Cookie Management: Consent and Trackers in E-commerce
Cookie compliance for e-commerce sites: GDPR/CNIL obligations, consent banner, list of trackers and best practices 2026.
Updated on
Certyneo Team
Writer — Certyneo · About Certyneo

Cookie regulation is not limited to the GDPR. It rests on a separate text — the so-called "ePrivacy" directive, transposed into French law — which requires prior consent before any information is read from or written to a user's device, regardless of whether that information constitutes personal data or not. This independence explains most formal notices: a non-personal tracker remains subject to consent.
What Is Covered, and What Isn't
The scope is broader than the word "cookie" suggests. It covers all methods of storing or accessing information on a terminal device: HTTP cookies, local storage, invisible pixels, device identifiers, and browser fingerprinting.
Two categories are exempt from the consent requirement, and they are interpreted strictly:
- Trackers strictly necessary for the provision of a service expressly requested by the user: shopping cart, session identifier, language preference memory, load balancing.
- Trackers whose sole purpose is to enable or facilitate electronic communication.
Audience measurement occupies a special zone: it can be exempted from consent under strict cumulative conditions — purpose limited to measurement alone, no cross-referencing with other processing, no transmission to third parties, limited retention period. A widely used analytics solution that cross-references data across sites or transmits it to its publisher does not meet these conditions.
The Rules for Collecting Consent
Three requirements structure the consent banner, and each has been the subject of sanctions.
Consent must be prior. No non-exempt tracker may be deposited before the user takes action. Deployment on page load, before any click, is an infringement in itself — this is the most frequently observed violation.
Refusing must be as simple as accepting. A banner featuring a prominent "Accept All" button while relegating refusal to a second-level settings menu does not satisfy this requirement. Both actions must be accessible at the same level and with the same number of clicks.
Consent must be freely given, specific, informed, and unambiguous. It cannot result from continued browsing, page scrolling, or a pre-checked box. It must be collected purpose by purpose, with the user able to accept audience measurement without accepting targeted advertising.
There is also the matter of withdrawal, which must be as easy as giving initial consent and accessible at all times, requiring a permanent access point on the site.
Durations and Retention
Two distinct durations are often confused.
The lifespan of trackers is capped in practice at thirteen months, with no automatic extension upon each new visit. Information collected through these trackers is retained for only a limited period beyond that.
The validity period of consent is distinct: the user's choice, whether positive or negative, must be retained so as not to ask again on every visit. Best practice recommends retaining this choice for about six months, with a refusal not to be re-solicited more frequently than an acceptance.
The controller must finally be able to prove that valid consent was obtained. This proof requires logging, for each user, the version of the banner displayed, the purposes presented, and the choice expressed. Without this logging, the claim "we collect consent" cannot be demonstrated — the same evidentiary logic that governs acceptance of the terms and conditions.
Shared Responsibilities
A website that integrates third-party trackers — an advertising network, a social network, an analytics tool — is not thereby relieved of its responsibility. The publisher who decides to deploy a tracker determines its purpose and bears responsibility for it, even when the tracker belongs to a third party.
Two practical consequences follow. An up-to-date inventory of the trackers actually deployed is essential, and it must be verified under real conditions rather than based on vendor documentation: tags added by marketing tools frequently escape the declared inventory. And relationships with third parties must be contractually formalized, identifying who is the data controller and who is the data processor.
Sanctions and Audits
A breach of tracker rules falls under its own regime: it is sanctioned on the basis of the special legislation, which allows the national supervisory authority to act directly, without going through the European cooperation mechanism. This explains the speed and the amount of the decisions handed down in this area.
Audits focus primarily on three points that are objectively verifiable from the outside: trackers deposited before consent, asymmetry between accepting and refusing, and trackers persisting after a refusal. These three points can be checked within minutes using a browser's developer tools, which makes exposure permanent.
Usage Scenarios
Online store with advertising. Separate purposes — operation, audience measurement, advertising — and allow distinct consent for each. Shopping cart trackers do not fall under consent requirements, while retargeting advertising trackers always do. This is a key point in the legal framework for an online store.
Showcase website with audience measurement. Check whether the chosen configuration meets the exemption conditions. If so, no banner is required for this purpose; if not, consent is required as for any other tracker.
Website redesign. Carry out the tracker inventory on the staging environment before going live, then redo it in production: tools added by marketing teams after launch are the most frequent source of discrepancy. This discipline aligns with the requirements described for secure payment standards.
Frequently Asked Questions
Do all cookies require consent? No. Those strictly necessary for a service expressly requested — cart, session, language preference — are exempt, as are those used solely to enable communication. The exemption is interpreted strictly.
Does continued browsing count as consent? No. Consent must be unambiguous and result from a positive act. Neither scrolling, nor continued browsing, nor a pre-checked box is sufficient.
Must refusing be as simple as accepting? Yes. Both options must be presented at the same level, with equivalent effort. Relegating refusal behind a settings menu is a clear-cut violation.
How long should the user's choice be retained? The choice, whether positive or negative, is retained to avoid re-asking on every visit — about six months in practice. This is distinct from the tracker lifespan, which is capped at thirteen months.
Is audience measurement exempt? Only under strict cumulative conditions: purpose limited to measurement, no cross-referencing, no transmission to third parties, limited retention. Most consumer-grade solutions do not meet these conditions in their default configuration.
Who is responsible for third-party trackers? The website publisher, as soon as it decides on their deployment and purpose. Responsibility is not transferred to the tracker provider.
Key Takeaways
Three violations account for most sanctions, and all three can be detected from the outside within minutes: trackers deposited before any consent, a refusal option that is more cumbersome to use than acceptance, and trackers that persist despite a refusal.
Two measures address this durably. A tracker inventory verified under real conditions rather than from documentation, redone after every production release. And consent logging that records the banner version, the purposes presented, and the choice expressed — without it, compliance is claimed but not demonstrable, which amounts to the same thing during an audit.
Try Certyneo for Free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Dive Deeper
Reference articles on this topic.
Continue reading about Security
Deepen your knowledge with these related articles.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications for electronic signature providers have become an essential selection criterion. Discover how to compare them effectively.

Electronic Signature: Traceability and Internal Audit in 2026
The traceability of an electronic signature has become a cornerstone of internal audit and legal compliance in business. Discover how to fully leverage it.

Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover the key requirements, synergies with eIDAS, and best practices to adopt.