Back to blog

Blog · Compliance & privacy

Cookies and trackers: what the CNIL requires, what an audit measures

In short The rule fits in one sentence: no non-essential tracker may be dropped before the visitor has said yes, and refusing must be as easy as accepting. Most of the sites we measure fail the first point without knowing it, because their banner appears while the scripts have already loaded. It is measurable from the outside, in a single visit, and it is the first gap an inspection finds.

The rule, plainly

A cookie strictly necessary for the site to work requires no consent: basket, logged-in session, remembering a language choice, and under conditions certain analytics measurements.

Everything else, advertising, social networks, non-exempt analytics, sharing with third parties, requires consent that is prior, freely given, specific, informed and unambiguous. Three practical consequences that banners rarely respect:

  • Prior means before the drop, not during page load.
  • Freely given means refusing must be as easy as accepting, on the same screen, in one click. An "Accept all" button facing a "Settings" link written in grey does not meet that condition.
  • Unambiguous means a positive action. Continuing to browse is not consent.

These are the points behind the heaviest penalties issued in France on this subject, and the most frequently recorded gap is not the absence of a banner, it is the drop before the click.

The most frequent mistake, and why it goes unnoticed

A site installs a consent banner, usually a plugin. The banner appears, the manager is configured, the owner considers the matter settled.

Except the analytics and social network scripts are still in the page code, before the banner. They therefore load as the page displays, that is to say before the visitor has seen the question. The banner blocks what comes after, not what has already gone.

This configuration is invisible from your own browser: you accepted once, your choice is remembered, and you never see a first-time visitor's experience again. It is however immediately visible from the outside, arriving on the site with no history.

The fix is to load those scripts conditionally, after consent, rather than leaving them in the page and hoping the banner takes care of it.

The question of transfers outside the European Union

A tracker that sends data to a server outside the European Union adds a legal layer to the consent question. The subject has seen several reversals over the past ten years, and it continues to evolve.

Without going into the legal detail, which is your adviser's territory, a reasonable position for a small or mid-sized company comes down to two points: prefer tools hosted in Europe when an alternative exists, and know precisely what your site loads. Many owners discover on auditing their site that they are sending data to three or four services they did not know existed, added by a theme or a previous contractor.

Our audit records the trackers dropped on arrival and their geographic origin. We pass no legal judgement, we establish a factual finding that your adviser can then qualify.

Check your site in three minutes, with no tool

  1. Open a private browsing window, so you arrive with no history and no remembered choice.
  2. Go to your site, and do not touch the banner.
  3. Open the browser developer tools, Application or Storage tab, Cookies section.

Everything that appears at that moment was dropped without your consent. If you find anything other than a session or preference cookie, the configuration needs revisiting.

Run the same test on the refuse button: click "Refuse", reload, and see whether the list is genuinely empty. A banner that drops despite a refusal is the most serious case, and it is not rare.

What we measure

Six findings in this category: the trackers present on arrival, how many, where they come from, the security attributes of the cookies set, the presence of a consent mechanism, and the presence of a reachable privacy policy.

We measure what a visitor receives on a first visit, without interacting with the banner. That is exactly the situation an inspection examines, and it is the only angle that reveals an early drop.

The technical side of cookies, their security attributes, is covered in the article on security headers. The obligations side is one for your legal adviser: our role stops at the measured finding.

Do your trackers fire before consent?

The audit records the trackers dropped on arrival and where they come from. Free, 30 seconds.

Analyze my website