Recent weeks brought several privacy developments affecting websites, digital advertising and consent management.
On 17 September, Advocate General Dean Spielmann issued an opinion in the Groupe Canal+ case, arguing that consent for direct marketing by unidentified “partners” may not be sufficiently informed. The case involves around 3.9 million people and follows a €600,000 CNIL fine against Groupe Canal+.
The same day, the EDPB finalised Guidelines 3/2025 on how the GDPR and Digital Services Act work together. The guidance covers online advertising, profiling, recommender systems, special-category data and protections for minors.
Lithuania’s data protection authority also published plain-language materials covering consent and tracking pixels, reinforcing that website compliance extends beyond traditional cookies.
Separately, the EDPB published draft Guidelines 04/2026 on GDPR fines. The draft addresses negligence, previous and recurring infringements, mitigating factors and whether a fine would be effective, proportionate and dissuasive.
For businesses, the main areas to review are third-party consent wording, the cookies, pixels and scripts operating on websites, whether user choices actually control tracking and profiling, how the two frameworks overlap, and whether recurring compliance failures are being identified and corrected.
Advocate General: Generic “Partner” Consent May Not Be Enough for Direct Marketing
The Groupe Canal+ case arose because the personal data had originally been collected by two internet service providers. Subscribers agreed that the providers’ “partners” could use their information for marketing, but those partners were not individually identified when consent was obtained.
The Advocate General’s opinion is that consent for unidentified partners to use personal data for direct marketing is valid only where the individual knows who those partners are.
Otherwise, fresh consent should be obtained before another organisation begins using the data for marketing.
The issue involves both GDPR consent and transparency requirements and Article 13 of the ePrivacy Directive, which governs unsolicited communications for direct-marketing purposes.
This is an Advocate General’s opinion, not a final judgment of the Court of Justice of the European Union.
The Court is not required to follow it, and the case remains pending.
Businesses relying on wording such as:
- “our partners”;
- “selected partners”;
- “trusted partners”; or
- “marketing partners”
should check whether a person giving consent can actually identify or understand which organisations may later use their data.
The Advocate General’s opinion does not establish a new cookie-banner rule. It concerns electronic direct marketing.
However, the underlying principle is still relevant to websites that share personal data with advertising, analytics or marketing providers.
For direct-marketing arrangements similar to the one in Groupe Canal+, businesses should review whether:
- the organisations that will actually use the data are sufficiently identified when consent is obtained;
- the purposes of processing are explained clearly; and
- the consent originally collected actually covers the organisation that later wants to use the data.
For website consent more generally, users should receive clear information about the third parties or recipient categories involved, the purposes of processing and the choices available to them.
EDPB Finalises Guidance on How the DSA and GDPR Work Together
The final EDPB Guidelines 3/2025 are particularly relevant to intermediary services and online platforms that fall within both frameworks.
One of the main areas of overlap is online advertising.
The DSA prohibits online platforms from presenting advertisements based on profiling that uses the special categories of personal data referred to in Article 9 GDPR.
These include data relating to:
- health;
- political opinions;
- religion;
- racial or ethnic origin;
- trade-union membership;
- sexual orientation; and
- certain biometric or genetic information.
The underlying processing may satisfy the GDPR’s legal-basis requirements, including an applicable Article 9(2) derogation, while the DSA still prohibits presenting profiling-based advertisements that use those special categories of data.
This is particularly relevant to behavioural advertising because sensitive characteristics do not always come directly from information a user submits. They may also be inferred from:
- browsing activity;
- searches;
- purchases;
- interests; or
- interactions with content and advertisements.
Recommender Systems and Profiling
The guidelines also address recommender systems.
For Very Large Online Platforms and Very Large Online Search Engines subject to Article 38 DSA, at least one recommender option must not be based on profiling.
The EDPB says:
- profiling and non-profiling options should be presented equally;
- users should not be nudged towards profiling; and
- while the non-profiling option is active, personal data should not continue to be collected and processed to profile that user for future recommendations.
The technical behaviour behind the user’s choice should match what the interface tells them.
Age Assurance
The EDPB also addresses age assurance.
It warns against:
- measures that unnecessarily identify users; and
- permanently storing age or age-range information solely on the basis of Article 28 DSA.
For organisations in scope, the practical task is to map the two sets of obligations separately.
Advertising, privacy and product teams need to understand:
- how profiles are created;
- whether sensitive characteristics are involved;
- what alternatives users are offered; and
- whether those choices are reflected technically.
Tracking Pixels Show Why Website Compliance Goes Beyond Cookies
In late August, Lithuania’s State Data Protection Inspectorate, VDAI, included both consent and tracking pixels in a set of 11 plain-language GDPR infographics for SMEs and the public.
Tracking pixels are typically small or invisible resources embedded in websites, emails or advertisements. When they load, information can be sent to another server.
Depending on the implementation, that information can show:
- whether content was viewed;
- when it was accessed;
- technical details about the browser or device; and
- other interaction data.
Website privacy reviews therefore need to account for more than conventional browser cookies.
Tracking can also involve:
- pixels;
- tags;
- scripts;
- local storage;
- advertising identifiers; and
- embedded third-party resources.
The VDAI has separately reminded organisations that privacy requirements apply to cookies and other tracking technologies, not just traditional cookies.
For website operators, this means understanding what actually happens when a page loads.
They should know:
- which cookies and scripts are activated;
- whether technologies requiring prior consent operate before that consent is obtained;
- what information they collect;
- which third parties receive it;
- whether optional tracking can be refused as easily as accepted; and
- whether withdrawing consent changes the website’s behaviour.
Users should be able to understand what is being tracked, why it is being tracked and what their choices mean.
A well-written notice does not solve a technical problem if advertising or analytics technologies that require prior consent begin collecting data before that consent is obtained.
EDPB Proposes New Guidance on GDPR Fines
EDPB Guidelines 04/2026 remain draft guidance under public consultation, with feedback open until 13 November 2026.
The proposed methodology asks five questions:
- Can the infringement attract an administrative fine?
- Can the party concerned be held liable?
- Was the infringement intentional or negligent?
- Do the Article 83(2) GDPR factors indicate that the infringement should be considered minor?
- Would a fine be effective, proportionate and dissuasive?
Two parts of the draft are particularly relevant to website compliance.
Negligence Does Not Necessarily Require Deliberate Wrongdoing
An organisation may not need to consciously know that it is breaching the GDPR before negligence becomes relevant.
The assessment can include what a reasonably diligent organisation should have known.
Applied to website compliance, that principle could mean that saying:
“We did not know the tracker was loading before consent.”
Should ordinary scans, testing, audits or change-management controls have detected it?
Websites change through:
- new analytics tools;
- advertising campaigns;
- plugins;
- tag-manager configurations; and
- third-party integrations.
A consent setup that worked correctly before those changes should not automatically be assumed to remain compliant afterwards.
Previous and Recurring Failures Can Matter
The draft treats relevant previous infringements as an aggravating factor and also gives examples where recurring failures reveal a pattern that can no longer be considered minor.
A single implementation mistake is therefore different from the same problem returning after several deployments or fixes.
If a marketing tag repeatedly begins loading before consent, for example, the issue may start to look like a weakness in the organisation’s compliance process rather than an isolated technical error.
Remediation can also matter.
Actions that may be relevant when regulators assess enforcement include:
- promptly stopping problematic processing;
- correcting technical or organisational measures; and
- addressing the root cause.
Remediation does not guarantee that a fine will be avoided.
It does, however, give organisations another reason to investigate recurring tracking and consent failures rather than repeatedly applying temporary fixes.
How a CMP Can Help Manage Consent and Tracking Choices
A Consent Management Platform (CMP) can help turn website consent and tracking requirements into working controls, including visitor choices, regional configurations, consent records and technical control of cookies and scripts.
In practice, that can include:
- Cookie Scanner: identifies website cookies and helps keep the cookie inventory and related disclosures up to date as a website changes.
- User consents recording: records website visitors’ consent choices within the CookieScript implementation and can support internal consent documentation.
- Third-party cookie blocking: helps enforce consent choices by controlling selected third-party technologies before the relevant consent is obtained.
- Geo targeting: can apply different consent configurations across jurisdictions where privacy requirements differ. Location detection should not be treated as proof of legal residency.
- Automatic script blocking
- Consent events
- Global privacy regulation support
- 42 languages
- Google Consent Mode v2
- Google Tag Manager integration
- Automatic monthly scans
- Advanced reporting
- Cookie Banner sharing
- IAB TCF 2.4 integration
- Privacy Policy Generator
- Cookie Policy Generator
CookieScript is a CMP that Google includes among the CMP partners available for Consent Mode setup. It is also a Google-certified CMP with Gold tier status.
A 14-day free trial of the Plus plan is available without requiring a credit card.
A CMP can support cookie scanning, website consent collection, configuration and technical enforcement, but it does not determine whether every individual data flow is lawful or replace the organisation’s wider GDPR compliance assessment.
Conclusion
The common thread across these developments is the gap between what users are told and what systems actually do.
The September guidance and enforcement direction place more weight on aligning disclosures, consent choices and technical behaviour—and on detecting when that alignment breaks after a website, advertising setup or third-party integration changes.
