Skip to Content

Cookies & consent: achieving compliance

Cookie banners, advertising trackers, audience measurement… Cookie management is one of the most visible compliance points on a website, and one of the most closely scrutinized by the CNIL. Here are the essential rules for staying compliant.

BCIT Formation logo
BCIT Formation is rated Excellent
4.7 · Trustpilot
1,000+ learners trained

When is consent required?

The principle is simple: unless an exception applies, storing and reading cookies and other trackers requires the user's prior consent. Until they have consented, no non-essential tracker may be placed.

Trackers that are strictly necessary for the operation of the service (shopping cart, authentication, certain limited audience measurement cookies) are exempt from this consent requirement. Everything else (advertising, tracking, social networks) requires a free and informed choice. This is the direct extension of the GDPR, as implemented by the CNIL.

The rules for valid consent

Accepting as simple as refusing

Refusing cookies must be as easy as accepting them: no “accept all” button without an equivalent way to refuse.

A free & informed choice

The user is clearly informed of the purposes before choosing; silence or simply continuing to browse does not constitute consent.

Granularity by purpose

The ability to consent purpose by purpose, rather than as a block, with easy access to details about the trackers.

Proof & reversibility

Consent must be provable, withdrawable as simply as it was given, and requested again periodically.

A highly monitored control point

Cookies are one of the areas most frequently checked and sanctioned by the CNIL, because non-compliance is visible to everyone from the homepage. Beyond the risk, a clear and fair banner is also a signal of respect sent to your visitors. It is consistent with our own cookie policy, deliberately limited to necessary trackers.

Control what actually runs

The technical difficulty is often that trackers are triggered before consent, even without the publisher realizing it (third-party scripts, marketing tags, video players…). Compliance therefore means mapping all trackers, blocking those that are not essential until consent has been collected, and verifying the site's actual behavior. These trackers must also be listed in the record of processing activities.

Bring your website into compliance, step by step

1

Inventory the trackers

Identify all cookies and trackers actually placed, including by third-party services.

2

Distinguish what is essential from the rest

Separate strictly necessary trackers (no consent required) from those subject to consent.

3

Block before consent

Make sure no non-essential tracker is triggered before the user's choice.

4

Improve the banner

Accept / refuse at the same level, clear information, choice by purpose, access to details.

5

Keep proof

Record consents and allow withdrawal at any time, just as simply.

6

Monitor over time

Check the website regularly: a new marketing tool can reintroduce a non-compliant tracker.

Why get support from BCIT?

A tracker audit

We reveal what actually runs on your website, before and after consent.

Pragmatic compliance

A fair and compliant banner, integrated into your GDPR compliance overall, without unnecessarily degrading your visitors' experience.

Connected to your GDPR

We integrate cookies into your GDPR approach overall, under the supervision of the DPO.

A finally compliant cookie banner

Let's take 15 minutes to audit your website's cookie management and define the priority fixes.