A seemingly comprehensive cookie banner does not guarantee a website's compliance. Tracking cookies before consent is obtained, an insufficiently visible opt-out button, imprecise information, biased consent, or the inability to easily reverse a choice: the CNIL's audits cover both the banner's presentation and its actual technical functionality.
This article was originally published in June 2021 and updated in September 2026.
In May 2021, the CNIL (French Data Protection Authority) issued around twenty formal notices to organizations that did not allow internet users to refuse cookies as easily as accepting them. This campaign marked the shift from a support phase to an active monitoring policy. Since then, the CNIL has continued its investigations and clarified its requirements, particularly regarding misleading consent banners.
What is a cookie or a tracker?
A cookie is a file that may be stored on a user's device when they visit a website, use a mobile application, or access a digital service.
However, the regulation does not apply solely to cookies in the technical sense. It more broadly concerns operations that allow information to be stored on a user's terminal or to access information already stored.
The following may be affected:
- cookies placed by the visited site;
- cookies placed by third parties;
- advertising identifiers;
- invisible pixels;
- tags ;
- certain audience measurement devices;
- the browser's local storage;
- identifiers generated by a mobile application;
- certain digital fingerprinting or fingerprinting ;
- trackers associated with videos, maps, social buttons or embedded content;
- as well as certain pixels inserted into emails.
The CNIL offers a detailed presentation of these technologies in its dossier on cookies and other trackers and on its page relating to the definition of cookies and trackers.
Do all cookies require consent?
No. It is necessary to distinguish between trackers that require the user's prior consent and those that can, under certain conditions, be exempt from it.
The principle stems in particular fromArticle 82 of the French Data Protection Act and the European directive known as "ePrivacy".
Cookies subject to consent
Trackers that are not strictly necessary for providing the service requested by the user are generally subject to prior consent.
This may include, in particular:
- advertising cookies;
- trackers used to personalize ads;
- cookies that allow tracking the user across multiple sites;
- trackers associated with social networks;
- personalization cookies that are not essential to the service;
- of certain audience measurement tools;
- or even trackers that allow a browsing profile to be established.
These trackers should, in principle, only be placed or read after valid consent has been given.
Cookies that may be exempt
Some cookies may be exempt from consent when they are strictly necessary for the operation of the service or for providing a feature expressly requested by the user.
The following may fall into this category, depending on their settings and purpose:
- cookies retain the user's choice regarding trackers;
- authentication cookies;
- cookies necessary for the security of the service;
- cookies that allow the contents of a shopping cart to be saved;
- the trackers necessary for the personalization of an expressly requested interface;
- certain audience measurement trackers meet the strict conditions defined by the CNIL.
The classification depends on the actual functioning of the tracker and not solely on its label. A tool presented as "necessary" or "statistical" therefore does not automatically benefit from an exemption.
The CNIL sets out the applicable principles in its presentation of the rules to be followed for cookies.
What are the conditions for valid consent?
When consent is required, it must be given before the relevant tracker is placed or read.
Consent must be:
- free;
- specific ;
- illuminated;
- unambiguous;
- expressed by a clear positive action;
- and capable of being withdrawn as easily as it was given.
Continuing to browse, simply scrolling down a page or closing the banner does not constitute a valid expression of consent.
The user must be able to understand:
- who uses trackers;
- for what purposes they are used;
- What are the consequences of his choice?
- if there are third parties likely to deposit or read trackers;
- and how he will be able to change his decision later.
The site manager must also be able to demonstrate that consent was indeed obtained under compliant conditions.
These requirements are set out in the CNIL guidelines and recommendation relating to cookies and other trackers.
Should refusing cookies be as simple as accepting them?
Yes.
This requirement is one of the CNIL's main areas of focus. When a website allows users to accept all cookies in a single action, they must be able to refuse them using a method that is just as simple.
A banner is therefore likely to be considered non-compliant when:
- An "Accept All" button is immediately visible, but no equivalent "Decline" button is offered;
- Refusal requires going through several configuration screens;
- the decline button is significantly less visible than the accept button;
- The size, color, or contrast of the buttons excessively promotes acceptance;
- The refusal link is indistinguishable from the information notices;
- the words used are ambiguous or unnecessarily complex;
- certain purposes are enabled by default;
- or the user is led to believe that they must accept cookies to continue browsing.
The CNIL expressly reiterates that refusing cookies should be as easy as accepting them.
Can a misleading presentation invalidate consent?
Yes. Compliance doesn't depend solely on the number of buttons or the words used. The CNIL examines the overall presentation of the interface and the effects of the user journey.
In December 2024, it announced that it had issued formal notices to several website publishers to modify their banners. The practices identified had the effect of encouraging internet users to accept cookies or making it more difficult to refuse them.
The following were among those implicated:
- a disproportionate emphasis on the acceptance option;
- a rejection button that is difficult to distinguish;
- an ambiguous presentation;
- difficult-to-understand wording;
- or a path leading the user to accept without considering the implications of their choice.
These guidance techniques are sometimes referred to as dark patterns. They can prevent the user from making a truly free and informed choice.
The campaign of formal notices announced by the CNIL in December 2024 confirms that the compliance analysis now focuses on the concrete balance of the interface and not solely on the formal presence of an opt-out option.
What information should be included on the cookie banner?
The information must be understandable without forcing the user to immediately read a very long legal policy.
A multi-level information system can be implemented.
First-level information
The banner should, in particular, allow the user to immediately understand:
- the main purposes of cookies;
- the identity of the site manager;
- the option to accept or refuse;
- the possible existence of partners or third parties;
- and the possibility of personalizing one's choice.
The purposes must be described with sufficient precision. Expressions such as "improve your experience," "optimize our services," or "our partners" may be insufficient if they do not allow for an understanding of the concrete uses of the trackers.
Detailed information
A cookie policy should provide more comprehensive information, including on:
- the categories of trackers used;
- their purposes;
- their origin;
- third parties likely to have access to it;
- their lifespan;
- the retention period for choices;
- the means of withdrawing consent;
- and, where applicable, the associated processing of personal data.
This policy must correspond to the trackers actually present on the site. Simply reproducing a generic template is insufficient if it does not reflect the site's technical operation.
Should the user be able to withdraw their consent?
Yes. Consent should not be irreversible.
The user must be able to reverse their decision at any time, and withdrawal must be as simple as initial acceptance.
The site may, for example:
- a permanent link "Manage my cookies";
- an icon accessible on all pages;
- a configuration module;
- or a function integrated into the cookie policy.
The withdrawal must have a real effect. It is not enough for the interface to indicate that consent has been withdrawn if the trackers in question continue to function.
The CNIL reminds us that consent must be able to be withdrawn simply and at any time.
What are the main technical errors?
A legally sound banner can mask non-compliant technical operation.
The most frequent anomalies include:
- the placement of advertising cookies before any action by the user;
- the triggering of non-exempt audience measurement trackers before consent;
- the continued placement of certain cookies after a refusal;
- the activation of trackers when simply closing the banner;
- the failure to properly communicate the choice to the partners;
- the automatic loading of videos or maps that deposit third-party trackers;
- the addition of a marketing tool that has not been integrated into the consent management platform;
- a difference between the desktop version and the mobile version;
- the absence of proof of consent;
- a withdrawal of consent without deletion or deactivation of the trackers concerned;
- or a cookie policy that no longer corresponds to the tools installed on the site.
These difficulties are common after:
- the redesign of a website;
- the installation of a new extension;
- the change of a statistical tool;
- the addition of an advertising solution;
- the integration of a video, a map or an external form;
- or a modification made by an agency, SEO provider, or marketing department.
Compliance therefore requires legal control, but also technical tests carried out before and after the user's choice.
Who is responsible for cookies placed by third parties?
The fact that a tracker is provided by a technical service provider, an advertising agency, a social network or a software publisher is not sufficient to absolve the site operator of all responsibility.
The allocation of obligations depends in particular on:
- the role of each actor;
- of the one who determines the purposes and means of the processing;
- control exercised over the deposit of the tracer;
- contractual stipulations;
- and the processing of any associated personal data.
The website publisher must therefore identify the third parties involved in the submission chain and ensure that the integrated tools respect the choices expressed by the users.
It is also necessary to examine the contracts concluded with:
- the consent management platform;
- the hosting provider;
- the agency in charge of the site;
- statistical solutions;
- advertising agencies;
- social media;
- and other service providers who may have access to the collected information.
The support must therefore link compliance with digital law and the GDPR with the analysis of contracts concluded with the various service providers.
What about cookie walls?
A cookie wall involves making access to a site or service conditional upon the acceptance of cookies or other trackers.
These devices are not automatically prohibited in all situations, but their legality must be assessed on a case-by-case basis. In particular, it is necessary to verify:
- if the user has a genuine choice;
- if a reasonable alternative is offered to him;
- if the imposed tracers are proportionate;
- if the information is sufficiently clear;
- and if the user can understand the consequences of their choice.
When a paid alternative is offered, its price and the conditions of access to the service must also be examined.
The CNIL presents the main analysis criteria in its recommendations relating to cookie walls or tracker walls.
How does the CNIL monitor websites?
The CNIL can intervene as a result of:
- of a complaint;
- of a report;
- of a thematic campaign;
- of information made public;
- or on his own initiative.
An inspection may include, in particular:
- the trackers deposited upon arrival at the site;
- how the decline button works;
- the consequences of a refusal;
- the withdrawal of consent;
- the visual presentation of the banner;
- the information provided;
- shelf life;
- the list of partners;
- and the organization's ability to justify its choices.
The procedure may lead to a request for explanations or documents, a formal notice, an order to comply, or the initiation of a sanction procedure.
Is a formal notice from the CNIL a sanction?
Not necessarily.
The formal notice requires the organization to cease one or more breaches within a specified timeframe. It may allow for rectification before initiating legal proceedings.
However, it should not be underestimated. The body must:
- to precisely identify the alleged shortcomings;
- retain evidence of the site's condition at the time of inspection;
- coordinate legal and technical interventions;
- respond within the given timeframe;
- document the corrections made;
- and verify that these corrections actually work.
A purely visual modification of the banner may be insufficient if the trackers continue to be triggered before consent or despite a refusal.
When the measures taken are not satisfactory or the shortcomings are particularly serious, the CNIL may initiate a sanction procedure.
What sanctions can the CNIL impose?
Depending on the nature and seriousness of the breaches, the CNIL may, in particular, impose the following measures:
- a reminder of the rules;
- an order to comply;
- a penalty;
- a limitation or prohibition of certain treatments;
- an administrative fine;
- and the publication of the decision.
The amount of a penalty is not determined solely by the presence of a non-compliant cookie. Other factors that may be taken into consideration include:
- the nature and seriousness of the breach;
- its duration;
- the number of people concerned;
- the purposes of the trackers;
- any economic benefits that may be gained;
- the cooperation of the organization;
- the corrective measures adopted;
- possible precedents;
- and the organization's financial situation.
The publication of a decision can also produce a significant reputational effect, regardless of the amount of the fine.
The sentence in the old article stating that organizations risked a sanction "of up to 2% of their turnover" therefore had to be removed: it did not sufficiently reflect the diversity of legal bases and measures that could be imposed.
How to perform a cookie compliance audit?
Website verification should not be limited to reading the banner. A complete audit can be organized in several stages.
1. Identify the tracers
It is necessary to identify all cookies, pixels, tags, identifiers and similar devices that may be activated.
The analysis must be carried out:
- before any choice;
- after overall acceptance;
- after a general refusal;
- after partial acceptance;
- and after the withdrawal of consent.
2. Identify their purpose and origin
For each tracer, the following must be determined:
- his publisher;
- its purpose;
- the information he accesses;
- its lifespan;
- its recipients;
- and the role of the different actors.
3. Determine the applicable regime
Each tracer must be classified according to whether it:
- requires prior consent;
- may be eligible for an exemption;
- or must be removed due to lack of purpose or sufficient justification.
4. Examine the consent process
We need to compare objectively:
- the number of actions required to accept;
- the number of actions required to refuse;
- the visibility of the buttons;
- the terms used;
- colours, sizes and contrasts;
- as well as the operation of the settings by purpose.
5. Verify the effectiveness of the choice
The control should confirm that:
- Cookies requiring consent are not placed before acceptance;
- The refusal effectively blocks the relevant trackers;
- the choice is passed on to third parties;
- and the withdrawal disables the corresponding treatments.
6. Update the documentation
The cookie policy, the privacy policy, the processing register and the contracts concluded with service providers must be consistent with the actual operation of the site.
7. Organize periodic inspections
An audit must be renewed after any significant modification to the site or its tools. Periodic verification also helps identify trackers added without having been integrated into the consent mechanism.
What should you do if you have doubts about the conformity of your headband?
The site operator should, at a minimum:
- carry out a technical inventory of the tracers;
- verify that no non-essential tracking is triggered before consent;
- to make refusal as simple and visible as acceptance;
- remove ambiguous wording;
- to allow a choice based on purpose;
- maintain permanent access to the settings;
- verify the effectiveness of the withdrawal;
- update its cookie policy;
- retain proof of the choices expressed;
- and document the checks carried out.
Using a consent management platform alone does not guarantee compliance. The tool must be properly configured and adapted to the trackers actually used.
Key takeaways
Cookie compliance is not simply a matter of installing a banner on a website.
She assumes that:
- the tracers must be precisely identified;
- Non-essential cookies should not be placed before consent is given;
- the information should be clear and understandable;
- consent must be free, specific, informed and unambiguous;
- refusal should be as simple as acceptance;
- the user's choices are technically respected;
- consent can be easily withdrawn;
- and compliance can be demonstrated.
The control campaigns undertaken since 2021 and the formal notices concerning misleading banners announced in 2024 show that the subject remains fully relevant.
ARST Avocats assists companies with website audits, drafting privacy and cookie policies, analyzing their relationships with service providers, and managing audits or procedures initiated by the CNIL (French Data Protection Authority). Discover our expertise in digital law, data protection, and GDPR.
Details on the crisis exit procedure
Focus on decrees no. 2021-1354 and 2021-1355 of October 16, 2021. Preliminary reminders. The companies concerned. The opening of the procedure. Conduct of the observation period. Determination of liabilities. Liability treatment plan. The consequences of the absence...
The new reform of Book VI of the Commercial Code
Ordinance 2021-1193 of September 15, 2021, issued pursuant to the PACTE Law and reforming Book VI of the Commercial Code, pursues a threefold objective: To transpose Directive 2019/1023 of June 20, 2019, known as the "Restructuring and Insolvency Directive"; to coordinate and...
Relief from forfeiture: what recourse is available in case of late filing of a claim?
A creditor who has not filed a claim within the statutory time limit may request relief from forfeiture. When a creditor has been omitted from the list drawn up by the debtor, they benefit from enhanced protection under the case law of the Court of Cassation.
Suretyship, mortgage guarantee and annual information for the surety
When the same person acts as personal guarantor for a debtor's obligations to a credit institution and also assigns one or more assets as collateral for those same obligations, the credit institution owes them the following information...
Businesses facing the introduction of the "health pass"
On July 25th, Parliament adopted a bill concerning the management of the health crisis, intended to implement the system for combating the spread of COVID-19 commonly known as the "health pass." This text is currently under review...
Exclusion clauses in insurance contracts: the Court of Cassation continues to tighten the noose!
Article L113-1 of the French Insurance Code, which authorizes insurers to limit their coverage by including exclusions in their contracts, requires that these exclusions be "formal and limited," otherwise they are void. On November 20, 2020, the Court of Cassation...
Deceptive business practices: UFC-Que Choisir files a complaint against SFR
On May 11, 2021, the consumer association UFC-Que Choisir announced that it had filed a complaint with the Paris Judicial Court against the company SFR for deceptive business practices. In January 2018 and December 2019, SFR, in its bid to conquer the mobile phone market, offered...
Support for business takeovers during the Covid period
Since the start of the health crisis, business buyers have been largely overlooked in government aid programs. Thus, if an entrepreneur had the foresight to purchase a business in 2020, they must be financially very strong; the majority of...
Closed-door meetings and other exceptional measures governing the holding of general assemblies and collegial meetings
Law No. 2021-689 of May 31, 2021, concerning the management of the exit from the health crisis, extends, once again, the application of the exceptional measures relating to the holding of general meetings until September 30, 2021 (Article 8, VI). Holding of meetings...
Tremplin Scheme – Financial boost for micro-enterprises and SMEs committed to the ecological transition
Implementation of the "France Relance" plan: Finance your ecological transition projects with financial aid from the "Tremplin pour la transition écologique des PME" (Springboard for the Ecological Transition of SMEs) program. Eligibility requirements for beneficiaries of "Tremplin" aid...