The GDPR (General Data Protection Regulation) has been in force since 2018, yet in 2026 many websites are still not compliant. The fines are real and they add up: the CNIL has issued more than 500 million euros in penalties since the regulation came into force, and its enforcement team now inspects small businesses, not just the tech giants.
If your site collects personal data, which covers almost every site with a contact form or Google Analytics, this guide sets out exactly what to do, in what order, and with which tools.
What is the GDPR and which businesses does it apply to?
The GDPR applies to any business that processes the data of European residents, whatever its size and wherever it is based. A French tradesperson with a contact form on their site, an online shop running Google Analytics, a coach sending a newsletter: all of them are covered.
What counts as personal data? Any information that identifies a person directly or indirectly: name, email, phone number, IP address, browsing cookies, purchase history, location, photograph.
The 7 core principles of the GDPR:
CNIL penalties for non-compliant businesses:
| Type of breach | Maximum fine |
|---|---|
| Minor (formal failings, information) | 10M€ or 2% of global turnover |
| Major (individual rights, security, transfers) | 20M€ or 4% of global turnover |
Real examples: Google fined 150M€ (non-compliant cookie banner), Amazon 746M€ (targeted advertising without valid consent), a self-employed doctor 5 000€ (patient records left unsecured). The CNIL also runs automated online checks across thousands of sites, small business sites included.
What are the 7 GDPR items every website must have?
1. A compliant cookie banner
The banner has to appear before any non-essential cookie is dropped. It must offer "Accept" and "Reject" with equal prominence (same size, same colour, no hidden or greyed out reject button), allow a granular choice by category, record consent with a timestamp, and ask again at least every 13 months.
Banned practices: cookie walls (blocking access to the site if the visitor refuses), a "Reject" button that is hidden or hard to find, treating scrolling or browsing as consent, pre-ticked boxes.
Recommended tools: Axeptio (polished UX, 50€/month), Tarteaucitron (open source, free but needs technical handling), Cookiebot (comprehensive, with an automatic cookie audit).
2. A privacy policy
A mandatory document, reachable from every page (a link in the footer). It must state: the identity of the data controller, the categories of data collected and why, the legal basis for each processing operation, who receives the data, any transfers outside the EU, retention periods, and users' rights and how to exercise them.
3. A legal notice
Mandatory for every professional site in France (the LCEN law). The publisher's identity (name, SIRET/SIREN, address, email), the publishing director, and the host (name and address). Use our free legal notice generator and it takes 2 minutes.
4. Compliant forms
Every form that collects data has to show: a note on how the data will be used, an unticked checkbox for optional uses, and a link to the privacy policy. Never ask for more information than you need at first contact.
5. Data security
HTTPS is mandatory (SSL certificate), passwords hashed (never in clear), data access limited to the people who need it, regular backups, access logs.
6. A record of processing activities
An internal document listing every processing operation with its purpose, data categories, recipients, retention period and security measures. Mandatory for companies with more than 250 staff, strongly recommended for everyone else.
7. Handling individual rights
You must allow: access to the data (a copy of what you hold), rectification, erasure (the "right to be forgotten"), portability (the data in a readable format), and objection. Response deadline: 1 month at most.
| Right | Description | Legal deadline |
|---|---|---|
| Access | Receive a copy of your data | 1 month |
| Rectification | Correct inaccurate data | 1 month |
| Erasure | Delete your data | 1 month |
| Portability | Receive your data in an exportable format | 1 month |
| Objection | Refuse processing based on legitimate interest | Immediate |
How do you make your site GDPR compliant in 4 weeks?
Week 1, Audit
List all the data you collect and why. Identify every cookie present on your site (tool: Cookiebot's free Cookie Checker). Check that your legal notice and privacy policy exist and are up to date. Test your cookie banner from a browser in private mode.
Week 2, Priority fixes
Put a compliant cookie banner in place (Axeptio or Tarteaucitron). Write or update your privacy policy. Generate your legal notice with our free tool. Update your forms to add the information notices.
Week 3, Security
Check that HTTPS is active on every page. Audit access to your back office (who can see what?). Set up automatic daily backups. Review your password policy.
Week 4, Documentation
Create your record of processing activities (an Excel sheet is enough). Define the internal process for handling rights requests (who replies, how quickly, how?). If you have a team, train them in the basics of the GDPR.
On Google Analytics 4: in 2026 GA4 is broadly accepted by the CNIL provided consent is collected before the cookies fire and IP anonymisation is switched on. Compliant cookie-free alternatives: Matomo (open source, can be hosted in France), Plausible or Fathom (European SaaS tools).
Frequently asked questions about GDPR compliance
Does the GDPR apply to a brochure site with no form?
Yes. If you use Google Analytics, the Meta Pixel, Google Tag Manager or any other third party tracker, you are collecting personal data (IP address, browsing cookies). A compliant cookie banner and a privacy policy are needed even for a brochure site with no form. Simply loading a Google Fonts typeface can drop a cookie, so check with a cookie audit tool.
Do I need to appoint a DPO (Data Protection Officer)?
Appointing a DPO is mandatory for public bodies and for companies whose core activity involves large scale processing of sensitive data (health, biometric data). For ordinary small businesses (tradespeople, shop owners, independent professionals, agencies) it is not mandatory, though it is strongly advised above 50 staff. Below that, the legal lead or the owner can take on the role.
Do essential cookies need consent?
No. Cookies strictly necessary for the site to work do not require consent: login session, shopping basket, language choice, CSRF security token. They do still have to be listed in your cookie policy. Only analytics cookies (Google Analytics), marketing cookies (Meta Pixel, Google Ads) and personalisation cookies need explicit, prior consent.
What actually happens if your site is not GDPR compliant?
For a small business: a formal notice from the CNIL with a deadline to comply (usually 3 months), then a fine proportionate to turnover if nothing is done. In practice the CNIL goes after serious breaches first (health data, passwords stored in clear, no security at all) rather than a missing legal notice. Since 2023, though, checks on non-compliant cookie banners have multiplied across every kind of site.
Can you use a privacy policy template found online?
With care. Generic templates take no account of your own processing: if you run Meta Ads retargeting, store health data or transfer data outside the EU, a standard template will fall short. Use a generator that asks about your actual activity, or bring in a specialist lawyer for sensitive processing.


