Skip to main content

Menu

Choose a theme and configure high-contrast mode. Preferences are saved in your browser only.

User Preferences

Theme

Pick a palette or follow your system preference.

High Contrast

Sharper text and borders. System follows your OS setting.

Andrea Tenderocookie-consent, privacy, gdpr

What are the penalties for non-compliant cookie consent practices?

Everyone knows that if you own a website, regardless of its type or purpose, you need to have a cookie consent banner and an appropriate cookie policy in place. If you don’t, you could be putting your business at risk, as penalties for cookie consent violations can be substantial, ranging from thousands of dollars or euros to much higher amounts depending on the applicable regulation, the nature of the violation, and the number of users affected.

In this article, we’ll explain what you can expect to pay if your website is not compliant with the requirements of the two most widely recognized privacy regulations affecting cookie practices: the GDPR and the CCPA.

What are the potential fines for using non-compliant cookies on websites?

The potential fines you can face for failing to comply with your website’s cookie requirements depend on several factors, including the privacy regulations that apply to your business (such as the GDPR or the CCPA) and the nature and severity of the violation. Since each regulation has different objectives and enforcement mechanisms, there is no equivalent penalty across all privacy laws. This is important to understand before looking at the specific amounts, as the potential fines under the GDPR are not calculated in the same way as those under the CCPA.

When people think about compliance penalties, they usually focus on the financial side, and understandably so. Regulatory fines can range from thousands of dollars or euros to much higher amounts for serious violations. If your website fails to meet the applicable cookie compliance requirements, the relevant supervisory authority or regulator may investigate your practices and impose administrative penalties if it determines that you have violated the law.

However, the financial penalty is only one of the possible consequences. Failing to comply with cookie and privacy regulations can also expose your business to legal disputes, regulatory investigations, reputational damage, and a loss of user trust. In some jurisdictions, affected users may also be entitled to seek compensation under certain circumstances (making the financial consequences even higher). For many businesses, these long-term consequences can be just as costly as the fine itself.

When a website fails to comply with applicable privacy laws, the legal risks can include regulatory investigations, enforcement actions, lawsuits, mandatory changes to your data collection practices, and, in some cases, compensation claims from affected users. That is why treating cookie compliance as an ongoing process (not just a one-time implementation) is so important.

Besides the financial and legal risks, there’s another consequence that many website owners overlook: the impact on their business. Users are becoming increasingly aware of online privacy, and if they notice that your website doesn’t respect their choices or doesn’t handle their data transparently, they may lose trust in your brand. That can lead to higher bounce rates, fewer conversions, and lower customer retention.

In other words, non-compliance isn’t just about the risk of fines. It can also affect your reputation, reduce users’ confidence in your website, and ultimately impact your marketing results and revenue.

The fine will depend on factors such as the company’s size and the severity of the violation, but you can expect it to range from tens of thousands of euros for smaller businesses to tens or even hundreds of millions for major tech companies.

Any violation of the GDPR or the applicable ePrivacy rules may result in a fine, although the final amount will depend on several factors, such as:

  1. The nature and gravity of the violation. The more serious the violation is, the higher the fine can end up being.
  2. The duration of the violation. If your website has been non-compliant for a long period of time, you can expect a higher penalty than if the issue was fixed quickly.
  3. The number of affected users. The more users affected by the violation, the greater the potential fine.
  4. The intent or negligence of the violation. If the authorities consider that the violation was intentional, the fine will generally be higher than if it was caused by negligence or a genuine mistake.
  5. The mitigation measures, as well as the cooperation with the authorities. If you cooperate with the investigation and fix the issue as soon as possible, the authorities may take that into account when deciding the final penalty.
  6. The financial status of the company. As mentioned at the beginning of this section, it won’t be the same fine for a large company as for a small business. The company’s financial situation is also taken into account when determining the amount of the fine.

Regarding what you can expect to pay, it depends. Unlike the CCPA (as we’ll see later), which establishes fixed per-violation penalty amounts, the GDPR does not provide a fixed list of violations and their corresponding fines. Instead, the authorities evaluate each case individually and determine the penalty based on the specific circumstances of each violation.

As a general rule, if you commit a serious infringement, the maximum fine can be up to €20 million or 4% of your company’s total worldwide annual turnover, whichever is higher. For less serious infringements, the maximum penalty is €10 million or 2% of your company’s total worldwide annual turnover, whichever is higher.

It is important to remember that these are maximum penalties, not automatic ones. In practice, most businesses receive much lower fines, especially if they cooperate with the authorities and correct the issue promptly. However, companies that repeatedly ignore the rules, affect a large number of users, or deliberately fail to comply with the GDPR can end up facing some of the largest privacy fines ever imposed.

Regarding the CCPA (the California Consumer Privacy Act), the potential penalties are generally lower than those under the GDPR. This law, enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General, is less strict in terms of the maximum penalties that can be imposed. However, that doesn’t mean they are affordable. Since penalties are generally calculated on a per-violation basis, they can quickly add up when a business affects a large number of consumers.

If you are wondering how much you can expect to pay if you are non-compliant, there are three main types of financial liability to keep in mind:

  • By intentionality (administrative or civil penalties): The CCPA distinguishes between unintentional and intentional violations. As of 2025, the maximum administrative or civil penalty is $2,663 per violation for standard violations and $7,988 per violation for intentional violations or violations involving the personal information of consumers under 16 years of age. Since these penalties apply to each violation, the total amount can become significant very quickly.
  • Business revenue threshold: As of 2025, a company may fall under the CCPA if it has annual gross revenues exceeding $26,625,000, among other qualifying criteria. This amount is not a fine and is not used to calculate penalties, but it is one of the thresholds that determine whether a business is subject to the CCPA.
  • Private actions by consumers: In certain cases involving qualifying data breaches, consumers may seek statutory damages ranging from $107 to $799 per consumer per incident, or actual damages if those are higher. This is separate from the administrative and civil penalties imposed by regulators and generally applies only to specific data breach situations, not cookie consent violations alone.

However, it is important to remember that regulators also consider the circumstances of each case. Factors such as whether the violation was intentional, how many consumers were affected, how long the non-compliance lasted, and whether the business cooperated with the investigation or promptly corrected the issue can all influence the final outcome.

We also wanted to clarify the difference between intentional and unintentional violations. Although the CCPA does not explicitly define what qualifies as an intentional or unintentional violation, we can reasonably infer the distinction based on how the law is generally enforced. For example, deliberately ignoring users’ requests to opt out or delete their personal information would likely be considered an intentional violation, as the business is fully aware that it is failing to comply with the law. On the other hand, having a cookie banner that is incorrectly configured due to a genuine technical error would more likely be treated as an unintentional violation, assuming the business was unaware of the issue and corrected it as soon as it was discovered.

As we have mentioned, while the CCPA has more defined per-violation penalties depending on whether the violation was intentional, there’s no overall cap on the total civil penalties that can accumulate. Under the GDPR, the situation is similar: although individual fines are subject to legal maximums (up to €20 million or 4% of a company’s worldwide annual turnover for the most serious infringements), there is no fixed limit on the total financial exposure a company may face across multiple violations.

Besides, even though these penalties may appear to be fixed amounts, that is not always the case in practice. Under the CCPA, statutory penalties are periodically adjusted for inflation. Under the GDPR, while the €20 million threshold is fixed, the alternative maximum of 4% of a company’s worldwide annual turnover means that potential fines can increase as a business grows.

In practice, organizations that commit serious violations affecting large numbers of users can end up paying millions of dollars or euros in penalties. The best approach is to prevent compliance issues in the first place. But if you have already identified a problem, fix it as soon as possible. Every additional day of non-compliance and every additional user affected can increase your potential liability.

This question has a straightforward answer: follow what the applicable privacy laws and regulations require. If you comply with the cookie consent requirements regarding how consent is collected, the information you provide to users, how consent records are stored, and how users can manage their preferences, you will significantly reduce your risk of fines.

Of course, compliance is not just about displaying a cookie banner. You also need to ensure that your website only sets non-essential cookies after obtaining valid consent, keeps consent records where required, and gives users an easy way to withdraw or update their choices. If you consistently follow these requirements and avoid the common mistakes that lead to fines in the first place, you are unlikely to face penalties for cookie consent violations.

That’s why we always recommend not only staying informed about applicable privacy laws and keeping up with their updates, but also choosing a cookie consent solution that is designed to comply with those requirements. A reliable solution can help you stay compliant over time and reduce the risk of costly mistakes as regulations continue to evolve.

There are many plugins, third-party platforms, and companies that claim to offer cookie consent banner solutions that comply with regulations such as the GDPR and the CCPA. However, after years of working with websites as developers, marketers, and website owners, we have found that many of these solutions overlook important compliance requirements, rely on outdated implementations, or even profit from your visitors’ consent data, potentially exposing website owners to unnecessary compliance risks.

So, where can you find a service that helps you stay compliant? Zest is one option. We built it by taking into account not only the essential legal requirements, but also the common shortcomings we have seen in many other cookie consent solutions. It is easy to install, free to use, designed to support compliance with major privacy regulations such as the GDPR and the CCPA, and automatically updated as privacy requirements evolve, so you don’t have to worry about keeping your cookie banner up to date.

Conclusion

Ultimately, being informed not only about cookie consent regulations but also about how non-compliance can affect your business is key to avoiding mistakes that you may later regret. The consequences of failing to comply with these regulations can have a significant financial impact on your business, while also damaging your reputation and reducing users’ trust in your website.

Even though unintentional non-compliance is generally treated less severely than intentional violations, “not being aware” won’t exempt you from penalties. That’s why it’s always worth using a cookie consent solution that is designed to comply with the applicable regulations and is kept up to date as privacy requirements evolve.

If you don’t know which solution to use, we remind you (again) that Zest is a free and easy-to-install option built to help you stay compliant with major privacy regulations like the GDPR and the CCPA. That way, you can focus on growing your website without having to worry about whether your cookie consent setup meets the latest requirements.

Andrea @ FreshJuice

Own your cookie banner.

Zest is free and MIT-licensed, and it doesn't phone home to anyone.
Drop the script in and you're done.