On a website or application, consent to cookies cannot be based on a biased choice. Users must be able to refuse non-essential trackers as easily as they can accept them.
This now well-established rule, however, is not simply a matter of adding a "Reject All" button. Compliance also requires not placing any trackers that require consent before the user's choice, presenting sufficiently clear information, effectively respecting the expressed refusal, and allowing the withdrawal of consent at any time.
The sanctions imposed by the CNIL show that the cookie banner must be considered as a genuine consent process, the compliance of which must be checked on legal, graphic and technical levels.
Which cookies require user consent?
The rules applicable to cookies and other trackers are based primarily on Article82 of the French Data Protection Act, which transposes into French law the provisions of the European "ePrivacy" directive.
This text concerns operations that allow access to information already stored on a user's device or the writing of information to it. It therefore covers traditional cookies, but also other tracking technologies used on websites, mobile applications, connected devices, or certain digital services.
The principle is as follows: any cookie or tracker that is not strictly necessary for the operation of the service requested by the user must, except in exceptional circumstances, be preceded by their consent.
The following are likely to be affected:
- advertising cookies;
- trackers that allow for the personalization of advertisements;
- cookies used to track a user across multiple websites;
- trackers associated with social media sharing buttons;
- some audience measurement cookies;
- tools for creating browsing profiles;
- trackers placed by third-party partners or service providers.
Conversely, some strictly necessary trackers may be placed without consent. These may include cookies used to save the contents of a shopping cart, secure authentication, remember the user's choice regarding cookies, or maintain a technical session.
Certain audience measurement tools may also be exempt, but only when they comply with all the conditions set by the CNIL (French Data Protection Authority). Simply labeling a cookie as "statistical" or "audience measurement" is therefore not sufficient to exempt it from requiring consent.
What constitutes valid consent for cookies?
Consent must meet the requirements of the General Data Protection Regulation. It must be freely given, specific, informed and unambiguous.
The user must perform a positive action clearly expressing their choice. Continuing to browse, scrolling down a page, or closing the banner cannot be considered acceptance.
The user's silence does not constitute consent. Until the user has accepted the relevant cookies, trackers requiring their agreement should not be placed or read on their device.
Furthermore, the user must have sufficiently precise information on:
- the purposes of cookies;
- the categories of trackers used;
- the identity of the data controller;
- the main third parties likely to deposit or read trackers;
- the consequences of its acceptance or refusal;
- the means by which he/she can withdraw his/her consent at a later date.
Therefore, consent cannot be obtained by means of a general or ambiguous formula that would not allow the scope of the proposed choice to be understood.
Why should refusal be as simple as acceptance?
Consent is truly free only if the user can refuse cookies without encountering more difficulty than accepting them.
A banner with an immediately visible "Accept all" button, but forcing the user to open several successive windows to refuse cookies, creates an imbalance in the proposed journey.
The multiple clicks required to refuse trackers are likely to discourage users and encourage them to choose the quickest option. Consent obtained under these conditions may not be considered freely given.
The CNIL recommendation of September 17, 2020 therefore recommends that consent collection interfaces allow the user to consent or not consent with the same degree of simplicity.
In practice, the safest solution is to display the following from the first level of the banner:
- an "Accept All" button;
- a "Reject All" button;
- a button or link labeled "Customize my choices".
The options for accepting and rejecting data must be presented in a sufficiently balanced way. It is not enough for a legally mandated "reject" button to exist; it must also be identifiable, understandable, and easily accessible.
Can the appearance of the banner influence the user's choice?
Compliance doesn't depend solely on the number of clicks. The graphical presentation can also artificially influence the user's decision.
A highly visible, colourful "Accept all" button placed in the centre of the banner, combined with a barely legible "Continue without accepting" button or one that fades into the background, is likely to create a misleading user journey.
These design techniques are sometimes referred to as "dark patterns" or manipulative interfaces. They consist of exploiting the presentation, colors, words used, or hierarchy of information to guide the user's behavior.
The two buttons do not need to be exactly identical. However, their design should not make the rejection button artificially harder to find or understand.
In particular, the following should be avoided:
- a very marked contrast solely for the benefit of the accept button;
- a significantly smaller font size for the refusal;
- an ambiguous formulation such as "Continue without personalization";
- a decline button relegated to a second screen;
- guilt-inducing or alarmist messages;
- a series of windows designed to make the user abandon their refusal;
- pre-ticked boxes in favor of depositing tracers.
The balance of the banner must therefore be appreciated as a whole: number of actions, placement of buttons, colours, contrast, font size and vocabulary used.
Is a "Reject All" button sufficient to ensure compliance?
No. The button must produce a real technical effect.
When a user clicks "Reject all," no cookies requiring consent should be placed. Any trackers that may have been placed before their choice should not continue to be read or used.
This point remains a frequent source of non-compliance. A banner may appear legally satisfactory even though the site's technical settings do not reflect the displayed choice.
On September 1, 2025, the CNIL (French Data Protection Authority) imposed a fine of €150 million on a company belonging to the SHEIN group. The authority noted, in particular:
- the placement of certain advertising trackers before any expression of consent;
- insufficient information on the purposes of cookies;
- the lack of complete information on the third parties involved;
- the deposit or reading of certain trackers despite the user's refusal;
- flawed consent withdrawal mechanisms.
This decision illustrates a crucial point: the compliance of a banner cannot be verified from a simple screenshot. It requires technical tests to identify the trackers deposited before and after each choice.
Should the user be able to change their mind?
Consent is not final. It must be able to be withdrawn at any time, as easily as it was given.
The site must therefore offer a permanent mechanism for modifying expressed preferences. This could take the form of:
- from a "Manage my cookies" link in the footer;
- a permanent button for managing preferences;
- of a clearly identifiable icon;
- from a section accessible from the privacy policy or the cookie policy.
The withdrawal must take effect for the future. The trackers in question must cease to be read or stored as soon as the user withdraws their consent.
The expressed choice must also be retained for a reasonable period so that the banner is not displayed on every subsequent visit. The CNIL (French Data Protection Authority) generally recommends retaining choices—both acceptance and refusal—for a period that avoids unduly soliciting the user.
Where should the "Personalize my choices" button be placed?
The user must be able to consent separately to the different purposes when these are distinct.
The second level of the banner allows users to accept or reject, by category:
- audience measurement;
- content personalization;
- personalized advertising;
- the features offered by social networks;
- trackers placed by certain partners.
The categories must be presented in clear language. General headings such as "Improve your experience" or "Optimize our services" are insufficient if they do not allow users to understand what the processing actually entails.
The options should not be enabled by default. The user must take a positive action to accept the cookie categories that require consent.
It is also necessary to make accessible the list of partners or third parties likely to deposit trackers, as well as the purposes pursued by each of them.
Are “cookie walls” prohibited?
A "cookie wall" consists of making access to a site or service conditional upon the acceptance of certain cookies, sometimes offering as an alternative paid access without advertising trackers.
This practice is not automatically prohibited. However, its legality must be assessed on a case-by-case basis to verify whether consent remains truly free.
The CNIL is examining, in particular:
- the existence of a real and fair alternative;
- the clarity of the information given to the user;
- the reasonableness of any potential financial compensation;
- the balance of presentation between the different options;
- the concrete consequences of the refusal;
- the possibility of accessing an equivalent service without consenting to advertising tracking.
In its decision against Google in September 2025, the CNIL (French Data Protection Authority) reiterated that access to a service may, in certain circumstances, be conditional upon the placement of advertising trackers. However, it is essential that the user clearly understands the consequences of their choice and that the alternatives are presented to them in a balanced manner.
A cookie wall should therefore not be used to artificially obtain consent that the user would not have freely given.
Who is responsible for cookies placed by service providers?
The website publisher cannot consider that it is absolved of all responsibility solely because the trackers are placed by a technical service provider, an advertising agency, a social network or an audience measurement tool.
It is up to him to identify the technologies present on his site and to verify the conditions under which they are activated.
Contracts concluded with service providers must specify, in particular:
- the nature of the tracers used;
- their purposes;
- the respective roles of the parties;
- the data collected;
- shelf life;
- potential data transfers outside the European Union;
- measures to ensure compliance with refusal or withdrawal of consent;
- the conditions under which compliance can be audited.
A website update, the addition of an advertising module, or the installation of a new extension can generate new cookies. Therefore, compliance must be checked periodically, and not just when the banner is created.
What are the risks of a non-compliant cookie banner?
The CNIL has powers of control, formal notice and sanction. In particular, it can examine the site remotely, request supporting documents, conduct on-site inspections or technically verify the trackers deposited.
Cookie regulation remains a key focus of its work. The €325 million fine imposed on Google and the €150 million fine imposed on SHEIN in 2025 confirm that the issue is no longer a mere graphic formality.
The amount of a penalty depends in particular on:
- the nature and seriousness of the breaches;
- the number of users concerned;
- the duration of the practices;
- economic benefits gained;
- the degree of cooperation of the organization;
- corrective measures adopted;
- of the existence of possible precedents.
Large platforms are not the only ones affected. Any company operating a website or application using trackers must be able to demonstrate the compliance of its system.
The law firm ARST Avocats has also dedicated a publication to CNIL controls and the risks associated with non-compliant cookies.
How can we practically audit our cookie banner?
An effective audit must combine legal, graphic, and technical analysis.
In particular, the following points should be checked:
- Have the trackers present on the site been identified?
- Are cookies requiring consent blocked before any user choice is made?
- Are the "Accept All" and "Reject All" buttons accessible at the same level?
- Does refusal require more action than acceptance?
- Does the graphic presentation artificially promote acceptance?
- Are the objectives explained clearly and precisely enough?
- Are the third parties likely to place trackers identified?
- Can the user make a choice based on purpose?
- Is the refusal technically respected?
- Can consent be withdrawn easily and at any time?
- Are the user's choices retained for an appropriate period of time?
- Do the banner descriptions actually correspond to the tools installed on the site?
- Is the cookie policy up-to-date and consistent with the privacy policy?
- Are the evidence of consent and successive versions of the banner kept?
- Is there a control procedure in place when adding a new service provider or module?
Key takeaways
The presence of a "Reject All" button is an important condition of compliance, but it is not sufficient.
A compliant cookie banner must allow the user to accept, refuse, or customize their choices without being steered towards one option over another. It must provide understandable information, prevent any premature placement of trackers, effectively respect the expressed choice, and allow for easy withdrawal of consent.
Compliance therefore depends as much on the design of the interface as on the technical functioning of the site.
Regular auditing of the banner and trackers actually placed remains essential, especially after any modification of the site, change of service provider or addition of a new advertising or statistical tool.
Morgan Jamet,
Partner Attorney – ARST Avocats

Morgan Jamet
Author
Insolvency Law Practice: Interview with Fanny Hurreau, Partner
Fanny Hurreau, could you tell us about your career path? My career as a lawyer is quite closely linked to that of the Arst firm...
Business law litigation: how to organize dispute management within the company?
Contracts, evidence preservation, insurance, lawyer, information on the opposing party and provisions: the reflexes enabling the company to better manage its business disputes.
Chaouki Gaddada presents the Social Law – Social Security department of the firm
Chaouki Gaddada, could you tell us about your background? Yes, of course. I was sworn in in October...
Morgan Jamet presents the Contracts department of the firm
Morgan Jamet presents the Contracts practice of the law firm ARST Avocats. ARST Avocats assists companies, their executives, and their legal departments in drafting, negotiating, auditing, and litigating their commercial contracts. Morgan Jamet, attorney...
Exclusion clauses in insurance contracts
Can an insurance company refuse coverage by invoking an exclusion clause? Validity of the clause, apparent characteristics, proof and dispute: the essential rules.
The tacit acceptance of the work: a strict interpretation
Acceptance is an essential step in the construction operation, particularly because of the consequences attached to it: starting point of construction-specific guarantees, transfer of risks, end of contractual guarantees, purging of defects...
Action in tort liability due to a breach of contract: the rights of the third party to the contract
A third party who suffers from the breach of contract may bring a tort claim against the debtor. However, they must demonstrate personal harm and comply with the terms and limitations stipulated in the contract.
Assistance to the franchisee in finding premises and area reservation contract
The area reservation agreement allows the prospective franchisee to search for a commercial property before finalizing their franchise agreement. Contract content, franchisor support, pre-contractual information document (DIP), financing, and responsibilities: precautions to take.
GDPR & Social Law: What you need to know?
GDPR and employment law: what are the employer's obligations? Recruitment, payroll, time tracking, performance reviews, video surveillance, remote work, absence management, and disciplinary procedures: employers deal with a multitude of issues on a daily basis...
Exclusions from guarantees: the Court of Cassation continues to take a tougher stance with insurers!
After a year in 2021 marked by the Court of Cassation's blows against the mechanisms allowing insurers to be relieved of their guarantee obligations (questioning of the two-year limitation period, broadening of the unenforceability of exclusions...