The verdict in three sentences
GDPR is not just for large groups: a simple contact form or a Google Analytics cookie is enough to make you a data controller. A non-compliant SMB risks a fine of up to 4% of its worldwide annual turnover (or 20 M€), on top of lost customer trust. Yet getting a brochure site compliant is fast and affordable: 800 to 3,000 € of work, an audit at 500–1,500 €, and a clear checklist secure the essentials.
The 2026 checklist in 15 points
Each point below is verifiable in minutes. Prioritise the lines marked "critical".
| # | Control point | Priority | Indicative cost |
|---|---|---|---|
| 1 | Compliant consent banner (refuse as easy as accept) | Critical | 300–800 € |
| 2 | Cookie blocking before consent | Critical | included |
| 3 | Up-to-date privacy policy | Critical | 200–500 € |
| 4 | Complete legal notices | High | 100–300 € |
| 5 | Data hosted in the EU | Critical | variable |
| 6 | Records of processing activities | High | 300–700 € |
| 7 | Legal basis documented per process | High | included |
| 8 | Explicit form consent | Critical | 150–400 € |
| 9 | Defined retention period | Medium | included |
| 10 | Working access/erasure rights | High | 200–500 € |
| 11 | HTTPS/SSL encryption | Critical | 0–100 € |
| 12 | Contract/DPA with sub-processors | High | included |
| 13 | Anonymised or consented analytics | High | 100–300 € |
| 14 | Breach notification procedure | Medium | 200–400 € |
| 15 | Appoint a DPO if required | Case-based | 0–1,500 €/yr |
The three items regulators flag most: the cookie banner (refusing must be as easy as accepting), cookies dropped before consent, and a missing or generic privacy policy.
The risks, quantified
Sanctions are not theoretical: regulators fine SMBs every year, often triggered by a single citizen complaint.
| Breach | Possible sanction | Frequency in audits |
|---|---|---|
| Cookies without valid consent | up to 2% of turnover | Very high |
| No privacy policy | formal notice + fine | High |
| Security failure (breach) | up to 4% of turnover | Medium |
| Access-rights non-compliance | fine + injunction | Medium |
| Unframed non-EU transfer | fine | Rising |
A formal notice is often the first signal: handling it on time avoids the fine but mobilises the owner in a rush. Anticipating costs 10 times less than reacting.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Sophie, owner of a 12-person consulting firm in Nantes, receives a complaint from a former prospect about her advertising cookies. Her site has neither a compliant banner nor an up-to-date privacy policy. She orders a 900 € audit then a 1,800 € remediation (compliant banner, policy, records, forms).
Math: total investment 2,700 €. Against a sanction risk of 2 to 4% of annual turnover (tens of thousands of euros for a 1.2 M€ turnover), the cost/risk ratio is decisive. The job wraps in 3 weeks, and the firm now shows a compliant banner that reassures its enterprise clients.
FAQ
How much does GDPR compliance for a brochure site cost? Budget 800 to 3,000 € depending on complexity (forms, analytics, sub-processors), plus a 500–1,500 € audit. A standard SMB lands around 2,000 to 2,700 € all-in.
Is a brochure site without e-commerce subject to GDPR? Yes, as soon as it drops cookies, offers a contact form or a newsletter. Collecting a single email address triggers the obligations.
Must the cookie banner let users refuse as easily as accept? Yes, that has been an explicit regulator requirement since 2022: "Reject all" must be as accessible as "Accept all". A banner hiding refusal is non-compliant.
Does an SMB always need a DPO? No, unless it processes sensitive data at scale or runs systematic monitoring. Most SMBs have no obligation, but naming an internal point of contact is recommended.
What is the real risk in an audit? A formal notice first, then a fine of up to 4% of worldwide annual turnover for serious breaches. Citizen complaints are the leading trigger for audits.
Let's scope your project. Tell us your sector, the number of forms/third-party tools on your site and your deadline: we run the audit then deliver a compliant site (consent banner, policy, records). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
