Management of Cookies: Consent and Trackers in E-commerce
Updated on
Writer — Certyneo · About Certyneo

Cookie regulation is not limited to the GDPR. It rests on a separate text — the so-called "ePrivacy" directive on privacy and electronic communications, transposed into French law — which requires prior consent before any reading or writing of information on a user's device, regardless of whether that information constitutes personal data or not. It is this independence that explains most formal notices: a non-personal tracker remains subject to consent.
What is covered, and what is not
The scope is broader than the word "cookie" suggests. It covers all processes for storing or accessing information on a device: HTTP cookies, local storage, invisible pixels, device identifiers, browser fingerprinting.
Two categories are exempt from the consent requirement, and they are interpreted strictly:
- Trackers strictly necessary for the provision of a service expressly requested by the user: shopping cart, session identifier, remembering a language choice, load balancing.
- Trackers whose sole purpose is to enable or facilitate electronic communication.
Audience measurement occupies a particular grey area: it can be exempted from consent under strict cumulative conditions — a purpose limited to measurement alone, no cross-referencing with other processing, no transmission to third parties, limited retention period. A widely used analytics solution that cross-references data across sites or transmits it to its publisher does not meet these conditions.
Rules governing collection
Three requirements structure the consent banner, and each has been the subject of sanctions.
Consent must be obtained in advance. No exempted tracker may be deposited before the user takes action. Depositing a tracker when the page loads, before any click, is a violation in itself — it is the most frequently observed failing.
Refusing must be as simple as accepting. A banner that displays a prominent "Accept All" button while relegating refusal to a second-level settings screen does not satisfy this requirement. Both actions must be accessible at the same level and with the same number of clicks.
Consent must be freely given, specific, informed and unambiguous. It cannot result from continued browsing, from scrolling the page, or from a pre-checked box. It must be collected on a per-purpose basis, with the user able to accept audience measurement without accepting targeted advertising.
In addition there is withdrawal of consent, which must be as easy as giving it initially and accessible at any time, which requires a permanent access point on the site.
Periods and retention
Two distinct periods are often confused.
The lifespan of trackers is capped in practice at thirteen months, with no automatic extension on each new visit. Information collected via these trackers is kept only for a limited period beyond that.
The validity period of consent is distinct: the user's choice, whether positive or negative, must be retained so as not to ask again on every visit. Recommended practice is to retain this choice for around six months, with a refusal not to be re-queried more frequently than an acceptance.
The controller must finally be able to prove that consent was validly obtained. This proof requires logging, for each user, the version of the banner displayed, the purposes presented and the choice expressed. Without this logging, the statement "we collect consent" cannot be demonstrated — the same evidentiary logic that governs acceptance of terms and conditions.
Shared responsibilities
A site that integrates third-party trackers — an advertising network, a social network, an analytics tool — is not thereby relieved of its responsibility. The publisher who decides to deploy a tracker determines its purpose and bears responsibility for it, even where the tracker belongs to a third party.
Two practical consequences follow. An up-to-date inventory of trackers actually deployed is essential, and it must be verified under real conditions rather than against providers' documentation: tags added by marketing tools frequently escape the declared inventory. And relationships with third parties must be governed by contract, identifying who is the data controller and who is the processor.
Sanctions and inspections
Failure to comply with tracker rules falls under a specific regime: it is sanctioned on the basis of the special text, which allows the national supervisory authority to act directly, without going through the European cooperation mechanism. This explains the speed and the amount of the decisions issued in this area.
Inspections focus primarily on three points that are objectively verifiable from the outside: trackers deposited before consent, asymmetry between accepting and refusing, and trackers persisting after a refusal. These three points can be checked within minutes using a browser's developer tools, which makes exposure constant.
Usage scenarios
Online store with advertising. Separate the purposes — operation, audience measurement, advertising — and allow distinct consent for each. Shopping cart trackers do not require consent, retargeting advertising trackers always do. This is a structuring point of the legal framework for an online store.
Showcase site with audience measurement. Check whether the chosen configuration meets the exemption conditions. If so, no banner is needed for this purpose; if not, consent is required as for any other tracker.
Site redesign. Carry out an inventory of trackers on the staging environment before going live, then redo it in production: tools added by marketing teams after launch are the most frequent source of discrepancy. This discipline mirrors the requirements described for secure payment standards.
Frequently asked questions
Do all cookies require consent? No. Those strictly necessary for a service expressly requested — cart, session, language preference — are exempt, as are those used solely to enable communication. The exemption is interpreted strictly.
Does continuing to browse count as consent? No. Consent must be unambiguous and result from a positive act. Neither scrolling, nor continued browsing, nor a pre-checked box is sufficient.
Must refusing be as simple as accepting? Yes. Both options must be presented at the same level, with equivalent effort. Relegating refusal behind a settings menu is a clear-cut violation.
How long should the user's choice be retained? The choice, whether positive or negative, is retained to avoid asking again on every visit — around six months in practice. This is distinct from the lifespan of trackers, capped at thirteen months.
Is audience measurement exempt? Only under strict cumulative conditions: purpose limited to measurement, no cross-referencing, no transmission to third parties, limited retention. Most consumer-grade solutions do not meet these conditions in their default configuration.
Who is responsible for third-party trackers? The site publisher, as soon as it decides on their deployment and purpose. Responsibility is not transferred to the tracker's provider.
Key takeaways
Three failings account for most sanctions, and all three can be detected from the outside within minutes: trackers deposited before any consent, a refusal that is more costly to express than an acceptance, and trackers that persist despite a refusal.
Two measures address this durably. An inventory of trackers verified under real conditions rather than from documentation, redone after every production release. And consent logging that records the version of the banner, the purposes presented and the choice expressed — without it, compliance is asserted but not demonstrable, which amounts to the same thing during an inspection.
Try Certyneo for free
Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.
Go deeper on the topic
Reference articles on this topic.
Certyneo Community
A question about electronic signatures?
Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.
Continue reading about Security
Deepen your knowledge with these related articles.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications from electronic signature service providers have become an essential selection criterion. Discover how to compare them effectively.

Electronic Signature: Traceability and Internal Audit in 2026
The traceability of an electronic signature has become a pillar of internal audit and legal compliance in business. Discover how to make the most of it.

Electronic Signature and ISO 27001 Standard: 2026 Guide
The ISO 27001 standard has become an essential benchmark for securing electronic signature processes in business. Discover key requirements, synergies with eIDAS, and best practices to adopt.