France built a GDPR fining machine, and it runs on complaints
The CNIL issued 23 sanctions in six months without naming a single company. The headline fines were never the real risk.
Since January, the French data protection regulator has issued 23 sanctions. The combined total is €133,750, an average of about €5,800 each. Nineteen of them started with an ordinary complaint. Not one of the companies was named in public. The CNIL reported the tally on 6 July.
That is the story worth watching this year, and it is the opposite of the story most people track.
The machine, not the megafine
When a GDPR fine makes the news, it usually has nine figures. The CNIL's own 2025 review counts €486.8 million in cumulative fines for the year. But that number is carried by a handful of large cases. The volume, the part that actually tells you how enforcement behaves, sits underneath it. Of the 83 sanctions the CNIL issued in 2025, 67 came through its simplified procedure. That is roughly four in five. The 23 handed down since January are all simplified too.
The simplified procedure has existed since 2022. It was built for cases that are not legally complicated. One person, the chair of the CNIL's restricted committee or a single member of it, decides and signs. The maximum fine is €20,000. The organisation is not named publicly. There is no hearing, no press release with a household brand in the headline.
That design is the point. A hundred-million-euro penalty is expensive to produce and rare by nature. A €5,000 fine signed by one person is cheap to produce, and it can be produced constantly. France has spent three years turning enforcement from an event into a process.
It runs on complaints, which means it runs on your worst day
Nineteen of the 23 began as complaints. That matters more than it looks. An enforcement model that depends on the regulator opening its own investigation only reaches the targets the regulator chooses. A model that runs on complaints reaches anyone a customer, an ex-employee, or a competitor decides to report. The trigger sits outside your control, and the cost of pulling it is one online form.
For a large company, a €20,000 fine is a rounding error. For the enforcement system, it is a way to touch far more organisations than the set-piece cases ever could. The risk is no longer concentrated at the top of the market. It has spread to the middle.
What actually gets fined
The 23 sanctions cluster in three unglamorous places.
Video surveillance. Cameras filming employees continuously with no exceptional justification, and cameras installed without the required prefectural authorisation. "Cameras must in no way film employees permanently if no exceptional circumstance justifies it," the CNIL said. The cases hit fast food outlets, urban transport, and railway-station shops.
Cookies. Consent banners that drop cookies before the visitor agrees, give incomplete information about what is being set, or make "accept" a single click while "refuse" takes several. The asymmetry is the violation.
Rights and cooperation. Eight of the 23 involved failures to answer access or deletion requests in time. Four of those were made worse by a failure to cooperate with the CNIL when it asked questions.
None of that is exotic. Every one of those failures is the kind of thing a mid-size company gets slightly wrong and assumes is too small to matter. The simplified procedure exists precisely to fine the things that are too small to matter, one at a time.
What good practice looks like
If you operate in France, or serve French residents, three checks cover most of this exposure.
CCTV: film the space, not the staff. Continuous employee monitoring needs a justification you can actually document, clear signage, and, where the law requires it, the prefectural authorisation. Proportionality is the test, not intent.
Cookie consent: make refuse as easy as accept. Set nothing before consent, describe what each cookie does, and give the "refuse" button the same weight as "accept". Symmetry is not a nicety here. It is the specific thing being fined.
Access and deletion requests: log them and meet the clock. The failure that gets sanctioned is rarely a wrong answer. It is silence. A route that records the request, tracks the deadline, and produces evidence you responded is most of the defence.
And when the regulator writes to you, answer. Non-cooperation turned four of these cases into heavier ones. Ignoring the letter is a second, separate finding on top of the first.
The through-line is that none of this needs a large compliance budget. It needs the basics documented, defensible, done. The gap the CNIL is fining is the gap between what companies think they have in place and what they actually have.
Why it travels
The CNIL is not the only regulator watching its own output. A procedure that produces steady, low-cost, high-volume enforcement is attractive to any authority under pressure to show activity without the cost of a marquee case. The specifics here are French, but the shift is not. Enforcement as a lottery that only the largest players lose is closing. Small, fast, and frequent is a different kind of risk, and it reaches companies the old model never touched.
The megafines will keep making headlines. The machine underneath them is what will reach most businesses. If this was useful, subscribe, and restack it for someone who still thinks they are too small to be on the list.
Not legal advice. Talk to your own counsel for that.
Abhishek

