Cookies and Data Privacy - €1,500,000 fine for American Express
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: February 2026
- Category: Cookies, Enforcement
Back in 2023, the French supervisory authority carried out inspections at the premises and on the website of American Express. In doing so, it identified a number of data protection violations. The investigation revealed that cookies were set on the company's website before users had the opportunity to consent to or reject their use. Since these cookies were used for advertising purposes, among other things, consent would have been required. Furthermore, the cookies were set even though users had rejected them in the corresponding selection window and even after users had revoked their previously given consent.
On 27th November 2025 the CNIL states that in determining the amount of the fine, it took into account, among other things, that the regulations governing cookies should be widely known due to their long history and widespread publicity by the authority.
The correct handling of cookies in terms of data protection law should already be known by now, given the numerous regulatory decisions and court rulings since the introduction of the GDPR. It is therefore surprising that even large companies are still not acting in compliance with data protection regulations in some cases, especially given the external impact of a website. There is an unmanageable number of potential complainants here and they are quite easy for authorities to check. The data protection-compliant configuration of your own website should therefore be taken seriously.
Should you have any questions or require further information, please do not hesitate to contact us any time.