Key takeaways in 30 seconds
- 3 mandatory documents: legal notice, privacy policy, and a cookie banner if you track visitors
- Consent must be explicit — pre-ticked boxes have been illegal since 2020
- Penalties are real: EU data protection authorities issue heavy fines every year, including for simple infringements
- Getting compliant takes 1 to 2 days for a standard brochure site
Why GDPR really concerns your small business
"It's for big companies." That is the classic mistake. Data protection authorities oversee small businesses as much as multinationals — and proportional penalties still hurt a small structure.
In practice, if your website:
- Uses Google Analytics or any other tracking tool
- Collects emails through a form
- Sets cookies (advertising, analytics, social media)
- Processes personal data of European customers
...then GDPR applies to you, and your site must be compliant.
The 3 documents every site must have
1. The legal notice
Mandatory for any professional in most EU countries. It should include:
- Name or company name of the site's publisher
- Registered office or professional address
- Contact phone and email
- Company registration number
- Name and details of the site's host
- If applicable: intra-EU VAT number
2. The privacy policy
Mandatory as soon as you collect personal data (a contact form email, analytics cookies, etc.). It must explain:
- What data you collect
- Why (the legal basis and purpose)
- How long you keep it
- Who has access (subprocessors, hosts, analytics tools)
- How users can exercise their rights (access, rectification, deletion)
3. The cookie consent banner
If your site sets non-essential cookies (analytics, advertising, social media), you must obtain consent before setting them — not after.
The rules in force:
- Refusing must be as easy as accepting
- No pre-ticked box
- The visitor must be able to accept or refuse before browsing
- Consent must be reversible (the user can change their mind)
The most common mistakes
- Using Google Analytics without prior consent — this is illegal. Several European sites have been sanctioned for exactly this.
- Having a banner with no clearly visible "Refuse" button — the close "X" does not count as refusal.
- Generic copy-pasted legal notices without the company's real information.
- Ignoring contact forms — a form's email field collects personal data. You must state how it is used.
What getting compliant actually involves
For a standard brochure site, basic compliance takes 1 to 2 days:
1. Write the legal notice with your real information
2. Write a privacy policy tailored to your tools (analytics, CRM, newsletter)
3. Install a cookie consent management solution (Axeptio, Cookiebot, or an open-source option)
4. Configure your analytics tool in "cookieless" or "IP anonymization" mode while waiting for consent
AeviaLaunch includes the legal pages natively in its templates — legal notice, privacy policy and cookie management are ready to customize from the start.
Official resources
- Your national data protection authority (e.g. CNIL in France, AEPD in Spain) — practical guides on GDPR obligations for small businesses
- Cookiebot Scanner — a free scan of your site to identify every cookie set
Do not underestimate GDPR compliance. It is not esoteric legal work — it is the foundation of the trust your visitors place in you.