The verdict in three sentences
Bringing a brochure site into GDPR compliance costs between 1,900 and 5,500 EUR in 2026 depending on depth (audit, compliant cookie CMP, notice rewrite, records of processing), in 2 to 4 weeks. The risk of inaction is disproportionate: France's CNIL can impose fines up to 4% of worldwide annual turnover or 20M EUR. In 2026, enforcement focuses primarily on cookie consent (compliant banner, refusal as easy as acceptance, no tracking before a choice is made).
The item breakdown
Compliance is not a single product but a set of deliverables. Here are the 2026 ranges for a brochure site.
| Item | Content | 2026 range (EUR) | Timeline |
|---|---|---|---|
| GDPR audit + records of processing | Data mapping, register | 1,000 - 3,000 | 1-2 wks |
| Compliant CMP / cookie banner | Consent, categorisation, logging | 500 - 1,500 | 3-5 d |
| Legal notices & privacy policy rewrite | Compliant texts, DPO, rights | 400 - 1,000 | 3-5 d |
| Form security (encryption, retention) | Minimisation, TLS, purge | 300 - 800 | 2-4 d |
| Indicative total | 1,900 - 5,500 | 2-4 wks |
The CMP (Consent Management Platform) is the most scrutinised item: it must block trackers before consent, offer one-click refusal and log proof of consent. A simple "OK" banner has long since stopped being enough.
CNIL's 2026 control points
Automated checks and complaints target recurring non-compliances. Here are the most sanctioned gaps and their remedy.
| Control point | Frequent non-compliance | Remedy |
|---|---|---|
| Cookie consent | Trackers set before choice | CMP with prior blocking |
| Accept/refuse symmetry | Hidden or multi-click refusal | Refuse button visible at level 1 |
| Retention period | Data kept indefinitely | Documented purge policy |
| Information | Missing or vague notices | Clear privacy policy |
| Records of processing | Non-existent | Register kept and up to date |
| Security | Forms over HTTP, no TLS | HTTPS + encryption |
Mini case study
Karim, manager of a consulting SME in Marseille (turnover 1.4M EUR), receives a CNIL formal notice after a complaint about cookies set without consent. The theoretical fine ceiling is 4% of turnover, i.e. 56,000 EUR.
Compliance quote: audit + records at 2,200 EUR, compliant CMP at 900 EUR, notice rewrite at 600 EUR, i.e. 3,700 EUR over three weeks. The benefit/risk ratio is overwhelming: 3,700 EUR invested removes a 56,000 EUR exposure and closes the CNIL file. Karim regularises within the deadline and documents his compliance for any future audit.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
What is the maximum CNIL fine?
Up to 4% of worldwide annual turnover or 20M EUR, whichever is higher. In practice, SMEs first receive a formal notice before a financial penalty.
Is an "accept all" cookie banner enough?
No. Refusal must be as easy as acceptance and no non-essential tracker may be set before the visitor's choice.
Are records of processing mandatory for a small business?
Yes in most cases as soon as there is regular data processing. It is also the first document requested during an audit.
How long to become compliant?
Between 2 and 4 weeks for a brochure site, with the audit and notice drafting being the longest steps.
Do I need a DPO?
Not always mandatory for an SME, but appointing a contact and documenting processing is strongly recommended and reassures in an audit.
Let's scope your project. Describe your site, forms and tracking tools, and we'll price the audit and full compliance. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.