourg Administrative Court annuls the 746 million euro fine imposed by the CNPD
By judgment no. 52757C of 12 March 2026, the Administrative Court of Luxembourg annulled the CNPD decision of July 2021 imposing 746 million euros on a major online commerce player for its behavioural advertising practices. The Court faults the authority for having analysed neither whether the conduct was intentional or negligent, nor the range of corrective measures available. The case is referred back to the CNPD.
The annulment concerns the method, not the substance of the case. The main point to remember is that the Luxembourg authority will have to reason its sanctions more finely, which lengthens proceedings without lowering the level of requirement.
End of the transition period to version 2.3 of the advertising consent framework
Published on 19 June 2025, version 2.3 of the IAB Europe Transparency and Consent Framework makes the disclosedVendors segment mandatory in the consent string. The transition period ended on 28 February 2026. Strings created after that date without this segment are considered invalid.
If your consent management platform has not been updated, the signals it produces may be rejected by your advertising partners. Ask your provider for written confirmation of the upgrade.
The Luxembourg CNPD can now bring collective actions
The act of 20 November 2025, in force since 25 November 2025, transposes Directive 2020/1828 on representative actions and creates a new Book 5 of the Consumer Code. The CNPD is recognised there as a qualified entity. It can therefore seek an injunction, a redress measure, or both, before the courts.
In Luxembourg, a GDPR breach affecting many customers can now lead to a collective redress action, on top of an administrative fine. The financial risk is no longer limited to the authority's penalty.
Critical joint opinion of the European authorities on the digital omnibus
The European Data Protection Board and the European Data Protection Supervisor have adopted a joint opinion on the digital omnibus proposal. They consider that redefining the notion of personal data goes well beyond a technical adjustment and departs from the case law of the Court of Justice. They do support, on the other hand, the measures against consent fatigue and banner proliferation, as well as automated machine-readable signals.
The framework applicable to trackers is going to move, but not yet. Follow the file without rewriting your banners right now: the text is not settled.
Switzerland: a major online retailer makes personalisation switchable off in one click
Following a formal recommendation from the FDPIC, the Digitec Galaxus site now allows site personalisation to be turned off in a single action, with automatic deactivation of the associated cookies. The authority had found that tying together the ordering process, account creation and processing for marketing purposes breached the principle of proportionality. The case has been closed.
In Switzerland too, tying a purchase to unnecessary marketing processing is a problem. Objecting must be as simple as opting in, and must actually carry through to the trackers that are set.
The CNIL issued 259 decisions in 2025, including 83 sanctions, 143 formal notices, 31 reminders of legal obligations and 2 warnings. The cumulative amount of the fines reaches 486,839,500 euros. Twenty-one organisations were sanctioned in relation to cookies and other trackers.
Trackers remain the leading ground for sanctions in France. An annual audit of your banner and of the scripts actually loaded is the minimum defensible position.
The CNIL sets out the rules for tracker consent valid across several devices
On 16 January 2026 the CNIL published its final recommendations on multi-device consent, arising from deliberation no. 2025-131 of 18 December 2025 amending the 2020 cookie recommendation. The mechanism is optional and only applies in environments where the user is authenticated. Refusal must remain as simple as acceptance and the information must state the scope of the choice. Work on multi-property consent is announced for 2026.
If your users have an account, you can attach their choice to that account rather than to the browser. Plan an explicit resolution rule for contradictory choices between devices.
Meta commits to offering a choice on personalised advertising in the European Union
After a non-compliance decision under the Digital Markets Act issued in April 2025, Meta committed to the European Commission to offer Facebook and Instagram users an alternative to the binary model. People can choose between fully personalised advertising and an experience using less personal data. These options were presented to European users in January 2026.
The model that offers only consent or a paid subscription is contested by regulators. If you are considering a consent wall, plan a third path that uses less data.
The European Commission proposes moving the cookie rules into the GDPR
Presented on 19 November 2025, the digital omnibus regulation proposal (procedure 2025/0360) moves into the GDPR the rules on access to information stored on terminal equipment, currently carried by the ePrivacy Directive. Consent remains the principle, with a broadened list of exempt purposes and the idea of a choice stored at browser level. The text is still under negotiation between the Parliament and the Council.
Nothing applies at this stage. Do not dismantle your consent mechanism in anticipation of a text that can still change.
Google withdraws ten technologies from the Privacy Sandbox programme
On 17 October 2025, Google announced that it was dropping ten technologies from the Privacy Sandbox programme, including Topics, Protected Audience, Attribution Reporting and Private Aggregation, citing a low level of adoption. A few building blocks are kept, notably CHIPS, FedCM and Private State Tokens.
The alternatives to third-party cookies promised by the browser will not arrive. Advertising trackers therefore remain subject to consent, with no technical replacement to expect.
The Court of Justice clarifies when pseudonymised data remains personal data
In case C-413/23 P between the European Data Protection Supervisor and the Single Resolution Board, the Court of Justice holds that pseudonymised data does not constitute personal data in every case and for every person. Depending on the circumstances, pseudonymisation can prevent a recipient from identifying the data subjects. Identifiability is assessed from the point of view of the controller at the time of collection, who remains obliged to inform the individuals.
The status of your data depends on who holds it and on what they can cross-reference. Document, for each recipient, the means actually available to them to re-identify a person.
The CNIL fines Google 325 million euros and Shein 150 million
On 3 September 2025, the CNIL issued two fines for failure to comply with the rules applicable to trackers. Google is sanctioned in particular for displaying advertisements between the messages in the inbox and for setting trackers during account creation without valid consent. The Irish subsidiary of Shein is sanctioned for setting advertising cookies from the very first visit and for insufficient information on the purposes and on refusal.
The record amount should not obscure the grievance: trackers set before the choice and incomplete information. These are exactly the points checked during online audits, whatever the size of the site.
The General Court of the European Union dismisses the action against the transfer framework to the United States
In case T-553/23, the General Court of the European Union dismissed the action for annulment brought against the adequacy decision of 10 July 2023 governing data transfers to the United States. It holds that the level of protection offered is essentially equivalent to the one guaranteed within the Union. An appeal was lodged before the Court of Justice in the autumn of 2025.
Transfers to a certified US provider remain possible today. Bear in mind, however, that an appeal is pending, and map your dependencies outside the European Union.
The CNIL replaces its evaluation programme with a self-assessment of audience measurement solutions
On 4 July 2025, the CNIL made available a self-assessment tool allowing vendors to check whether their audience measurement solution can be exempted from consent. The former evaluation programme and its public list of solutions came to an end on 1 January 2026. Vendors must document their analysis and cannot claim any CNIL certification.
A marketing claim along the lines of exempt solution is no longer enough. Ask your provider for the self-assessment document and for the exact configuration to apply, because the site publisher remains liable in case of an audit.
The Belgian Market Court rules on the advertising consent framework
By judgment of 14 May 2025, the Brussels Market Court confirms that the consent string known as the TC String is personal data and that IAB Europe acts as controller for the processing of user preferences under the TCF. It rejects that classification, on the other hand, for the processing carried out through the OpenRTB protocol. The fine of 250,000 euros is maintained, the initial decision having been annulled on procedural grounds.
The consent string produced by your platform is personal data in its own right. It must appear in your record of processing activities and in the information you give your visitors.
Chrome drops its new prompt on third-party cookies
On 22 April 2025, Google announced that it would keep its current approach to third-party cookies in Chrome and would not roll out the dedicated prompt that had been planned. Users keep the ability to manage their preferences in the browser settings. This decision brings to an end several years of announcements about the disappearance of third-party cookies.
The disappearance of third-party cookies, often presented as imminent, will not happen through the browser. Your consent obligations, for their part, are unchanged and stem from the law, not from Chrome.
The Swiss federal commissioner publishes a guide on cookies and similar technologies
On 3 February 2025 the FDPIC published a guide describing the requirements applicable to the processing of data by means of cookies and similar technologies by private controllers. It derives these requirements from the Federal Act on Data Protection, its ordinance and case law. Version 1.1 of the document was released on 6 October 2025.
Swiss law does not mirror the European prior consent regime, but it does require transparency and proportionality. If you address a Swiss audience, align your privacy policy with this guide rather than assuming equivalence with the GDPR.