Cookies and trackers on a French training organisation's website: what the CNIL actually requires
An up-to-date enrolment form, complete legal notices, a well-drafted privacy policy — and, somewhere under the hood of the website, an analytics tool or an embedded YouTube video quietly dropping cookies with no banner in sight. This is one of the most common blind spots among training organisations that have carefully handled their Qualiopi and “operational” GDPR compliance without ever looking at the technical layer of their own showcase website. Here is what the CNIL actually requires, and how to check your situation without spending days on it.
The principle: consent before any tracker is dropped
The obligation stems from Article 82 of the French Data Protection Act (loi Informatique et Libertés), which transposes the European “ePrivacy” directive into French law. This text requires obtaining the internet user’s consent before any operation to write or read information on their device — a cookie, a tracking pixel, an identifier stored in local storage — except for limited exceptions.
Simply continuing to browse a website no longer counts as a valid expression of consent, under the CNIL’s guidelines. A clear, positive action is required: clicking “Accept”, ticking a box, toggling a switch. A pre-checked box or a banner that disappears at the first click anywhere on the page is not enough.
What falls outside the consent requirement
Not all cookies are covered. The CNIL allows for several exemptions, to be read narrowly:
- Cookies strictly necessary to deliver a service explicitly requested by the user: remembering the contents of a shopping cart before payment, authenticating a learner’s session, technical load balancing on the server.
- Certain audience-measurement tools that meet a precise framework: purpose strictly limited to producing anonymised statistics for the site itself, no cross-referencing with other databases or transmission to third parties, clear information for the user, and an easy way to opt out.
Outside these two cases, an advertising tracking tool, a video embedded from a third-party platform, a live chat provided by an external vendor, or even a simple social-media counter all require prior consent, collected before the tracker is dropped — meaning before the video even auto-loads, for instance.
Where most sites fail: the reject button
Under its guidelines and its recommendation on “cookies and other trackers”, the CNIL is explicit on a point that remains, by far, the most common mistake: refusing cookies must be as easy as accepting them. In practice, a “Reject all” button must appear on the very first screen of the banner, with the same visual prominence as “Accept all”. A banner that displays “Accept” as a big coloured button and only offers refusal after clicking “Settings”, then unchecking each purpose one by one, is not compliant — even if a way to refuse technically exists somewhere.
A landmark study by researchers from MIT and UCL, presented at the CHI conference in 2020 (Nouwens et al., Dark Patterns after the GDPR), analysed the consent banners of the most visited websites in the UK: only 11.8% met the minimal requirements of European law, and removing the friction imposed on refusal (for example, dropping the “Settings” step) dramatically increased the refusal rate in a controlled experiment with 40 participants — proof that these interface choices are far from neutral (study available). A second study, by Utz, Degeling, Fahl, Schaub and Holz, presented at the CCS 2019 conference, tested more than 80,000 real visitors to a German website and confirmed that the banner’s position on screen and how choices are worded strongly influence the consent rate obtained. In other words: a poorly designed banner is not just a legal risk — it also biases the actual measurement of your visitors’ preferences.
What to actually check on your organisation’s website
A full cookie audit, with an exhaustive map of every tracker, remains a technical exercise beyond most small organisations. A few common-sense checks cover the essentials:
- Inventory of embedded third-party tools: Google Analytics or an equivalent, a Meta/LinkedIn pixel for your trainee-recruitment campaigns, a live chat widget, YouTube or Vimeo videos embedded on your course pages, a customer-review widget.
- Blocking before consent: these tools should only load, and therefore drop a cookie, after actual consent has been given — not when the page loads. Most CMS platforms (WordPress, Webflow) offer dedicated plugins for this conditional loading.
- A banner with two equivalent buttons: “Accept all” and “Reject all” visible simultaneously on the first screen, with no mandatory intermediate step to refuse.
- Consent retention period: the CNIL recommends a maximum of six months before asking the user for consent again.
- An up-to-date cookie register and policy: a dedicated page, either standalone or built into your privacy policy, should list the categories of cookies used, their purpose, and their lifetime — a document you can also leverage for the transparency required by Indicator 1 on public information.
What a training organisation actually risks
Cookies and trackers rank, year after year, among the most frequent grounds for CNIL inspections and sanctions, across organisations of every size. For small entities, the CNIL has had a simplified sanction procedure in place since 2022, with fines usually ranging from a few thousand euros up to a 20,000-euro cap for a legal entity — nowhere near the headline sanctions of tens or hundreds of millions of euros handed to high-traffic platforms, but very real and already applied to small businesses and associations. A training organisation processing prospect and trainee data, often through a CRM connected to its website, fits a profile the CNIL can readily inspect, particularly following a complaint filed by an internet user.
Beyond the risk of a fine, a poorly configured cookie banner also damages the experience of a prospective trainee or funder browsing your site before committing — a signal of professionalism, or of amateurism, from the very first visit.
Take action
Cookie compliance fits naturally into your broader GDPR groundwork rather than being treated as a separate task. The Kit Certif Complet provides privacy-policy and data-processing-register templates you can adapt to your site; the ebook Créer son organisme de formation en 30 jours walks through the GDPR fundamentals to put in place from the moment you set up your organisation; and the full pack brings both resources together to secure your online presence without hiring a costly provider for a compliance task that is actually manageable in a few hours.
Frequently asked questions
+Does a small training organisation really need a cookie banner?
Yes, as soon as the site drops or reads trackers that are not strictly necessary for the service the visitor explicitly requested — typically a standard analytics tool, an advertising pixel, or an embedded video widget. The size of the organisation does not exempt it: the CNIL sanctions small businesses as well as large groups, through a simplified procedure once a breach is established.
+Which cookies can be dropped without asking for consent?
Trackers strictly necessary to deliver the service explicitly requested by the user (shopping cart, session authentication, technical load balancing), and, under strict conditions set by the CNIL, certain audience-measurement tools that meet precise criteria (purpose limited to internal statistics, no cross-referencing with other processing, clear information, easy opt-out). Outside these cases, prior consent is required.
+Does my site's banner need a reject button at the same level as accept?
Yes. Since its guidelines, the CNIL has required that refusing be as simple as accepting: a 'Reject all' button must appear on the first screen of the banner, with the same visual prominence as 'Accept all'. A flow that forces users to click 'Settings' and then uncheck each purpose one by one is not compliant.
+What does a training organisation risk if its cookie banner isn't compliant?
Under the simplified sanction procedure, which applies to modest-sized structures, CNIL fines generally range from a few thousand euros up to a 20,000-euro cap. The heaviest sanctions, running into tens or hundreds of millions of euros, target players with massive traffic — but cookies and trackers remain, year after year, the leading reason for CNIL inspections and sanctions, small businesses included.