Skip to main content
Praxikon

Enforcement

Coolblue fined 40,000 euros on objection for cookies without consent

Date
Status
status not established
Body
Autoriteit Persoonsgegevens
Reference
Beslissing op bezwaar AP van 23 december 2024 (kenmerk vertrouwelijk), herroept boetebesluit van 11 januari 2024
Amount
€40,000

What it is about

From 28 April to 17 June 2020 Coolblue used a cookie banner that assumed implied consent ('if you continue we assume you agree'), with a pre ticked personal cookie package. It kept doing so after a warning letter from the Dutch DPA of 29 November 2019. There was therefore no valid consent and no legal basis (Article 5(1)(a) with Article 6(1)(a) GDPR, see also Planet49). Coolblue admitted the breach and only objected to the amount. The DPA upheld the objection, revoked the decision of 11 January 2024 and set the fine at 40,000 euros. It started from the lower category II (base fine 310,000 euros) and went below that range, given the low seriousness, the non sensitive data, the breach ending before the investigation was announced, unclear remediation deadlines and the long delay between the warning letter and the first decision.

What this means in practice

Implied consent and pre ticked boxes are never valid consent: the visitor must actively opt in. A warning letter from the DPA makes a later breach culpable. Taking too long to fix it, for example through lengthy A/B tests, still leads to a fine. Factors such as a short duration, non sensitive data, an unclear remediation deadline and slow decision making by the DPA can still substantially reduce the fine on objection.

The GDPR articles concerned

Source: Autoriteit Persoonsgegevens, beslissing op bezwaar boete Coolbluechecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

The counterpart in the other law

Case law8 of 17

Guidelines8 of 14

Enforcement and fines8 of 10

Legislation in motion6 of 11