Configure CNIL exemption opt-out tracking with a consent manager (CMP)
This guide provides general technical implementation advice. It does not constitute legal advice. Consult with a qualified privacy professional to ensure full compliance with applicable laws.
Website owners are responsible for their website’s compliance with privacy laws. This includes responsibility for collecting and retaining a log of their visitors’ valid tracking consents where required.
A Consent Management Platform (CMP) helps website owners manage visitor consent for cookie-based and cookieless tracking. It typically presents visitors with a consent banner explaining data processing activities and allows them to accept or decline specific purposes, such as Analytics or Marketing.
You can integrate a consent manager with Matomo using the Matomo tracking code or Matomo Tag Manager.
Matomo supports three tracking approaches, depending on your organisation’s legal requirements and tracking needs:
- Opt-out Tracking for CNIL Exemption: For organisations relying on the CNIL consent exemption for website analytics, limited tracking is permitted, provided that conditions of exemption are met and users are offered a clear opt-out mechanism. Refer to the integration guide on how to configure a consent manager to opt-out tracking with CNIL compliance enabled.
- Consent-based Tracking: For websites targeting users in countries that require prior consent for use of cookies and similar technologies for analytics and marketing (for example, most or EU and EEA countries), enable cookieless or cookie-based Matomo tracking only after obtaining visitor consent.
- Adaptive Tracking: For websites operating outside the EU/UK/EEA, in countries where prior consent is either not required or only required when the analytics processes personal data, you can enable cookie-based tracking with consent and fallback to cookieless tracking if consent is not given (unless the visitor opts out of all tracking).
This guide provides general guidance for configuring a consent manager (CMP) for visitors to opt-out tracking when CNIL compliance is enabled in Matomo. These steps are not specific to a particular consent manager and may vary depending on the CMP you use.
To set up consent-based or adaptive tracking for your consent manager, refer to the CMP-specific integration guides.
Opt-out Tracking (CNIL Exemption)
The French supervisory authority, the Commission nationale de l’informatique et des libertés (CNIL) permits certain forms of website analytics to be used without prior consent, provided that strict conditions are met. This is commonly referred to as CNIL consent exemption for audience measurement tools. Our self-assessment against CNIL consent-exemption criteria can be found here.
Note: To comply with this exemption, you must implement the necessary settings in Matomo to ensure data collection remains privacy-friendly and adheres to CNIL’s guidelines.
Refer to the Matomo Analytics Configuration Guide and Self-Assessment as required for CNIL consent-exemption (English version or French version).
While CNIL’s exemption is specific to France, supervisory authorities in a small number of other EU countries have also exempted narrow scope of website analytics from consent (with opt-out right). The Opt-out tracking method can also be used in the context of those exemptions, if Matomo is configured in line with the specific requirements. Refer to the ePrivacy Directive overview, National Implementations, and Matomo’s Website Analytics Guide for details.
Configure the Consent Manager
To configure tracking under the CNIL exemption (opt-out model), it’s important to assess whether your site qualifies for this setup. Consult with your data privacy officer or legal team before relying on the CNIL exemption.
If you fully comply with CNIL’s criteria for exempt audience measurement tools, there are different approaches you can take to integrate with your consent manager platform (CMP). Some consent managers provide specific CNIL settings, for example:
- Didomi provides a CNIL (France) configuration when customising the consent notice in Consent Notice > Customization > Specific settings.
- Klaro’s
config.jsfile lets you setoptOut: trueto load the Matomo service before consent is given.
When setting up opt-out tracking under the CNIL exemption, follow these guidelines for your consent manager and website configuration:
- Your website targets visitors in countries where CNIL or very similar exemption exists (e.g., France, Spain, Italy), or you have an establishment in such countries:
- Configure your CMP to either load Matomo Analytics cookies and start tracking without prior consent, or
- Re-categorise the Matomo cookies as Essential/Necessary.
- The CMP banner must clearly inform users about the use of consent exempt website analytics tracking and include a visible and easily accessible opt-out mechanism (e.g. a link to your privacy policy with an opt-out checkbox).
- If your website serves a broader audience that targets visitors from countries that require prior consent for cookie based or cookieless website analytics (e.g. most of EU countries):
- Consider splitting your banner configuration if the CMP supports region-specific geotargeting and consent rules.
If you do not use a CMP to provide the Matomo opt-out mechanism, you can provide one directly on your website using one of the following methods:
- Use the Matomo opt-out form: Follow the guide on how to include a web analytics opt-out feature on your site to embed the Matomo opt-out form. The form includes the required JavaScript to allow visitors to opt-out of tracking.
- Create a custom opt-out: Follow the developer guide to create your own opt-out using HTML and JavaScript.
Configure Matomo Tag Manager
If you are using Matomo Tag Manager in an opt-out configuration:
- Do not use consent-based triggers for Matomo Analytics tags. The tags should fire automatically, even without consent.
- Ensure all active tags fall within CNIL-compliant functionality. For example, UserID tracking is not permitted).
- Check the Matomo Configuration Variable does not have consent settings enabled (e.g., Require tracking or Require cookie consent).
Test the opt-out integration
Once configured, test the tracking behaviour and validate your privacy compliance setup.
- Perform test actions on your website and view the Visitors > Real-time report to verify tracking requests are sent to Matomo.
- Open the browser’s developer tools and select to opt-out of tracking.
- View the Application or Storage > Cookies tab to verify that the
mtm_consent_removedcookie is set. - Perform test actions on your website and view the Real-time report to ensure no tracking requests are sent to Matomo after opting out.
- Change the settings to opt back in and perform test actions to resume tracking.
- Check the Real-time report to ensure tracking requests are sent to Matomo.
This test confirms that the integration respects the user’s choice to opt out and behaves in accordance with CNIL’s exemption criteria.
⚠️ If you use Matomo features like Heatmaps, User ID, Ecommerce, Advertising Conversion, or Session Recording, or you want to access or export raw data, you must switch to Consent-based Tracking, as these features fall outside the exemption. Refer to the CMP-specific integration guides to configure consent to track.