Skip to main content

Identify the services subject to consent

Cookie, who are you?

Written by Alexandre Dias Da Silva

Once you have the complete list of your services, you must identify those that must be subject to the consent of your visitors. A single criterion makes the decision: does the service deposit or read information on the visitor's terminal (computer, phone, tablet) without this being strictly necessary for the site to function or for the service they requested?

Your services do not all collect the same type of data, nor for identical purposes

Legally, you are required to submit to consent all services that deposit or read information on your visitors' terminals, provided that it is not strictly necessary for the site to function or for the service they requested. This applies to most tracking, analytics, or advertising services: they require explicit user agreement before being loaded on the site.

The criterion is not the collection of personal data. A service may require consent even if the information it deposits or reads is not personal data: it is access to the terminal that triggers the obligation. Conversely, a service that processes personal data without ever depositing or reading anything on the terminal falls under GDPR (legal basis, visitor information), but not this rule. For details on this distinction, see Do you need a cookie banner?.

Your services can be classified into 3 categories, which we describe below:

Services subject to consent

The majority of services that track or trace visitor behavior are subject to consent. Highly diverse, they can enable the establishment of targeted advertising, sharing content on social networks, or even tracking a visitor's activity on a website in detail.

It is possible that some of these services that in principle require consent may be exempted, but this only concerns certain specific categories described below.

Services exempt from consent because "strictly necessary"

  • Technical services, allowing the website to function correctly (ensuring that all elements display properly, for example)

  • CMPs (consent banners, such as Axeptio), allowing to record the visitor's preferences regarding cookies for a period of 6 months

  • In certain cases, audience measurement services, allowing to understand how users use the website and verify that it functions correctly. They are not all, nor are they always, exempt from consent!

What does the law say on this subject?

To answer this question, we base ourselves on official texts.

The rule comes from the ePrivacy Directive (Article 5.3), transposed into each Member State by national law. In France, it is Article 82 of the Data Protection and Freedoms Act: any action aimed at accessing information already stored in a user's terminal, or recording information on it, requires their prior consent.

This same article provides for two exceptions, to be assessed independently of each other. Consent is not required if the action:

  • has the sole purpose of enabling or facilitating communication by electronic means;

  • or is strictly necessary for the provision of an online communication service at the express request of the user.

This rule applies regardless of the nature of the information deposited or read: it is not conditional on the presence of personal data. The GDPR, for its part, governs the processing of personal data that may follow — it determines the legal basis on which this processing is based and what you must tell your visitors.

✅ For France and regarding cookies relating to statistics, we invite you to visit the CNIL website (National Commission for Data Protection and Freedoms); for other countries, we invite you to check with the regulatory authority of the country concerned.

These services do not require prior consent, but you can choose to display them on a dedicated information screen in your Axeptio banner. This allows you to adopt an even more transparent approach with your users, giving them a complete overview of all services present on your site.

Audience measurement services exempt from consent according to CNIL

Certain audience measurement services can be configured to meet the exemption criteria established by CNIL: a purpose strictly limited to measuring the site's audience, for the exclusive account of its publisher, without cross-referencing with other processing or tracking navigation on other sites. The French data protection authority (CNIL) has assessed that the following services can be exempt from consent if they respect the configuration specified by CNIL.

Other audience measurement trackers could be exempt from consent provided they meet all the exemption criteria specified by CNIL. We therefore recommend that you verify with your legal counsel whether you can or cannot obtain consent exemption for an audience measurement tracker not listed below:

Expand to see the list of audience measurement services that can be configured to be exempt from consent

Shake helps you identify services subject to consent Our Shake scanner can help you easily identify which services on your site must be subject to consent. For services referenced in our database, the generated PDF report specifies whether it must be subject to consent. This provides a solid starting point for determining which services must be subject to consent. However, it is important to note that Shake may not be exhaustive and that some services may not be listed or up to date in our database.

In case of doubt, contact the services concerned If, after using Shake, you have doubts about a service or are not certain whether it should be subject to consent, it is essential to clarify the situation. To do this: - Contact the support of the service in question to obtain detailed information about what it deposits or reads on visitors' terminals. - Consult the service's documentation to find out whether it uses cookies, localStorage, pixels, or other trackers, and for what purposes.

Did this answer your question?