Contents
- Is a privacy policy mandatory on a website in France?
- Does a brochure website with no contact form need a privacy policy?
- What must a GDPR privacy policy contain?
- Which legal basis should I state for each processing purpose?
- What is the difference between a privacy policy, a cookie policy and a legal notice?
- What should a privacy policy template say, section by section?
- Where should the privacy policy go on my website?
- What is the fine for not having a privacy policy in France?
- What are the most common privacy policy mistakes?
- Will the EU Digital Omnibus change the GDPR information duty?
- How do I check my privacy policy before publishing it?
On 19 September 2024, a gun shop selling online and in store was fined €20,000 by the CNIL (the French data protection authority) under its simplified procedure. Alongside data security and the right to erasure, the CNIL found two breaches you can read straight off a privacy policy: “information of individuals and transparency” and “retention period”. Not a tech giant: a shop with an e-commerce site.
The GDPR is EU-wide, so the core rules below are the same across the EU. What is French is the enforcer (the CNIL), its simplified sanction procedure, a criminal penalty on top, and a separate cookie provision in French law. A contact form is enough to make a « politique de confidentialité » (privacy policy) mandatory, and a brochure site with no form rarely escapes it. Here is what the text says, and an annotated template, section by section.
Is a privacy policy mandatory on a website in France?
Yes, as soon as the site collects any personal data: articles 13 and 14 of the GDPR require you to inform people at the time of collection. The regulation never uses the words “privacy policy”, but that is the form this information takes on a website.
What the law says
Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; […]
Article 12 adds the how: information “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”. For data obtained from a third party (a bought list, contacts gathered from LinkedIn), article 14 requires you to inform people within a reasonable period of no more than one month, or at the latest when you first contact them.
What triggers the obligation on a small business website:
| On your site | Data collected | Privacy policy |
|---|---|---|
| Contact or quote form | Name, email, phone, message | Mandatory |
| Newsletter sign-up | Email, first name, opens and clicks | Mandatory |
| Customer accounts, online shop | Identity, addresses, orders, payment | Mandatory |
| Online booking | Name, contact details, time slot, subject | Mandatory |
| Audience measurement tool | Tracker ID, pages viewed, IP address | Mandatory, with the cookie information |
| Embedded video, map or social network | IP address sent to the provider, sometimes trackers | Mandatory |
| Plain page with no form or third-party tool | IP address in server logs | See the next question |
The official French government page on mandatory website information (in French) gives the contact form as an example and states that this policy must be separate from your « CGV » (terms of sale).
Does a brochure website with no contact form need a privacy policy?
In almost every case, yes. Even without a form, a site records IP addresses in its server logs, and the Court of Justice of the European Union has ruled that an IP address can be personal data for the website publisher.
In the Breyer judgment of 19 October 2016, the Court held that a dynamic IP address recorded by a website publisher is personal data for that publisher when it has legal means to have the person identified through their internet access provider.
Other processing almost always comes on top, often invisible:
- an audience measurement tool installed by your agency or your theme;
- a YouTube video, a map or a font loaded from a third-party server, which passes the visitor’s IP address to that third party;
- a displayed email address: the messages you receive are data collected from the people who send them.
Only a site that collects strictly nothing escapes article 13, and that means checking every script and every embedded item. A ten-line policy costs less than that check.
flowchart TD
A["Your website"] --> B{"Form, account or newsletter?"}
B -->|Yes| P["Full policy mandatory"]
B -->|No| C{"Analytics or embedded content?"}
C -->|Yes| P2["Policy mandatory, with a cookie section"]
C -->|No| D{"Server logs or contact email?"}
D -->|Yes| P3["A short policy is enough"]
D -->|No| E["No collection: check every script"]To see what your home page actually loads, the free cookie scanner detects known trackers and the cookies set on first load.
What must a GDPR privacy policy contain?
The information listed in article 13 of the GDPR: who processes the data, why and on what basis, who it is shared with, where it goes, how long it is kept, and which rights people can exercise. Some items apply only “where applicable” (DPO, transfers, automated decision-making).
| Required information | Article | What to write in practice |
|---|---|---|
| Identity and contact details of the controller | 13(1)(a) | Company name, address, contact email |
| Contact details of the data protection officer | 13(1)(b) | Only if you have appointed one |
| Purposes and legal basis | 13(1)(c) | One line per use: answering enquiries, sending the newsletter, invoicing |
| Legitimate interests pursued | 13(1)(d) | If a purpose relies on legitimate interest, which one |
| Recipients or categories of recipients | 13(1)(e) | Team, host, email marketing tool, payment provider, accountant |
| Transfers outside the European Union | 13(1)(f) | Country and safeguard: adequacy decision or standard contractual clauses |
| Retention period or criteria | 13(2)(a) | One period per category of data |
| Rights of access, rectification, erasure, restriction, objection, portability | 13(2)(b) | The list, and the address where to exercise them |
| Right to withdraw consent | 13(2)(c) | For the newsletter and trackers that require consent |
| Right to lodge a complaint | 13(2)(d) | With a supervisory authority: the CNIL in France, with its address or website |
| Whether providing the data is mandatory or optional | 13(2)(e) | Which fields are required and what happens if they are missing |
| Automated decision-making, profiling | 13(2)(f) | Only for fully automated decisions with legal or similarly significant effects (art. 22) |
A data protection officer (DPO) is only mandatory in the cases set out in article 37 of the GDPR (public body, large-scale monitoring or large-scale sensitive data): a solo consultant does not have one, and the line disappears. And for any new use of the data, article 13(3) requires you to inform people before, not after.
For a US provider certified under the EU-US framework, cite the adequacy decision of 10 July 2023; otherwise, the safeguard you rely on, most often standard contractual clauses, and where to see it.
Which legal basis should I state for each processing purpose?
Each purpose rests on one of the six bases in article 6 of the GDPR: consent, contract, legal obligation, vital interests, public interest task, legitimate interest.
| Common processing | Usual legal basis |
|---|---|
| Answering a quote request | Pre-contractual steps (art. 6(1)(b)) |
| Answering a simple question | Legitimate interest in replying to enquiries (art. 6(1)(f)) |
| Managing orders and delivery | Performance of the contract (art. 6(1)(b)) |
| Invoicing and keeping accounting records | Legal obligation (art. 6(1)(c)) |
| Newsletter to consumer prospects | Consent (art. 6(1)(a)) |
| Offers to a customer for products similar to those bought | Legitimate interest, according to the CNIL standard (in French) |
| Non-exempt audience measurement | Consent, collected through the cookie banner |
The CNIL explains each basis on its legal bases page (in French). The choice shapes the rights: no objection to a legal obligation, while consent can always be withdrawn.
What is the difference between a privacy policy, a cookie policy and a legal notice?
The legal notice says who publishes the site, the privacy policy what you do with personal data, the cookie policy which trackers are placed on the visitor’s device. Three texts, three legal foundations, often three pages.
| Legal notice (« mentions légales ») | Privacy policy | Cookie policy | |
|---|---|---|---|
| Law | LCEN, art. 1-1 (French) | GDPR, art. 12 to 14 (EU-wide) | French Data Protection Act, art. 82 (French) |
| Answers | Who publishes and hosts the site? | What do you do with my data? | Which trackers, what for, for how long? |
| Applies to | Every business website | Every site that collects data | Every site that places trackers |
| Penalty | Criminal | CNIL | CNIL |
No text requires three separate pages: the cookie policy can be a section of the privacy policy. What matters is that the banner and both policies describe the same trackers, purposes and lifetimes. The detail is in our guides to the legal notice for a website in France and the CNIL-compliant cookie banner.
What should a privacy policy template say, section by section?
A good template follows the order of article 13 and describes your real processing. Example for Claire, an HR consultant running a SASU (a single-shareholder simplified joint-stock company): contact form, newsletter, online booking and audience measurement.
1. Controller. “The controller is Claire Martin Conseil, SASU, [registered office address]. For any question about your data: [dedicated email].” Comment: use an address someone reads regularly, because that is where access requests will land.
2. Data collected and whether it is mandatory. “Contact form: name, email and message are required, phone number is optional. Without an email address, we cannot reply to you.” Comment: this is article 13(2)(e), often forgotten. Mark the required fields in the form too.
3. Purposes and legal bases. “Answering your quote requests (pre-contractual steps); sending you our newsletter (consent); issuing and keeping invoices (legal obligation).” Comment: never “we use your data to improve our services” with nothing more specific.
4. Recipients. “Your data is intended for Claire Martin Conseil. It is processed on our behalf by our host, our newsletter tool, our booking tool and, for invoices, our accountant.” Comment: the category of provider is enough, but each one must be covered by a contract that complies with article 28 of the GDPR.
5. Transfers outside the European Union. “Our booking tool hosts data in the United States; this transfer is covered by [safeguard and link].” Comment: if everything is hosted in Europe, say so in one sentence.
6. Retention periods. “Contact requests with no follow-up: 3 years after your last message. Newsletter: until you unsubscribe. Invoices: 10 years. Audience measurement: trackers 13 months, data collected 25 months.” Comment: every period has a source. The 3 years for a prospect come from the CNIL standard on managing commercial activities (in French), the 10 years from article L123-22 of the « Code de commerce » (Commercial Code), the 13 and 25 months from the CNIL’s recommendations on audience measurement (in French).
7. Your rights. “You can access your data, rectify it, erase it, restrict its processing, object to its processing, request its portability and withdraw your consent at any time, by writing to [email].” Comment: article 12(3) gives you one month to respond, extendable by two months if you tell the person.
8. Complaints. “If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr).” Comment: article 13(2)(d), a right based on article 77. Its absence gives away an imported template.
9. Last updated. “Last updated: 7 October 2026.” Comment: not required as such, but it lets you prove what was displayed.
Your record of processing activities already contains sections 3, 4, 5 and 6: purposes, recipients, transfers and retention periods. Fill it in first, then write the policy from it: the two documents must say the same thing.
Where should the privacy policy go on my website?
On a dedicated page, reachable from every page of the site (usually in the footer), and summarised in a few lines under each form. The CNIL recommends layered information: the essentials at the point of collection, the detail one click away.
The official page on entreprendre.service-public.fr (in French) asks for a link that is “clearly visible on every page of the site”. In its guidance on informing individuals (in French), the CNIL puts the controller’s identity, the purposes and the rights in the first layer. It also publishes sample information notices (in French), including one for a data collection form. Under Claire’s contact form, that gives:
The information you enter is used by Claire Martin Conseil to answer your request and kept for 3 years after your last message. You can access, rectify or erase it by writing to [email]. Learn more: [privacy policy].
There is no need for an “I accept the privacy policy” checkbox: informing people is not collecting consent, and the box suggests the processing depends on it. Keep checkboxes for genuine consent, such as signing up to the newsletter.
What is the fine for not having a privacy policy in France?
A breach of articles 12 to 14 of the GDPR carries a fine of up to €20 million or 4% of worldwide annual turnover, whichever is higher. In a case with no particular difficulty, the CNIL can use its simplified procedure, capped at €20,000 for a business with turnover below €50 million.
The general cap is set by article 83(5)(b) of the GDPR, and applies across the EU. The simplified procedure (in French) is French: its cap is set by article 22-1 of the « loi Informatique et Libertés » (French Data Protection Act), in the version in force since 28 May 2026: a €20,000 fine and a €100 penalty per day of delay, raised to €100,000 and €500 per day when worldwide turnover exceeds €50 million. The decision is not made public.
There is also a French criminal side: article R625-10 of the « Code pénal » (Criminal Code) punishes failure to provide the information required by articles 13 and 14 of the GDPR with a fine for a 5th-class petty offence: up to €1,500 for an individual (art. 131-13) and €7,500 for a company (art. 131-41), excluding repeat offences.
What has actually been imposed, according to the CNIL’s list of sanctions (in French):
| Date | Organisation | Breaches found (extract) | Sanction |
|---|---|---|---|
| 12 March 2026 | Catalogue distance selling (simplified procedure) | Information of individuals (exercising rights), right of access | €5,000 |
| 3 July 2025 | Distance selling of furniture and home decor | Retention period, information of individuals, cookies, marketing | €600,000 |
| 3 April 2025 | Building works brokerage and project management (simplified procedure) | Information of individuals (exercising rights), failure to cooperate | €10,000 and an injunction |
| 12 December 2024 | Communications and video production agency (simplified procedure) | Transparency and information (exercising rights), right of access | €6,000 |
| 19 September 2024 | Gun shop, online and in store (simplified procedure) | Retention period, information and transparency, erasure, security | €20,000 |
The landmark case is still Google: €50 million on 21 January 2019 (SAN-2019-001, in French), notably because the information required by article 13 was “excessively scattered” across several documents. The Conseil d’État (France’s highest administrative court) upheld (in French) the fine on 19 June 2020, noting that the information available was “sometimes incomplete, in particular as regards the data retention period”. Our guide to CNIL fines details the procedures and amounts.
What are the most common privacy policy mistakes?
A copied template that does not describe your business, forgotten providers, and retention periods that are missing or “unlimited”.
- Forgetting your processors. The email marketing tool, the CRM, the booking tool, the payment provider, the host: each one receives data and must be listed among the recipients, with any transfer outside the EU flagged.
- Writing “for as long as necessary”. Article 13(2)(a) accepts criteria when a fixed period is impossible, but a vague phrase is not a criterion. The CNIL says so on its page on retention periods (in French): “personal data cannot be kept indefinitely”.
- Basing everything on consent. Invoicing is a legal obligation, delivery is a contract: relying on consent would suggest it can be withdrawn.
- Never updating it. New tool, new provider: the policy must follow.
Will the EU Digital Omnibus change the GDPR information duty?
Not so far. On 19 November 2025 the European Commission proposed a “Digital Omnibus” regulation that amends the GDPR among other texts, but as of 7 October 2026 the procedure is still ongoing and article 13 applies as currently worded.
According to the European Parliament’s procedure file 2025/0360(COD), proposal COM(2025) 837 is still awaiting its committee vote and has been neither adopted nor published in the Official Journal: the CNIL checks compliance against the current text.
How do I check my privacy policy before publishing it?
Compare it point by point with article 13 and with your real processing, ideally starting from your record of processing.
To check that your home page links to your legal documents, run the free website audit. To see where your whole site stands, take the website compliance quiz. And if you sell online, read on with our guides to terms of sale in France and the mandatory legal documents for a French business.
Sources
- CNIL Regulation (EU) 2016/679 (GDPR), art. 12 to 14: transparency and information to be provided (in French)
- CNIL Regulation (EU) 2016/679 (GDPR), art. 5 and 6: principles and lawfulness of processing (in French)
- CNIL Regulation (EU) 2016/679 (GDPR), art. 28 and 37: processor and data protection officer (in French)
- CNIL Regulation (EU) 2016/679 (GDPR), art. 77 and 83: complaints and administrative fines (in French)
- EUR-Lex Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
- CNIL Conformité RGPD : comment informer les personnes et assurer la transparence ? (GDPR compliance: informing individuals and ensuring transparency, in French)
- CNIL RGPD : exemples de mentions d’information (GDPR: sample information notices, in French)
- CNIL Les bases légales (legal bases, in French)
- CNIL Les durées de conservation des données (data retention periods, in French)
- CNIL Référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL standard on personal data processing for managing commercial activities, in French)
- CNIL Cookies : solutions pour les outils de mesure d’audience (cookies: solutions for audience measurement tools, in French)
- CNIL Les sanctions prononcées par la CNIL (sanctions issued by the CNIL, in French)
- CNIL La procédure de sanction simplifiée (the simplified sanction procedure, in French)
- Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act, « loi Informatique et Libertés »), art. 22-1 (version in force since 28 May 2026, amended by Loi n° 2026-403 du 26 mai 2026)
- Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act), art. 82
- Légifrance Code pénal (Criminal Code), art. R625-10
- Légifrance Code pénal (Criminal Code), art. 131-13
- Légifrance Code pénal (Criminal Code), art. 131-41
- Légifrance Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l’économie numérique (LCEN, Law on Confidence in the Digital Economy), art. 1-1
- Légifrance Code de commerce (Commercial Code), art. L123-22
- entreprendre.service-public.fr Mentions obligatoires sur le site internet d’un entrepreneur individuel (mandatory information on a sole trader’s website, in French)
- EUR-Lex CJEU, 19 October 2016, Breyer, C-582/14
- EUR-Lex Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (EU-US Data Privacy Framework)
- Parlement européen, Observatoire législatif Simplification of the digital legislative framework, Digital Omnibus (Omnibus VII), procedure 2025/0360(COD)
- Légifrance Délibération de la formation restreinte n° SAN-2019-001 du 21 janvier 2019 (CNIL restricted committee decision against Google, in French)
- Conseil d’État RGPD : le Conseil d’État rejette le recours dirigé contre la sanction de 50 millions d’euros infligée à Google par la CNIL (the Conseil d’État upholds the CNIL’s €50 million fine against Google, in French)
General information, not legal advice. This guide describes the rules that apply in France as of 7 October 2026. For a specific situation, consult a lawyer. Spotted a mistake or a change in the law? Write to us.

