GDPR Marketing Compliance in France: Cookies and Consent Guide
Discover GDPR marketing compliance in France, covering cookie consent, email and SMS marketing, telephone prospecting, tracking pixels, retargeting, CNIL guidance, ePrivacy rules, lawful bases, and practical compliance strategies for businesses.
GDPR marketing compliance in France requires more than adding a cookie banner or an unsubscribe link. Marketing teams need to understand how the GDPR interacts with ePrivacy rules, French legislation, CNIL guidance, and, for some channels, consumer-protection requirements.
The legal route depends on the activity. Advertising cookies may require prior consent before they operate. B2C email prospecting generally follows an opt-in model, while certain B2B communications can operate under an opt-out framework. Telephone prospecting to consumers changed significantly in August 2026, and new CNIL recommendations now address tracking pixels in emails and cross-device cookie consent.
Consent is therefore important, but it is not the answer to every marketing privacy question.
This guide explains how GDPR marketing rules apply in France across cookies, consent, email and SMS marketing, telephone prospecting, tracking pixels, retargeting, partner data and consent-management systems.
Which Privacy Rules Apply to Marketing in France?
Marketing privacy in France sits across several overlapping legal frameworks. Organisations should first identify what data is processed, which technology is used, who receives the marketing and which channel is involved.
For marketing teams, this can include CRM records, customer databases, advertising identifiers, behavioural profiles, contact details and other information linked to identifiable individuals.
Article 21 also gives individuals the right to object at any time to processing of their personal data for direct marketing purposes.
ePrivacy Rules
TheePrivacy Directive 2002/58/EC adds more specific rules for electronic communications and technologies that store information on, or access information from, a user's terminal equipment.
This is why GDPR analysis alone is not enough for activities such as cookies, tracking technologies and electronic prospecting.
Article 82 is particularly important for cookies, pixels and other technologies that read or write information on a user's device.
CNIL
The Commission nationale de l'informatique et des libertés, or CNIL, interprets and enforces these requirements in France and publishes practical guidance for organisations.
The starting question should therefore not be simply:
"Do we have GDPR consent?"
A better sequence is:
What is the marketing activity? Which technology and channel are involved? Does ePrivacy or French law require prior consent? What GDPR lawful basis supports the related personal-data processing?
What Lawful Basis Applies to Marketing Under GDPR?
One of the most common marketing privacy mistakes is treating GDPR lawful basis and ePrivacy consent as the same question.
They are not.
An organization may need to determine both:
which GDPR lawful basis supports the processing of personal data; and
whether a separate ePrivacy or French-law rule requires prior consent for the channel or technology.
Consent
Consent can be an appropriate GDPR lawful basis for certain marketing activities.
Where an organization relies on consent, it must meet the GDPR standard. Consent must be freely given, specific, informed, and unambiguous, and based on a genuine affirmative choice.
The organisation must also be able to demonstrate that valid consent was obtained.
Legitimate Interests
Recital 47 of the GDPR recognizes that processing for direct marketing purposes may constitute a legitimate interest.
That does not create a general exemption from marketing privacy rules.
Where legitimate interests are used, the organization should assess the purpose, necessity of the processing, impact on individuals, and safeguards used to protect their interests and rights.
Individuals also retain the right to object to direct marketing.
Legitimate Interests Cannot Bypass Cookie Consent
This distinction is particularly important for digital advertising.
A company cannot avoid a separate requirement for prior tracker consent simply by selecting legitimate interests as the GDPR lawful basis for the personal data processing that follows.
If Article 82 requires consent before a non-exempt advertising tracker is deposited or read, that requirement remains relevant regardless of the GDPR lawful basis selected for a related processing operation.
Cookie Consent in France: When Is It Required?
Under the French framework, users generally need to consent before certain cookies and other trackers are deposited on or read from their devices.
The CNIL'sguidance on cookies and trackers confirms that prior consent is the principle for trackers that do not qualify for an exemption.
Businesses should therefore classify trackers according to their actual purpose, configuration, and operation, rather than relying on the category assigned by a consent management platform or technology vendor.
Trackers Commonly Requiring Consent
Prior consent is generally relevant to technologies used for purposes such as:
targeted or personalized advertising;
cross-site tracking;
advertising-platform integrations;
social media advertising; and
other non-essential tracking activities.
Some audience-measurement tools also require consent, depending on their configuration and how the collected information is reused or shared.
No Non-Exempt Trackers Before Consent
A consent banner does not fix a tracker that has already fired.
Where consent is required, the relevant technology should remain inactive until the user has made a valid choice.
Marketing teams should test this technically rather than assuming that a CMP configuration is working as expected.
Which Cookies May Be Exempt from Consent?
Not every cookie or tracker requires prior consent.
Article 82 provides an exemption where an operation is strictly necessary for the provision of a service expressly requested by the user or has the exclusive purpose of enabling or facilitating electronic communication.
Depending on the circumstances, examples may include certain technologies used for:
authentication;
shopping baskets;
security;
load balancing; or
user-interface functions required to deliver the requested service.
The key word is necessary.
A tracker does not become necessary simply because the marketing department considers the resulting information commercially important.
Advertising attribution, behavioral profiling, and campaign optimization should not be classified as essential merely because the organization relies on them to measure performance.
Audience Measurement Requires Careful Assessment
The CNIL also recognizes that certain audience-measurement trackers may qualify for an exemption where strict conditions are met.
The exemption is not automatic.
For example, the tool should generally remain limited to audience measurement for the publisher, should not enable cross-site tracking, and should not involve inappropriate data combination or third-party reuse.
Organizations relying on an exemption should document why the particular configuration satisfies the relevant conditions.
Data Protection Officer (DPO) Training
Build Practical Expertise in GDPR and Data Protection
Strengthen your knowledge of GDPR compliance, DPO responsibilities, data protection governance, privacy risks, and practical compliance management.
Where consent is required, the user's choice must meet the GDPR standard.
Consent Requires an Affirmative Choice
Pre-ticked boxes, default acceptance and inactivity should not be treated as valid consent.
The user must take a positive action.
Statements such as "By continuing to browse, you accept our cookies" are not an adequate substitute for a valid consent mechanism.
Consent Must Be Specific and Informed
Users should understand the purposes for which trackers operate.
A banner should avoid vague statements such as "we use cookies to improve your experience," where that wording does not explain important activities such as advertising, personalization, or measurement.
Where several materially different purposes require consent, the interface should allow those purposes to be understood and, where appropriate, selected separately.
Refusing Should Be as Easy as Accepting
The CNIL expects refusal to be practically as easy as acceptance.
A prominent "Accept All" button should not be paired with a hidden or unnecessarily complex refusal route.
The first layer should normally give the user clear access to acceptance, refusal and more detailed settings.
Withdrawal Must Remain Accessible
Users should also be able to change their preferences later.
A persistent cookie setting or privacy link can help users reopen the consent interface and withdraw or modify a previous choice.
It should be as straightforward to withdraw consent as it was to provide it.
Consent Must Be Provable
The organization should retain enough information to demonstrate the context in which consent was obtained.
Depending on the system, this may include:
the date and time of the choice;
purposes presented to the user;
consent wording or interface version;
the user's choice; and
subsequent withdrawal or modification.
A generic field containing only "consent = yes" may not provide sufficient context.
Designing a CNIL-Compliant Cookie Banner
A consent management platform can support compliance, but installing one does not transfer responsibility away from the website operator.
Marketing, privacy, and technical teams should assess whether the interface and underlying tag behavior work together correctly.
First Layer
The first layer should communicate the main purposes of non-exempt tracking and provide an understandable choice.
Users should be able to accept, refuse, or access more detailed settings without unnecessary friction.
Second Layer
Where several distinct tracking purposes are used, a second layer can provide purpose-specific controls and additional information.
Possible categories may include advertising, personalization, and audience measurement.
Category names alone are not enough. Users should be able to understand what the trackers actually do.
Test the Technical Implementation
Compliance depends on behavior, not labels.
Test whether:
Advertising tags remain blocked before consent;
Refusal prevents the relevant trackers from operating;
Changes to preferences propagate through the tag manager;
withdrawal stops the affected processing; and
Newly added marketing technologies are incorporated into the consent framework.
GDPR and Email Marketing in France
Email marketing rules depend significantly on the identity of the recipient and their relationship with the sender.
For electronic commercial prospecting sent to consumers, prior consent is generally required.
The organization should collect that consent before sending the marketing communication and retain appropriate evidence of the recipient's choice.
Existing Customer Exception
A limited exception can apply where an organization obtained the customer's contact details directly in connection with a previous sale and uses those details to promote its own similar products or services.
The conditions of the exception still matter.
The customer should have been given an opportunity to object when their details were collected and should receive a simple opportunity to object in each subsequent communication.
Being an existing customer does not automatically permit every form of marketing.
B2B Email Marketing
Professional prospecting can operate differently.
An opt-out model may apply where the communication is relevant to the recipient's professional activity and the other applicable requirements are satisfied.
The professional should still be informed about the use of their data and given a simple means of objecting.
Every Marketing Email Needs an Exit
Each marketing email should provide a visible and functional unsubscribe mechanism.
Operationally, the unsubscribe should propagate to the appropriate CRM, campaign management, and suppression systems.
Removing a person from one mailing list while continuing equivalent prospecting through another connected system can create compliance problems.
SMS, MMS, and Automated Marketing Communications
SMS, MMS, and automated calling technologies are also subject to electronic-prospecting rules.
For B2C commercial prospecting through these channels, prior consent is generally required.
Organizations should avoid storing a single generic "marketing consent" flag where several channels are involved.
A person who agrees to email marketing should not automatically be treated as having consented to:
SMS marketing;
advertising trackers;
automated calls; or
unrelated third-party prospecting.
Consent records should reflect the actual channel and purpose covered by the user's choice.
Consumer Telephone Marketing Changed on 11 August 2026
France introduced an important change to consumer telephone prospecting on 11 August 2026.
TheCNIL's guidance on telephone prospecting states that businesses must now generally obtain prior consent before commercially prospecting individual consumers by telephone.
Prior Consent Is Now the General Starting Point
Under the new regime, consumers generally cannot be commercially cold-called unless they have provided prior consent.
An exception remains where the call concerns an ongoing contract, subject to the applicable statutory conditions.
Businesses should therefore be able to identify why each calling activity is permitted and retain evidence supporting that conclusion.
Do Not Assume the Old BLOCTEL Logic Is Sufficient
CRM and call-centre systems designed around the previous general opt-out environment should be reassessed.
Teams should review:
telephone consent fields;
lead-source evidence;
suppression rules;
call permissions;
external call-centre instructions; and
workflows for acquired or shared leads.
A historical record showing that a consumer did not opt out is not the same as evidence of prior consent under the new general regime.
The CNIL has also indicated that implementing texts are expected to provide further detail on the new framework. Organisations should therefore monitor official guidance as the regime is operationalised.
Marketing Rules by Channel
The correct compliance route depends on the channel, technology and recipient relationship.
Marketing activity
Core compliance question
Typical requirement
Advertising cookies
Can the tracker operate before a choice?
Prior consent generally required
Strictly necessary cookies
Is the tracker necessary for the requested service?
Consent may be exempt
B2C email
Has the consumer validly opted in?
Prior consent generally required, subject to limited exceptions
B2B email
Is the message relevant to the recipient's professional activity?
Opt-out framework may apply
B2C SMS
Has valid consent been obtained?
Prior consent generally required
Email tracking pixels
What does the pixel measure and does an exemption apply?
Case-specific Article 82 analysis
Consumer telephone marketing
Has the consumer previously consented?
Prior consent generally required since 11 August 2026
Retargeting
Which trackers and identifiers are used?
Tracker and GDPR requirements may both apply
This table should be used as a compliance orientation tool rather than a substitute for analysing the exact data flow.
The absence of an ePrivacy consent requirement does not automatically mean that the related processing falls outside the GDPR. Conversely, identifying a GDPR lawful basis does not eliminate a separate consent requirement applying to the technology or channel.
Tracking pixels are typically invisible technical elements embedded in emails. When the message is opened or displayed, the pixel can generate information about the recipient's interaction with the communication.
Depending on the implementation, this can reveal information such as:
whether the email was opened;
when it was opened;
device-related information; and
other data associated with engagement.
Assess the Purpose, Not Just the Technology
Not every use of a pixel presents the same compliance analysis.
A technology used for limited technical purposes may need to be assessed differently from one used for behavioral profiling, engagement scoring, or personalized marketing.
Marketing teams should therefore define each purpose before determining whether consent is required or whether an exemption may apply.
Existing Databases Need Attention
The CNIL's recommendation includes transitional considerations for certain email addresses collected before publication of the recommendation.
This makes it particularly important for organizations to distinguish between legacy databases and new collection processes rather than assuming one implementation can be applied universally.
Withdrawal and Evidence Must Work in Practice
Where consent is required, organizations should ensure that withdrawal prevents the relevant tracking from continuing.
Consent records, marketing-platform settings, and suppression mechanisms should match the way the pixel actually operates.
Cross-device consent arises where a user's tracker preference may apply across several devices associated with the same authenticated account.
For example, a user might make a cookie choice on a laptop that is subsequently applied to their smartphone or tablet.
Make the Scope of the Choice Clear
Users should understand whether their choice applies only to the current browser or across several devices.
A consent interface should not create the impression that a preference is device-specific if the organization intends to synchronize it across an authenticated account.
Preserve Genuine Choice
Cross-device functionality should not make acceptance, refusal, or withdrawal more difficult.
Users should retain meaningful control regardless of whether the preference applies locally or across multiple terminals.
Synchronize Withdrawal Consistently
If consent is presented as account-wide, withdrawal should operate consistently with that representation.
Marketing and product teams should therefore test both the user interface and the technical preference-synchronization process.
Retargeting, Social Advertising, and Customer-List Audiences
Digital advertising commonly combines cookies, advertising identifiers, customer data and third-party advertising platforms.
These campaigns may involve several distinct processing operations.
Retargeting
Retargeting typically involves monitoring behavior so that personalized advertising can be shown later.
Where cookies or equivalent trackers are used, prior consent may be required before the technology operates.
Associated personal data processing must also comply with the GDPR.
Compliance with the tracker rule does not automatically resolve the GDPR analysis, and vice versa.
Customer-List Advertising
Uploading customer identifiers to an advertising platform for matching or audience creation requires a separate privacy assessment.
The enforcement risk is real.
On 22 January 2026, the CNIL announced a €3.5 million sanction concerning the transfer of loyalty-programme member data to a social network for advertising targeting without valid consent.
This is an enforcement example rather than a rule that every customer-list advertising operation necessarily relies on the same lawful basis.
The correct assessment depends on the data flow, purpose, transparency arrangements, and applicable GDPR and ePrivacy requirements.
Map the Parties' Roles
Before activating a campaign, organizations should determine whether the advertiser, platform, and other intermediaries act as controllers, joint controllers, or processors for the relevant activities.
Those roles affect transparency, contracts, data-subject rights, and accountability.
Can Marketing Data Be Shared with Partners?
Sharing or purchasing prospect data does not automatically create permission to market to the individuals concerned.
The recipient still needs to determine whether the intended use is lawful and consistent with the circumstances in which the data was collected.
Transparency About Partners Matters
Privacy information should explain where data may be shared for commercial prospecting and provide meaningful information about the recipients or categories of recipients.
Generic wording such as "selected partners" may be difficult to defend where it does not enable individuals to understand the intended downstream marketing use.
B2C Partner Prospecting
Where a partner intends to carry out electronic B2C prospecting that requires consent, the consent framework should validly cover that downstream activity.
The organisation collecting the data should not treat the transfer itself as evidence that the partner has permission to prospect.
Purchased Lists Require Due Diligence
Before using an acquired marketing list, verify:
how the information was collected;
what individuals were told;
which consent or objection mechanism applied;
which recipients or categories of partners were disclosed; and
whether the planned campaign is compatible with those circumstances.
A vendor statement that a database is "GDPR compliant" is not enough by itself.
Marketing teams should retain documentation supporting the source and permitted use of acquired contact data before importing it into a CRM, advertising platform, or campaign-management system.
Consent Management and Evidence
Marketing privacy compliance does not end when the signup form or cookie banner goes live.
The organization needs systems capable of demonstrating what a person agreed to and reflecting later changes across connected technologies.
Maintain Meaningful Records
Depending on the context, records may include:
timestamp;
collection source;
relevant purpose;
marketing channel;
wording or consent-interface version; and
later withdrawal or modification.
The objective is to demonstrate the context of the choice rather than simply store a binary consent flag.
Avoid Unnecessary Identity Collection
Evidence should remain proportionate.
An organization should not create unnecessary identifying data solely to demonstrate cookie consent where less intrusive evidence would be sufficient.
Propagate Withdrawal
Where an activity depends on consent, withdrawal should stop that activity.
Suppression and preference changes may need to propagate through:
CRM systems;
email platforms;
SMS tools;
advertising platforms;
tag-management systems; and
other connected marketing technologies.
Version Consent Language
For marketing purposes, platforms and partners change.
Versioning consent language allows organizations to identify what the individual was told at a particular time and assess whether an expanded or materially changed purpose requires a new choice.
GDPR Marketing Compliance Flow
A practical marketing compliance process should begin before the campaign is activated.
Common GDPR Marketing Compliance Mistakes
Several recurring mistakes expose organizations to avoidable risk.
Better approach: Identify the recipient, channel, and context before deciding which prospecting rule applies.
Ignoring Email Tracking Pixels
Better approach: Include pixels in the marketing technology inventory and assess their purpose, legal treatment, and withdrawal controls.
Trusting Purchased Lists Without Evidence
Better approach: verify the source, transparency information, and permissions before using the data.
Keeping Legacy Telephone Permissions
Better approach: update CRM and calling workflows to reflect the consumer opt-in regime effective from 11 August 2026.
Strengthen Data Protection Governance
Turn Marketing Privacy Rules Into Stronger Data Governance
Marketing compliance requires more than adding a cookie banner or unsubscribe link. Organisations need people who can distinguish GDPR lawful bases from ePrivacy consent requirements, evaluate new tracking technologies and coordinate privacy controls across marketing, IT and compliance teams.
The French Compliance Institute'sData Protection Officer (DPO) Training helps professionals develop practical knowledge of GDPR governance, data-protection responsibilities, and privacy risk management.
These capabilities can support organizations managing marketing data, consent systems, advertising technologies, third-party platforms, and wider GDPR compliance.
Conclusion
GDPR marketing compliance in France requires organizations to look beyond a cookie banner and understand how GDPR interacts with ePrivacy rules, French legislation, and CNIL guidance.
The marketing channel matters. Advertising trackers, B2C email, B2B prospecting, tracking pixels, partner marketing, and telephone calls do not all follow the same compliance route. Each activity should be assessed according to its purpose, technology, recipient, and legal framework.
The regulatory environment is also evolving. In 2026, the CNIL finalized recommendations on cross-device consent and email tracking pixels, while France moved consumer telephone prospecting to a prior-consent regime from 11 August 2026.
Marketing teams that connect consent, technology governance, channel-specific rules, and reliable evidence will be better positioned to run effective campaigns without sacrificing data protection compliance.
Frequently Asked Questions
No. The rule depends on the processing activity, technology and marketing channel. Some forms of electronic consumer prospecting and tracking require prior consent, while other activities may use another GDPR lawful basis or operate under an opt-out framework.
No. Certain trackers that are strictly necessary to provide a service expressly requested by the user can qualify for an exemption. Advertising trackers and many other non-essential technologies generally require prior consent.
Potentially. Certain audience-measurement trackers may qualify for a CNIL exemption where their purpose and configuration meet strict conditions. Analytics tools should therefore be assessed individually rather than automatically classified as essential.
Not where Article 82 requires prior consent for the tracker. Legitimate interests may be relevant to the GDPR processing analysis, but they do not override a separate French or ePrivacy requirement for consent before a non-exempt tracker is deposited or read.
It depends on the recipient. B2C electronic prospecting generally requires prior consent, subject to limited exceptions such as certain marketing to existing customers. B2B prospecting may operate under an opt-out framework where the communication relates to the recipient's professional activity.
Since 11 August 2026, prior consent is generally required before commercially prospecting consumers by telephone. An exception remains for certain calls concerning an ongoing contract, subject to the applicable legal conditions.
It depends on the purpose and implementation. The CNIL's April 2026 recommendation sets out circumstances in which consent may be required and where limited exemptions may potentially apply. Organisations should assess each use rather than treating all pixels alike.
Yes. Where processing depends on consent, individuals must be able to withdraw it. The withdrawal should be effective in practice and should stop the relevant activity across connected marketing systems.
Explore CSRD France requirements, scope, ESRS, double materiality, reporting, assurance, and 2026 reforms. Discover a practical roadmap for French companies to strengthen ESG compliance, governance,...
Learn what an AI compliance officer does, including EU AI Act compliance, AI governance, risk management, GDPR alignment, vendor oversight, AI literacy, and the skills...
Choosing a selection results in a full page refresh.