Twenty-five European data protection authorities are running a coordinated action on transparency and information obligations — Articles 12, 13 and 14 — launched 19 March 2026. Your cookie banner is an Article 13 notice delivered at the moment of collection, which puts it squarely in scope. This is not hypothetical: of the 21 organisations the CNIL sanctioned over trackers in 2025, one of the three stated grounds was inadequate information that made informed consent impossible. The findings phase is running now.
Most coverage of European enforcement is written in the future tense — regulators will tighten, scrutiny is increasing. This one has a date, a number and a phase you can locate yourself on the calendar, so it is worth being precise about what it is.
What the CEF actually is
Every year the European Data Protection Board picks one topic and the national authorities work it in a coordinated way, rather than each pursuing its own priorities. Previous rounds covered cloud use in the public sector (2023), data protection officers (2024) and the right of access (2025).
For 2026 the topic is compliance with transparency and information obligations under Articles 12, 13 and 14 GDPR. It launched on 19 March 2026 with 25 authorities taking part.
What those authorities do is deliberately broad: they contact controllers across different sectors “either through enforcement actions or fact-finding exercises”, with follow-up where warranted. So a first contact may be a questionnaire rather than an investigation — which is not a reason to relax, because the answers feed the next stage.
The timeline is the part worth internalising. National actions run through 2026. In the second half of 2026 the participating authorities pool and discuss what they found, and a consolidated report goes to the EDPB for adoption, explicitly to enable targeted follow-ups nationally and at EU level.
We are in the second half of 2026. The pooling is happening now, and the follow-ups come after it.
Why this lands on your banner
Transparency sounds like a privacy-policy problem, and teams file it under legal. But Article 13 governs information given at the point of collection, and for cookies and trackers that point is the banner. The banner is not a doorway to the disclosure; on first visit, it is the disclosure.
Article 12 then sets the standard for how it must be delivered: concise, transparent, intelligible and easily accessible, in clear and plain language. Every one of those adjectives is a design constraint, and each one is routinely lost in the fight to keep a banner small.
The typical first-layer banner says some version of “we use cookies to improve your experience”. Measured against Article 13, that sentence carries almost nothing: not who the controller is, not the specific purposes, not the legal basis for each, not the recipients, not retention, not the rights that follow, not how to withdraw.
Some of that legitimately belongs on a second layer — the law permits layering. The question a regulator asks is whether the layering informs or buries.
This is already a sanctioned failure, not a theoretical one
Here is the part that turns an EDPB announcement into something with teeth.
In its 2025 sanctions review the CNIL reported 486,839,500 euros in fines across 83 sanctions, plus 143 formal notices. Of those, 21 organisations were sanctioned over cookies and trackers, on three grounds:
- placing trackers without user consent;
- inadequate information provided — insufficient to obtain informed consent;
- failing to give effect to a refusal or a withdrawal of consent.
That middle ground is a transparency failure. It is the same subject matter the CEF is now examining across 25 jurisdictions, and it was already worth sanctioning on its own before any coordinated action existed. The two largest penalties in that set were 325 and 150 million euros, imposed on organisations the CNIL held could not claim ignorance of the applicable rules.
So the honest framing is not “regulators may start looking at transparency”. It is: at least one major authority has been fining for it, and now twenty-five are comparing notes.
What to check on your own banner
Four questions, in the order that finds problems fastest:
- Does the first layer name the actual purposes? “Improve your experience” is not a purpose. “Measure which pages are read” and “build advertising audiences” are.
- Does it identify the recipients? This is the weakest point on most sites, and the easiest to check — see below.
- Is withdrawal explained, and reachable? Article 13 requires telling people about the right to withdraw. A persistent link in the footer is the usual answer; a banner that cannot be recalled after dismissal fails this.
- Would a non-specialist understand it? “Plain language” is a legal standard, not a courtesy. If your copy needs the reader to know what a pixel is, it is not clear language.
On question 2, there is a test that takes a minute and consistently finds gaps: compare the third parties your banner declares against the ones that actually load. The declared list comes from whenever someone last updated it. The real list changes every time a tag is added, a plugin updated, or an embed dropped into a template.
When those two lists diverge, the disclosure is inaccurate — and inaccurate disclosure is the exact failure mode both the CEF and the CNIL’s second ground are about. Scan your site to see everything that actually fires, then read your own banner next to the result. The gap is usually larger than teams expect, and it is not the CMP’s fault: it is drift.
The short version
Nothing about the law changed here. What changed is coordination: 25 authorities, one topic, a shared findings phase running right now, and a consolidated report designed to produce follow-ups. Meanwhile the failure being examined is one that has already produced nine-figure fines.
If your banner has not been read closely since it was installed, this is a good quarter to read it — next to a list of what your site is really loading. We covered the related failure, refusals that do not take effect, in why refusing does not delete anything.