GDPR compliance for your website: the complete checklist
A GDPR-compliant website rests on 8 points: legal notice, privacy policy, a cookie banner with a genuine choice, minimised HTTPS forms, a record of processing activities, processor contracts, defined retention periods and a process for access and deletion requests. GDPR has applied since May 2018, and France's regulator, the CNIL, can issue fines of up to 20 million euros or 4% of worldwide turnover.
- GDPR in force since May 2018, enforced in France by the CNIL
- Fines of up to 20 million euros or 4% of worldwide turnover
- 8 points to check, from the cookie banner to the processing record
- Access and deletion requests must be answered within 1 month
- Compliant from day one: Neting websites from 490 € and 990 €
What does a non-compliant website actually risk?
A non-compliant website faces sanctions from the CNIL, France's data protection authority, of up to 20 million euros or 4% of worldwide turnover. GDPR has applied since May 2018 to any business that collects personal data, even a single e-mail address through a contact form. Being small is no shield: one complaint from a customer, employee or competitor is enough to trigger an inspection. Before any fine, the regulator can issue a public formal notice, which durably damages a local company's reputation. One important note: this article is a practical checklist for business owners, it does not replace tailored legal advice.
What are the 8 points on the GDPR checklist?
A compliant website rests on 8 essentials: a legal notice, a privacy policy, a cookie banner offering a genuine choice, minimised forms served over HTTPS, a record of processing activities, contracts with your processors, defined retention periods, and a process for handling access and deletion requests. The table below sums up the concrete action expected for each one.
| Point | Concrete action |
|---|---|
| 1. Legal notice | Identify the publisher, the host and a contact channel |
| 2. Privacy policy | Explain which data, why, and for how long |
| 3. Cookie banner | Refusing as easy as accepting, nothing set before the choice |
| 4. Forms | Ask only for what you need, entire site on HTTPS |
| 5. Processing record | List every use of personal data in an internal document |
| 6. Processors | Check the contracts: hosting, newsletter, analytics |
| 7. Retention periods | Set a duration per data type, then actually delete |
| 8. Individual rights | Answer access or erasure requests within 1 month |
Legal notice vs privacy policy: what is the difference?
The legal notice identifies who publishes the website, while the privacy policy explains what you do with people's data. The first is mandatory for any professional site in France: company name, address, hosting provider and a way to reach you. The second details, for each processing activity, its purpose, legal basis, retention period and the visitor's rights. Copy-pasting another site's policy is a trap: it describes processing you do not perform and omits what you actually do. Keep it short, write it in plain language, and update the page every time you add a new tool.
Cookies and consent: how do you get it right in practice?
The rule is simple: no analytics or advertising cookie may be set before the visitor has agreed. Consent must be free and informed: a Refuse all button as visible as Accept all, no pre-ticked boxes, and a permanent link to change one's mind at any time. Continuing to browse does not count as consent. Only cookies strictly necessary for the service (cart, session) are exempt. The official guidelines are published by the CNIL: that is the reference to follow, not your CMS default settings.
What are the most common mistakes in small businesses?
The most frequent mistakes are a cookie banner with no refuse option, forms that ask for too much, and deletion requests left unanswered. Close behind: a site still partly on HTTP, a newsletter built from business cards without consent, a generic privacy policy, no processing record at all, and prospect data kept forever. None of these fixes is expensive: most take a few hours of work. The real risk is doing nothing on the assumption that GDPR only concerns large corporations.
How should you handle access and deletion requests?
You must answer any access, rectification or erasure request within 1 month. In practice: name a contact point in your privacy policy, verify the requester's identity, then provide a copy of the data or confirm its deletion. Keep a written trace of every request and every answer. Remember the copies too: backups, e-mailing tool, CRM. For a small business, a one-page written procedure is enough, provided it is genuinely applied.
How do you get a website that is compliant from day one?
The cheapest approach is to build compliance in from the start rather than patching it afterwards. Neting websites ship compliant by default: HTTPS, a cookie banner with a genuine choice, legal pages, privacy policy and minimised forms, from the Essential package at 490 € (live 5 days after specs sign-off) and with the Business package at 990 € for up to 8 pages, booking and payment included. Hosting from 29 €/month includes maintenance, which keeps the site compliant over time. Free quote, answer within 24h. And keep the other regulatory workstream in sight: digital accessibility, covered in our guide to web accessibility.
Frequently asked questions
Is a simple showcase website without a shop covered by GDPR?
Does a small business need to appoint a data protection officer?
Are audience analytics tools allowed under GDPR?
How much does GDPR compliance cost for a website?
Describe your project in the form: honest reply within 24h, free and with no strings attached.
Related guides
Web accessibility: is your site compliant with the 2025 law?
The European Accessibility Act has applied since 28 June 2025. Who is covered, the 8 priority fixes and how to test your site in 15 minutes, without panic.
Read the guideWebsite quotes: how to compare two proposals that have nothing in common
An 800 € quote versus a 6,000 € quote: an 8-line reading grid, the extras hiding between the lines, and the one question that settles it before you sign.
Read the guideCore Web Vitals: is your website's speed driving customers away?
A slow website costs you customers. LCP, INP and CLS explained in plain English, Google's thresholds, a free 2-minute test and the 6 most common speed killers.
Read the guide