GDPR and Cookie Consent on WordPress: A Practical Guide

by Francis Rozange | Oct 2, 2026 | WordPress

On November 20, 2025, the French data protection authority, the CNIL, fined the publisher of vanityfair.fr 750,000 euros. The site did have a cookie banner, a “Refuse all” button and a consent management platform. But one cookie was set before any click, refusal was not respected, and withdrawing consent left most cookies in place.

Most WordPress sites combine the same ingredients: audience measurement, YouTube videos, Google fonts, a banner plugin installed one day and never checked since. The rules have been known since 2020, and the CNIL now fines small organizations too.

This guide covers what the law requires in the EU, what the CNIL concretely expects from a banner, what Google imposes with its Consent Mode, what WordPress already does and what the main plugins do. It ends with a ten-minute audit. It gives practical guidance, not legal advice: for a specific situation, talk to a lawyer.

What the law actually requires

The device rule: ePrivacy and its national versions

The cookie banner does not come from the GDPR. It comes from the 2002 EU ePrivacy Directive, transposed into each member state’s law, in France as article 82 of the Data Protection Act. The rule: reading or writing information on a visitor’s device requires their consent.

There are only two exceptions. Trackers whose sole purpose is to carry out a communication, and those strictly necessary for a service the user explicitly requested. Everything else, non-exempt audience measurement, advertising, social networks, embedded content, needs prior agreement.

The rule applies whether or not the data is personal. The Court of Justice of the European Union said so in 2019 in the Planet49 ruling, which also held that a pre-ticked box is not consent. It covers cookies, but also browser local storage, pixels and other tracking techniques, as the European Data Protection Board clarified in 2024.

What the GDPR adds: valid, provable consent

The GDPR supplies the definition of consent: freely given, specific, informed and unambiguous, expressed through a clear affirmative act. Silence, inactivity or a pre-ticked box do not count. Withdrawing consent must be as easy as giving it, and the site owner must be able to prove consent was obtained.

The GDPR also governs what happens next: data read from cookies needs a legal basis. Legitimate interest does not allow setting a non-essential tracker without consent, even if the banner interface presents it that way.

What does not need consent

Some trackers are exempt: the one that remembers the cookie choice itself, login and security cookies, a store’s cart, the language chosen by the visitor, load balancing. WooCommerce’s cart cookies fall into this category; the recently viewed products cookie is closer to a preference, to be assessed.

Audience measurement can also be exempt in France, under strict conditions: anonymous statistics, for the publisher alone, with no tracking across other sites and no cross-referencing with other data. The CNIL also recommends limiting tracker lifetime, to thirteen months for example, keeping data twenty-five months at most and informing visitors, who must be able to opt out. Our comparison of WordPress analytics plugins details which tools can qualify.

2025 and 2026: a regulation dropped, a reform under discussion

The ePrivacy Regulation, meant to replace the directive since 2017, no longer exists: the European Commission withdrew its proposal, a withdrawal published in the Official Journal on October 6, 2025. The 2002 directive therefore remains the law.

In November 2025, the Commission proposed, in its “Digital Omnibus”, to overhaul cookie rules: one-click refusal, choices remembered for at least six months, preferences set in the browser, simple audience measurement exempt from consent. In early October 2026, the text was still awaiting a decision by the European Parliament’s committees. Nothing has changed for your site.

The CNIL rules, button by button

The CNIL set out its doctrine in guidelines and a recommendation from September 2020, applicable since the end of March 2021. The recommendation was consolidated in January 2026 to cover multi-device consent. Here is what it means for a banner in practice.

Nothing before the choice

No tracker that requires consent may be read or written before the visitor has made a choice. Continuing to browse, scrolling the page or closing the banner without answering does not count as agreement. If closing the window means refusal, the banner must say so.

Refuse as easily as accept

This is a point the CNIL regularly sanctions. The CNIL puts it simply: refusing trackers must be as easy as accepting them. The CNIL strongly recommends offering refusal on the same screen and as easily as acceptance. It gives the example of two buttons, “Accept all” and “Refuse all”, at the same level and in the same format, and recommends buttons and fonts of the same size.

A clearly visible “Continue without accepting” link can be enough. The CNIL has been clear since its December 2021 sanctions, and repeated it in 2026: if a site lets visitors accept all cookies in one click, it must let them refuse all in one click. A “Settings” button in place of refusal is not enough.

Inform, and name the partners

Before the choice, visitors must know the purposes of the trackers, the identity of everyone setting them, reachable from the first screen, the consequences of refusing and how to change their decision. A “Customize my choices” button at the same level allows a choice per purpose.

Remember and withdraw the choice

The choice, acceptance as well as refusal, must be stored. The CNIL considers six months a good practice before asking again. Visitors must be able to withdraw consent as simply as they gave it, for example with a “Manage cookies” link or an icon present on every page.

The banner itself must work with a keyboard and be readable by a screen reader: our guide to WordPress accessibility fixes applies to it too.

Cookie walls

Making site access conditional on accepting cookies is not banned outright in France: the Council of State refused a general ban in 2020. The CNIL looks at each case and expects a real and fair alternative, at a reasonable price if paid. The European Board, by contrast, considers that such a wall makes consent not freely given. Treat the practice as very risky.

The real case: Vanity Fair and the four faults of a banner

The CNIL decision against Les Publications Condé Nast, publisher of Vanity Fair, Vogue and GQ, published on November 27, 2025, is valuable for a WordPress administrator. The vanityfair.fr site looks like many editorial sites: articles, advertising, Google Analytics, a consent platform built on the TCF advertising framework. The faults found are ones a misconfigured banner easily reproduces.

Six years of warnings

It all started in December 2019, with a complaint by the privacy group noyb. The CNIL ran several online checks, reminded the publisher of its obligations in 2021, then in September 2021 formally ordered it to obtain consent before any non-exempt cookie. The procedure was closed in July 2022.

A new noyb complaint revived the case. The CNIL checked the site again in July and November 2023, then in February 2025. Between June and October 2023, the site had received more than six million visitors in France. A hearing took place on November 6, 2025, and the decision came on November 20.

What the inspectors saw

First breach: a cookie before any choice. In November 2023, a Google cookie called NID was set on arrival. The publisher called it a technical error, fixed in January 2024. The CNIL replied that the fix changed nothing about the finding.

Second breach: false categories. In the preferences panel, three advertising processes, such as linking different devices or combining offline data sources, appeared “always active” among strictly necessary cookies that could not be turned off. The publisher explained that the TCF framework imposed them that way. The CNIL ruled that this did not excuse failing to inform visitors properly.

Third breach: refusal ignored. After clicking “Refuse all”, inspectors still found the Google NID cookie, a cookie tied to the site’s ad library and a cookie counting the videos watched.

Fourth breach, the most instructive: withdrawal without effect. In February 2025, after accepting, inspectors withdrew their consent. Out of fifty cookies, twelve disappeared and thirty-eight remained. Two of them, including a Google Analytics cookie, were still sent to the site’s own domain with every request.

The publisher argued that the Analytics scripts were disabled and nothing went to Google. The CNIL answered that the values still reached its own domain, so it was reading them, with no exempt purpose. It even named the technical fix: change the cookie’s expiry date so the browser stops sending it.

The decision

The fine came to 750,000 euros, with the company named publicly for two years. The CNIL counted as aggravating factors the exchanges going back to 2019, the 2021 formal notice and fixes made only after each check. The publisher pointed to the measures taken since, including a change of consent platform and mandatory staff training.

A week later, American Express Carte France, the group’s French subsidiary, received a 1.5 million euro fine for very similar faults: advertising trackers on arrival, after refusal, and still read after withdrawal. At the other end of the scale, a simplified procedure in place since 2022 lets the CNIL quickly fine straightforward cases, often small organizations, with fines capped at 20,000 euros.

What a WordPress administrator should take away

Test your banner yourself, before any click, after a refusal and after a withdrawal. “Strictly necessary” is a legal category, not a checkbox in a plugin. Cookies set by your own domain count as much as third-party ones. Withdrawing consent must stop cookies being read, not just stop scripts loading. A certified platform does not transfer your responsibility to its vendor.

Small glowing glass tokens still drifting through a closed barrier

Google Consent Mode v2: what changed in March 2024

A Google rule, not a law

Consent Mode is a Google mechanism that passes the visitor’s consent state to its tags. Version 2 added two signals, ad_user_data and ad_personalization, for visitors from the European Economic Area, the United Kingdom and Switzerland.

No law requires it: Google requires it by contract, in connection with its consent policy and the EU Digital Markets Act. Since early March 2024, without these signals, European visitors are no longer included in the advertising audiences linked to Google Analytics. To serve personalized ads with AdSense, a Google-certified platform integrated with the TCF has been required since January 2024 in the EEA and the UK, and since July 2024 in Switzerland.

Consent Mode does not collect consent: it passes on the consent your banner obtained. Google also states that it does not check the legal compliance of the platforms it certifies.

The signals and the two modes

Four signals matter for most sites: ad_storage, ad_user_data, ad_personalization and analytics_storage. Basic mode blocks Google tags until the visitor has chosen; on refusal, nothing is sent to Google.

Advanced mode loads the tags right away. While consent is denied, they send cookieless requests that include, among other things, a timestamp, the browser, the referring page and the consent state. Google uses them for finer conversion modeling. Sending these before any choice raises a real question under the European guidelines on URL and pixel tracking; to our knowledge, no CNIL decision has settled it yet.

Another trap: Google’s documentation contradicts itself on the default state in advanced mode. One help page says the system defaults to “granted” until a choice is configured, with possible regional differences for the EEA, Switzerland and the UK, while the developer documentation describes a “denied” default. So declare the “denied” default yourself.

The code: deny by default before the tag

A consent plugin normally writes this code for you. It illustrates the principle documented by Google: declare denial by default before loading the tag, then update the signals when the visitor accepts.

<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag('consent', 'default', {
    'ad_storage': 'denied',
    'ad_user_data': 'denied',
    'ad_personalization': 'denied',
    'analytics_storage': 'denied'
  });
</script>
<!-- Google tag here -->
<script>
  // Called by the banner only when the visitor clicks "Accept all".
  function allConsentGranted() {
    gtag('consent', 'update', {
      'ad_storage': 'granted',
      'ad_user_data': 'granted',
      'ad_personalization': 'granted',
      'analytics_storage': 'granted'
    });
  }
</script>

Order matters: Google warns that defaults do not work if they are declared after the tag.

What WordPress core already does

The privacy policy page

Since version 4.9.6, released in May 2018, WordPress lets you create or choose a privacy policy page under Settings, Privacy. A guide there gathers the text suggested by core and by plugins that use the dedicated function. The documentation points out that using these resources correctly remains your responsibility.

Export and erasure requests

Under Tools, two screens handle requests to access and erase personal data. The person confirms their request by email, then the administrator generates an archive or erases the data. Exports stay on the server for three days.

These tools only cover core and the plugins that hook into them. Erasure does not touch backups. A site that collects data through an incompatible plugin has to handle it manually.

The comment cookie checkbox

WordPress 4.9.6 also added a checkbox to the comment form asking for the visitor’s agreement before saving their name, email and website in the browser. Since version 4.9.8, an option under Settings, Discussion shows or hides that checkbox, and it is on by default for new installs. Without the checkbox, WordPress does not set these cookies at all: core only stores them with the visitor’s agreement.

Core offers no banner, no blocking of third-party scripts and no shared consent interface. That is the job of plugins.

WP Consent API: the missing link between plugins

A WordPress site often combines a banner plugin with several plugins that set cookies: analytics, store, social sharing. Without a common language, each one has to guess what the visitor accepted. The WP Consent API plugin, published under the WordPress umbrella, provides that language.

It defines five categories, functional, preferences, statistics, anonymous statistics and marketing, and functions to query them. The banner plugin records the choice; the others ask, before setting a cookie, whether the relevant category is accepted.

// A tracking plugin declares support, then checks consent before setting cookies.
$plugin = plugin_basename( __FILE__ );
add_filter( "wp_consent_api_registered_{$plugin}", '__return_true' );

if ( function_exists( 'wp_has_consent' ) && wp_has_consent( 'marketing' ) ) {
	// Load marketing code here.
}

Beware the trap: the plugin does not handle consent itself. Without a banner plugin declaring an opt-in mode, every category answers “yes”. It has more than 200,000 active installs, and Site Kit by Google, WooCommerce and WP Statistics support it. Proposed for core as early as 2020, it remains a separate plugin in WordPress 7.1.

Choosing a consent plugin

A banner plugin must block scripts until the visitor has chosen, offer refusal at the same level as acceptance, keep proof of consent and pass Consent Mode signals if you use Google’s advertising tools. The main ones, in October 2026:

  • Complianz: more than one million installs, setup wizard, cookie scan, script and iframe blocking with placeholders, France-specific rules. Certified by Google. Premium version from $59 per year.
  • CookieYes: more than one million installs, banner active on installation, automatic blocking, consent log hosted in its online service. Free up to 5,000 page views per month, then from $10 per month.
  • Real Cookie Banner: more than 100,000 installs, many service templates and content blockers, consents stored in your own database. TCF and Consent Mode reserved for the Pro version, from 59 euros per year.
  • Cookiebot: more than 100,000 installs, automatic scanning and blocking, an online service priced by number of pages. Free for a small site, then from 7 euros per month.
  • Borlabs Cookie: paid only, outside the official directory, very complete content blockers, from 49 euros per year before tax.

A word of caution about Cookie Compliance, formerly Cookie Notice, with more than 800,000 installs: its simplest mode, without an account, does not block scripts automatically, keeps no consent records and offers consent on scroll, which is invalid in Europe. Only its account-connected mode blocks scripts automatically.

Google certification means the plugin can talk to the TCF framework and Consent Mode, not that your banner is compliant. Vanity Fair’s publisher relied on the TCF framework, and that did not protect it. The vendors themselves say so: installing the plugin is not enough, the configuration is yours.

YouTube, Google Fonts and embedded content

youtube-nocookie does not solve everything

YouTube’s privacy-enhanced mode replaces the video’s domain with youtube-nocookie.com. Google only promises that the video viewed will not be used to personalize the YouTube experience and that ads will not be personalized. It does not promise that nothing is stored on the device.

The CNIL requires consent before activating external content that sets trackers, either through the banner or at the moment the content is launched. The right solution is a placeholder: an image and a “Load video” button, which most consent plugins can set up.

Google Fonts and the Munich ruling

Google Fonts sets no cookies. The problem is the IP address: every font load sends the visitor’s IP address to Google. In January 2022, a Munich court ordered a site to pay a visitor 100 euros in damages for this reason, noting that the fonts could have been hosted locally.

WordPress responded: the Themes Team recommended local hosting, and the WordPress 6.5 Font Library downloads Google fonts to your server. The theme directory rules, however, still allow Google Fonts as the only remote resource. So check your theme. Hosting your own fonts also improves performance, as our guide to Core Web Vitals fixes shows.

Audit your banner in ten minutes

Open your site in a private browsing window, with the browser’s developer tools, on the Application and Network tabs.

  1. Before any click, list cookies and local storage. Only exempt trackers should appear. In the Network tab, no requests to an ad network or a non-exempt measurement tool.
  2. Look at the banner. Is refusal at the same level, size and style as acceptance? Is the list of partners reachable?
  3. Click “Refuse all”, then browse several pages. No new non-exempt tracker should appear.
  4. Accept, then withdraw your consent through the provided link. The relevant cookies should disappear, or at least stop being sent to the server.
  5. Test a page with a video or an embedded map: nothing should load before you agree.
  6. If you use Google, check with Tag Manager’s preview tool that the default state is “denied” and switches to “granted” after acceptance.

Repeat this audit after every new plugin, every new tracking script and every theme change. Do not forget forms: a consent box for marketing messages must never be pre-ticked, and our comparison of WordPress form plugins details the information to give at the foot of each form.

Summary table

Plugin Where consents are stored Consent Mode and TCF Best for
Complianz Proof of consent, detailed records in premium Yes, TCF in premium WordPress sites that want everything set up in place
CookieYes Vendor’s online service Yes, TCF from Pro Small sites that want to start fast
Real Cookie Banner Your WordPress database In the Pro version Sites that want to keep their data in-house
Cookiebot Vendor’s online service Yes, TCF in premium Several platforms managed together
Borlabs Cookie Your WordPress database Yes Sites heavy on embedded content
WP Consent API None, just a shared language Not applicable Everyone, alongside the banner

Frequently asked questions

Do I need a banner if I only use exempt audience measurement?

Not for that measurement, if the tool and its configuration meet every condition of the exemption, and if visitors can opt out. But the slightest non-exempt tracker, a YouTube video or a share button for example, brings back the need for consent.

Is a “Continue without accepting” link enough?

It can be if it is clearly visible and as easy to use as the accept button. In any case, the CNIL expects one-click refusal whenever acceptance takes one click, which such a link provides. Two equivalent buttons remain the safest solution.

Does Consent Mode replace a banner?

No. It passes the choice expressed in your banner on to Google’s tools. Without a banner that collects valid consent, it has nothing to pass on.

Does a Google-certified platform guarantee compliance?

No. Certification covers technical integration with the TCF framework and Consent Mode. Google itself states that it does not check legal compliance. The Vanity Fair case shows it: relying on the TCF framework did not spare the publisher from checking what its banner actually did.

How long should the visitor’s choice be kept?

The CNIL considers six months a good practice, for acceptance as well as refusal. Do not confuse this with the thirteen-month lifetime the CNIL recommends for exempt audience measurement trackers.

Conclusion

Cookie rules fit in three sentences: nothing before the choice, refuse as easily as accept, a withdrawal that has a real effect. The rest is configuration, and that is where sites fail. Vanity Fair had a banner and a consent platform; what it lacked was a check of what its site actually did.

Choose a plugin that blocks scripts, set Consent Mode to deny by default, replace videos and maps with click-to-load placeholders, host your fonts. Then open your browser’s developer tools and check. Ten minutes are enough, and the CNIL works the same way in its online checks.

Sources


LaFactory designs, builds and maintains WordPress and WooCommerce sites, and develops its own plugins. Talk to us about your WordPress project.

Francis Rozange

Former section editor at Libération, he runs LaFactory, an international web agency since 1996.

Cart