# Cookie banner in France: CNIL rules, traps and real fines in 2026

> The banner itself is not mandatory: prior consent is, as soon as a non-exempt tracker (advertising, standard Google Analytics, social media pixels) is placed. The CNIL, France’s data protection authority, requires refusing to be as easy as accepting, on the very first screen, and it fines small online shops too: up to €20,000 under the simplified procedure for an SME (€3,000 for a distance-selling site in October 2025), €150 million for SHEIN.

Source: https://legalnest.io/en/guides/cookie-banner-france-cnil/
Updated on 8 October 2026. Checked against the law in force on 07/10/2026.
General information, not personalised legal advice.

On 16 October 2025, a distance-selling shop was [fined €3,000](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil) over its cookies by the CNIL (the « Commission nationale de l’informatique et des libertés », France’s data protection authority). You will never know which one: under the [simplified procedure](https://www.cnil.fr/fr/23-nouvelles-sanctions-simplifiees), the CNIL does not publish the names of the companies it fines. Six weeks earlier, on 1 September 2025, [SHEIN was fined €150 million](https://www.cnil.fr/en/cookies-placed-without-consent-shein-fined-150-million-euros-cnil) for trackers placed before the visitor clicked anything and a “Reject all” button that did not stop new trackers being placed. Between those two extremes the rules are the same, and they fit in a few lines.

## Is a cookie banner mandatory in France?

The banner itself is not mandatory: what is mandatory is the visitor’s prior consent before any non-exempt tracker is stored or read. As soon as your site uses advertising, a social media pixel or Google Analytics in its standard configuration, you need a consent mechanism, and a banner is the most common form.

The principle is EU-wide: it comes from Article 5(3) of the [ePrivacy Directive (Directive 2002/58/EC)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32002L0058), which each member state writes into its own law. In France, that is article 82 of the « loi Informatique et Libertés » (French Data Protection Act). What this guide describes on top of it is French: the CNIL’s guidelines, recommendation and FAQ, and the fines it imposes.

**What the law says**

> Tout abonné ou utilisateur d’un service de communications électroniques doit être informé de manière claire et complète, sauf s’il l’a été au préalable, par le responsable du traitement ou son représentant : 1° De la finalité de toute action tendant à accéder, par voie de transmission électronique, à des informations déjà stockées dans son équipement terminal de communications électroniques, ou à inscrire des informations dans cet équipement ; 2° Des moyens dont il dispose pour s’y opposer. Ces accès ou inscriptions ne peuvent avoir lieu qu’à condition que l’abonné ou la personne utilisatrice ait exprimé, après avoir reçu cette information, son consentement qui peut résulter de paramètres appropriés de son dispositif de connexion ou de tout autre dispositif placé sous son contrôle. Ces dispositions ne sont pas applicables si l’accès aux informations stockées dans l’équipement terminal de l’utilisateur ou l’inscription d’informations dans l’équipement terminal de l’utilisateur : 1° Soit, a pour finalité exclusive de permettre ou faciliter la communication par voie électronique ; 2° Soit, est strictement nécessaire à la fourniture d’un service de communication en ligne à la demande expresse de l’utilisateur.
> 
> *Unofficial translation:* Any subscriber or user of an electronic communications service must be informed clearly and completely, unless they have already been informed, by the controller or its representative: 1° of the purpose of any action seeking to access, by electronic transmission, information already stored in their electronic communications terminal equipment, or to write information to that equipment; 2° of the means available to them to object to it. Such access or writing may only take place on condition that the subscriber or user has given their consent, after receiving this information; that consent may result from appropriate settings of their connection device or of any other device under their control. These provisions do not apply if accessing information stored in the user’s terminal equipment or writing information to the user’s terminal equipment: 1° has the sole purpose of enabling or facilitating communication by electronic means; or 2° is strictly necessary for the provision of an online communication service at the user’s express request.
>
> Source: [Loi n° 78-17 du 6 janvier 1978, art. 82 (French Data Protection Act)](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000037813978)

Three takeaways from this text. It covers any “tracker”, not just cookies: pixels, browser local storage, device fingerprinting and advertising identifiers are all included, as the [CNIL points out](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/comment-mettre-mon-site-web-en-conformite) (in French). It applies whether or not the data is personal ([CNIL FAQ, question 8](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ), in French). And after a refusal or withdrawal, the publisher must stop all reading and writing from its site, including by partners whose tags it has embedded (question 29).

The CNIL set out how to apply this article in two texts adopted on 17 September 2020: the [guidelines (deliberation n° 2020-091)](https://www.cnil.fr/sites/default/files/atoms/files/lignes_directrices_de_la_cnil_sur_les_cookies_et_autres_traceurs.pdf), which restate the law, and the [recommendation (deliberation n° 2020-092)](https://www.cnil.fr/sites/default/files/2026-01/recommandation_cookies_consolidee.pdf), a non-binding practical guide whose consolidated version was published on 16 January 2026 after an amendment on multi-device consent (deliberation n° 2025-131 of 18 December 2025). Both are in French.

## Which cookies are exempt from consent in France?

Trackers strictly necessary for the service the visitor asked for are exempt: shopping basket, authentication, remembering the cookie choice, load balancing, expected interface personalisation and, under strict conditions, audience measurement. Everything else (advertising, retargeting, social sharing, embedded videos, tools that reuse the data) requires prior consent.

The list comes from the [CNIL’s compliance page](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/comment-mettre-mon-site-web-en-conformite) and its [cookie FAQ](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ), updated on 29 April 2026 (both in French).

| Tracker | Consent? | What the CNIL says |
|---|---|---|
| Shopping basket, billing | No | Exempt: necessary for the service requested |
| Account login, authentication security | No | Exempt, including limiting automated login attempts |
| Cookie that remembers the “accept / reject” choice | No | Exempt |
| Language, interface layout | No | Exempt if personalisation is an expected part of the service |
| Load balancing | No | Exempt |
| Audience measurement for your own account only, anonymous statistics | No, under conditions | Exempt if every condition is met (see below) |
| Google Analytics in standard configuration | Yes | The provider reuses the data for its own purposes |
| Fraud prevention in general | Yes | Not exempt, except user-centred security |
| CAPTCHA that reuses data (reCAPTCHA is named) | Yes | Consent required if the provider reuses the data |
| Meta, TikTok and Google Ads pixels, retargeting | Yes | Advertising, personalised or not, as soon as a tracker measures it |
| Share buttons, embedded video that drops trackers | Yes | Consent, which can be asked when the content is activated |

The diagram below sums up the reasoning, tracker by tracker.

```mermaid
flowchart TD
  A["A tracker reads or writes on the visitor’s device"] --> B{"Basket, login, cookie choice, security?"}
  B -->|Yes| X["Exempt: informing users recommended"]
  B -->|No| C{"Used to measure audience?"}
  C -->|No| Y["Prior consent required"]
  C -->|Yes| D{"For you only, anonymous stats, no cross-site tracking?"}
  D -->|No| Y
  D -->|Yes| E{"Provider does not reuse data for itself?"}
  E -->|Yes| Z["Exempt: inform and allow objection"]
  E -->|No| Y
```

**The “strictly necessary” trap**

Labelling a cookie “strictly necessary” does not make it exempt. That was one of the breaches found against the publisher of vanityfair.fr, fined €750,000 on 20 November 2025: cookies presented as strictly necessary, with no useful information about their purposes.

## Is Google Analytics exempt from cookie consent in France?

No, not in its standard configuration: the [CNIL](https://www.cnil.fr/fr/mesurer-la-frequentation-de-vos-sites-web-et-de-vos-applications) names Google Analytics among the offers that fall outside the exemption, because the provider reuses the data for its own purposes. Only an audience measurement tool configured to meet every condition of the exemption can do without consent.

Those conditions are set out on the [CNIL’s page on audience measurement](https://www.cnil.fr/fr/cookies-solutions-pour-les-outils-de-mesure-daudience) (in French, published on 4 July 2025): a purpose limited to measuring the site’s audience exclusively on the publisher’s behalf, anonymous statistics only, no cross-referencing with other processing, no transfer of non-anonymous data to third parties, no tracking of browsing on other sites or apps. The CNIL also recommends a tracker lifetime of thirteen months with no automatic extension, and data retention of twenty-five months at most.

On Google Analytics specifically, its page [« Mesurer la fréquentation de vos sites web »](https://www.cnil.fr/fr/mesurer-la-frequentation-de-vos-sites-web-et-de-vos-applications) (measuring traffic on your websites, in French) recalls that its restricted committee (the CNIL body that imposes sanctions) ruled in decision SAN-2020-008 of 18 November 2020 that these cookies “are not strictly necessary for the provision of the service”.

The CNIL no longer publishes a list of exempt tools: it has replaced it with a self-assessment tool for providers ([FAQ, question 12](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ)) and, in an inspection, it will check the actual configuration; both the publisher and the provider can be held liable. In practice, if you cannot show that your tool ticks every box, put it behind consent.

## What must a CNIL-compliant cookie banner include?

A compliant banner states the purposes and the companies involved, collects a clear affirmative action, lets visitors refuse as easily as they accept from the first screen, and lets them withdraw their choice at any time. Before any click, no tracker that needs consent may be placed.

The requirements, drawn from the CNIL’s [guidelines](https://www.cnil.fr/sites/default/files/atoms/files/lignes_directrices_de_la_cnil_sur_les_cookies_et_autres_traceurs.pdf), [recommendation](https://www.cnil.fr/sites/default/files/2026-01/recommandation_cookies_consolidee.pdf) and [FAQ](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ):

- **Nothing before the choice.** Advertising cookies placed “as soon as they arrived on the site” were the first breach in both the [SHEIN](https://www.cnil.fr/en/cookies-placed-without-consent-shein-fined-150-million-euros-cnil) and [vanityfair.fr](https://www.cnil.fr/en/cookies-placed-without-consent-company-publishes-website-vanityfairfr-fined-750000-euros) decisions.
- **Purposes on the first layer**, in plain words (“Personalised advertising”, “Audience measurement”), with a link to the up-to-date list of companies that place trackers.
- **A clear affirmative action.** Continuing to browse is not consent: the CNIL treats it as a refusal (FAQ, question 19). Closing the banner is not acceptance either.
- **Refusing as easily as accepting.** A “Reject all” button on the first layer, looking the same as “Accept all”, is expected, or failing that an equally simple way to refuse (question 37). A refusal available only on the second layer, behind “Settings”, is not good enough (question 38).
- **No deceptive design**: a greyed-out or smaller reject button, or wording that suggests consent is compulsory.
- **A choice per purpose**, at least on a second layer: advertising, audience measurement, social media.
- **Withdrawal at any time**, through a “Manage my cookies” link in the footer or a permanent icon. Withdrawal must actually work: after a refusal, no more reading or writing of the trackers concerned, third-party ones included (question 29).

A “Continue without accepting” link is still allowed. On 19 June 2026, the [Conseil d’État (n° 501417)](https://www.conseil-etat.fr/fr/arianeweb/CE/decision/2026-06-19/501417) (France’s highest administrative court, decision in French) dismissed an association’s request to remove from the recommendation the example of a banner with that link in the top right corner: it held that refusal was available on the same screen and with the same ease.

Your banner does not live on its own: your [privacy policy](/en/guides/privacy-policy-france/) and your cookie policy must describe the same trackers, the same purposes and the same retention periods.

## How long should cookie consent last in France?

The CNIL considers six months, for consent and refusal alike, to be generally appropriate. It is good practice, not a legal deadline: the period is assessed case by case, but asking again at every visit after a refusal weighs on the freedom of choice.

The CNIL’s [compliance page](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/comment-mettre-mon-site-web-en-conformite) and its [FAQ (question 21)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ) both use these six months. Do not confuse this period with the lifetime of exempt audience measurement cookies (thirteen months) or with the retention of the data they collect (twenty-five months).

## How do I prove cookie consent?

Whoever relies on consent must be able to prove it, at any time. The CNIL suggests several non-exclusive methods: time-stamped screenshots of each version of the banner, time-stamped code deposits, third-party audits, and a configuration history kept by the consent management platform provider.

These methods are listed on the CNIL page [« Cookies et traceurs : que dit la loi ? »](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/que-dit-la-loi) (what the law says, in French). In practice, for a Shopify or WooCommerce store: a dated screenshot of the banner every time it changes, an export of your consent tool’s configuration, and a consent log if your tool provides one.

## Are cookie walls allowed in France?

Not banned in principle, but tightly framed: since the Conseil d’État decision of 19 June 2020, the CNIL assesses case by case whether a visitor who refuses has a real and fair alternative. For an online shop, blocking access to the catalogue until advertising is accepted is very hard to justify.

The [criteria published by the CNIL on 16 May 2022](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookie-walls/la-cnil-publie-des-premiers-criteres-devaluation) (in French): a real and fair alternative to access the content without trackers, offered by the publisher itself or, failing that, whose existence it can show on another publisher’s site; if that alternative is paid, a reasonable price the publisher must be able to justify; a wall limited to the purposes that fund the service (targeted advertising, not editorial personalisation); and, for those who choose paid access, no trackers that need consent.

## Is Google Consent Mode enough to be compliant?

No: Consent Mode collects no consent at all, it passes the choice made in your banner on to Google tags. You still need a compliant banner, and “advanced” mode, which sends requests to Google before any choice is made, calls for caution.

According to [Google’s documentation](https://developers.google.com/tag-platform/security/concepts/consent-mode), it is the publisher’s job to obtain consent, through a banner or a consent management platform. In “basic” mode, Google tags stay blocked until the user interacts with the banner, and nothing is sent if they refuse. In “advanced” mode, tags load as soon as the page opens and, while consent is refused, send Google “cookieless” pings (timestamp, browser, referring page, consent status).

Neither the [CNIL’s cookie FAQ](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ) nor its guidelines mention Consent Mode. But article 82 covers any access to information on the device, not just cookies, and the [European Data Protection Board’s Guidelines 2/2023](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en), EU-level guidance, extend the rule to pixel and URL-based tracking. With no official position on these pings, basic mode is the safer choice.

## What are the fines for a non-compliant cookie banner in France?

The legal maximum for a breach of article 82 is €10 million or 2% of annual worldwide turnover, whichever is higher. Straightforward cases go through the simplified procedure, capped at €20,000 for most companies and with no name published, and the CNIL uses it regularly for cookies.

The maximum is set by article 20 of the [French Data Protection Act](https://www.cnil.fr/fr/la-loi-informatique-et-libertes) (in French), which also provides for a penalty payment of up to €100,000 per day of delay. The cap of the [simplified procedure](https://www.cnil.fr/fr/la-procedure-de-sanction-simplifiee) rises to €100,000 when worldwide turnover exceeds €50 million. The [CNIL’s 2025 review](https://www.cnil.fr/en/sanctions-and-corrective-measures-cnils-actions-2025) counts 21 organisations sanctioned for breaching the rules on trackers: placing them without consent, insufficient information, refusal or withdrawal not taken into account. By 6 July 2026, the CNIL had issued [23 simplified sanctions since January](https://www.cnil.fr/fr/23-nouvelles-sanctions-simplifiees), €133,750 in total; among the cookie-related breaches, it cites banners where accepting took one click while refusing meant going through “Customise” and then a settings screen.

```datatable title="Selected CNIL cookie-related sanctions (2025-2026)" filter
Date,Organisation,Amount,Breaches,Source
2026-03-26,Ticketing and events company (simplified procedure),"€15,000 and injunction","Consent and information (cookies), other GDPR breaches","[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-12-18,Travel agency (simplified procedure),"€2,000 and injunction",Consent and information (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-11-27,Distance-selling company,"€500,000 and injunction",Consent and information (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-11-27,Payment card issuer,"€1,500,000",Consent (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-11-20,Les Publications Condé Nast (vanityfair.fr),"€750,000","Cookies before any choice, confusing information, refusal not respected","[SAN-2025-010](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052851847)"
2025-11-13,Footwear retailer (simplified procedure),"€5,000",Consent and information (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-10-16,Specialist distance seller (simplified procedure),"€3,000",Consent (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-10-09,General distance seller (simplified procedure),"€4,000",Consent and information (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-09-01,SHEIN (Infinite Styles Services Co. Limited),"€150,000,000","Trackers on arrival, incomplete information, refusal not respected","[SAN-2025-005](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052182271)"
2025-09-01,Google LLC and Google Ireland Limited,"€325,000,000 and injunction","Cookies at account creation, ads in Gmail","[SAN-2025-004](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052182222)"
2025-07-03,Furniture and home decor distance seller,"€600,000","Information and consent (cookies), marketing, data retention","[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
2025-06-18,General distance seller (simplified procedure),"€3,000",Consent (cookies),"[CNIL list (in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil)"
```

What these decisions show: online retail appears in most rows, and the detailed decisions always find the same mistakes (trackers before the choice, vague information, refusal ignored). Our guide to [CNIL fines](/en/guides/cnil-fines/) explains the procedure, from online inspection to decision.

## Do email tracking pixels need consent under the CNIL’s 2026 recommendation?

Since recommendation n° 2026-042, published in the « Journal officiel » (France’s official gazette) on 14 April 2026, the invisible pixel that measures email opens is treated like a cookie: consent in principle, unless its use is strictly limited to measuring the deliverability of an email linked to a service the recipient asked for. The three-month grace period for existing mailing lists expired, in principle, on 14 July 2026.

[Deliberation n° 2026-042](https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000053876850) was adopted on 12 March 2026, on the basis of the same article 82. According to the [CNIL’s presentation page](https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels) and its [Q&A of 22 July 2026](https://www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques) (both in French):

- **Deliverability exemption**: possible for an email linked to a service requested (order confirmation, subscription renewal, security alert) or an expressly requested newsletter, if the pixel is only used to spot recipients who no longer open your emails so you can remove them from your lists. In principle, only the date of the last open is needed. Abandoned-cart reminders, being promotional, do not qualify.
- **Consent required** as soon as the pixel is used for anything else: time of opening, personalising sends. Collecting the IP address and anonymising it afterwards is not enough to stay within the exemption. Marketing sent to an existing customer under the “similar products or services” rule is not a requested service: its pixel is not exempt.
- **Aggregate statistics**: an overall open rate remains possible without consent, from data collected by an exempt pixel and then anonymised.
- **Existing lists**: for addresses collected before 14 April 2026, recipients had to be clearly informed and allowed to object within three months of publication, around 14 July 2026, a deadline the CNIL accepts may be extended “reasonably” if sending volumes justify it and this is documented. Without that information, you must now collect consent or stop using the pixels concerned.

If your shop sends campaigns through an email marketing tool, check whether open tracking is switched on by default, and add this purpose to your consent collection.

## Will the EU Digital Omnibus get rid of cookie banners?

Not today: the European Commission’s proposal of 19 November 2025 is still under discussion, and as of 7 October 2026 article 82 and the CNIL’s rules apply unchanged. Even if adopted as drafted, it would keep the principle of consent.

The [proposal COM(2025) 837](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837) would move the rule into a new Article 88a of the GDPR. It would add exemptions, including aggregate audience measurement carried out by the publisher for its own use, require that refusal be possible with a single-click button, ban asking for consent again for at least six months after a refusal, and provide for automated, machine-readable choice signals (Article 88b). According to the [European Parliament’s procedure file](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360(COD)), the text is awaiting a committee decision. No application date has been set: do not take your banner down.

## How do I check my cookie banner in ten minutes?

Open your site in a private window, click nothing, and look at which cookies are already there: that is exactly what the CNIL recorded when it inspected shein.com and vanityfair.fr. Then reject everything, reload, and check that no advertising tracker appears.

**Cookie banner: what to check**

- [ ] No advertising or non-exempt measurement cookie is placed **before** any click
- [ ] A **“Reject all”** button (or a clearly visible “Continue without accepting” link) is on the first screen
- [ ] Refusing takes as many clicks as accepting, with a button of the same size and legibility
- [ ] Purposes are named on the first layer, with a link to the list of third-party companies
- [ ] After a refusal, no new tracker is placed and existing ones are no longer read
- [ ] A “Manage my cookies” link lets visitors change their mind from any page
- [ ] The choice is stored, ideally for six months, refusals included
- [ ] Google Analytics, pixels and embedded videos wait for consent, unless an exempt configuration is demonstrated
- [ ] Your email tracking pixels have been reviewed against the CNIL’s April 2026 recommendation
- [ ] The cookie policy lists the same trackers as those actually placed
- [ ] A dated screenshot of the banner and an export of its configuration are archived as proof

For the first point, the [free cookie checker](https://app.legalnest.io/tools/cookies?lang=en) reads your home page as the server sends it: it spots known trackers and consent banners, flags those that load without waiting for the visitor’s choice and the cookies set on first load. It does not replace a test in a real browser, because scripts can load others once they run. Like our other [free tools](/en/tools/), it needs no account.

**With Legalnest**: Legalnest does not provide the banner itself: you need a consent management tool for that. Legalnest does generate your cookie policy through a questionnaire and publishes it on a dated public page. In the “Website” compliance score, the banner is a self-declared item: you state that it is in place, Legalnest does not scan your site.

The banner is only one part of your site: also check your [legal notice](/en/guides/legal-notice-website-france/), your [GDPR record of processing](/en/guides/gdpr-record-of-processing/) if you handle customer data, or take stock in a few questions with the [website compliance quiz](/en/guides/website-compliance-quiz/).

## Frequently asked questions

### Does a website with no ads and no Google Analytics need a cookie banner in France?

No, if all its trackers are exempt: shopping basket, login, remembering the cookie choice, load balancing, audience measurement configured under the CNIL’s conditions. Article 82 of the French Data Protection Act only requires consent for trackers that are not strictly necessary. The CNIL still recommends telling visitors about these cookies, for example in the cookie policy. An embedded video from a platform that drops cookies, or an advertising pixel, is enough to make consent necessary.

### Is a “Reject all” button mandatory on a cookie banner in France?

Yes, or failing that a way to refuse that is as simple as accepting, on the same screen. A “Reject all” button at the same level and with the same look as “Accept all” is the solution the CNIL cites; a clearly visible “Continue without accepting” link was also found acceptable by the Conseil d’État on 19 June 2026. Forcing users through “Customise” to refuse, when one click is enough to accept, is among the breaches the CNIL fined under the simplified procedure in 2026.

### How long should I store a visitor’s cookie consent or refusal?

The CNIL considers six months, for consent and refusal alike, to be generally appropriate. The period is assessed case by case, but asking again at every visit after a refusal undermines the freedom of choice. For exempt audience measurement cookies, the CNIL recommends a lifetime of thirteen months at most and data retention of twenty-five months at most.

### Does Google Analytics require cookie consent in France?

In its standard configuration, yes. The CNIL lists Google Analytics among the offers that fall outside the exemption because the provider reuses the data for its own purposes, and its restricted committee ruled in 2020 that these cookies were not strictly necessary. Since the CNIL replaced its list of exempt tools with a self-assessment tool, it is up to the website publisher to show that its configuration meets every condition.

### What fine does a small business risk for a non-compliant cookie banner in France?

The legal maximum for a breach of article 82 is €10 million or 2% of worldwide turnover, but straightforward cases go through the simplified procedure, capped at €20,000 (€100,000 if worldwide turnover exceeds €50 million). In 2025 the CNIL used it to impose cookie fines of €2,000 to €7,000 on a travel agency, distance-selling sites and press publishers, and up to €20,000 when other breaches were added. The company’s name is not published under this procedure.

### Do I need consent for tracking pixels in a newsletter sent to French subscribers?

Yes in principle, since CNIL recommendation n° 2026-042 published on 14 April 2026, as soon as the pixel is used to know who opens and when, or to personalise sends. Only a pixel limited to measuring the deliverability of an email linked to a service the recipient asked for, such as an expressly requested newsletter, can be exempt. For addresses collected before 14 April 2026, recipients had to be informed and allowed to object before 14 July 2026.


## Sources

- [Loi n° 78-17 du 6 janvier 1978 relative à l’informatique, aux fichiers et aux libertés (French Data Protection Act), art. 82](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000037813978) (Légifrance)
- [Loi n° 78-17 du 6 janvier 1978, consolidated text (art. 20: corrective measures and maximum fines, in French)](https://www.cnil.fr/fr/la-loi-informatique-et-libertes) (CNIL)
- [Directive 2002/58/EC of 12 July 2002 on privacy and electronic communications (ePrivacy Directive), Article 5(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32002L0058) (EUR-Lex)
- [Délibération n° 2020-091 du 17 septembre 2020 (CNIL guidelines on cookies and other trackers under article 82, in French)](https://www.cnil.fr/sites/default/files/atoms/files/lignes_directrices_de_la_cnil_sur_les_cookies_et_autres_traceurs.pdf) (CNIL)
- [Recommandation « cookies et autres traceurs » (CNIL recommendation on cookies, deliberation n° 2020-092 of 17 September 2020), consolidated version published on 16 January 2026 with deliberation n° 2025-131 of 18 December 2025 (in French)](https://www.cnil.fr/sites/default/files/2026-01/recommandation_cookies_consolidee.pdf) (CNIL)
- [Questions-réponses sur les lignes directrices modificatives et la recommandation « cookies et autres traceurs » (CNIL cookie FAQ, in French)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ) (CNIL)
- [Cookies et traceurs : comment mettre mon site web en conformité ? (making your website compliant, in French)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/comment-mettre-mon-site-web-en-conformite) (CNIL)
- [Cookies et traceurs : que dit la loi ? (what the law says, in French)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/que-dit-la-loi) (CNIL)
- [Cookies : solutions pour les outils de mesure d’audience (audience measurement tools, in French)](https://www.cnil.fr/fr/cookies-solutions-pour-les-outils-de-mesure-daudience) (CNIL)
- [Mesurer la fréquentation de vos sites web et de vos applications (measuring traffic on your websites and apps, in French)](https://www.cnil.fr/fr/mesurer-la-frequentation-de-vos-sites-web-et-de-vos-applications) (CNIL)
- [Cookie walls : la CNIL publie des premiers critères d’évaluation (first assessment criteria for cookie walls, in French)](https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookie-walls/la-cnil-publie-des-premiers-criteres-devaluation) (CNIL)
- [Conseil d’État (France’s highest administrative court), 19 juin 2026, n° 501417, association Pour un RGPD respecté et autres (in French)](https://www.conseil-etat.fr/fr/arianeweb/CE/decision/2026-06-19/501417) (Conseil d’État)
- [Cookies placed without consent: SHEIN fined 150 million euros by the CNIL](https://www.cnil.fr/en/cookies-placed-without-consent-shein-fined-150-million-euros-cnil) (CNIL)
- [Délibération SAN-2025-005 du 1er septembre 2025 (SHEIN decision, in French)](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052182271) (Légifrance)
- [Cookies and advertisements inserted between emails: Google fined 325 million euros by the CNIL](https://www.cnil.fr/en/cookies-and-advertisements-inserted-between-emails-google-fined-325-million-euros-cnil) (CNIL)
- [Délibération SAN-2025-004 du 1er septembre 2025 (Google decision, in French)](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052182222) (Légifrance)
- [Cookies placed without consent: the company that publishes the website “vanityfair.fr” fined 750,000 euros by the CNIL](https://www.cnil.fr/en/cookies-placed-without-consent-company-publishes-website-vanityfairfr-fined-750000-euros) (CNIL)
- [Délibération SAN-2025-010 du 20 novembre 2025 (vanityfair.fr decision, in French)](https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000052851847) (Légifrance)
- [Les sanctions prononcées par la CNIL (list of CNIL sanctions, in French)](https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil) (CNIL)
- [La CNIL a prononcé 23 nouvelles sanctions depuis janvier au titre de la procédure simplifiée (23 simplified-procedure sanctions since January, in French)](https://www.cnil.fr/fr/23-nouvelles-sanctions-simplifiees) (CNIL)
- [La procédure de sanction simplifiée (the simplified sanction procedure, in French)](https://www.cnil.fr/fr/la-procedure-de-sanction-simplifiee) (CNIL)
- [Sanctions and corrective measures: the CNIL’s actions in 2025](https://www.cnil.fr/en/sanctions-and-corrective-measures-cnils-actions-2025) (CNIL)
- [Pixels de suivi dans les courriers électroniques : la CNIL publie ses recommandations pour mieux protéger la vie privée (tracking pixels in emails, in French)](https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels) (CNIL)
- [Délibération n° 2026-042 du 12 mars 2026 portant adoption d’une recommandation relative aux pixels de suivi dans les courriers électroniques (CNIL recommendation on email tracking pixels)](https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000053876850) (Légifrance)
- [Questions-réponses : recommandation relative aux pixels dans les courriers électroniques de la CNIL (FAQ on the email pixel recommendation, in French)](https://www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques) (CNIL)
- [Proposal for a Regulation (Digital Omnibus), COM(2025) 837 final of 19 November 2025](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837) (EUR-Lex)
- [Procedure 2025/0360(COD): Digital Omnibus, procedure file](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360(COD)) (European Parliament, Legislative Observatory)
- [Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en) (European Data Protection Board)
- [Consent mode overview (technical documentation)](https://developers.google.com/tag-platform/security/concepts/consent-mode) (Google)
