Websites11 min read

GDPR/CNIL website compliance checklist (2026)

Mohamed Bah·Fondateur, Kolonell
September 4, 2026
Share:
GDPR/CNIL website compliance checklist (2026)

GDPR/CNIL website compliance checklist (2026)

Websites

The verdict in three sentences

A GDPR-compliant brochure website rests on four pillars: cookie consent (CMP), processing register, up-to-date legal notices and privacy policy, and hosting security. In 2026, full compliance costs 800 to 3,000 EUR (ex. tax) depending on site size, in 2 to 4 weeks. The risk justifies the investment: a CNIL fine can reach 20 M EUR or 4% of worldwide revenue.

The 2026 GDPR checklist and its cost

Here are the items to cover for a standard brochure site, with 2026 orders of magnitude in France.

ItemWhat's neededCost ex. tax 2026
Cookie consent CMPCompliant banner, refuse as easy as accept200-600 EUR
Legal noticesPublisher, host, publication director100-300 EUR
Privacy policyPurposes, duration, data subject rights200-500 EUR
Processing registerMap of collected data300-800 EUR
Form securityHTTPS, minimization, encryption150-400 EUR
Audit + attestationOverall check, recommendations400-1,000 EUR

A simple site (5 pages, one contact form) reaches compliance for 800-1,200 EUR; a site with blog, tracking and newsletter rises to 2,000-3,000 EUR.

CNIL sanctions: what you really risk

The CNIL grades its sanctions. Understanding the scale helps you prioritize. These figures are legal ceilings or 2026 observations; the actual sanction depends on severity.

BreachExamplePossible sanction
Cookies without consentTrackers set before agreement20,000-150,000 EUR (SMB)
Missing legal noticesPublisher not identifiableformal notice + fine
Unreported data breachClient file exposed, silenceup to 10 M EUR or 2% revenue
Serious breachMassive unlawful processingup to 20 M EUR or 4% revenue
No registerNo traceabilitypriority formal notice

Even for an SMB, a customer complaint or an online audit can trigger a procedure. The CNIL favors formal notices, but repeat offenses cost dearly.

Mini case study

Mr. Bernard, head of a construction SMB in Nantes (30 employees, brochure site with a quote form and Google Analytics), has neither a compliant CMP nor a processing register.

Compliance quote: CMP 400 EUR + notices/policy 500 EUR + register 600 EUR + audit 500 EUR = 2,000 EUR (ex. tax), delivered in 3 weeks. Against that, a complaint over non-consented trackers would expose his SMB to a fine estimated between 20,000 and 50,000 EUR. The cost/risk ratio is at least 1 to 15: compliance is the cheapest insurance his company has.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

FAQ

Is a cookie banner enough to be compliant?

No. The CMP must let users refuse as easily as accept, and no tracker may fire before consent. You also need the register, legal notices and an up-to-date privacy policy.

How long does compliance take?

Between 2 and 4 weeks for a standard brochure site: audit, document drafting, CMP installation and form security. A complex site with e-commerce takes longer.

Does an SMB need a DPO?

Not always mandatory, but recommended if you process sensitive or large-scale data. Many SMBs outsource a shared DPO for 100-300 EUR/month rather than hiring one.

Is the processing register really required?

Yes, it is mandatory as soon as you process personal data regularly. It is often the first document the CNIL requests during an audit. Its absence is a breach in itself.

How often should the audit be redone?

An annual audit is the right cadence: regulation, your tools and your processing evolve. Budget 400-1,000 EUR/year to maintain compliance and document your diligence.

Let's scope your project. Send us your site URL and the list of your processing activities: we'll scope GDPR/CNIL compliance between 800 and 3,000 EUR (ex. tax), delivered in 2 to 4 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#RGPD#CNIL#conformite site#cookies consentement#mentions legales#amende CNIL#checklist RGPD#protection donnees
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.