Key Takeaways
- CNIL, France's data protection authority, published cookie guidelines that went through a real legal fight: its original 2019 guidelines banned cookie walls outright, but France's highest administrative court partially struck that ban down in June 2020. Cookie walls are legal today, assessed case by case, not banned.
- Rejecting cookies has to be exactly as easy as accepting them. CNIL fined Google €150 million and Facebook €60 million on December 31, 2021, specifically because accepting took one click while rejecting took several.
- A narrow list of cookies, including shopping carts, authentication, and load balancing, is exempt from consent as strictly necessary. Analytics cookies can also skip consent, but only if they stay anonymous, aggregated, and unlinked to other identifying data.
- Consent choices have to be kept for at least 6 months, so a returning visitor isn't re-prompted every session.
CNIL, the French national data protection authority, enforces its own cookie guidelines alongside GDPR and the ePrivacy Directive, and the specifics diverge from a generic GDPR cookie-banner setup in a few concrete ways. Below: what CNIL actually requires, the real legal history behind its cookie-wall position, and the fines that show what enforcement looks like in practice.
Secure Privacy is a cookie and consent management platform that generates CNIL- and GDPR-compliant consent banners alongside CCPA, LGPD, and 55+ other privacy laws.
What Is CNIL, and What Does It Enforce?
CNIL (Commission Nationale de l'Informatique et des Libertés) is France's independent data protection authority, established by the French Data Protection Act of January 6, 1978, originally in response to public opposition to a government program that would have assigned every French citizen a unique identifier linking their government records together. CNIL enforces the French Data Protection Act itself, GDPR, and the ePrivacy Directive, and can investigate complaints and issue fines for violations of any of them.
CNIL cookie guidelines apply to your business if it's based in France or French overseas territories, or if it collects or processes personal data of French residents, the same territorial-scope logic GDPR uses generally.
Are Cookie Walls Legal Under CNIL's Guidelines?
Yes, with real conditions, and this is worth getting precisely right because CNIL's own position changed. CNIL's original 2019 guidelines imposed an absolute ban on cookie walls, mechanisms that block access to a site's content unless the visitor accepts cookies. France's Conseil d'État, the country's highest administrative court, partially struck that ban down in June 2020, specifically the blanket-prohibition provision, and CNIL revised its guidelines that October to reflect the ruling.
The current position: cookie walls aren't automatically banned, but their legality has to be assessed case by case. If you use one, you have to clearly disclose to the visitor what happens if they decline, specifically, that they won't be able to access the content or service without consenting. CNIL published further evaluation criteria in May 2022, requiring that a visitor who declines be offered a real and satisfactory alternative, not a token one, before a cookie wall can be considered compliant. Any source still describing CNIL as banning cookie walls outright is working from the pre-2020 guidelines, not the law as it actually stands today.
How Does CNIL Handle Consent Rejection and Withdrawal?
Users have to be able to refuse cookies exactly as easily as they accept them, and inaction or scrolling can't be treated as consent. This isn't a soft guideline: CNIL fined Google €150 million and Facebook €60 million on December 31, 2021, specifically because both companies let visitors accept cookies in one click while requiring several clicks to reject them. Criteo, a separate ad-tech company, was fined €40 million for related GDPR violations.
Consent withdrawal has to be just as simple as giving it. A banner that makes accepting easy but buries the withdrawal option in a multi-step preference center doesn't meet CNIL's standard, even if the initial consent flow looked compliant.
Which Cookies Are Exempt From Consent?
A specific, narrow list of cookies doesn't require consent because they're considered strictly necessary for the site to function or to deliver a service the visitor actually requested: cookies that store a visitor's own cookie preferences, authentication cookies (including fraud-prevention measures like limiting bot login attempts), shopping-cart cookies, interface-customization cookies like language selection, load-balancing cookies, and cookies that let a paying site limit free access to sample content.
Beyond the strictly-necessary exemption, CNIL groups cookies into the same broad purposes GDPR guidance generally uses: necessary, statistics, preferences, and marketing. Necessary cookies are the exempt list above; statistics, preferences, and marketing cookies all require consent unless a cookie in the statistics category separately qualifies for the analytics exemption below.
Analytics cookies get a narrower, conditional exemption. CNIL treats them as necessary for legitimate site-performance measurement, but only if they generate anonymous or aggregated statistics and aren't combined with other data or used to identify individual visitors. Google Analytics specifically doesn't qualify for this exemption under CNIL's guidance, since its standard configuration doesn't meet that anonymity bar.
How Long Can Cookies Actually Stay on a Visitor's Device?
CNIL caps the cookie itself, separately from how long you keep a record of someone's consent choice. A cookie's own lifespan can't exceed 13 months from when it's set, after which it has to expire or be reset, not silently renewed. Data collected through analytics cookies is capped separately: it can't be kept in an identifiable form for longer than 25 months. These are different limits from the 6-month consent-retention rule below, one caps the cookie's life, the other caps how long you hold the resulting data, and a compliant setup has to respect all three windows at once.
What Does a CNIL-Compliant Cookie Banner Actually Need?
The banner has to state the purpose of each cookie or cookie category before the visitor makes a choice, with "Accept All" and "Reject All" given equal visual prominence, not one styled as a bold call-to-action and the other as fine print. No pre-ticked boxes or pre-activated toggles are allowed; if a visitor takes no action, none of the optional cookies should load. Consent has to be collected per category, typically through a "customize" or "preferences" option, and the banner needs a link to a fuller policy page covering the actual controllers, processors, and third parties involved.
Once collected, a consent choice, whether accepted or rejected, has to be kept for at least 6 months so returning visitors aren't re-prompted on every visit.
Compliance Checklist
- Create a cookie banner that requests consent before any non-essential cookie loads.
- Give "Accept All" and "Reject All" equal prominence, with no dark-pattern styling favoring one.
- Skip pre-ticked boxes; if the visitor takes no action, non-essential cookies stay blocked.
- Offer a granular "customize" option so visitors can consent per category, not just all-or-nothing.
- If using a cookie wall, clearly disclose the consequence of declining before the visitor decides.
- Exempt only the strictly-necessary categories CNIL actually lists, and scope analytics-cookie exemptions to genuinely anonymous, aggregated data.
- Store consent choices for at least 6 months.
- Keep real-time, exportable consent logs in case CNIL requests them during an investigation.
A consent management platform that already ships CNIL's specific requirements, equal-prominence buttons, per-category consent, and 6-month consent retention, closes most of this checklist automatically rather than needing each rule implemented by hand. Secure Privacy's banners are built to this standard alongside GDPR and 55+ other frameworks, so a CNIL-specific rebuild isn't a separate project.
FAQ
Does CNIL ban cookie walls?
No, not outright. CNIL's original 2019 guidelines banned them, but France's Conseil d'État partially struck that ban down in June 2020. Cookie walls are legal today if their use is disclosed clearly and their legality holds up case by case.
What's the biggest CNIL cookie fine issued so far?
Google's €150 million fine, issued December 31, 2021, alongside a €60 million fine against Facebook, both over cookie-rejection mechanisms that required more clicks than acceptance did.
Are analytics cookies exempt from CNIL's consent requirement?
Only if they produce anonymous, aggregated statistics and aren't combined with other data to identify individual visitors. Google Analytics's standard configuration doesn't meet that bar under CNIL's guidance.
How long do I have to keep a record of a visitor's cookie consent choice?
At least 6 months, whether the visitor accepted or rejected cookies, so they aren't re-prompted on every return visit within that window.
Do "Accept All" and "Reject All" really need to look the same?
Yes. CNIL's guidelines require equal visual prominence for both options. Styling one as a prominent button and the other as a small text link is exactly the pattern that drew CNIL's €150 million fine against Google.
