WordPress cookie banner: CNIL 2024 compliance without sacrificing your bounce rate
The CNIL has been actively enforcing since 2023. The 5 most common mistakes among WordPress-based accommodation providers — and how to fix them in 15 minutes.
The CNIL is enforcing — and hotels are in the crosshairs
Since the CNIL updated its cookie guidelines in 2024, the commission has stepped up its sector-specific inspections. The hotel and tourism sector is particularly exposed because it makes heavy use of tracking tools (Google Analytics, Meta Pixel, Booking pixels) without always having the right legal basis in place.
A CNIL fine for cookie non-compliance: between €5,000 (micro-businesses) and several million € (large enterprises). But the real risk for an independent business is the public formal notice — visible on the CNIL's website — which destroys your reputation.
The 5 critical mistakes (and how to fix them)
"Continue without accepting" isn't offered
The CNIL requires that declining cookies be just as simple as accepting them. A prominent "Accept all" button plus a tiny "Settings" link = non-compliant. You need a "Reject all" button at the same visual level as "Accept all".
Third-party scripts load before consent
Your Google Analytics collects data as soon as the page loads — before the visitor has even clicked anything. This is the most common violation, and the most heavily sanctioned. Your banner must block third-party scripts until consent is obtained.
Consent isn't granular
"Accept all cookies" or nothing is no longer enough. The CNIL requires that users be able to accept by purpose: statistics separate from marketing, preferences separate from social media. Your plugin must support distinct purposes.
No proof of consent is kept
In the event of an inspection, the CNIL can ask for proof that user X did indeed consent on date Y. If you don't store consent logs, you can't prove your compliance — even if your banner looks correct visually.
The banner slows down your site
Some cookie solutions load 300-500 KB of JavaScript before any content. The result: your Core Web Vitals (LCP, CLS) collapse, and Google penalizes your organic rankings. Compliance and performance shouldn't be at odds.
What your banner needs to do (CNIL 2024 checklist)
- "Reject all" button as visible as "Accept all"
- Third-party scripts blocked before consent
- Granular choice by purpose (statistics / marketing / preferences)
- Choice remembered for 13 months maximum (CNIL recommendation)
- Ability to withdraw consent at any time
- Consent log kept server-side
- Load time < 50ms so it doesn't impact Core Web Vitals
- Interface available in French (and in the visitor's language if multilingual)
Market solutions: Livada Cookies' positioning
The leading SaaS solutions (Cookiebot, Axeptio, CookieYes…) are full-featured but billed monthly and per site — the cost quickly adds up for an independent business or a chain of properties.
Livada Cookies is a native WordPress plugin (no external script) at €14/year for 1 site, €39/year for 10 sites. It integrates Google Consent Mode v2 (GA4, Google Ads & Site Kit drop no cookies before consent), automatically detects installed tracking plugins, stores timestamped consent logs, and loads in under 30 ms.
Always compare pricing and features on the official websites before choosing: positioning changes over time.
Getting compliant in 15 minutes
With any serious plugin (Livada Cookies or otherwise), here's the process:
- Install the plugin and activate the banner
- Configure the purposes (statistics, marketing, preferences)
- Link each Google/Meta script to its purpose in the plugin
- Verify that scripts are properly blocked before consent (F12 → Network)
- Enable the consent log
- Test the "Reject all" button = zero cookies dropped
Ready to stop wasting time?
Livada SEO + Cockpit give you the pro tools to take action — tested on real hotels and campsites.