Skip to main content
Aevia
Retour au blog
CybersécuritéMarch 20, 20266 min de lecture

GDPR in 2026: what your website absolutely must have

Cookies, legal notice, privacy policy — GDPR obligations are not optional. A clear guide to making your site compliant without drowning in legal jargon.

Key takeaways in 30 seconds

  • 3 mandatory documents: legal notice, privacy policy, and a cookie banner if you track visitors
  • Consent must be explicit — pre-ticked boxes have been illegal since 2020
  • Penalties are real: EU data protection authorities issue heavy fines every year, including for simple infringements
  • Getting compliant takes 1 to 2 days for a standard brochure site

Why GDPR really concerns your small business

"It's for big companies." That is the classic mistake. Data protection authorities oversee small businesses as much as multinationals — and proportional penalties still hurt a small structure.

In practice, if your website:

  • Uses Google Analytics or any other tracking tool
  • Collects emails through a form
  • Sets cookies (advertising, analytics, social media)
  • Processes personal data of European customers

...then GDPR applies to you, and your site must be compliant.


The 3 documents every site must have

1. The legal notice

Mandatory for any professional in most EU countries. It should include:

  • Name or company name of the site's publisher
  • Registered office or professional address
  • Contact phone and email
  • Company registration number
  • Name and details of the site's host
  • If applicable: intra-EU VAT number

2. The privacy policy

Mandatory as soon as you collect personal data (a contact form email, analytics cookies, etc.). It must explain:

  • What data you collect
  • Why (the legal basis and purpose)
  • How long you keep it
  • Who has access (subprocessors, hosts, analytics tools)
  • How users can exercise their rights (access, rectification, deletion)

3. The cookie consent banner

If your site sets non-essential cookies (analytics, advertising, social media), you must obtain consent before setting them — not after.

The rules in force:

  • Refusing must be as easy as accepting
  • No pre-ticked box
  • The visitor must be able to accept or refuse before browsing
  • Consent must be reversible (the user can change their mind)

The most common mistakes

  • Using Google Analytics without prior consent — this is illegal. Several European sites have been sanctioned for exactly this.
  • Having a banner with no clearly visible "Refuse" button — the close "X" does not count as refusal.
  • Generic copy-pasted legal notices without the company's real information.
  • Ignoring contact forms — a form's email field collects personal data. You must state how it is used.

What getting compliant actually involves

For a standard brochure site, basic compliance takes 1 to 2 days:

1. Write the legal notice with your real information

2. Write a privacy policy tailored to your tools (analytics, CRM, newsletter)

3. Install a cookie consent management solution (Axeptio, Cookiebot, or an open-source option)

4. Configure your analytics tool in "cookieless" or "IP anonymization" mode while waiting for consent

AeviaLaunch includes the legal pages natively in its templates — legal notice, privacy policy and cookie management are ready to customize from the start.


Official resources

  • Your national data protection authority (e.g. CNIL in France, AEPD in Spain) — practical guides on GDPR obligations for small businesses
  • Cookiebot Scanner — a free scan of your site to identify every cookie set

Do not underestimate GDPR compliance. It is not esoteric legal work — it is the foundation of the trust your visitors place in you.

Prêt à passer à l'action ?

Site web, audit sécurité ou gestion client — parlons de votre projet en 30 minutes.