Skip to main content
Category: Laws and Regulations

CNIL Recommendation

Also known as: CNIL Recommendations, CNIL Guidelines and Recommendations
Simply put

A CNIL Recommendation is guidance issued by France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), to help organizations understand and apply personal data protection rules in practice. These recommendations illustrate how the law applies to specific topics, such as mobile applications or artificial intelligence, often using concrete examples. They are intended to support compliance but generally do not replace the underlying legal obligations themselves.

Formal definition

A CNIL Recommendation is a form of soft-law guidance published by the CNIL, the French supervisory authority, to clarify how the GDPR and related national and EU data protection frameworks apply to particular contexts (for example, mobile applications, AI, or informing data subjects). CNIL recommendations frequently complement guidelines endorsed by the European Data Protection Board (EDPB) and may provide practical, example-based interpretation aimed at controllers, processors, developers, and other actors. As guidance reflecting the authority's interpretive and enforcement positions, such recommendations are typically influential but do not, on their own, constitute binding statutory rules; their status, scope, and weight depend on the specific instrument and the underlying legal basis, and interpretations may evolve over time. The precise legal effect of any given recommendation, and its interaction with regimes outside France, is outside the scope of this definition and should be assessed against the specific text and applicable law.

Why it matters

For organizations operating in or targeting users in France, CNIL Recommendations offer some of the most practical, example-based interpretation available on how abstract data protection obligations translate into concrete design and operational choices. Because the GDPR and the ePrivacy rules are often drafted at a high level, the recommendations issued by France's supervisory authority help controllers, processors, and developers understand what a data protection authority may expect in specific contexts, such as mobile applications, artificial intelligence, or informing data subjects. This practical guidance can reduce uncertainty when building consent flows, drafting privacy notices, or configuring tracking technologies.

At the same time, it is important to understand the status of this guidance. CNIL Recommendations are generally a form of soft law: they reflect the authority's interpretive and enforcement positions and are typically influential, but they do not on their own replace the underlying statutory obligations under the GDPR and related national and EU frameworks. Aligning with a recommendation can support a compliance posture, but it is not a substitute for legal analysis of the specific facts, and it does not automatically establish lawfulness under every applicable regime.

Because CNIL Recommendations speak primarily to the French context, their weight outside France is limited, even though they frequently complement guidelines endorsed by the European Data Protection Board. Readers operating across the EU, the UK, or US states should not treat French guidance as universal, and should recognize that interpretations may evolve over time as the authority updates its positions.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance in France or for services targeting French users can use CNIL Recommendations as practical, example-based guidance on how the authority interprets data protection obligations in specific contexts. They should treat this guidance as influential but not as a replacement for assessing the underlying legal requirements against their own facts.
Mobile application developers and providers
The CNIL has issued recommendations aimed at all those involved in developing and making available mobile applications, with the goal of enhancing personal data protection. Developers and app publishers can consult these to understand expected practices, while recognizing that guidance may evolve and that its application depends on the specifics of each app.
Teams building or deploying AI systems
Organizations developing or using artificial intelligence involving personal data may find the CNIL's AI recommendations, published to promote responsible AI use while ensuring GDPR compliance, useful for framing their approach. This guidance supports compliance efforts but does not by itself resolve the legal questions specific to a given system.
Legal counsel advising on French and EU data protection
Counsel can use CNIL Recommendations to anticipate the authority's interpretive and enforcement positions, particularly where they complement EDPB-endorsed guidelines. Because the recommendations are generally soft law whose weight depends on the specific instrument and its legal basis, counsel should assess each against its own text and the applicable law, and should be cautious about extending French guidance to other jurisdictions.

Inside CNIL Recommendation

Scope and legal basis
CNIL (the French data protection authority) recommendations and guidelines interpret the French implementation of the ePrivacy Directive (the rules on placing and accessing information on a user's device) alongside the GDPR (governing any subsequent processing of personal data). These instruments express CNIL's enforcement expectations for cookies and similar technologies in France; they are not binding law in the same way as statute, but they signal how the authority is likely to assess compliance.
Consent standard for non-essential technologies
The recommendations generally reflect that consent for analytics, advertising, and functional cookies must meet the GDPR standard of being freely given, specific, informed, and unambiguous, requiring a clear affirmative action. Strictly necessary cookies are generally treated as exempt from consent.
Interface and design expectations
CNIL guidance typically addresses how consent choices are presented, including the expectation that refusing should be as straightforward as accepting, and that continued browsing does not by itself constitute valid consent. The scope of these interface expectations is France-specific and reflects CNIL's own interpretation.
Coverage of cookie-like technologies
The recommendations generally apply not only to cookies but to similar technologies such as pixels, local storage, SDKs, and fingerprinting, since these fall within the same rules on accessing or storing information on a device.
Record-keeping and demonstrability
CNIL guidance typically touches on the ability to demonstrate that valid consent was obtained, which relates to consent logging and record-keeping obligations under the GDPR's accountability principle.

Common questions

Answers to the questions practitioners most commonly ask about CNIL Recommendation.

Does the CNIL Recommendation on cookies apply everywhere in the EU?
No. CNIL guidance and recommendations are issued by France's data protection authority and reflect the CNIL's interpretation of the ePrivacy rules as implemented in France and of the GDPR. While other EU data protection authorities address similar issues and sometimes reach comparable conclusions, each Member State has its own regulator and national implementation of the ePrivacy Directive. CNIL positions are influential but not automatically binding or applicable outside France, so you should check the guidance of the relevant authority for each jurisdiction in which you operate.
If we follow the CNIL Recommendation, are we guaranteed to be compliant?
Not necessarily. A CNIL recommendation typically sets out practical measures the authority considers helpful for demonstrating compliance, but recommendations generally describe suggested practices rather than the only lawful approach. Following it can support your compliance posture, but it does not replace an assessment of your specific facts, and it primarily addresses expectations in France. Compliance ultimately depends on the underlying legal requirements and how they apply to your particular processing, so legal judgment remains necessary.
How should we present the accept and refuse options on our cookie banner in light of CNIL guidance?
The CNIL has generally taken the position that refusing cookies should be as easy as accepting them, which in practice points toward offering a refuse option at the same level as the accept option rather than burying it behind additional steps. How you implement this depends on your banner design and the technologies in scope. This describes the CNIL's expectation in France; other authorities may frame the point differently, and you should confirm the current guidance applicable to your situation.
Which cookies can we set before obtaining consent under the CNIL's approach?
The CNIL, consistent with the ePrivacy framework, distinguishes between technologies that are strictly necessary to provide a service the user has requested and those that are not. Strictly necessary or essential cookies are generally exempt from prior consent, while analytics, advertising, and similar functional technologies typically require consent before being placed. The exemption is applied narrowly, and the same logic extends to non-cookie technologies such as pixels, local storage, SDKs, and fingerprinting. Classifying a given cookie as essential is fact-specific and can be contested, so document your reasoning.
What should we do about consent record-keeping to align with CNIL expectations?
Under the GDPR's accountability principle, you should generally be able to demonstrate that valid consent was obtained, which typically involves logging the choices made by users. The CNIL has emphasized the ability to prove consent, so maintaining records of when and how consent was collected, and enabling withdrawal that is as easy as giving consent, supports this. The exact retention period and format for these records are not fixed by a single universal rule, so decide based on your accountability needs and any applicable guidance.
How does the CNIL treat continued browsing or scrolling as a form of consent?
The CNIL has generally taken the view that simply continuing to browse or scroll does not constitute valid consent, because consent under the GDPR must result from a clear affirmative action and be unambiguous. In practice this means relying on implied consent from continued navigation is widely regarded as insufficient in France and across most EU jurisdictions. Requirements differ under some non-EU frameworks, such as certain US state laws that rely on opt-out mechanisms, so this reflects the EU-style opt-in standard rather than a universal rule.

Common misconceptions

CNIL recommendations are binding law that applies across the EU.
CNIL is the French supervisory authority, and its recommendations and guidelines express how it interprets and expects to enforce the French implementation of the ePrivacy rules and the GDPR. They carry significant weight in France but are not statute, and other EU authorities may take differing positions. Practitioners outside France should consult their own national authority's guidance.
Following CNIL guidance guarantees compliance everywhere a website operates.
Cookie consent obligations vary between the EU, the UK, and individual US states such as under the CCPA and CPRA, which often rely on opt-out rather than opt-in. Aligning with CNIL guidance addresses French expectations but does not automatically satisfy other jurisdictions, and it supports rather than replaces legal judgment.
Consent obtained under the ePrivacy-based cookie rules covers all GDPR obligations for the data collected.
The ePrivacy rules govern the placing of and access to information on a device, while the GDPR governs the processing of any personal data that follows. Satisfying one does not automatically satisfy the other, and separate obligations may apply to the subsequent processing.

Best practices

Ensure refusing non-essential cookies is presented as easily as accepting them, and do not rely on continued browsing as a form of consent.
Treat analytics, advertising, and functional technologies as generally requiring prior consent, while identifying which cookies genuinely qualify as strictly necessary and therefore exempt.
Apply the same consent approach to cookie-like technologies such as pixels, local storage, SDKs, and fingerprinting, since they fall within the same rules.
Maintain consent logs and records so you can demonstrate that consent met the GDPR standard of being freely given, specific, informed, and unambiguous.
Use CMPs and similar tools to support consent management, but combine them with legal review rather than assuming any tool guarantees compliance.
Where you operate beyond France, check the applicable requirements in the UK, other EU member states, and relevant US state regimes, since obligations and enforcement positions differ and continue to evolve.