CNIL homepage: cookie fines, Artificial Intelligence governance, new privacy resources

The CNIL’s homepage spotlights recent enforcement actions, European guidance, and public awareness efforts. Highlights include major cookie fines, a joint commitment on Artificial Intelligence governance, and updated privacy resources.

The CNIL’s English homepage highlights a mix of enforcement, guidance, and public outreach. A featured item showcases an English-language graphic narrative called The Privacy Agency, inspired by manga, designed to help raise awareness among teenagers about personal data and online privacy. Enforcement remains a central theme: as part of a cookie regulation action plan initiated in 2019, the CNIL imposed fines of 325 million euros on Google and 150 million euros on Shein for failures to comply with cookie rules. The authority also published final recommendations to help professionals design mobile applications with stronger privacy protection, following a public consultation.

Recent news items underscore ongoing European coordination and national oversight. The European Data Protection Board adopted opinions on draft United Kingdom adequacy decisions, posted on 20/10/2025. On 16/10/2025, the EDPB published guidelines on the interaction between the GDPR and the Digital Markets Act and announced coordinated European-level transparency checks. At the national level, the CNIL reported a sanction against the Samaritaine regarding hidden cameras, published on 23/09/2025, and the closure of an injunction issued against Orange, published on 18/09/2025. The homepage also reiterates the awareness initiative for teenagers through The Privacy Agency, listed in news on 12/09/2025.

Artificial Intelligence governance features prominently. A joint statement on trustworthy data governance for Artificial Intelligence notes that twenty data protection authorities have committed to fostering innovative and privacy-protecting Artificial Intelligence, published on 18/09/2025. The item reflects growing cross-border collaboration among authorities on emerging technologies while emphasizing data protection safeguards.

The CNIL also spotlights practical resources. A 2024 edition of the practice guide for the security of personal data is featured, alongside two documents: The CNIL in a nutshell 2025 and Cybersecurity 2024 – GDPR: the best prevention against cyber risks. Together, these resources and updates illustrate the regulator’s dual focus on enforcement and education, combining sanctions and European guidance with toolkits and recommendations to support better compliance and privacy-by-design practices.

58

Impact Score

What businesses need to know about the EU cyber resilience act

The EU cyber resilience act is turning product cybersecurity into a legal requirement for companies that sell digital products into the European Union. A key compliance milestone arrives in September 2026, well before the full regulation takes effect in 2027.

Claude Mythos and cyber insurance’s next inflection point

Claude Mythos is being treated by governments and regulators as a potential systemic cyber risk with implications for financial stability and insurance markets. Its emergence is intensifying pressure on insurers to clarify whether Artificial Intelligence-enabled cyber losses are covered, excluded, or require new stand-alone products.

OpenAI expands ChatGPT ads with self-serve manager

OpenAI is widening its ChatGPT ads pilot with a beta self-serve Ads Manager, new bidding options and broader measurement tools. The push signals a deeper move into advertising as the company expands the program into several international markets.

OpenAI launches Artificial Intelligence deployment consulting unit

OpenAI has created a new consulting and deployment business aimed at helping enterprises build and roll out Artificial Intelligence systems. The move mirrors a similar push by Anthropic and signals a broader effort by model providers to capture more of the enterprise services market.

SK Group warns DRAM shortages could curb memory use

SK Group chairman Chey Tae-won warned that customers may reduce memory consumption through infrastructure and software optimization if DRAM suppliers fail to raise output. Demand from Artificial Intelligence data centers is keeping the market tight as memory makers weigh expansion against the long timelines for new fabs.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.