23 sanctions in six months: the CNIL is speeding up its fast-track procedure, often over a single complaint
The CNIL has issued 23 sanctions since January 2026 through its simplified procedure, totaling €133,750 — 19 of them triggered by an individual complaint. Video surveillance, non-compliant cookie banners, and unanswered access or erasure requests are the main grounds. What actually starts one of these cases, and how to stay off the list.
On July 9, 2026, the CNIL announced it had issued 23 sanctions since January 2026 under its simplified procedure, for a combined €133,750 — an average of roughly €5,800 per case. Nineteen of the twenty-three originated from a complaint filed by an individual, not from a CNIL-initiated audit. The grounds break down into three recurring patterns: excessive video surveillance (cameras filming employees continuously, or running without the required prefectural authorization), non-compliant cookie banners (accepting cookies takes one click, refusing them takes several), and failure to honor access or erasure requests — eight of the twenty-three cases, four of which were aggravated by a lack of cooperation with the CNIL once it followed up.
How the simplified procedure works
- →Created in 2022, it is reserved for cases that raise no particular legal difficulty — most consumer complaints about cookies, cameras, or unanswered rights requests fall squarely into that category.
- →A single sanction under this procedure is capped at €20,000, and can be combined with an order to comply, sometimes under a daily penalty.
- →The decision is taken unilaterally by the CNIL president or a delegated member, without the collegiate hearing an ordinary sanction requires — which means cases move fast.
- →The sanctioned organization’s name is not made public, unlike CNIL’s headline fines against large companies — the exposure is financial and procedural, not reputational.
What it means for your SMB
The usual mental model for GDPR risk is a major audit targeting a large company — the kind that makes headlines. That is not what these 23 cases look like. Nineteen started because one customer, one employee, or one visitor filed a complaint after a bad experience: a cookie banner that would not let them refuse in one click, a camera they noticed was always on, an email asking to be forgotten that never got a reply. None of that requires the CNIL to come looking for you — it only requires someone unhappy enough to report it, and the fast-track procedure is built precisely to process that kind of case quickly. The aggravating factor in a third of the rights-request cases is not the original mistake — it is silence afterward, once the CNIL itself asks for an explanation.
Before a complaint reaches the CNIL: four checks
- →Test your own cookie banner as a visitor would: does refusing all cookies take exactly as many clicks as accepting them?
- →Audit your cameras: prefectural authorization for any space open to the public, no continuous filming of a single employee’s workstation, and a documented, limited retention period.
- →Give access and erasure requests a route that cannot get lost in a shared inbox — the legal deadline to respond is one month, extendable to three for complex cases, and it starts running the day the request lands, not the day someone notices it.
- →If the CNIL contacts you following a complaint, respond and cooperate — the data shows non-cooperation gets treated as its own aggravating factor, independent of how serious the underlying issue was.
The recurring failure point in the rights-request cases is structural, not a matter of bad faith: a data subject request arrives at contact@ or support@, mixed in with sales inquiries and spam, and nobody flags it as a legal deadline until it is already late. That is exactly the gap an email triage agent is built to close — sorting a shared inbox, extracting the request, and routing it to whoever owns compliance the moment it lands, instead of the day someone happens to scroll far enough down. Twenty-three cases in six months, mostly triggered by one dissatisfied person each, suggests this fast-track enforcement is becoming routine rather than exceptional — the kind of risk worth closing before it turns into a complaint.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
EU AI Act: what became mandatory on August 2, 2026 — and what it means for your SMB
19 August 2026·5 min read
Business & compliance
Claude now watermarks its text: what Anthropic’s move changes — and doesn’t — for your SMB’s AI content
18 August 2026·5 min read
Business & compliance
Computer History: ChatGPT now remembers your activity — except in France (for now)
17 August 2026·5 min read