Business

How do you make your website GDPR compliant in 2026: cookie banner, privacy policy and legal notice?

8 April 2026Updated on 18 September 20267 min readBy Bilel Bettaieb, founder
#gdpr compliance website small business 2026
#cnil compliant cookie banner france
#website privacy policy gdpr
#mandatory legal notice website france
#cnil fines personal data non-compliance

The GDPR (General Data Protection Regulation) has been in force since 2018, yet in 2026 many websites are still not compliant. The fines are real and they add up: the CNIL has issued more than 500 million euros in penalties since the regulation came into force, and its enforcement team now inspects small businesses, not just the tech giants.


If your site collects personal data, which covers almost every site with a contact form or Google Analytics, this guide sets out exactly what to do, in what order, and with which tools.


GDPR compliance and personal data protection
GDPR compliance and personal data protection


What is the GDPR and which businesses does it apply to?


The GDPR applies to any business that processes the data of European residents, whatever its size and wherever it is based. A French tradesperson with a contact form on their site, an online shop running Google Analytics, a coach sending a newsletter: all of them are covered.


What counts as personal data? Any information that identifies a person directly or indirectly: name, email, phone number, IP address, browsing cookies, purchase history, location, photograph.


The 7 core principles of the GDPR:

  • Lawfulness: every processing operation needs a legal basis (consent, contract, legitimate interest, legal obligation)
  • Purpose: the data you collect must serve a specific purpose, declared in advance
  • Minimisation: collect only what is strictly necessary for the stated purpose
  • Accuracy: data must be kept up to date and corrected when wrong
  • Storage limitation: no indefinite storage, set retention periods
  • Integrity and confidentiality: protect data against unauthorised access
  • Accountability: be able to prove your compliance at any time

  • CNIL penalties for non-compliant businesses:


    Type of breachMaximum fine
    Minor (formal failings, information)10M€ or 2% of global turnover
    Major (individual rights, security, transfers)20M€ or 4% of global turnover

    Real examples: Google fined 150M€ (non-compliant cookie banner), Amazon 746M€ (targeted advertising without valid consent), a self-employed doctor 5 000€ (patient records left unsecured). The CNIL also runs automated online checks across thousands of sites, small business sites included.


    What are the 7 GDPR items every website must have?


    1. A compliant cookie banner

    The banner has to appear before any non-essential cookie is dropped. It must offer "Accept" and "Reject" with equal prominence (same size, same colour, no hidden or greyed out reject button), allow a granular choice by category, record consent with a timestamp, and ask again at least every 13 months.


    Banned practices: cookie walls (blocking access to the site if the visitor refuses), a "Reject" button that is hidden or hard to find, treating scrolling or browsing as consent, pre-ticked boxes.


    Recommended tools: Axeptio (polished UX, 50€/month), Tarteaucitron (open source, free but needs technical handling), Cookiebot (comprehensive, with an automatic cookie audit).


    2. A privacy policy

    A mandatory document, reachable from every page (a link in the footer). It must state: the identity of the data controller, the categories of data collected and why, the legal basis for each processing operation, who receives the data, any transfers outside the EU, retention periods, and users' rights and how to exercise them.


    3. A legal notice

    Mandatory for every professional site in France (the LCEN law). The publisher's identity (name, SIRET/SIREN, address, email), the publishing director, and the host (name and address). Use our free legal notice generator and it takes 2 minutes.


    4. Compliant forms

    Every form that collects data has to show: a note on how the data will be used, an unticked checkbox for optional uses, and a link to the privacy policy. Never ask for more information than you need at first contact.


    5. Data security

    HTTPS is mandatory (SSL certificate), passwords hashed (never in clear), data access limited to the people who need it, regular backups, access logs.


    6. A record of processing activities

    An internal document listing every processing operation with its purpose, data categories, recipients, retention period and security measures. Mandatory for companies with more than 250 staff, strongly recommended for everyone else.


    7. Handling individual rights

    You must allow: access to the data (a copy of what you hold), rectification, erasure (the "right to be forgotten"), portability (the data in a readable format), and objection. Response deadline: 1 month at most.


    RightDescriptionLegal deadline
    AccessReceive a copy of your data1 month
    RectificationCorrect inaccurate data1 month
    ErasureDelete your data1 month
    PortabilityReceive your data in an exportable format1 month
    ObjectionRefuse processing based on legitimate interestImmediate

    Step by step GDPR compliance
    Step by step GDPR compliance

    How do you make your site GDPR compliant in 4 weeks?


    Week 1, Audit

    List all the data you collect and why. Identify every cookie present on your site (tool: Cookiebot's free Cookie Checker). Check that your legal notice and privacy policy exist and are up to date. Test your cookie banner from a browser in private mode.


    Week 2, Priority fixes

    Put a compliant cookie banner in place (Axeptio or Tarteaucitron). Write or update your privacy policy. Generate your legal notice with our free tool. Update your forms to add the information notices.


    Week 3, Security

    Check that HTTPS is active on every page. Audit access to your back office (who can see what?). Set up automatic daily backups. Review your password policy.


    Week 4, Documentation

    Create your record of processing activities (an Excel sheet is enough). Define the internal process for handling rights requests (who replies, how quickly, how?). If you have a team, train them in the basics of the GDPR.


    On Google Analytics 4: in 2026 GA4 is broadly accepted by the CNIL provided consent is collected before the cookies fire and IP anonymisation is switched on. Compliant cookie-free alternatives: Matomo (open source, can be hosted in France), Plausible or Fathom (European SaaS tools).


    Frequently asked questions about GDPR compliance


    Does the GDPR apply to a brochure site with no form?


    Yes. If you use Google Analytics, the Meta Pixel, Google Tag Manager or any other third party tracker, you are collecting personal data (IP address, browsing cookies). A compliant cookie banner and a privacy policy are needed even for a brochure site with no form. Simply loading a Google Fonts typeface can drop a cookie, so check with a cookie audit tool.


    Do I need to appoint a DPO (Data Protection Officer)?


    Appointing a DPO is mandatory for public bodies and for companies whose core activity involves large scale processing of sensitive data (health, biometric data). For ordinary small businesses (tradespeople, shop owners, independent professionals, agencies) it is not mandatory, though it is strongly advised above 50 staff. Below that, the legal lead or the owner can take on the role.



    No. Cookies strictly necessary for the site to work do not require consent: login session, shopping basket, language choice, CSRF security token. They do still have to be listed in your cookie policy. Only analytics cookies (Google Analytics), marketing cookies (Meta Pixel, Google Ads) and personalisation cookies need explicit, prior consent.


    What actually happens if your site is not GDPR compliant?


    For a small business: a formal notice from the CNIL with a deadline to comply (usually 3 months), then a fine proportionate to turnover if nothing is done. In practice the CNIL goes after serious breaches first (health data, passwords stored in clear, no security at all) rather than a missing legal notice. Since 2023, though, checks on non-compliant cookie banners have multiplied across every kind of site.


    Can you use a privacy policy template found online?


    With care. Generic templates take no account of your own processing: if you run Meta Ads retargeting, store health data or transfer data outside the EU, a standard template will fall short. Use a generator that asks about your actual activity, or bring in a specialist lawyer for sensitive processing.


    Share this article