Skip to content

Do a Few Google or Meta Cookies Really Matter?

6 min readBy Jussi Saarinen

Yes. For billions of euros. European regulators have now handed out over €2 billion in fines for getting cookie consent wrong.

You know that cookie banner on your website? The one your marketing agency set up two years ago? European regulators have now handed out over €2 billion in fines for getting it wrong.

Two billion. With a B.

Still think those tracking pixels are no big deal?


They Started With the Giants

When regulators got serious about cookie enforcement in 2020, they went after the biggest fish first.

Google has been fined three times by France alone:

  • €100 million in 2020 for placing advertising cookies before users clicked accept.
  • €150 million in 2021 for making it harder to reject cookies than accept them. Users needed five clicks to say no. One click to say yes.
  • €325 million in 2025 for cookie violations plus sneaking ads into Gmail inboxes.

Facebook paid €60 million in 2021. Same story. One click to accept, three clicks to reject. The reject button was buried and mislabeled.

Amazon got hit with €746 million in 2021. Their advertising system was tracking users without proper consent.

Microsoft paid €60 million in 2022 because Bing made it nearly impossible to refuse cookies.

TikTok received a €5 million fine in 2023. Multiple clicks to reject, one button to accept all.

These cases set the rules. The precedents exist. And now regulators are moving down the list.


Now They're Coming for Everyone Else

In 2024 and 2025, the fines started hitting normal businesses. Not tech giants. Regular companies using the same tools you probably use.

Two Swedish pharmacy chains paid a combined €3.9 million in 2024. Their Meta Pixel was sending customer health data to Facebook. What medicines people browsed. What they put in their cart. The pharmacies had enabled a feature called Advanced Automatic Matching without understanding what it actually did.

A Swedish bank paid €1.3 million in 2024. Their misconfigured Meta Pixel sent financial data on one million customers to Meta.

Finland's largest pharmacy chain received a €1.1 million fine in 2025. One of the biggest GDPR penalties in Finnish history. Their Meta Pixel and Google Analytics transmitted data about which medicines customers viewed and purchased. For four years.

None of these companies meant to break the law. They were using standard marketing tools. The same tools running on millions of websites right now.


"I Didn't Know" Won't Save You

Think of it like taxes.

If you make mistakes on your tax return, even honest ones, you still owe the money. The tax office won't forgive penalties because you didn't understand the rules. You were supposed to get it right.

Data protection works exactly the same way.

When regulators scan your website and find your Meta Pixel firing before consent, or your analytics collecting data it shouldn't, they will not care that you didn't know. They will not care that your marketing agency set it up. They will not care that everyone else does the same thing.

You are the data controller. You are responsible.

The Swedish pharmacies reported their own problems. They cooperated fully. They fixed everything immediately. They still paid millions.


Your Turn Is Coming

For years, small businesses assumed regulators were too busy chasing Google to notice them. That assumption is now dangerous.

The pattern is obvious:

  • 2020 to 2021: Big Tech gets fined, precedents get established.
  • 2022 to 2023: Enforcement continues, adtech companies like Criteo pay €40 million.
  • 2024 to 2025: Regular businesses start getting hit. Pharmacies. Banks. Retailers.

Regulators now have the legal precedents. They have the technical tools. Researchers are scanning websites and reporting violations to authorities. That is exactly how the Finnish pharmacy case started. A PhD researcher found the problem and reported it.

The question is not whether enforcement will reach businesses your size. The question is when.


What You Should Do

Find out what is actually on your website. Most business owners have no idea. Marketing installed a pixel years ago. A developer added analytics. Someone clicked a checkbox without reading what it does. Scan your site. See what is really there.

Check when things fire. The most common violation is tracking that starts before the user consents. Your cookie banner might look fine, but if pixels are running in the background before anyone clicks accept, you have a problem.

Understand your tools. That Advanced Automatic Matching feature in Meta Pixel? The one that caused the Swedish pharmacy fines? It is a checkbox. Many businesses enabled it without knowing what it does.


The Point

A few cookies can cost you millions.

The era when only tech giants worried about this is over. The rules are set. The tools exist. The regulators are working their way down.

When they knock on your door, saying you didn't know will not help. Just like taxes, the responsibility was always yours.

Sort it out now, on your terms. Or sort it out later, on theirs.

Safe browsing,

Jussi Saarinen

Founder

GDPR Scanner
Privacy that pays off.

Built in Finland, EU
for businesses everywhere.

Scan your website for free at

gdprscanner.eu