---
title: "GDPR analytics in France — CNIL exemption explained"
description: "How analytics runs lawfully in France without a cookie banner. CNIL exemption criteria, the 14-point self-assessment, and the Digital Omnibus impact."
canonical_url: "https://sealmetrics.com/gdpr-analytics/france/"
lang: "en"
date_modified: 2026-05-29
content_type: "product"
owner: "web"
llm_priority: "useful"
last_verified: "2026-05-29"
source: https://sealmetrics.com/gdpr-analytics/france/
publisher: SealMetrics
---

Country — France · CNIL

# Analytics in France. *Without a cookie banner.*

The CNIL has published explicit exemption criteria for analytics since 2020. This is what the exemption requires, how the 2025 self-assessment tool works, and what changed with the 2026 Digital Omnibus.

TL;DR

The CNIL exemption allows web analytics to run on French sites without a cookie banner when the implementation meets five criteria: a strictly limited audience-measurement purpose, no cross-site tracking, anonymised or uncollected IPs, no merging with other personal data, and aggregate-only reporting. SealMetrics meets each criterion by design — no identifier is generated, no cookie is set, no IP is collected, no cross-site data path exists. The architecture sits inside the exemption rather than depending on it.

- **5 CNIL criteria** defined in 2020, reaffirmed 2024, aligned with EDPB Opinion 5/2019.
- **14 technical points** in the 2025 auto-évaluation tool — each documented publicly.
- **No cookie banner** required for the analytics layer; other tools (ad pixels) still need consent.
- **Dublin processing** keeps the implementation inside the GDPR adequacy zone — no Schrems II transfer.

## The 5 CNIL criteria

The CNIL exemption is not vague. Five operational requirements define the boundary. An analytics tool either meets each one by design or it does not qualify.

01

### Strictly limited purpose

CNIL requires

Measurement must serve only audience analytics — no marketing, no advertising, no profiling.

SealMetrics

Aggregate channel and conversion counts only. No identifier, no profile, no audience export to ad platforms.

02

### No cross-site tracking

CNIL requires

The tool must not enable tracking the visitor across other websites.

SealMetrics

First-party server-side. The pixel runs on your own domain. No third-party cookie, no cross-site identifier.

03

### IP anonymisation or non-collection

CNIL requires

Last octet of IP addresses must be removed before processing (or IPs not collected at all).

SealMetrics

No IP address is ever stored — it has no column in any analytics database. The IP is used transiently in memory during request handling and then discarded. The CNIL requirement is met by exceeding it.

04

### No merging with other personal data

CNIL requires

Analytics data must not be combined with personal data from other sources.

SealMetrics

There is no personal data to merge. Aggregate counts are isolated from any CRM, advertising or marketing identifier.

05

### Aggregate-only reporting

CNIL requires

Reports must be aggregate. No individual-level data may be exposed.

SealMetrics

Every report is aggregate — by channel, campaign, landing page, country, device class. No per-visitor view exists in the product.

## The 14-point self-assessment

In July 2025 the CNIL published an [auto-évaluation tool](https://www.cnil.fr/fr/cookies-solutions-pour-les-outils-de-mesure-daudience) translating the five high-level criteria into 14 concrete technical requirements covering data retention, IP anonymisation, cookie use, cross-site behaviour, exports and more. Each must be met for the exemption to apply.

We published our complete answer to each of the 14 points in [a public blog post](https://sealmetrics.com/blog/cnil-self-assessment-published/) — copy patterns directly into your DPO review, or send the link with our DPA and the TPSR package. Two examples of the shape:

CNIL: Last octet of IP must be removed.

SealMetrics: No IP address is ever stored — it is used transiently in memory during request handling and then discarded.

CNIL: Cookies must not exceed 13 months retention.

SealMetrics: No persistent cookies are used.

## What the 2026 Digital Omnibus changed

The EU Digital Omnibus (Nov 2025, in force 2026) consolidated the patchwork of five existing data instruments and gave authorities sharper enforcement tools. Three things matter for French operators:

- **Reject-all parity is now formal.** Banner asymmetry (highlighting “accept” vs hiding “reject”) is enforceable at the EU level, not just by CNIL national action. Costs of running a defensible banner went up.
- **Article 5(3) enforcement clarified.** Authorities have explicit jurisdiction over breaches involving terminal-device storage. The CNIL no longer has to reach for adjacent grounds.
- **The exemption itself survived intact.** Anonymous non-tracking analytics remains explicitly out of Art. 5(3) scope. The economics now favour exempt architectures more strongly than before.

For the operator’s view of what changed, see [the marketer’s guide to the Digital Omnibus](https://sealmetrics.com/blog/eu-digital-omnibus-cookie-banners-analytics/).

## What it means for your French site

Three practical outcomes for an operator running a French site with SealMetrics installed:

### Banner scope shrinks (or disappears)

If SealMetrics is the only analytics layer and the only tools that set cookies are strictly-necessary (cart, session, fraud), no consent dialog is required. If you also run ad pixels or A/B testing tools, the banner shrinks to those specific consents.

### Privacy policy still required

Transparency obligations apply regardless of consent. The privacy policy must mention the analytics tool, its purpose, data categories, retention, and lawful basis. A template is included in our TPSR package.

### 100% of French traffic measured

French rejection rates against standard banners run 50–60%. With no banner gate, every visitor is counted on the same anonymous-aggregate basis — no Consent Mode modelling required to fill the gap.

## CNIL primary sources

- [CNIL — Cookies and other tracking devices (English)](https://www.cnil.fr/en/cookies-and-other-tracking-devices)
- [CNIL — Solutions for audience measurement tools (auto-évaluation, French)](https://www.cnil.fr/fr/cookies-solutions-pour-les-outils-de-mesure-daudience)
- [EDPB Opinion 5/2019 — referenced by CNIL guidance](https://edpb.europa.eu/sites/default/files/files/file1/edpb_opinion_201905_dpia_lists_fr.pdf)

## Common DPO questions

Does the CNIL exemption mean no cookie banner at all?

It means no cookie banner is required for the analytics layer specifically. If your site also runs Google Ads pixels, Meta pixels, A/B testing tools or any tool that sets cookies, those tools still require consent. The banner scope shrinks to the tools that actually need it — often substantially. Many French eCommerce teams reduce the banner scope to one or two products instead of the catch-all banner.

Is the CNIL exemption a 'workaround'?

No. The CNIL has published explicit criteria for analytics exemption since 2020, reaffirmed in 2024 and aligned with the EDPB Opinion 5/2019. The exemption is the original carve-out the regulation contemplated for genuine audience measurement that does not enable tracking. Architectures that meet the criteria are not exploiting a loophole; they are using the regulation as written.

How does the 2025 CNIL self-assessment tool work?

In July 2025 the CNIL released an auto-évaluation covering 5 permitted objectives and 14 technical criteria. Operators document how their analytics implementation meets each requirement. We published our complete self-assessment in a public blog post — useful to copy patterns from or share with your DPO.

What if my analytics is hosted in another EU country?

The exemption applies as long as the processing happens in the EU (no third-country transfer). SealMetrics processes exclusively in Dublin, Ireland — within scope of GDPR adequacy, no Schrems II transfer assessment required.

Did the Digital Omnibus 2026 change the CNIL position?

Not on the exemption itself. The Omnibus formalised reject-all banner parity, harmonised dark-pattern enforcement, and gave authorities sharper teeth on Art. 5(3) violations — all of which raise the cost of running cookie-based analytics. The exemption for anonymous non-tracking analytics survived intact and now contrasts even more favourably with the banner-dependent path.

What does the privacy policy still need to say?

Transparency is required even when consent is not. The privacy policy must describe the analytics tool, its purpose, the data categories processed (channel, landing page, aggregate counts), the retention period, and the lawful basis (Art. 6(1)(f) legitimate interest, paired with the ePrivacy Art. 5(3) exemption). A privacy policy template is included in our TPSR package.

## Related reading

[Pillar

### Consentless analytics

The full legal framework — GDPR Art. 6, ePrivacy Art. 5(3), six EU authorities aligned.](https://sealmetrics.com/consentless-analytics/)[Blog

### The CNIL self-assessment, published

All 14 technical criteria with SealMetrics’ actual answers — copy directly into your DPO review.](https://sealmetrics.com/blog/cnil-self-assessment-published/)[Blog

### GDPR analytics without consent

The Art. 6 / Art. 5(3) reasoning that underpins the CNIL exemption — explained for marketers.](https://sealmetrics.com/blog/gdpr-analytics-without-consent/)[Blog

### EU Digital Omnibus — marketer guide

What changed in the 2026 enforcement framework and what to action this quarter.](https://sealmetrics.com/blog/eu-digital-omnibus-cookie-banners-analytics/)[Tool

### Regulatory gap analysis

Audit your stack requirement by requirement — and see where it falls out of compliance.](https://sealmetrics.com/reg-gap-analysis/)

## One *CNIL review*. Done.

Book a walkthrough with the founder. Bring your DPO. We answer the 14 self-assessment points live and ship the DPA + TPSR package on the call.

[Book a demo →](https://sealmetrics.com/demo/)[Start 14-day trial](https://my.sealmetrics.com/register)

Built by a founder · supported by a founder · EU-hosted by design
