You may have received an email along these lines: "Your site doesn't comply with GDPR, you risk a fine of up to 20 million euros." Enough to panic, which is exactly the sender's aim, often someone selling a miracle solution.
Let's take a breath. Yes, GDPR concerns your site. But for a small business, it isn't an insurmountable undertaking, and even less a threat of a giant fine. Those spectacular penalties target large groups; for small outfits, the CNIL (the French data protection authority) acts in the vast majority of cases through formal notices, meaning requests to put things right, not through fines. Its 2025 report confirms it: across all its decisions, formal notices are far more numerous than financial penalties.
So the aim of this article isn't to frighten you, but to tell you, calmly, what a small-business site really has to comply with. And it's simpler than you think.
GDPR concerns your site, but not the way it's sold to you
First thing to understand: GDPR applies as soon as your site collects the slightest piece of personal data. A contact form, a newsletter sign-up, an analytics tool: all of it counts. A showcase site with no shop is therefore covered, if only modestly.
Second thing, reassuring: since GDPR, there's no longer a prior declaration to send to the CNIL. The old logic of a form to file has gone. Instead, you have to be compliant and be able to show it in the event of a check. For a small business, that comes down to a few documents and a few good habits.
One of these documents deserves clarifying, because a misconception is going around: the record of processing activities isn't reserved for large companies. The CNIL recommends that every organisation keep one. Good news, for a small business a simplified version is more than enough: a simple table listing your processing activities (the site and its forms, your customer database, your marketing), what you collect there, why, and how long you keep it. The CNIL provides a free template on cnil.fr.
And a well-built site includes most of these habits from the start. That's what Pixel Prisme does: every site we deliver comes with its legal pages in place and minimal forms, so you start out compliant, without thinking about it.
The two pages your site must have
It all starts with two pages, accessible from your site's footer.
The legal notice. This is an obligation that comes from a 2004 law (the LCEN), separate from GDPR but just as unavoidable. It makes it possible to identify who is behind the site. It must include: your name or your company name, your address, your contact details, your SIRET number (and the RCS or the trades register depending on your activity), and your host's contact details.
The privacy policy. This is the GDPR side. It explains, in plain terms, what data you collect (via the form, the newsletter, the analytics), why, how long you keep it, who has access to it, and what people's rights are. To get started, the CNIL makes free information-notice templates available on its site, cnil.fr, to adapt to your business.
One trap to avoid at all costs: copy-pasting another site's notices. They'll name the wrong controller, the wrong purposes, the wrong retention periods, and protect you from nothing. These two pages must reflect your actual situation. Pixel Prisme writes them bespoke for each project, like the rest of a site's delivery, because an accurate legal page is a thousand times better than a copied one.
Your forms: only ask for what's needed
GDPR rests on a simple, common-sense principle: only collect the data that's genuinely useful. This is what's called data minimisation.
In concrete terms, a contact form only needs the name, a way to get back in touch (email or phone) and the message. Asking for a date of birth or other information for no reason is both pointless and contrary to the principle.
Two habits are then enough. Under the form, add a short note: who processes the data, why ("to answer your enquiry"), for how long, and a link to your privacy policy. And for the newsletter or marketing only, add an unticked checkbox: there, explicit consent is mandatory, and you have to be able to keep a record of it (date, form used) in the event of a check. On the other hand, simply to answer a quote request, this consent isn't needed: answering an enquiry someone sends you is part of your service, which is a different legal basis from consent.
The cookie banner: the good surprise
Here's the most stubborn misconception: "you need a cookie banner on every site". It's false, and it's genuinely good news.
The exact rule, set out by the CNIL: the consent banner is only mandatory for non-essential trackers, such as advertising, profiling (tracking your visitors in order to target them), social media share buttons, or a standard analytics tool that tracks users. For these cases, the banner is required, and refusing must be as simple as accepting.
But the CNIL exempts from consent the cookies strictly necessary for the site to work and analytics set up in a low-key way: a purpose limited to simple visitor statistics, anonymous data, with no cross-referencing against other files or tracking from one site to another. In that case, no more need for an intrusive banner: a simple note in the privacy policy is enough.
In other words, a showcase site that simply measures its traffic in a respectful way can do perfectly well without the banner that annoys everyone. This is precisely Pixel Prisme's approach: we favour low-key, privacy-respecting analytics, which most often avoids the banner, for a lighter, more pleasant site.
Beware, though, of a common trap: if you've already installed Google Analytics in its standard version, you aren't exempt. It's the most widespread tool, and as it is, it requires a consent banner. Same thing for a social media advertising pixel. If you're attached to these tools, the banner is mandatory, with refusing as simple as accepting, and we then set it up properly. The real question to ask yourself: do you need this level of tracking, or are simple visitor statistics enough for you?
Retention periods and people's rights
Two last obligations, simple to keep up.
Don't keep data indefinitely. The principle: no longer than necessary. The CNIL gives a concrete benchmark for marketing: don't keep a prospect or an inactive customer beyond 3 years after their last contact. Past that point, you delete or anonymise. A simple reminder in your diary to have a clear-out once a year is more than enough for a small business.
Let people exercise their rights. Anyone can ask you to access their data, correct it or delete it. You don't need a complicated setup: a dedicated email address, given in your privacy policy, is enough. The only firm rule: reply within one month.
Basic security, which is also part of GDPR
Protecting data also means securing it. Here again, nothing out of reach for a small business. The fundamentals recommended by the CNIL: a site on https (the little padlock), strong passwords with two-factor authentication where possible, regular backups, and a site kept up to date.
One point that ties in with GDPR: knowing where your data is hosted. Hosting within the European Union makes everything simpler. Some very widespread tools, on the other hand, store the data in the United States (American email services, form or analytics tools): it isn't forbidden, but it calls for particular safeguards, to be checked in their terms. If in doubt, choosing European providers spares you the question. It's a subject we also touch on in domain name and professional email.
A word, finally, on responsibility. In the eyes of the CNIL, it's you, the site's owner, who is responsible for its data, even if an agency built it. Hence the value of starting with a provider who lays the right foundations. Pixel Prisme delivers sites secure by default, up to date and well hosted, because security isn't an option you add later, but a foundation.
In short
GDPR isn't the mountain that's waved at you to sell you solutions in a panic. For a small-business site, the essentials come down to a few things: a complete legal notice, a privacy policy specific to your business, forms that only ask for what's needed, an audit of your cookies (often with no banner at the end of it), reasonable retention periods, an address for people's rights, and basic security. None of these steps requires being a lawyer, and the CNIL helps out with free templates.
The simplest thing is to start with a site designed to be compliant from the outset. At Pixel Prisme, that's our standard for businesses in Toulouse and beyond: legal pages in place, minimal forms, respectful analytics and security by default. If you're unsure about your situation, let's talk for 30 minutes, no strings attached: we'll take stock, calmly.