In Europe, consent for cross-device tracking is regulated by the GDPR and national data privacy regimes.
The French data protection authority (CNIL) adopted regulations for cross-device tracking in 2020. In January 2026, CNIL updated recommendations for cross-device cookie consent, providing details, practical examples, and use cases for multi-device consent.
The guidance applies to logged-in users. When a logged-in user selects their cookie choice on one device, the company applies that choice to their account on another device.
Today, users access content on many electronic devices, including smartphones, personal computers, laptops, TVs, and tablets. Showing cookie banners on every device could be annoying. This guide explains how to collect multi-device consent in a compliant, user-friendly way.
What CNIL Says About Cross-Device Cookie Consent
CNIL recognizes cross-device Cookie Consent as a method to allow an authenticated user to express their cookie preferences once and have those choices applied across multiple devices or authenticated environments.
Multi-device consent improves user experience, as the consent choices are no longer linked to a particular device but to the user's account associated with a website. When a user selects their choice on a device connected to their account, it is automatically applied to the other devices.
Importantly, CNIL's recommendations concern authenticated environments. This means that users should be logged in and cross-device consent must be linked to a user's account rather than attempting to recognize unrelated devices. Cookie Consent across devices allows associating consent preferences with the account and synchronizes them across devices when the user accesses the service from another authenticated environment.
For example, a user may accept or reject certain types of cookies while logged into an account on a smartphone. With cross-device consent, those same preferences could then apply when the user signs into the same service from a laptop, tablet, or connected TV.
Implementing cross-device consent is not mandatory. Organizations can choose whether to apply it. If they choose to apply a cross-device consent system, it must be explained in a privacy notice or a Privacy Policy.
Independently of whether organizations apply a cross-device consent mechanism or not, general consent requirements continue to apply. Consent must therefore remain freely given, specific, informed and unambiguous, and users must be able to withdraw it.
Note that the same cross-device scope must apply to the user's other choices. If a user can consent across all connected devices with one action, they must also be able to refuse or withdraw that consent across all connected devices as easily as it was easy to accept consent.
Not sure if your website uses cookies? Scan your website for free and see what cookies your website uses:
Conditions for the Implementation of Cross-Device Consent
Organizations must be transparent about the scope of consent, collect informed choices, inform users after logging in from new devices, and treat cookie choices consistently. When obtaining conflicting consent choices, organizations may prioritize the most recent choice or the preferences already stored in the user's account; however, they must clearly explain to users how such contradictions are resolved.
Organizations implementing CNIL cross-device consent need to design the mechanism, so users understand that consent applies across devices. Organizations therefore should follow these CNIL consent recommendations:
1. Transparency about the scope of consent
Before accepting or rejecting cookies, users should be clearly informed that their preference will apply to other authenticated devices and environments.
2. Informed choices
Organizations must provide transparent, clear, and timely information about multi-device consent. A person who clicks "Accept" while browsing on their phone may reasonably believe that the decision concerns only that phone unless they are told otherwise. Organizations must therefore inform about the broader consent scope. They must inform users about the multi-device consent mechanism at the first layer of the consent interface, without pressing additional links. CNIL recommends using a Consent Management Platform (CMP) to provide this information to users.
3. Inform users after logging in from new devices
CNIL also recommends providing additional information when the user connects from a new device. For example, organizations could provide a temporary notification explaining that cookie preferences already associated with the account are being applied on the new device.
4. Consistent multi-device consent mechanism
The cross-device mechanism must treat Cookie Consent, refusal, and withdrawal consistently. When consent is account-wide, changing or withdrawing that consent should have corresponding account-wide effects.
5. Managing conflicting consent choices
A website visitor may reject advertising cookies before signing in on a laptop but later could sign in to an account that contains consent to advertising cookies. A cross-device system needs a predictable way to determine which preference takes precedence.
CNIL offers two possible approaches:
- An organization may prioritize the most recent choice over the previous one; or
- An organization may prioritize the preferences already stored in the user's account.
Whichever model is selected, organizations must clearly explain how they resolve such contradictions so users understand which choices will ultimately apply.
Users must understand the multi-device consent mechanism across all devices and environments. Once a user logs into the account, they must be informed of conflicting cookie choices, which choices will ultimately apply, and how users can modify the consent choices.
Use a Consent Management Platform (CMP) to manage Cookie Consent across devices.
CookieScript CMP is a Google-certified CMP, which allows managing cross-device cookie consent, supports Google Consent Mode v2, and offers these key functionalities:
- Cross-domain cookie consent sharing
- Cookie banner sharing
- Google Consent Mode v2 integration
- IAB TCF v2.2 integration
- Google Tag Manager integration
- Global Privacy Control
- Certification by Google
- Integrations with website builders like Wix, Shopify, Magento, etc.
- Highly customizable cookie banner.
- CookieScript API
- Cookie Scanner
- Consent recordings
- Third-party cookie blocking
- Geo-targeting
- Self-hosted code
Best Practices for Implementing Cross-Device Consent Management
Organizations implementing cookie consent synchronization should use these best practices:
- Implement clear consent architecture
Start by applying clear consent architecture rather than treating synchronization as an additional technical feature added to an existing Cookie Banner. - Maintain the user's relevant consent choices at the account level
Maintaining consent choices at the account level ensures that the CMP can apply those choices consistently across all user-authenticated systems. The CMP should also distinguish between cookies that require consent and strictly necessary ones that do not require consent. - Respect the data minimization principle
In accordance with the GDPR’s principle of data minimization, the CNIL recommends that organizations do not share personal data with service providers that may process it. CNIL recommends systematically replacing direct identifiers with a technical identifier to link a user’s different devices. - Explicitly explain the cross-device scope
Instead of relying on a generic statement such as "We use cookies," organizations should clearly inform users that their preference will apply to other authenticated devices and environments. - Treat acceptance and refusal equally
Your cross-device consent management system should treat both acceptance and refusal equally. Refusing non-essential cookies should not require significantly more effort. - Implement a multi-device consent mechanism consistentl
Implement a mechanism that treats cookie consent, refusal, and withdrawal consistently across devices. Changing or withdrawing that consent should have corresponding account-wide effects. - Establish a rule for conflicting consent choices
Organizations should establish a defined rule for resolving conflicts between device-level choices made before authentication and preferences already associated with the account. That rule should be technically consistent and communicated to users, so users can make informed choices. - Keep consent records
Organizations should record cross-device consent preferences, including details like how and when relevant preferences were collected, what information was presented to users, what scope the choice covered, and how subsequent changes were handled. This supports accountability and makes it easier to investigate synchronization problems or consent disputes. - Test cross-device cookie consent.
Lastly, test CNIL cross-device cookie consent across browsers, mobile applications, desktops, tablets, and other supported environments. Test whether cookie acceptance, refusals, granular preferences, subsequent changes, and withdrawals propagate as intended.
Frequently Asked Questions
What is CNIL cross-device consent?
CNIL cross-device consent allows a user’s cookie and tracker preferences to be associated with an authenticated account and applied across multiple devices or authenticated environments. The goal is to reduce repeated consent requests while preserving transparency and user control. Read CNIL's official recommendations.
How to share cookie consent across devices?
Cookie consent can be shared across devices by associating a user’s consent preferences with their authenticated account. When the user signs in on another device, browser, or application, the system can retrieve the stored preferences and apply them to that environment. CNIL specifically provides recommendations for multi-device consent implementation.
Is cross-device cookie consent allowed under the GDPR?
Yes. Cross-device consent can be implemented provided that the consent collected continues to meet applicable GDPR and cookie-consent requirements. Users must be properly informed about the scope of their choice, including that their preferences may apply to other devices connected to the same account. Businesses should use a CMP like CookieScript to manage cross-device cookie consent.
What are the main requirements for sharing cookie consent across devices?
Organizations should clearly inform users that their consent choices may apply across authenticated devices, ensure that refusal and withdrawal are as easy as acceptance, and define how conflicts between local device preferences and account-level preferences are handled. Consent must still meet applicable GDPR and cookie-consent requirements.
Does a user need to be logged in for cross-device consent?
Under CNIL’s cross-device consent recommendations, the mechanism applies to authenticated environments. This allows an organization to associate consent preferences with a user account and apply them when the user signs in from another supported device or application.
Should refusal and withdrawal also be synchronized across devices?
Yes. A cross-device consent mechanism should synchronize cookie acceptance, refusals, granular preferences, and all other subsequent consent changes. If consent applies across authenticated devices, users should also be able to refuse or withdraw consent with comparable ease, and those updated preferences should be reflected across devices.