GDPR: what your business website must comply with

GDPR frightens people, often wrongly. Many self-employed people receive alarming emails brandishing fines of several million euros, and end up believing their little showcase site is a ticking time bomb. The reality is simpler: yes, GDPR concerns your site as soon as it collects the slightest piece of data, but for a small business, the obligations are clear, few and proportionate. Here's what you really have to comply with, explained calmly, including the good surprise about the famous cookie banner.

A website's personal data and privacy protected by a padlock

You may have received an email along these lines: "Your site doesn't comply with GDPR, you risk a fine of up to 20 million euros." Enough to panic, which is exactly the sender's aim, often someone selling a miracle solution.

Let's take a breath. Yes, GDPR concerns your site. But for a small business, it isn't an insurmountable undertaking, and even less a threat of a giant fine. Those spectacular penalties target large groups; for small outfits, the CNIL (the French data protection authority) acts in the vast majority of cases through formal notices, meaning requests to put things right, not through fines. Its 2025 report confirms it: across all its decisions, formal notices are far more numerous than financial penalties.

So the aim of this article isn't to frighten you, but to tell you, calmly, what a small-business site really has to comply with. And it's simpler than you think.

GDPR concerns your site, but not the way it's sold to you

First thing to understand: GDPR applies as soon as your site collects the slightest piece of personal data. A contact form, a newsletter sign-up, an analytics tool: all of it counts. A showcase site with no shop is therefore covered, if only modestly.

Second thing, reassuring: since GDPR, there's no longer a prior declaration to send to the CNIL. The old logic of a form to file has gone. Instead, you have to be compliant and be able to show it in the event of a check. For a small business, that comes down to a few documents and a few good habits.

One of these documents deserves clarifying, because a misconception is going around: the record of processing activities isn't reserved for large companies. The CNIL recommends that every organisation keep one. Good news, for a small business a simplified version is more than enough: a simple table listing your processing activities (the site and its forms, your customer database, your marketing), what you collect there, why, and how long you keep it. The CNIL provides a free template on cnil.fr.

And a well-built site includes most of these habits from the start. That's what Pixel Prisme does: every site we deliver comes with its legal pages in place and minimal forms, so you start out compliant, without thinking about it.

The two pages your site must have

It all starts with two pages, accessible from your site's footer.

The legal notice. This is an obligation that comes from a 2004 law (the LCEN), separate from GDPR but just as unavoidable. It makes it possible to identify who is behind the site. It must include: your name or your company name, your address, your contact details, your SIRET number (and the RCS or the trades register depending on your activity), and your host's contact details.

The privacy policy. This is the GDPR side. It explains, in plain terms, what data you collect (via the form, the newsletter, the analytics), why, how long you keep it, who has access to it, and what people's rights are. To get started, the CNIL makes free information-notice templates available on its site, cnil.fr, to adapt to your business.

One trap to avoid at all costs: copy-pasting another site's notices. They'll name the wrong controller, the wrong purposes, the wrong retention periods, and protect you from nothing. These two pages must reflect your actual situation. Pixel Prisme writes them bespoke for each project, like the rest of a site's delivery, because an accurate legal page is a thousand times better than a copied one.

Your forms: only ask for what's needed

GDPR rests on a simple, common-sense principle: only collect the data that's genuinely useful. This is what's called data minimisation.

In concrete terms, a contact form only needs the name, a way to get back in touch (email or phone) and the message. Asking for a date of birth or other information for no reason is both pointless and contrary to the principle.

Two habits are then enough. Under the form, add a short note: who processes the data, why ("to answer your enquiry"), for how long, and a link to your privacy policy. And for the newsletter or marketing only, add an unticked checkbox: there, explicit consent is mandatory, and you have to be able to keep a record of it (date, form used) in the event of a check. On the other hand, simply to answer a quote request, this consent isn't needed: answering an enquiry someone sends you is part of your service, which is a different legal basis from consent.

Here's the most stubborn misconception: "you need a cookie banner on every site". It's false, and it's genuinely good news.

The exact rule, set out by the CNIL: the consent banner is only mandatory for non-essential trackers, such as advertising, profiling (tracking your visitors in order to target them), social media share buttons, or a standard analytics tool that tracks users. For these cases, the banner is required, and refusing must be as simple as accepting.

But the CNIL exempts from consent the cookies strictly necessary for the site to work and analytics set up in a low-key way: a purpose limited to simple visitor statistics, anonymous data, with no cross-referencing against other files or tracking from one site to another. In that case, no more need for an intrusive banner: a simple note in the privacy policy is enough.

In other words, a showcase site that simply measures its traffic in a respectful way can do perfectly well without the banner that annoys everyone. This is precisely Pixel Prisme's approach: we favour low-key, privacy-respecting analytics, which most often avoids the banner, for a lighter, more pleasant site.

Beware, though, of a common trap: if you've already installed Google Analytics in its standard version, you aren't exempt. It's the most widespread tool, and as it is, it requires a consent banner. Same thing for a social media advertising pixel. If you're attached to these tools, the banner is mandatory, with refusing as simple as accepting, and we then set it up properly. The real question to ask yourself: do you need this level of tracking, or are simple visitor statistics enough for you?

Retention periods and people's rights

Two last obligations, simple to keep up.

Don't keep data indefinitely. The principle: no longer than necessary. The CNIL gives a concrete benchmark for marketing: don't keep a prospect or an inactive customer beyond 3 years after their last contact. Past that point, you delete or anonymise. A simple reminder in your diary to have a clear-out once a year is more than enough for a small business.

Let people exercise their rights. Anyone can ask you to access their data, correct it or delete it. You don't need a complicated setup: a dedicated email address, given in your privacy policy, is enough. The only firm rule: reply within one month.

Basic security, which is also part of GDPR

Protecting data also means securing it. Here again, nothing out of reach for a small business. The fundamentals recommended by the CNIL: a site on https (the little padlock), strong passwords with two-factor authentication where possible, regular backups, and a site kept up to date.

One point that ties in with GDPR: knowing where your data is hosted. Hosting within the European Union makes everything simpler. Some very widespread tools, on the other hand, store the data in the United States (American email services, form or analytics tools): it isn't forbidden, but it calls for particular safeguards, to be checked in their terms. If in doubt, choosing European providers spares you the question. It's a subject we also touch on in domain name and professional email.

A word, finally, on responsibility. In the eyes of the CNIL, it's you, the site's owner, who is responsible for its data, even if an agency built it. Hence the value of starting with a provider who lays the right foundations. Pixel Prisme delivers sites secure by default, up to date and well hosted, because security isn't an option you add later, but a foundation.

In short

GDPR isn't the mountain that's waved at you to sell you solutions in a panic. For a small-business site, the essentials come down to a few things: a complete legal notice, a privacy policy specific to your business, forms that only ask for what's needed, an audit of your cookies (often with no banner at the end of it), reasonable retention periods, an address for people's rights, and basic security. None of these steps requires being a lawyer, and the CNIL helps out with free templates.

The simplest thing is to start with a site designed to be compliant from the outset. At Pixel Prisme, that's our standard for businesses in Toulouse and beyond: legal pages in place, minimal forms, respectful analytics and security by default. If you're unsure about your situation, let's talk for 30 minutes, no strings attached: we'll take stock, calmly.

Further reading

FAQ

Frequently asked questions

Your questions, clear answers.

Where do I start to get my site compliant?

No need to aim for perfect compliance straight away. Six steps, in this order, cover the essentials for a small business:

  • Display a complete legal notice (who publishes the site, who hosts it, your SIRET number).
  • Write a clear privacy policy specific to your business, never copied from another site.
  • Under your forms, add a short information note and a link to that policy.
  • Audit your cookies: with no advertising or profiling, you can often avoid the banner.
  • Set reasonable retention periods and delete old contacts.
  • Set up an email address for access or deletion requests.
Is a cookie banner really mandatory on my site?

Not always, contrary to popular belief. The consent banner is only mandatory for non-essential trackers: advertising, profiling, social media sharing, or a standard analytics tool. The CNIL, on the other hand, exempts from consent the cookies strictly necessary for the site and low-key analytics (anonymous, with no data cross-referencing or tracking between sites). A simple showcase site set up this way just needs a note in its privacy policy, with no intrusive banner.

Is my small showcase site really covered by GDPR?

Yes, as soon as it collects data: a contact form, a newsletter or a simple analytics tool are enough. But the obligations stay proportionate to your size. A typical small business generally doesn't need to appoint a data protection officer (DPO). A record of processing activities is still expected, but its simplified version (a table of your processing activities) is enough. For the rest, a legal notice, a privacy policy, minimal forms and a bit of security cover the essentials.

How long can I keep my contacts and my customer database?

The principle: no longer than necessary. The CNIL gives a useful benchmark for marketing: don't keep a prospect's or an inactive customer's data beyond 3 years after their last contact. Beyond that, you delete or anonymise. Some legal obligations (accounting) require keeping specific documents for longer, but in a separate archive, not in your day-to-day marketing database.