Because valid consent must be informed, specific, and freely given. CNIL’s position is that passive behaviour, such as browsing a site or leaving browser defaults unchanged, does not show an active user choice. Organisations need an explicit action that reflects a real decision, plus a clear way to withdraw consent later. Without that, the consent basis is too weak for compliance.
Why browser defaults and casual navigation fail the consent test
CNIL treats cookie consent as a deliberate legal choice, not a side effect of using the web. Browser defaults, continued browsing, or simply moving around a site do not tell you what the user understood, accepted, or rejected. That is why consent has to be demonstrated through an active action that is separate from normal browsing behaviour.
For a consent signal to be credible, it must map to a real decision about the specific purposes of processing. If the user only changes nothing in the browser or keeps scrolling, the organisation cannot show that the person was informed in advance, had a genuine choice, and understood what they were agreeing to. The issue is evidential as much as legal, because passive behaviour is ambiguous.
In practice, the consent mechanism must sit ahead of the processing trigger and make the choice visible. A site that loads tracking cookies before the user has acted, or that treats mere page use as approval, is relying on implied permission rather than consent. Under CNIL’s model, that is too weak unless another legal basis applies and is actually supportable.
What makes consent valid under CNIL guidance
CNIL’s standard follows the core consent tests: it must be informed, specific, freely given, and unambiguous. The practical consequence is that the user should see what cookie categories or purposes are involved, be able to accept or refuse with comparable ease, and understand that refusal does not strip away unrelated access to the site.
EU General Data Protection Regulation (GDPR) is the underlying legal reference point because it requires consent to be a clear affirmative act and makes withdrawal as easy as giving consent. CNIL’s guidance applies that principle to cookie banners, preference centers, and any interface that asks users to authorize tracking or similar non-essential processing.
The practical bar is higher than a banner that merely informs. A valid design separates essential functionality from optional analytics, advertising, or profiling, and it gives the user a meaningful ability to choose among those purposes. If the interface nudges the user so heavily that refusal is obscured or harder than acceptance, the organisation risks turning consent into a formality rather than a lawful basis.
How to design a consent flow that stands up to review
CNIL-compliant flows usually need two things at once: an explicit affirmative action and a durable record of what the user chose. The action can be a button, switch, or comparable control, but it should be specific enough that a reviewer can distinguish acceptance from mere site use. The record should show the version of the notice, the purposes presented, and the option to withdraw later.
Identity Data Privacy and Consent Guide is useful here because it covers consent management, privacy by design, and retention discipline in the same control story. That matters when cookie choices are tied to broader privacy obligations, since the organisation needs both a lawful prompt and a defensible way to honour later withdrawal or deletion requests.
A strong implementation also avoids consent fatigue. If users are repeatedly re-prompted without a reason, or if banners are redesigned so that the choice becomes confusing, trust declines and the consent signal gets weaker. The best approach is not the most aggressive prompt, but the clearest one: one that records a genuine decision and can be reproduced if challenged.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Article 7 — Conditions for Consent | Cookie consent validity turns on clear affirmative, informed consent and easy withdrawal. |
| Recommendation — Design cookie flows so acceptance is explicit, informed, and as easy to withdraw as to give. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | Cookie consent flows are part of privacy controls and lawful personal data processing. |
| Recommendation — Document consent handling as a privacy control and verify notices, choices, and retention are governed. | ||
Practitioner Guidance
What to verify: Confirm that no non-essential cookies are set before the user acts, and that the banner or preference center presents accept and reject in a genuinely usable way. If a site uses continued browsing as its signal, treat that as a design flaw rather than a minor wording issue.
What practitioners underestimate: The hardest part is often not the banner text, but proving that consent was specific to each purpose and could be withdrawn as easily as it was given. That means the consent log, purpose taxonomy, and downstream tag firing need to align, or the legal story falls apart during review.
Practitioner takeaway: For CNIL, consent is only valid when the interface captures an active, informed choice before processing begins, and when the organisation can show that the choice was both specific and reversible.
Related resources from NHI Mgmt Group
- What do teams get wrong most often when implementing cookie consent under CNIL guidance?
- What do organisations get wrong about proving valid cookie consent after the fact?
- How should organisations implement cookie consent banners to meet CNIL expectations without weakening user choice?
- How should websites design cookie consent banners so consent is legally valid under TDDDG and GDPR?