Analytics cookies generally need prior consent under applicable EU device-storage rules unless a specific exemption covers the configured use. The answer depends on the operations, purposes and national rules. Calling a tool first-party, cookieless or privacy-friendly does not establish an exemption.
This guide provides a decision process for website owners and privacy teams. France is used as a clearly identified national example. It does not create a permission that can automatically be applied throughout Europe, and UK PECR requires a separate assessment.
Separate device access from personal-data processing
There are two questions to answer:
| Question | What to examine |
|---|---|
| Does the implementation store or access information on a device? | Cookies, browser storage, identifiers and other relevant technical operations |
| Does it process personal data? | Identifiability, purposes, recipients, lawful basis, retention and other GDPR requirements |
Article 5(3) of the ePrivacy Directive governs the first question through national implementing rules. Its consent requirement has exceptions for transmission and what is strictly necessary for a service explicitly requested by the user. GDPR legitimate interests cannot substitute for consent where that device operation requires it. ePrivacy Directive, Article 5(3)
An exemption for device access does not settle the lawful basis for personal-data processing. Conversely, an argument about anonymised reports does not establish that the preceding collection was exempt. Our GDPR and ePrivacy overview explains the wider framework.
A decision process for an analytics deployment
Use the following sequence before deciding whether to load analytics without a banner choice. It is a review method, not an automated legal determination.
- Describe the exact implementation. Record the product version, enabled features, browser code, identifiers, server processing and recipients.
- Identify device storage and access. Inspect what happens on a fresh visit, including requests that do not create cookies.
- Identify the applicable national rules. Do not select a favourable country's guidance merely because the provider is based there.
- Test a specific exemption against the configuration. If a required condition is not established, do not rely on that exemption. Obtain consent or redesign and reassess.
- Assess personal-data processing separately. Resolve lawful basis, transparency, retention, recipient roles and transfers where relevant.
- Verify the deployed behaviour. A configuration document is not evidence that the production tags follow it.
Keep the decision attached to the configuration version. A later change that links analytics to advertising or adds a cross-site identifier can change the assessment.
France: what CNIL's audience-measurement exemption covers
CNIL describes an exemption for restricted audience measurement performed exclusively for the publisher, producing anonymous statistics. Its conditions exclude combining the data with other processing, passing non-anonymous data to third parties and tracking people across different sites or applications.
CNIL also recommends informing users, limiting tracker duration, avoiding automatic renewal on each visit and periodically reviewing retention. Its guidance gives thirteen months as an example tracker lifetime and recommends a maximum twenty-five months for collected information. These are France-specific recommendations, not EU-wide defaults.
CNIL provides a self-assessment process. A provider must not market a qualifying configuration as CNIL-certified or validated, and a self-assessment does not bind the regulator. CNIL's audience-measurement guidance
Ask the provider for the documented configuration and check your own deployment against it. The name of a product, a previous listing or an exemption claim on a sales page is insufficient evidence.
Two illustrative implementation decisions
A publisher measuring navigation problems: its team proposes a narrowly configured audience tool and documents purpose restrictions, fields, recipients and retention against the applicable national guidance. The next step is to verify every condition and inspect the deployed requests. The example does not itself establish eligibility.
A shop linking analytics to advertising audiences: its team enables user matching and sends events to advertising destinations. It should not carry over an earlier assessment for restricted audience measurement. The additional purposes and disclosures need review before activation.
The useful difference is the processing, not whether both products have an “analytics” label.
Does cookieless analytics avoid consent requirements?
Not necessarily. The EDPB's technical-scope guidance examines operations including pixels, URL tracking and certain IP-based techniques. It interprets the scope of Article 5(3); it does not decide every consent exemption or declare every server request subject to consent. EDPB Guidelines 2/2023
Ask what “cookieless” means in the proposed implementation. It might mean no persistent browser cookie, while the system still reads device information, receives identifiers or combines events. Alternatively, a narrowly scoped backend statistic may involve different operations. Assess what occurs rather than treating the label as either an automatic exemption or an automatic violation.
Similarly, server-side collection changes the route. It does not by itself answer whether the initial device access or subsequent forwarding is permitted. See server-side tracking: benefits and limits.
What about GA4 and Google Consent Mode?
Do not treat GA4 as exempt merely because you disabled an advertising setting or because its cookies are first-party. Review the complete collection and processing configuration against the rules you intend to rely on.
Google Consent Mode controls supported tag behaviour; it does not provide legal permission. In advanced mode, denied storage consent can still result in cookieless requests. Those requests need their own assessment. The choice between basic blocking and advanced measurement should follow the approved processing decision. Google's Consent Mode overview
Use our basic vs advanced Consent Mode guide for the technical comparison. Where consent is required, use a clear choice interface and verify what rejection and withdrawal actually do.
Questions to ask an analytics provider
Use these questions to request concrete evidence rather than a general compliance statement:
| Ask the provider | Evidence to request |
|---|---|
| What does the browser read, store and send? | Field list, cookie/storage inventory and example request payloads |
| Which exemption do you rely on? | Named jurisdiction, current authority guidance and a condition-by-condition assessment |
| Which settings are required? | Versioned configuration instructions and a list of incompatible features |
| Who uses the data and for what? | Recipient roles, contracts, reuse terms and subprocessor information |
| Can data be linked across visits or sites? | Identifier design, matching functions and isolation controls |
| What is retained and where? | Retention settings for events, identifiers, reports, logs and backups |
| What happens when the configuration changes? | Change notification and a process to reassess the deployment |
Review both default and optional features. A tool can have an eligible restricted configuration and a different deployment that does not meet the same conditions.
Validate the decision with technical checks
Create expected results before opening the browser. Use test data and keep sensitive identifiers out of shared request exports.
- Fresh visit: record scripts, storage and requests before any choice.
- Rejection: verify that consent-dependent analytics remains restricted through navigation.
- Analytics only: ensure advertising features do not become enabled through a shared flag.
- Withdrawal: inspect later browser events, queued work and server forwarding.
- Returning visit: verify saved preferences and any configuration changes.
- Exemption-based deployment: inspect the restrictions that support the exemption, not just the absence of a banner.
Compare evidence with the provider's documentation. Investigate discrepancies such as an unlisted identifier, a second destination or logs retaining fields that the event filter removes. Route unresolved questions to the privacy and implementation owners before relying on the exemption.
FAQ
Can legitimate interests replace cookie consent?
Not where the device-storage or access operation requires consent. The separate GDPR lawful-basis assessment does not remove that requirement.
Is Matomo automatically exempt from consent?
No. Assess the specific configuration and applicable national conditions. Product names and self-hosting do not establish eligibility, and CNIL's process is not product certification.
Does anonymising reports remove the need to assess collection?
No. Examine the data before aggregation, the device operations and intermediate storage. A report can omit identifiers even when earlier processing used them.
Is an analytics exemption valid across the whole EU?
Do not assume so. Review relevant national rules and guidance. A configuration justified for one jurisdiction needs a separate applicability assessment elsewhere.
Can a site use analytics without any cookie banner?
Potentially, if all relevant operations are outside the consent requirement or properly exempt and other obligations are met. That conclusion requires an assessment of the whole site, including advertising, embeds and other tracking tools.
Choose the implementation after the assessment
If analytics needs consent, our cookie banner examples show how to explain the choice. For a wider review, use the GDPR readiness assessment, explore cookie consent implementation or request a free consent audit.
