The verdict in three sentences
GDPR compliance is not a checkbox at the end of a project: it's a requirement to build into the brief from day one. A compliant cookie banner, a record of processing activities, signed DPAs with your processors and EU hosting cover most of the risk. The cost of compliance (1,000-5,000 EUR) is trivial next to a data-authority fine that can reach 4 % of worldwide turnover.
The 2026 compliance checklist
Every line below is verifiable. Tackle them by risk: cookies and information notices account for most complaints filed with data authorities.
| Item | Obligation | Expected status | Indicative cost |
|---|---|---|---|
| Cookie banner | Explicit consent, refusal as easy as accept | Compliant CMP | 0-1,200 EUR/yr |
| Legal notice | Publisher, host, editor | Page published | Included |
| Privacy policy | Purposes, durations, rights | Page up to date | 300-800 EUR |
| Record of processing | Required from 1 activity | Document kept | 500-1,500 EUR |
| Processor DPAs | Art. 28 contract | Signed (host, CRM...) | Included |
| Hosting | Data in the EU | EU server | See host |
| Security | HTTPS, updates, backups | Active | Included in maintenance |
| Forms | Minimisation + legal basis | Limited fields | Included |
Cookies, retention and fines: the numbers that matter
Recent enforcement targeted deceptive banners and the absence of a "reject all" button. Get ahead of it with documented retention periods.
| Data / processing | Usual retention | Legal basis |
|---|---|---|
| Audience-measurement cookies | 13 months max | Consent |
| Prospect (contact form) | 3 years after last contact | Legitimate interest |
| Customer (invoicing) | 10 years (accounting duty) | Legal obligation |
| CV / application | 2 years (unless agreed) | Consent |
| Inactive account | Deletion / anonymisation | Minimisation |
| Major fine | Up to 20 M EUR or 4 % of turnover | — |
| General-obligation fine | Up to 10 M EUR or 2 % of turnover | — |
Mini case study
Sophie, owner of a services SME in Bordeaux (2.4 M EUR turnover), receives a complaint about a cookie banner with no reject button. Rather than risk a fine (theoretically up to 96,000 EUR at 4 % of turnover), she commissions full compliance: compliant CMP, rewritten privacy policy, records created, DPAs signed. Invoice: 2,800 EUR, delivered in three weeks. The risk/cost ratio is decisive: she protects her brand and closes the case with no further action.
FAQ
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Must an SME appoint a DPO?
Not necessarily. A DPO is required for large-scale monitoring or sensitive data. Most SMEs designate an internal point of contact, which is enough while processing stays limited.
Is the cookie banner really mandatory?
Yes, as soon as you drop non-essential cookies (non-exempt analytics, advertising). Refusal must be as easy as acceptance, or you face direct sanction.
Must my host be in Europe?
It's not an absolute obligation, but EU hosting greatly simplifies compliance and avoids non-EU transfer questions. It's the safest choice for an SME.
What's the real financial risk for an SME?
Beyond the fine (up to 4 % of turnover), the real risk is reputational and operational: formal notice, negative publicity and management time. Compliance typically costs 1,000-5,000 EUR.
How long does compliance take?
Two to four weeks for a brochure site, more for e-commerce collecting customer data. The key is documenting processing and securing consent.
Let's scope your project. Describe your site, your forms and your tools (CRM, analytics) and we'll price full GDPR compliance. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
