Skip to main content
Certyneo
Security

Cookie Management: Consent and Trackers in E-commerce

Cookie compliance for e-commerce sites: GDPR/CNIL obligations, consent banner, tracker list and best practices 2026.

Certyneo Team6 min read

Updated on

Certyneo Team

Writer — Certyneo · About Certyneo

a group of white letters on a wooden surface

Cookie regulation is not limited to the GDPR. It rests on a separate text — the so-called "ePrivacy" directive on privacy and electronic communications, transposed into French law — which requires prior consent before any reading or writing of information on a user's device, regardless of whether that information constitutes personal data. This independence explains most formal notices: a non-personal tracker remains subject to consent.

What is covered, and what is not

The scope is broader than the word "cookie" suggests. It covers all processes for storing or accessing information on a device: HTTP cookies, local storage, invisible pixels, device identifiers, browser fingerprinting.

Two categories are exempt from the consent requirement, and they are interpreted strictly:

  • Trackers strictly necessary for the provision of a service expressly requested by the user: shopping basket, session identifier, remembering a language choice, load balancing.
  • Trackers whose sole purpose is to enable or facilitate electronic communication.

Audience measurement sits in a particular grey area: it can be exempted from consent under strict cumulative conditions — purpose limited solely to measurement, no cross-referencing with other processing, no transmission to third parties, limited retention period. A widely used analytics tool that cross-references data between sites or transmits it to its publisher does not meet these conditions.

The rules governing collection

Three requirements structure the consent banner, and each has been the subject of sanctions.

Consent must be given in advance. No exempted tracker may be placed before the user takes action. Placing a tracker when the page loads, before any click, is an infringement in itself — it is the most frequently observed breach.

Refusing must be as simple as accepting. A banner offering a prominent "Accept all" button while pushing refusal to a second-level settings screen does not meet this requirement. Both actions must be accessible at the same level and with the same number of clicks.

Consent must be freely given, specific, informed and unambiguous. It cannot result from continued browsing, scrolling down the page, or a pre-ticked box. It must be collected purpose by purpose, with the user able to accept audience measurement without accepting targeted advertising.

There is also the matter of withdrawal, which must be as easy as giving initial consent and accessible at any time, requiring a permanent access point on the site.

Durations and retention

Two distinct time periods are often confused.

The lifespan of trackers is capped in practice at thirteen months, with no automatic extension on each new visit. Information collected via these trackers is only kept for a limited time beyond that.

The validity period of consent is distinct: the user's choice, whether positive or negative, must be retained so as not to ask again on each visit. Recommended practice is to retain this choice for around six months, and a refusal should not be queried more frequently than an acceptance.

Finally, the controller must be able to prove that consent was validly obtained. This proof requires logging, for each user, the version of the banner displayed, the purposes presented and the choice made. Without this logging, the statement "we collect consent" cannot be demonstrated — the same evidential logic that governs the acceptance of terms and conditions.

Shared responsibilities

A website that integrates third-party trackers — an advertising network, a social network, an analytics tool — is not thereby relieved of its responsibility. The publisher who decides to place a tracker determines its purpose and bears responsibility for it, even where the tracker belongs to a third party.

There are two practical consequences. An up-to-date inventory of the trackers actually deployed is essential, and it must be verified under real conditions rather than against providers' documentation: tags added by marketing tools frequently escape the declared inventory. And relationships with third parties must be set out contractually, identifying who is the data controller and who is the processor.

Sanctions and inspections

Breaches of tracker rules fall under a specific regime: they are sanctioned on the basis of the special text, which allows the national supervisory authority to act directly, without going through the European cooperation mechanism. This explains the speed and the size of the fines issued in this area.

Inspections primarily focus on three points that can be verified from the outside: trackers placed before consent, asymmetry between accepting and refusing, and trackers persisting after a refusal. These three points can be checked within minutes using a browser's developer tools, making exposure constant.

Usage scenarios

Online shop with advertising. Separate purposes — functionality, audience measurement, advertising — and allow distinct consent for each. Basket trackers do not fall under consent requirements, whereas retargeting advertising trackers always do. This is a structuring point of the legal framework for an online shop.

Showcase website with audience measurement. Check whether the configuration chosen meets the exemption conditions. If so, no banner is required for that purpose; if not, consent is required as for any other tracker.

Website redesign. Carry out the tracker inventory in the staging environment before going live, then redo it in production: tools added by marketing teams after launch are the most frequent source of discrepancy. This discipline mirrors the requirements described for secure payment standards.

Frequently asked questions

Do all cookies require consent? No. Those strictly necessary for a service expressly requested — basket, session, language preference — are exempt, as are those used solely to enable communication. The exemption is interpreted strictly.

Does continuing to browse count as consent? No. Consent must be unambiguous and result from a positive act. Neither scrolling, nor continued browsing, nor a pre-ticked box is sufficient.

Must refusing be as simple as accepting? Yes. Both options must be presented at the same level, with equivalent effort. Relegating refusal behind a settings menu constitutes a clear breach.

How long should the user's choice be retained? The choice, whether positive or negative, should be retained to avoid asking again on each visit — around six months in practice. This is distinct from the lifespan of trackers, capped at thirteen months.

Is audience measurement exempt? Only under strict cumulative conditions: purpose limited to measurement, no cross-referencing, no transmission to third parties, limited retention. Most mainstream tools do not meet these conditions in their default configuration.

Who is responsible for third-party trackers? The website publisher, as soon as they decide to deploy them and determine their purpose. Responsibility is not transferred to the tracker's provider.

Key takeaways

Three breaches account for most sanctions, and all three can be observed from the outside within minutes: trackers placed before any consent, refusal being harder to express than acceptance, and trackers that persist despite a refusal.

Two measures address this durably. A tracker inventory verified under real conditions rather than on documentation, redone after each production release. And consent logging that records the version of the banner, the purposes presented and the choice made — without it, compliance is claimed but cannot be demonstrated, which amounts to the same thing during an inspection.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.