Cookie Management: Consent and Trackers in E-commerce
Cookie compliance for e-commerce sites: GDPR/CNIL obligations, consent banner, tracker list and best practices 2026.
Updated on
Certyneo Team
Writer — Certyneo · About Certyneo

Cookie regulation is not limited to the GDPR. It rests on a separate text — the so-called "ePrivacy" directive, transposed into French law — which requires prior consent before any reading or writing of information on the user's device, regardless of whether that information is personal data or not. It is this autonomy that explains most of the formal notices: a non-personal tracker remains subject to consent.
What is covered, and what is not
The scope is broader than the word "cookie" suggests. It concerns all processes for storing or accessing information on a device: HTTP cookies, local storage, invisible pixels, device identifiers, browser fingerprinting.
Two categories are exempt from the consent requirement, and they are interpreted strictly:
- Trackers that are strictly necessary for the provision of a service expressly requested by the user: shopping cart, session identifier, remembering a language choice, load balancing.
- Trackers whose exclusive purpose is to enable or facilitate a communication sent by electronic means.
Audience measurement occupies a particular grey area: it can be exempted from consent under strict cumulative conditions — purpose limited to measurement alone, no cross-referencing with other processing, no transmission to third parties, limited retention period. A widely used analytics solution that cross-references data between sites or transmits it to its publisher does not meet these conditions.
The rules for collecting consent
Three requirements structure the consent banner, and each has been the subject of sanctions.
Consent must be given in advance. No non-exempt tracker may be deposited before the user takes action. Deposit at page load, before any click, is an infringement in itself — this is the most frequently observed breach.
Refusing must be as simple as accepting. A banner offering a prominent "Accept all" button while relegating refusal to a second-level settings screen does not satisfy this requirement. Both actions must be accessible at the same level and with the same number of clicks.
Consent must be freely given, specific, informed and unambiguous. It cannot result from continued browsing, scrolling the page, or a pre-ticked box. It must be collected per purpose, with the user being able to accept audience measurement without accepting targeted advertising.
In addition, there is withdrawal, which must be as easy as giving initial consent and accessible at any time, which requires a permanent access point on the site.
Durations and retention
Two distinct durations are often confused.
The lifespan of trackers is capped in practice at thirteen months, with no automatic extension on each new visit. Information collected through these trackers is only retained for a limited time beyond that.
The validity period of consent is distinct: the user's choice, whether positive or negative, must be retained so as not to ask again on every visit. The recommended practice is to retain this choice for around six months, with a refusal not to be re-queried more frequently than an acceptance.
The controller must finally be able to prove that valid consent was collected. This evidence requires logging, for each user, the version of the banner displayed, the purposes presented and the choice expressed. Without this logging, the statement "we collect consent" cannot be demonstrated — the same evidentiary logic that governs acceptance of the terms and conditions.
Shared responsibilities
A site that integrates third-party trackers — advertising network, social media, analytics tool — is not thereby relieved of its responsibility. The publisher who decides to deploy a tracker determines its purpose and bears responsibility for it, even when the tracker belongs to a third party.
Two practical consequences follow. An up-to-date inventory of the trackers actually deployed is essential, and it should be verified under real conditions rather than from providers' documentation: tags added by marketing tools frequently escape the declared inventory. And relationships with third parties must be contractualised, identifying who is the data controller and who is the processor.
Sanctions and inspections
Breach of the rules on trackers falls under its own regime: it is sanctioned on the basis of the specific text, which allows the national supervisory authority to act directly, without going through the European cooperation mechanism. This explains the speed and the amounts of the decisions issued in this area.
Inspections focus primarily on three points that can be objectively verified from the outside: trackers deposited before consent, asymmetry between accepting and refusing, and trackers persisting after a refusal. These three points can be checked within minutes using a browser's developer tools, which makes exposure constant.
Usage scenarios
Online shop with advertising. Separate the purposes — functioning, audience measurement, advertising — and allow distinct consent for each. Shopping-cart trackers do not fall under consent requirements, whereas retargeting advertising trackers always do. This is a structuring point of the legal framework for an online shop.
Showcase site with audience measurement. Check whether the configuration used meets the exemption conditions. If so, no banner is necessary for this purpose; if not, consent is required as for any other tracker.
Website redesign. Carry out the inventory of trackers on the staging environment before going live, then redo it in production: tools added by marketing teams after go-live are the most frequent source of discrepancy. This discipline aligns with the requirements described for secure payment standards.
Frequently asked questions
Do all cookies require consent? No. Those strictly necessary for a service expressly requested — cart, session, language preference — are exempt, as are those used exclusively to enable a communication. The exemption is interpreted strictly.
Does continuing to browse count as consent? No. Consent must be unambiguous and result from a positive act. Neither scrolling, nor continued browsing, nor a pre-ticked box is sufficient.
Must refusing be as simple as accepting? Yes. Both options must be presented at the same level, with equivalent effort. Relegating refusal behind a settings menu is a clear-cut breach.
How long should the user's choice be retained? The choice, whether positive or negative, is retained to avoid asking again on every visit — around six months in practice. This is distinct from the lifespan of trackers, capped at thirteen months.
Is audience measurement exempt? Only under strict cumulative conditions: purpose limited to measurement, no cross-referencing, no transmission to third parties, limited retention. Most consumer-grade solutions do not meet these in their default configuration.
Who is responsible for third-party trackers? The site publisher, as soon as it decides on their deployment and purpose. Responsibility is not transferred to the tracker provider.
Key takeaways
Three breaches account for most of the sanctions, and all three can be detected from the outside within minutes: trackers deposited before any consent, refusal being more cumbersome to express than acceptance, and trackers that persist despite a refusal.
Two mechanisms provide a lasting response. An inventory of trackers verified under real conditions rather than from documentation, redone after every go-live. And a consent log that records the version of the banner, the purposes presented and the choice expressed — without it, compliance is asserted but not demonstrable, which amounts to the same thing during an inspection.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Dive deeper
Reference articles on this topic.
Continue reading about Security
Deepen your knowledge with these articles related to the topic.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications from electronic signature service providers have become an essential selection criterion. Discover how to compare them effectively.

Electronic Signature: Traceability and Internal Audit in 2026
The traceability of an electronic signature has become a pillar of internal audit and legal compliance in business. Discover how to make the most of it.

Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover key requirements, synergies with eIDAS, and best practices to adopt.