GDPR Marketing Compliance in France: Cookies and Consent Guide

Discover GDPR marketing compliance in France, covering cookie consent, email and SMS marketing, telephone prospecting, tracking pixels, retargeting, CNIL guidance, ePrivacy rules, lawful bases, and practical compliance strategies for businesses.

GDPR marketing France infographic showing a secure 3D data protection system with a central privacy shield, consent controls, cookies, email, messaging, analytics, legal compliance, and protected marketing channels.

GDPR marketing compliance in France requires more than adding a cookie banner or an unsubscribe link. Marketing teams need to understand how the GDPR interacts with ePrivacy rules, French legislation, CNIL guidance, and, for some channels, consumer-protection requirements.

The legal route depends on the activity. Advertising cookies may require prior consent before they operate. B2C email prospecting generally follows an opt-in model, while certain B2B communications can operate under an opt-out framework. Telephone prospecting to consumers changed significantly in August 2026, and new CNIL recommendations now address tracking pixels in emails and cross-device cookie consent.

Consent is therefore important, but it is not the answer to every marketing privacy question.

This guide explains how GDPR marketing rules apply in France across cookies, consent, email and SMS marketing, telephone prospecting, tracking pixels, retargeting, partner data and consent-management systems.

Which Privacy Rules Apply to Marketing in France?

Marketing privacy in France sits across several overlapping legal frameworks. Organisations should first identify what data is processed, which technology is used, who receives the marketing and which channel is involved.

GDPR

The GDPR, Regulation (EU) 2016/679 governs the processing of personal data.

For marketing teams, this can include CRM records, customer databases, advertising identifiers, behavioural profiles, contact details and other information linked to identifiable individuals.

Article 21 also gives individuals the right to object at any time to processing of their personal data for direct marketing purposes.

ePrivacy Rules

The ePrivacy Directive 2002/58/EC adds more specific rules for electronic communications and technologies that store information on, or access information from, a user's terminal equipment.

This is why GDPR analysis alone is not enough for activities such as cookies, tracking technologies and electronic prospecting.

French Article 82

France implements the terminal-access rules through Article 82 of the Loi Informatique et Libertés.

Article 82 is particularly important for cookies, pixels and other technologies that read or write information on a user's device.

CNIL

The Commission nationale de l'informatique et des libertés, or CNIL, interprets and enforces these requirements in France and publishes practical guidance for organisations.

The starting question should therefore not be simply:

"Do we have GDPR consent?"

A better sequence is:

What is the marketing activity? Which technology and channel are involved? Does ePrivacy or French law require prior consent? What GDPR lawful basis supports the related personal-data processing?

What Lawful Basis Applies to Marketing Under GDPR?

One of the most common marketing privacy mistakes is treating GDPR lawful basis and ePrivacy consent as the same question.

They are not.

An organization may need to determine both:

  1. which GDPR lawful basis supports the processing of personal data; and

  2. whether a separate ePrivacy or French-law rule requires prior consent for the channel or technology.

Consent

Consent can be an appropriate GDPR lawful basis for certain marketing activities.

Where an organization relies on consent, it must meet the GDPR standard. Consent must be freely given, specific, informed, and unambiguous, and based on a genuine affirmative choice.

The organisation must also be able to demonstrate that valid consent was obtained.

Legitimate Interests

Recital 47 of the GDPR recognizes that processing for direct marketing purposes may constitute a legitimate interest.

That does not create a general exemption from marketing privacy rules.

Where legitimate interests are used, the organization should assess the purpose, necessity of the processing, impact on individuals, and safeguards used to protect their interests and rights.

Individuals also retain the right to object to direct marketing.

Legitimate Interests Cannot Bypass Cookie Consent

This distinction is particularly important for digital advertising.

A company cannot avoid a separate requirement for prior tracker consent simply by selecting legitimate interests as the GDPR lawful basis for the personal data processing that follows.

If Article 82 requires consent before a non-exempt advertising tracker is deposited or read, that requirement remains relevant regardless of the GDPR lawful basis selected for a related processing operation.

GDPR marketing France infographic illustrating two legal tests for marketing activity: GDPR lawful basis and ePrivacy prior consent, with both checks required before activation.

Cookie Consent in France: When Is It Required?

Under the French framework, users generally need to consent before certain cookies and other trackers are deposited on or read from their devices.

The CNIL's guidance on cookies and trackers confirms that prior consent is the principle for trackers that do not qualify for an exemption.

Businesses should therefore classify trackers according to their actual purpose, configuration, and operation, rather than relying on the category assigned by a consent management platform or technology vendor.

Trackers Commonly Requiring Consent

Prior consent is generally relevant to technologies used for purposes such as:

  • targeted or personalized advertising;

  • cross-site tracking;

  • advertising-platform integrations;

  • social media advertising; and

  • other non-essential tracking activities.

Some audience-measurement tools also require consent, depending on their configuration and how the collected information is reused or shared.

No Non-Exempt Trackers Before Consent

A consent banner does not fix a tracker that has already fired.

Where consent is required, the relevant technology should remain inactive until the user has made a valid choice.

Marketing teams should test this technically rather than assuming that a CMP configuration is working as expected.

Which Cookies May Be Exempt from Consent?

Not every cookie or tracker requires prior consent.

Article 82 provides an exemption where an operation is strictly necessary for the provision of a service expressly requested by the user or has the exclusive purpose of enabling or facilitating electronic communication.

Depending on the circumstances, examples may include certain technologies used for:

  • authentication;

  • shopping baskets;

  • security;

  • load balancing; or

  • user-interface functions required to deliver the requested service.

The key word is necessary.

A tracker does not become necessary simply because the marketing department considers the resulting information commercially important.

Advertising attribution, behavioral profiling, and campaign optimization should not be classified as essential merely because the organization relies on them to measure performance.

Audience Measurement Requires Careful Assessment

The CNIL also recognizes that certain audience-measurement trackers may qualify for an exemption where strict conditions are met.

The exemption is not automatic.

For example, the tool should generally remain limited to audience measurement for the publisher, should not enable cross-site tracking, and should not involve inappropriate data combination or third-party reuse.

Organizations relying on an exemption should document why the particular configuration satisfies the relevant conditions.

Data Protection Officer (DPO) Training

Build Practical Expertise in GDPR and Data Protection

Strengthen your knowledge of GDPR compliance, DPO responsibilities, data protection governance, privacy risks, and practical compliance management.

 Explore DPO Training →

What Makes Cookie Consent Valid?

Displaying a banner is only the beginning.

Where consent is required, the user's choice must meet the GDPR standard.

Consent Requires an Affirmative Choice

Pre-ticked boxes, default acceptance and inactivity should not be treated as valid consent.

The user must take a positive action.

Statements such as "By continuing to browse, you accept our cookies" are not an adequate substitute for a valid consent mechanism.

Consent Must Be Specific and Informed

Users should understand the purposes for which trackers operate.

A banner should avoid vague statements such as "we use cookies to improve your experience," where that wording does not explain important activities such as advertising, personalization, or measurement.

Where several materially different purposes require consent, the interface should allow those purposes to be understood and, where appropriate, selected separately.

Refusing Should Be as Easy as Accepting

The CNIL expects refusal to be practically as easy as acceptance.

A prominent "Accept All" button should not be paired with a hidden or unnecessarily complex refusal route.

The first layer should normally give the user clear access to acceptance, refusal and more detailed settings.

Withdrawal Must Remain Accessible

Users should also be able to change their preferences later.

A persistent cookie setting or privacy link can help users reopen the consent interface and withdraw or modify a previous choice.

It should be as straightforward to withdraw consent as it was to provide it.

Consent Must Be Provable

The organization should retain enough information to demonstrate the context in which consent was obtained.

Depending on the system, this may include:

  • the date and time of the choice;

  • purposes presented to the user;

  • consent wording or interface version;

  • the user's choice; and

  • subsequent withdrawal or modification.

A generic field containing only "consent = yes" may not provide sufficient context.

Designing a CNIL-Compliant Cookie Banner

A consent management platform can support compliance, but installing one does not transfer responsibility away from the website operator.

Marketing, privacy, and technical teams should assess whether the interface and underlying tag behavior work together correctly.

First Layer

The first layer should communicate the main purposes of non-exempt tracking and provide an understandable choice.

Users should be able to accept, refuse, or access more detailed settings without unnecessary friction.

Second Layer

Where several distinct tracking purposes are used, a second layer can provide purpose-specific controls and additional information.

Possible categories may include advertising, personalization, and audience measurement.

Category names alone are not enough. Users should be able to understand what the trackers actually do.

Test the Technical Implementation

Compliance depends on behavior, not labels.

Test whether:

  • Advertising tags remain blocked before consent;

  • Refusal prevents the relevant trackers from operating;

  • Changes to preferences propagate through the tag manager;

  • withdrawal stops the affected processing; and

  • Newly added marketing technologies are incorporated into the consent framework.

GDPR and Email Marketing in France

GDPR marketing France infographic showing a five-step cookie consent flow: block tracking before choice, choose preferences, activate only permitted trackers, allow withdrawal, and retain evidence for compliance.

Email marketing rules depend significantly on the identity of the recipient and their relationship with the sender.

The CNIL's guidance on electronic commercial prospecting distinguishes between prospecting to consumers and professionals.

B2C Email Marketing

For electronic commercial prospecting sent to consumers, prior consent is generally required.

The organization should collect that consent before sending the marketing communication and retain appropriate evidence of the recipient's choice.

Existing Customer Exception

A limited exception can apply where an organization obtained the customer's contact details directly in connection with a previous sale and uses those details to promote its own similar products or services.

The conditions of the exception still matter.

The customer should have been given an opportunity to object when their details were collected and should receive a simple opportunity to object in each subsequent communication.

Being an existing customer does not automatically permit every form of marketing.

B2B Email Marketing

Professional prospecting can operate differently.

An opt-out model may apply where the communication is relevant to the recipient's professional activity and the other applicable requirements are satisfied.

The professional should still be informed about the use of their data and given a simple means of objecting.

Every Marketing Email Needs an Exit

Each marketing email should provide a visible and functional unsubscribe mechanism.

Operationally, the unsubscribe should propagate to the appropriate CRM, campaign management, and suppression systems.

Removing a person from one mailing list while continuing equivalent prospecting through another connected system can create compliance problems.

SMS, MMS, and Automated Marketing Communications

SMS, MMS, and automated calling technologies are also subject to electronic-prospecting rules.

For B2C commercial prospecting through these channels, prior consent is generally required.

Organizations should avoid storing a single generic "marketing consent" flag where several channels are involved.

A person who agrees to email marketing should not automatically be treated as having consented to:

  • SMS marketing;

  • advertising trackers;

  • automated calls; or

  • unrelated third-party prospecting.

Consent records should reflect the actual channel and purpose covered by the user's choice.

Consumer Telephone Marketing Changed on 11 August 2026

France introduced an important change to consumer telephone prospecting on 11 August 2026.

The CNIL's guidance on telephone prospecting states that businesses must now generally obtain prior consent before commercially prospecting individual consumers by telephone.

Prior Consent Is Now the General Starting Point

Under the new regime, consumers generally cannot be commercially cold-called unless they have provided prior consent.

An exception remains where the call concerns an ongoing contract, subject to the applicable statutory conditions.

Businesses should therefore be able to identify why each calling activity is permitted and retain evidence supporting that conclusion.

Do Not Assume the Old BLOCTEL Logic Is Sufficient

CRM and call-centre systems designed around the previous general opt-out environment should be reassessed.

Teams should review:

  • telephone consent fields;

  • lead-source evidence;

  • suppression rules;

  • call permissions;

  • external call-centre instructions; and

  • workflows for acquired or shared leads.

A historical record showing that a consumer did not opt out is not the same as evidence of prior consent under the new general regime.

The CNIL has also indicated that implementing texts are expected to provide further detail on the new framework. Organisations should therefore monitor official guidance as the regime is operationalised.

Marketing Rules by Channel

The correct compliance route depends on the channel, technology and recipient relationship.

Marketing activity

Core compliance question

Typical requirement

Advertising cookies

Can the tracker operate before a choice?

Prior consent generally required

Strictly necessary cookies

Is the tracker necessary for the requested service?

Consent may be exempt

B2C email

Has the consumer validly opted in?

Prior consent generally required, subject to limited exceptions

B2B email

Is the message relevant to the recipient's professional activity?

Opt-out framework may apply

B2C SMS

Has valid consent been obtained?

Prior consent generally required

Email tracking pixels

What does the pixel measure and does an exemption apply?

Case-specific Article 82 analysis

Consumer telephone marketing

Has the consumer previously consented?

Prior consent generally required since 11 August 2026

Retargeting

Which trackers and identifiers are used?

Tracker and GDPR requirements may both apply

This table should be used as a compliance orientation tool rather than a substitute for analysing the exact data flow.

The absence of an ePrivacy consent requirement does not automatically mean that the related processing falls outside the GDPR. Conversely, identifying a GDPR lawful basis does not eliminate a separate consent requirement applying to the technology or channel.

Tracking Pixels in Marketing Emails

On 14 April 2026, the CNIL published its final recommendation on tracking pixels in emails.

Tracking pixels are typically invisible technical elements embedded in emails. When the message is opened or displayed, the pixel can generate information about the recipient's interaction with the communication.

Depending on the implementation, this can reveal information such as:

  • whether the email was opened;

  • when it was opened;

  • device-related information; and

  • other data associated with engagement.

Assess the Purpose, Not Just the Technology

Not every use of a pixel presents the same compliance analysis.

A technology used for limited technical purposes may need to be assessed differently from one used for behavioral profiling, engagement scoring, or personalized marketing.

Marketing teams should therefore define each purpose before determining whether consent is required or whether an exemption may apply.

Existing Databases Need Attention

The CNIL's recommendation includes transitional considerations for certain email addresses collected before publication of the recommendation.

This makes it particularly important for organizations to distinguish between legacy databases and new collection processes rather than assuming one implementation can be applied universally.

Withdrawal and Evidence Must Work in Practice

Where consent is required, organizations should ensure that withdrawal prevents the relevant tracking from continuing.

Consent records, marketing-platform settings, and suppression mechanisms should match the way the pixel actually operates.

Cross-Device Cookie Consent

On 16 January 2026, the CNIL published final recommendations on multi-terminal or cross-device consent.

Cross-device consent arises where a user's tracker preference may apply across several devices associated with the same authenticated account.

For example, a user might make a cookie choice on a laptop that is subsequently applied to their smartphone or tablet.

Make the Scope of the Choice Clear

Users should understand whether their choice applies only to the current browser or across several devices.

A consent interface should not create the impression that a preference is device-specific if the organization intends to synchronize it across an authenticated account.

Preserve Genuine Choice

Cross-device functionality should not make acceptance, refusal, or withdrawal more difficult.

Users should retain meaningful control regardless of whether the preference applies locally or across multiple terminals.

Synchronize Withdrawal Consistently

If consent is presented as account-wide, withdrawal should operate consistently with that representation.

Marketing and product teams should therefore test both the user interface and the technical preference-synchronization process.

Retargeting, Social Advertising, and Customer-List Audiences

Digital advertising commonly combines cookies, advertising identifiers, customer data and third-party advertising platforms.

These campaigns may involve several distinct processing operations.

Retargeting

Retargeting typically involves monitoring behavior so that personalized advertising can be shown later.

Where cookies or equivalent trackers are used, prior consent may be required before the technology operates.

Associated personal data processing must also comply with the GDPR.

Compliance with the tracker rule does not automatically resolve the GDPR analysis, and vice versa.

Customer-List Advertising

Uploading customer identifiers to an advertising platform for matching or audience creation requires a separate privacy assessment.

The enforcement risk is real.

On 22 January 2026, the CNIL announced a €3.5 million sanction concerning the transfer of loyalty-programme member data to a social network for advertising targeting without valid consent.

This is an enforcement example rather than a rule that every customer-list advertising operation necessarily relies on the same lawful basis.

The correct assessment depends on the data flow, purpose, transparency arrangements, and applicable GDPR and ePrivacy requirements.

Map the Parties' Roles

Before activating a campaign, organizations should determine whether the advertiser, platform, and other intermediaries act as controllers, joint controllers, or processors for the relevant activities.

Those roles affect transparency, contracts, data-subject rights, and accountability.

Can Marketing Data Be Shared with Partners?

Sharing or purchasing prospect data does not automatically create permission to market to the individuals concerned.

The recipient still needs to determine whether the intended use is lawful and consistent with the circumstances in which the data was collected.

Transparency About Partners Matters

Privacy information should explain where data may be shared for commercial prospecting and provide meaningful information about the recipients or categories of recipients.

Generic wording such as "selected partners" may be difficult to defend where it does not enable individuals to understand the intended downstream marketing use.

B2C Partner Prospecting

Where a partner intends to carry out electronic B2C prospecting that requires consent, the consent framework should validly cover that downstream activity.

The organisation collecting the data should not treat the transfer itself as evidence that the partner has permission to prospect.

Purchased Lists Require Due Diligence

Before using an acquired marketing list, verify:

  • how the information was collected;

  • what individuals were told;

  • which consent or objection mechanism applied;

  • which recipients or categories of partners were disclosed; and

  • whether the planned campaign is compatible with those circumstances.

A vendor statement that a database is "GDPR compliant" is not enough by itself.

Marketing teams should retain documentation supporting the source and permitted use of acquired contact data before importing it into a CRM, advertising platform, or campaign-management system.

Consent Management and Evidence

Marketing privacy compliance does not end when the signup form or cookie banner goes live.

The organization needs systems capable of demonstrating what a person agreed to and reflecting later changes across connected technologies.

Maintain Meaningful Records

Depending on the context, records may include:

  • timestamp;

  • collection source;

  • relevant purpose;

  • marketing channel;

  • wording or consent-interface version; and

  • later withdrawal or modification.

The objective is to demonstrate the context of the choice rather than simply store a binary consent flag.

Avoid Unnecessary Identity Collection

Evidence should remain proportionate.

An organization should not create unnecessary identifying data solely to demonstrate cookie consent where less intrusive evidence would be sufficient.

Propagate Withdrawal

Where an activity depends on consent, withdrawal should stop that activity.

Suppression and preference changes may need to propagate through:

  • CRM systems;

  • email platforms;

  • SMS tools;

  • advertising platforms;

  • tag-management systems; and

  • other connected marketing technologies.

Version Consent Language

For marketing purposes, platforms and partners change.

Versioning consent language allows organizations to identify what the individual was told at a particular time and assess whether an expanded or materially changed purpose requires a new choice.

GDPR Marketing Compliance Flow

A practical marketing compliance process should begin before the campaign is activated.

GDPR marketing France decision flowchart showing how to assess personal data, apply GDPR and tracker rules, determine consent requirements, identify lawful processing, provide transparency, manage objections and withdrawal, record evidence, and monitor vendors and processors.

Common GDPR Marketing Compliance Mistakes

Several recurring mistakes expose organizations to avoidable risk.

Treating GDPR as the Only Marketing Rule

Better approach: Check GDPR alongside ePrivacy requirements, Article 82, CNIL guidance, and applicable consumer law.

Firing Advertising Tags Before the User Chooses

Better approach: Keep non-exempt advertising and tracking technologies inactive until valid consent has been recorded.

Making Cookie Rejection Harder Than Acceptance

Better approach: Give users equally practical access to acceptance and refusal.

Using Legitimate Interests to Bypass Tracker Consent

Better approach: Analyze GDPR lawful basis and Article 82 consent requirements separately.

Treating B2B and B2C Marketing as Identical

Better approach: Identify the recipient, channel, and context before deciding which prospecting rule applies.

Ignoring Email Tracking Pixels

Better approach: Include pixels in the marketing technology inventory and assess their purpose, legal treatment, and withdrawal controls.

Trusting Purchased Lists Without Evidence

Better approach: verify the source, transparency information, and permissions before using the data.

Keeping Legacy Telephone Permissions

Better approach: update CRM and calling workflows to reflect the consumer opt-in regime effective from 11 August 2026.

Strengthen Data Protection Governance

Turn Marketing Privacy Rules Into Stronger Data Governance

Marketing compliance requires more than adding a cookie banner or unsubscribe link. Organisations need people who can distinguish GDPR lawful bases from ePrivacy consent requirements, evaluate new tracking technologies and coordinate privacy controls across marketing, IT and compliance teams.

The French Compliance Institute's Data Protection Officer (DPO) Training helps professionals develop practical knowledge of GDPR governance, data-protection responsibilities, and privacy risk management.

These capabilities can support organizations managing marketing data, consent systems, advertising technologies, third-party platforms, and wider GDPR compliance.

Conclusion

GDPR marketing compliance in France requires organizations to look beyond a cookie banner and understand how GDPR interacts with ePrivacy rules, French legislation, and CNIL guidance.

The marketing channel matters. Advertising trackers, B2C email, B2B prospecting, tracking pixels, partner marketing, and telephone calls do not all follow the same compliance route. Each activity should be assessed according to its purpose, technology, recipient, and legal framework.

The regulatory environment is also evolving. In 2026, the CNIL finalized recommendations on cross-device consent and email tracking pixels, while France moved consumer telephone prospecting to a prior-consent regime from 11 August 2026.

Marketing teams that connect consent, technology governance, channel-specific rules, and reliable evidence will be better positioned to run effective campaigns without sacrificing data protection compliance.

Frequently Asked Questions

No. The rule depends on the processing activity, technology and marketing channel. Some forms of electronic consumer prospecting and tracking require prior consent, while other activities may use another GDPR lawful basis or operate under an opt-out framework.

No. Certain trackers that are strictly necessary to provide a service expressly requested by the user can qualify for an exemption. Advertising trackers and many other non-essential technologies generally require prior consent.

Potentially. Certain audience-measurement trackers may qualify for a CNIL exemption where their purpose and configuration meet strict conditions. Analytics tools should therefore be assessed individually rather than automatically classified as essential.

Not where Article 82 requires prior consent for the tracker. Legitimate interests may be relevant to the GDPR processing analysis, but they do not override a separate French or ePrivacy requirement for consent before a non-exempt tracker is deposited or read.

It depends on the recipient. B2C electronic prospecting generally requires prior consent, subject to limited exceptions such as certain marketing to existing customers. B2B prospecting may operate under an opt-out framework where the communication relates to the recipient's professional activity.

Since 11 August 2026, prior consent is generally required before commercially prospecting consumers by telephone. An exception remains for certain calls concerning an ongoing contract, subject to the applicable legal conditions.

It depends on the purpose and implementation. The CNIL's April 2026 recommendation sets out circumstances in which consent may be required and where limited exemptions may potentially apply. Organisations should assess each use rather than treating all pixels alike.

Yes. Where processing depends on consent, individuals must be able to withdraw it. The withdrawal should be effective in practice and should stop the relevant activity across connected marketing systems.