Skip to content
PeekWellThe Rulebook
Join now

Reject all cookies: tracking that carries on anyway

At a glance

EU-02CriticalGDPR Art. 7(3); ePrivacy Art. 5(3)

Peeky clicks Reject all on a fresh visit and compares what loads with the accept-all visit, looking for trackers that run after the visitor said no.

Last checked against the source:

I need to fix thisI need the rule

The rule

This check looks at whether a page keeps the promise its banner makes when the visitor says no. The legal base is the one in EU-01: Article 5(3) of the ePrivacy Directive allows storing or reading information on a visitor’s device only with consent, and that consent is the GDPR’s. This check covers the other half, the right to refuse and to take consent back.

The EDPB reads Article 7(3) of the GDPR as meaning that “the controller must ensure that consent can be withdrawn by the data subject as easy as giving consent and at any given time” (para. 113). On what follows a withdrawal it says: “if consent is withdrawn, all data processing operations that were based on consent and took place before the withdrawal of consent - and in accordance with the GDPR - remain lawful, however, the controller must stop the processing actions concerned” (para. 117). If the withdrawal right falls short, it says, “the consent mechanism of the controller does not comply with the GDPR” (para. 116).

The EDPB’s wording is about withdrawal. The CNIL applies the same logic to a refusal at the first visit.

The CNIL is the most specific about this. Its recommendation says that any inaction, or any action other than a positive act signifying consent, must be read as a refusal, and that in that case “aucune opération de lecture ou d’écriture soumise au consentement ne peut légalement avoir lieu” (no read or write operation that needs consent may take place; translation ours). On withdrawal it says users must be able to withdraw at any time, that it must be as simple to withdraw as to give consent, and that for the withdrawal to be effective “il peut être nécessaire de mettre en place des solutions spécifiques pour garantir l’absence de lecture ou d’écriture des traceurs précédemment utilisés” (it may be necessary to put specific measures in place to make sure trackers used earlier are no longer read or written).

For the ePrivacy side, each Member State sets its own penalties. In France the CNIL applies Article 82 of the Informatique et Libertés law, which is the basis it named in the SHEIN, American Express and Condé Nast decisions. In Spain the AEPD applies Article 22.2 of the LSSI and, in PS/00051/2023, noted that a “light” infringement of it can carry a fine of up to EUR 30,000.

The decisions below show three patterns: refusal ignored from the first click (SHEIN, American Express), withdrawal that does not stop what was already running (SEAT, American Express, Condé Nast), and, in the AEPD’s Grupo Massimo Dutti decision, a settings link that existed but did not take back what an earlier accept had allowed.

What PeekWell checks and how

EU-02 asks one question: after the visitor clicked Reject all, did anything non-essential still run? The scan answers it by comparing two visits.

In the first visit the scan opens a public page in a fresh browser context and clicks the Reject all button. It finds the button using common consent-tool selectors and label heuristics, then records every network request and cookie that follows. In the second visit, with a clean context again, it clicks Accept all and records the same things. The two sets are compared. A tracker from the maintained signature list that appears in the reject visit becomes a finding, and the exact requests are logged as the evidence.

Code makes the decision from that evidence. A language model may help read an unusual button label or write the explanation, but it never decides that a tracker fired.

The capture is the same as in EU-01, but the question differs. EU-01 asks what loaded before anyone touched the banner. EU-02 asks what loaded after the visitor said no.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. The button is found with common consent-tool selectors and label heuristics, so an unusual banner may not be recognised. It does not run the sequence in several of the Spanish decisions, where a visitor accepts first and then withdraws through the settings panel, so a site that stops tracking on a first refusal but not after a later withdrawal is outside what a scan can say. Collection that happens on a server or inside an app is also outside a browser visit. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

The CNIL and the AEPD both record their findings from their own visits to the sites. The SHEIN decision, from the CNIL on 1 September 2025, records that new cookies were still placed after Refuse all and that others already present continued to be read. The fine was EUR 150 million.

The CNIL’s later decisions follow the same line. On 20 November 2025 it fined the publisher of vanityfair.fr EUR 750,000 after finding that new cookies were still placed, and existing ones read, once a visitor had refused or withdrawn. A week later it fined American Express Carte France EUR 1.5 million for advertising trackers placed despite a refusal and for trackers still read after a withdrawal. The company had corrected its setup during the procedure, which the CNIL noted.

Spain shows the same pattern with smaller amounts. In the SEAT procedure the AEPD recorded that after the visitor chose to reject through the settings panel, the Google cookies set at the earlier acceptance were still present and were still being sent in later requests. SEAT paid EUR 12,000 and the procedure ended. In the Massimo Dutti decision the AEPD found that after a visitor had accepted, clicking Reject all, or switching each group to off, left the third-party cookies in use, and fined EUR 5,000.

For a company the consequences are practical. The facts are visible from outside. And the evidence is the requests themselves, which the authorities captured in their own browsers.

Smaller companies and larger companies

The rule has no size threshold, and none of the decisions above turns on the size of the company.

In a small company the banner usually comes from a plugin or a hosted site builder. Someone sets the plugin up, sees the banner appear and moves on. The plugin hides the choice but does not control the tags, because the analytics script was pasted into the theme years ago and the chat widget loads from the page footer. Nobody tests the Reject button. A Spanish limited company, Local Verticals, S.L., ended its procedure PS/00040/2024 by paying EUR 6,000 after the AEPD recorded that clicking Rechazar todo left YouTube and DoubleClick cookies in use. The AEPD’s decision does not say how big the company is, so it is not listed as a smaller-company case here.

In a larger company the problem is spread out. A tag manager holds many tags owned by different teams, the consent tool is configured once and then changed by a release, and a consent state saved on one domain may not reach another. Withdrawal is the harder half, because cookies set at the earlier acceptance have to be cleared and the vendors told. The SEAT and American Express decisions are both about that second half.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Infinite Styles Services Co. Limited (SHEIN)

    CNIL (France), 2025€150 million

    The CNIL found that several cookies, particularly for advertising, were placed on visitors' devices as soon as they arrived on shein.com, even before they interacted with the information banner. It also found that clicking Refuse all, or withdrawing consent, did not stop new cookies being placed.

    Read the CNIL (France) publication about Infinite Styles Services Co. Limited (SHEIN)
  • American Express Carte France

    CNIL (France), 2025€1.5 million

    On 27 November 2025 the CNIL fined the company over trackers placed without consent. It found that advertising trackers were placed on the visitor's device despite a refusal, and that when a visitor accepted and then withdrew consent, the trackers already placed continued to be read. The company had brought itself into line during the procedure.

    Read the CNIL (France) publication about American Express Carte France
  • Les Publications Condé Nast (vanityfair.fr)

    CNIL (France), 2025€750,000

    On 20 November 2025 the CNIL fined the publisher of vanityfair.fr. It found that after a visitor refused or withdrew consent, new cookies that need consent were still placed and cookies already present were still read, and that the Refuse all button did not work as it should.

    Read the CNIL (France) publication about Les Publications Condé Nast (vanityfair.fr)
  • SEAT, S.A. (alleged; procedure ended by voluntary payment)

    AEPD (Spain), 2024€12,000 paid after two reductions (€20,000 proposed)

    In the opening of the procedure the AEPD recorded that, after a visitor withdrew consent through the cookie panel, the Google cookies set earlier stayed in the browser and were still being sent to the server in later requests. SEAT paid the reduced amount on 8 October 2024, which ended the procedure and counts as an acknowledgement of responsibility.

    Read the AEPD (Spain) publication about SEAT, S.A. (alleged; procedure ended by voluntary payment)

Smaller companies

No published decision on rejected or withdrawn cookie choices could be confirmed at a regulator's own page for a company whose size the regulator states, so no smaller-company case is listed.

How to fix it

The fix is to make the visitor’s choice the thing that controls every tag. The CNIL recommends a link available at all times for withdrawal, named something descriptive such as “gérer mes cookies” or “cookies”, or a cookie icon on every page.

  1. Reproduce it. Open your site in a private window with the network tab open. Click Reject all and reload a couple of pages. Write down every third-party request and cookie that appears after the click.
  2. Find what is outside the banner tool. A script in the theme, a plugin that adds its own tracking, an embedded video or a chat widget will each ignore the banner. Move them behind the consent tool’s categories or remove them.
  3. Fire tags only from the accept event. In the tag manager, trigger each non-essential tag on the consent tool’s accept event, and make sure a reject leaves them without a trigger. Check that a saved Reject is still honoured on the next page.
  4. Make withdrawal work. Add a permanent Cookie settings link or icon in the footer. When a visitor switches categories off, stop the tags, delete the cookies you set, and where a vendor offers it, tell the vendor.
  5. Re-scan. Clear cookies and storage, click Reject all, and run a scan again. Then accept, withdraw through the settings link, and check by hand that the requests stop, since a scan does not cover that sequence.

Consent mode and similar settings change what a vendor’s tag does, not whether the tag runs. Whether a given setup satisfies an authority is a question for your legal adviser, and Peeky reports only what it sees.

Questions

Does clicking reject all actually stop cookies?

It should, and regulators have fined companies where it did not. The CNIL's 2025 decisions against SHEIN and American Express both record cookies still being placed after a visitor refused.

The visitor's refusal has to change what the page does, not only what the banner shows.

How do you withdraw cookie consent?

Through a permanent link or icon on the site, usually called Cookie settings or Manage cookies. The EDPB says withdrawing should be as easy as giving consent, and that when it is withdrawn the site must stop the processing concerned.

The CNIL suggests a link available at all times, or a small cookie icon in a screen corner.

Is a website allowed to keep using a cookie after consent is withdrawn?

No. The EDPB's guidelines say that when consent is withdrawn the controller must stop the processing actions concerned. The earlier processing stays lawful, but nothing new should start. The CNIL adds that specific measures may be needed so trackers used earlier are no longer read.

Why does my cookie banner not work after I reject?

Usually a tag is running outside the banner tool's control. A script pasted into the theme, a tag manager trigger set to page load, or a widget that starts on its own will ignore the visitor's choice. The fix is to start every non-essential tag from the banner tool's accept event.

How does Peeky check that reject all works?

Peeky opens your public page in a clean browser, clicks the Reject all button, and writes down every request and cookie that appears. It compares that with a second visit where accept was clicked. Peeky does not sign in, and it does not test accept-then-withdraw.

Filed with

The rule

ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC

Read the rule (ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC)

A case

Infinite Styles Services Co. Limited (SHEIN)

CNIL (France), 2025

Read the decision (Infinite Styles Services Co. Limited (SHEIN))

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, adopted 4 May 2020 (section 5.2, paras. 112 to 117)
  2. CNIL, Recommandation sur les cookies et autres traceurs, consolidated version published 16 January 2026 (sections 2 and 3)
  3. CNIL, Cookies et autres traceurs: lignes directrices modificatives et recommandation (17 September 2020)
  4. CNIL, Cookies placed without consent: SHEIN fined 150 million euros (1 September 2025)
  5. CNIL, Cookies: la CNIL sanctionne AMERICAN EXPRESS d'une amende de 1,5 million d'euros (27 November 2025)
  6. CNIL, Cookies déposés sans consentement: la CNIL sanctionne la société éditrice du site vanityfair.fr (20 November 2025)
  7. AEPD (Spain), resolution ending procedure PS/00284/2024 by voluntary payment (SEAT, S.A.)
  8. AEPD (Spain), resolution in procedure PS/00051/2023 (Grupo Massimo Dutti, S.A.)
  9. AEPD (Spain), resolution ending procedure PS/00040/2024 by voluntary payment (Local Verticals, S.L.)

Last checked against the source:

For information only. Not legal advice.