Practical Guide8 min read

Legal Notices & GDPR: What Your Website Must Display

GDPR fines can reach €20M. Legal notices, privacy policy, cookie banners: everything your website must display to comply with the law in 2026.

Legal Notices & GDPR: What Your Website Must Display

Every website published in France or targeting French users must comply with specific legal obligations. Missing legal pages: fines up to €75,000 (individuals) and €375,000 (companies). GDPR non-compliance: up to €20M or 4% of global turnover. Here's exactly what you need — no legal jargon.

Mandatory Legal Pages

PageRequired ByFine if MissingPriority
Legal Notice (Mentions Légales)LCEN Law (2004)Up to €75,000Critical
Privacy PolicyGDPR (2018)Up to €20M or 4%Critical
Cookie PolicyGDPR + ePrivacyUp to €20MCritical
Terms of Sale (CGV)Consumer CodeUp to €15,000 (e-com)If selling online
Terms of Use (CGU)RecommendedNo fine, but exposureRecommended

What Your Legal Notice Must Include

  • Full company name and legal form (SARL, SAS, EI, etc.)
  • SIRET/SIREN number and RCS registration
  • Registered address
  • Contact info — phone and/or email
  • Director/editor name (directeur de publication)
  • Hosting provider — name, address, phone number
  • VAT number if applicable
  • Professional order — if regulated profession (architect, lawyer, etc.)

Privacy Policy Essentials

SectionWhat to IncludeExample
Data collectedList all personal data typesName, email, IP address, cookies
PurposeWhy you collect each data typeContact form, analytics, newsletter
Legal basisConsent, legitimate interest, contractConsent for newsletter, contract for orders
Retention periodHow long you keep dataContact forms: 3 years, invoices: 10 years
Third partiesWho receives the dataGoogle Analytics, Stripe, Mailchimp
User rightsAccess, rectify, delete, portContact DPO at [email protected]

GDPR Compliance Checklist

  • Cookie consent banner — Before ANY non-essential cookie
  • Privacy policy — What data, why, how long, who has access
  • Opt-in for marketing — Pre-checked boxes are ILLEGAL
  • Data access rights — Visitors can request, modify, delete data
  • Data processing record — Document what you process
  • Data breach notification — 72 hours to notify CNIL
  • DPO appointment — Required if large-scale data processing

Cookie Banner Rules

RuleCompliant Non-Compliant
ConsentAccept / Refuse equally visibleOnly "Accept" button
Pre-loadingNo cookies before consentCookies loaded on page visit
CategoriesGranular choice by categoryAll-or-nothing
RevocationEasy to change preferencesNo way to modify consent
Cookie wallSite usable without consent"Accept or leave" blocking
CNIL enforcement is real: €120M+ in 2024 fines. The CNIL increasingly targets SMEs with non-compliant sites, especially those using Google Analytics without consent. In 2022, the CNIL ruled that standard Google Analytics was itself non-compliant due to US data transfers.

E-commerce: Additional Obligations

  • 14-day withdrawal right — No reason needed for returns
  • Clear pricing — All taxes and shipping visible before purchase
  • Delivery deadlines — Mandatory expected delivery times
  • Payment security — PCI-DSS compliance
  • Order confirmation — Email with all purchase details
  • Online dispute resolution (ODR) — Link to EU mediator platform
"We thought legal pages were just a formality until a competitor reported us to the CNIL for non-compliant cookies. The audit process took 3 months and cost us €8,000 in legal fees. We now make compliance a priority from day one — it's much cheaper to do it right the first time." — Laurent P., e-commerce owner

Need legally compliant pages?

Every website we build includes fully compliant legal pages.
Free GDPR compliance check for your existing site.

Check my compliance
Free quote
No commitment
Response within 24h

Common Mistakes

  • Copying legal pages from another site — Must reflect YOUR specific practices
  • Using Google Analytics without consent — CNIL ruled this non-compliant
  • No cookie banner or "Accept only" banner — Refuse button must be equally visible
  • Pre-checked marketing checkboxes — Explicitly illegal under GDPR
  • No data retention policy — You must delete data after purpose is fulfilled
  • Ignoring the right of deletion — You must honor requests within 30 days

Common Legal Mistakes That Cost Businesses

Legal compliance isn't just about avoiding fines — it's about building trust with increasingly privacy-aware consumers. Here are the most costly mistakes we see on business websites and how to avoid them:

MistakeRiskGDPR FineFix
No cookie consent bannerUsing tracking without consentUp to €20MCMP with opt-in before tracking
Pre-checked consent boxesInvalid consent under GDPRUp to 4% revenueAll boxes must be unchecked by default
Missing data deletion processUsers can't exercise their rightsComplaint to CNILClear "Delete my data" contact
No SSL certificateData transmitted in clear textSecurity obligationHTTPS is free via Let's Encrypt
Outdated legal pagesInformation no longer accurateLegal obligationReview twice per year

The biggest mistake of all? Copying legal pages from another website. Every business has unique data processing activities, and copy-pasting someone else's privacy policy means it won't accurately describe your practices — which is itself a GDPR violation. Always customize your legal documents to match your actual data handling.

GDPR Penalties: Real Risks for SMBs

SMBs often think GDPR only applies to large corporations. That's wrong — data protection authorities audit all company sizes and penalties can reach €20 million or 4% of worldwide annual turnover. In 2024, bakeries, doctors, and craftspeople were penalized for basic failures: contact forms without explicit consent, cookies placed before acceptance, customer data stored without time limits. The five priority actions for compliance: write an accessible privacy policy, configure a compliant cookie banner (active consent, no pre-checked boxes), limit data collection to strict necessity, document your processing in a register, and respond to access or deletion requests within 30 days. These actions take one working day and protect you against 95% of penalty risks.

GDPR Compliance Checklist for Small Businesses

GDPR compliance isn't just a legal obligation — it's a trust signal that improves conversions. Visitors who see clear privacy practices are 23% more likely to share their contact information. Your compliance checklist: (1) publish a comprehensive privacy policy explaining what data you collect, why, and how long you keep it. (2) Add a cookie consent banner with granular opt-in/opt-out options — not just a "Accept All" button. (3) Ensure every form has a link to your privacy policy. (4) Implement data minimization — don't collect data you don't need. (5) Keep a record of processing activities (mandatory under Article 30). (6) Appoint a Data Protection Officer if you process sensitive data at scale.

For small businesses, the biggest risk is complacency. CNIL (France's data protection authority) has increased enforcement against SMBs since 2023, with fines starting at €5,000 for basic violations. The average cost of becoming GDPR compliant for a small business is €500-2,000 — a fraction of potential fines and infinitely cheaper than the reputational damage of a data breach. Start with the essentials: privacy policy, cookie banner, and data processing register.

Cookie Consent: The Right Way to Implement It

Most cookie banners are technically non-compliant. Common mistakes: pre-checked consent boxes (illegal under GDPR), no way to refuse cookies without extra steps, loading tracking scripts before consent is given, and dark patterns that make "Accept All" more prominent than "Reject." A compliant cookie banner must: present Accept and Reject options with equal visual weight, allow granular consent by category (necessary, analytics, marketing), not load any non-essential cookies before explicit consent, and remember the user's choice for subsequent visits.

Tools like Tarteaucitron.js (French, CNIL-recommended), Cookiebot, or OneTrust handle the technical implementation. Configure them to block all non-essential scripts until consent is granted. This means your Google Analytics, Facebook Pixel, and marketing tools won't fire until the user actively agrees — which may reduce your analytics data by 30-40%, but that's the legal requirement. Compensate by optimizing your opt-in rate: explain the value of cookies ("We use analytics to improve your experience") rather than just stating the requirement.

FAQ

Can I copy legal pages from another site?

Absolutely not. Your pages must reflect YOUR data practices, details, and services. Templates are a starting point but must be customized.

Do I need a cookie banner for analytics only?

Yes, if your tool uses cookies (like Google Analytics). Consent BEFORE the script loads. Cookie-free tools (Plausible, Fathom) don't require consent.

What if I'm a freelancer?

Same rules. List your name, SIRET, and address. Use a domiciliation address for privacy if working from home.

How often should I update legal pages?

Every time you add a new tool that collects data (analytics, CRM, email marketing), change hosting, or modify data practices. Review at least annually.

Can I use a free legal page generator?

For basic compliance, generators are a starting point. But they often miss specific details about your data processing. For e-commerce or sensitive data, invest in professional legal review.

Legal pages aren't just a checkbox — they're a trust signal. Professional legal pages show visitors you take privacy seriously and operate a legitimate business.

Related Articles

Get legally compliant pages →