Every website published in France or targeting French users must comply with specific legal obligations. Missing legal pages: fines up to €75,000 (individuals) and €375,000 (companies). GDPR non-compliance: up to €20M or 4% of global turnover. Here's exactly what you need — no legal jargon.
Mandatory Legal Pages
| Page | Required By | Fine if Missing | Priority |
|---|---|---|---|
| Legal Notice (Mentions Légales) | LCEN Law (2004) | Up to €75,000 | Critical |
| Privacy Policy | GDPR (2018) | Up to €20M or 4% | Critical |
| Cookie Policy | GDPR + ePrivacy | Up to €20M | Critical |
| Terms of Sale (CGV) | Consumer Code | Up to €15,000 (e-com) | If selling online |
| Terms of Use (CGU) | Recommended | No fine, but exposure | Recommended |
What Your Legal Notice Must Include
- Full company name and legal form (SARL, SAS, EI, etc.)
- SIRET/SIREN number and RCS registration
- Registered address
- Contact info — phone and/or email
- Director/editor name (directeur de publication)
- Hosting provider — name, address, phone number
- VAT number if applicable
- Professional order — if regulated profession (architect, lawyer, etc.)
Privacy Policy Essentials
| Section | What to Include | Example |
|---|---|---|
| Data collected | List all personal data types | Name, email, IP address, cookies |
| Purpose | Why you collect each data type | Contact form, analytics, newsletter |
| Legal basis | Consent, legitimate interest, contract | Consent for newsletter, contract for orders |
| Retention period | How long you keep data | Contact forms: 3 years, invoices: 10 years |
| Third parties | Who receives the data | Google Analytics, Stripe, Mailchimp |
| User rights | Access, rectify, delete, port | Contact DPO at [email protected] |
GDPR Compliance Checklist
- Cookie consent banner — Before ANY non-essential cookie
- Privacy policy — What data, why, how long, who has access
- Opt-in for marketing — Pre-checked boxes are ILLEGAL
- Data access rights — Visitors can request, modify, delete data
- Data processing record — Document what you process
- Data breach notification — 72 hours to notify CNIL
- DPO appointment — Required if large-scale data processing
Cookie Banner Rules
| Rule | Compliant | Non-Compliant |
|---|---|---|
| Consent | Accept / Refuse equally visible | Only "Accept" button |
| Pre-loading | No cookies before consent | Cookies loaded on page visit |
| Categories | Granular choice by category | All-or-nothing |
| Revocation | Easy to change preferences | No way to modify consent |
| Cookie wall | Site usable without consent | "Accept or leave" blocking |
E-commerce: Additional Obligations
- 14-day withdrawal right — No reason needed for returns
- Clear pricing — All taxes and shipping visible before purchase
- Delivery deadlines — Mandatory expected delivery times
- Payment security — PCI-DSS compliance
- Order confirmation — Email with all purchase details
- Online dispute resolution (ODR) — Link to EU mediator platform
"We thought legal pages were just a formality until a competitor reported us to the CNIL for non-compliant cookies. The audit process took 3 months and cost us €8,000 in legal fees. We now make compliance a priority from day one — it's much cheaper to do it right the first time." — Laurent P., e-commerce owner
Need legally compliant pages?
Every website we build includes fully compliant legal pages.
Free GDPR compliance check for your existing site.
Common Mistakes
- Copying legal pages from another site — Must reflect YOUR specific practices
- Using Google Analytics without consent — CNIL ruled this non-compliant
- No cookie banner or "Accept only" banner — Refuse button must be equally visible
- Pre-checked marketing checkboxes — Explicitly illegal under GDPR
- No data retention policy — You must delete data after purpose is fulfilled
- Ignoring the right of deletion — You must honor requests within 30 days
Common Legal Mistakes That Cost Businesses
Legal compliance isn't just about avoiding fines — it's about building trust with increasingly privacy-aware consumers. Here are the most costly mistakes we see on business websites and how to avoid them:
| Mistake | Risk | GDPR Fine | Fix |
|---|---|---|---|
| No cookie consent banner | Using tracking without consent | Up to €20M | CMP with opt-in before tracking |
| Pre-checked consent boxes | Invalid consent under GDPR | Up to 4% revenue | All boxes must be unchecked by default |
| Missing data deletion process | Users can't exercise their rights | Complaint to CNIL | Clear "Delete my data" contact |
| No SSL certificate | Data transmitted in clear text | Security obligation | HTTPS is free via Let's Encrypt |
| Outdated legal pages | Information no longer accurate | Legal obligation | Review twice per year |
The biggest mistake of all? Copying legal pages from another website. Every business has unique data processing activities, and copy-pasting someone else's privacy policy means it won't accurately describe your practices — which is itself a GDPR violation. Always customize your legal documents to match your actual data handling.
GDPR Penalties: Real Risks for SMBs
SMBs often think GDPR only applies to large corporations. That's wrong — data protection authorities audit all company sizes and penalties can reach €20 million or 4% of worldwide annual turnover. In 2024, bakeries, doctors, and craftspeople were penalized for basic failures: contact forms without explicit consent, cookies placed before acceptance, customer data stored without time limits. The five priority actions for compliance: write an accessible privacy policy, configure a compliant cookie banner (active consent, no pre-checked boxes), limit data collection to strict necessity, document your processing in a register, and respond to access or deletion requests within 30 days. These actions take one working day and protect you against 95% of penalty risks.
GDPR Compliance Checklist for Small Businesses
GDPR compliance isn't just a legal obligation — it's a trust signal that improves conversions. Visitors who see clear privacy practices are 23% more likely to share their contact information. Your compliance checklist: (1) publish a comprehensive privacy policy explaining what data you collect, why, and how long you keep it. (2) Add a cookie consent banner with granular opt-in/opt-out options — not just a "Accept All" button. (3) Ensure every form has a link to your privacy policy. (4) Implement data minimization — don't collect data you don't need. (5) Keep a record of processing activities (mandatory under Article 30). (6) Appoint a Data Protection Officer if you process sensitive data at scale.
For small businesses, the biggest risk is complacency. CNIL (France's data protection authority) has increased enforcement against SMBs since 2023, with fines starting at €5,000 for basic violations. The average cost of becoming GDPR compliant for a small business is €500-2,000 — a fraction of potential fines and infinitely cheaper than the reputational damage of a data breach. Start with the essentials: privacy policy, cookie banner, and data processing register.
Cookie Consent: The Right Way to Implement It
Most cookie banners are technically non-compliant. Common mistakes: pre-checked consent boxes (illegal under GDPR), no way to refuse cookies without extra steps, loading tracking scripts before consent is given, and dark patterns that make "Accept All" more prominent than "Reject." A compliant cookie banner must: present Accept and Reject options with equal visual weight, allow granular consent by category (necessary, analytics, marketing), not load any non-essential cookies before explicit consent, and remember the user's choice for subsequent visits.
Tools like Tarteaucitron.js (French, CNIL-recommended), Cookiebot, or OneTrust handle the technical implementation. Configure them to block all non-essential scripts until consent is granted. This means your Google Analytics, Facebook Pixel, and marketing tools won't fire until the user actively agrees — which may reduce your analytics data by 30-40%, but that's the legal requirement. Compensate by optimizing your opt-in rate: explain the value of cookies ("We use analytics to improve your experience") rather than just stating the requirement.
FAQ
Can I copy legal pages from another site?
Absolutely not. Your pages must reflect YOUR data practices, details, and services. Templates are a starting point but must be customized.
Do I need a cookie banner for analytics only?
Yes, if your tool uses cookies (like Google Analytics). Consent BEFORE the script loads. Cookie-free tools (Plausible, Fathom) don't require consent.
What if I'm a freelancer?
Same rules. List your name, SIRET, and address. Use a domiciliation address for privacy if working from home.
How often should I update legal pages?
Every time you add a new tool that collects data (analytics, CRM, email marketing), change hosting, or modify data practices. Review at least annually.
Can I use a free legal page generator?
For basic compliance, generators are a starting point. But they often miss specific details about your data processing. For e-commerce or sensitive data, invest in professional legal review.
Legal pages aren't just a checkbox — they're a trust signal. Professional legal pages show visitors you take privacy seriously and operate a legitimate business.

