Compliance

Discover
Legalnest
Language FR EN
Annotated template 15 min read

Website privacy policy in France: mandatory even for a brochure site? GDPR contents and template 2026

Key takeaways

As soon as a website collects personal data (a contact form, a newsletter, customer accounts, audience measurement, even plain server logs), articles 13 and 14 of the GDPR require you to inform the people concerned: that is the job of the privacy policy. It says who processes the data, why, on what legal basis, with which providers, for how long and how to exercise their rights, including with the CNIL (the French data protection authority). Leaving it out exposes you to a CNIL fine: up to €20 million or 4% of worldwide turnover, and up to €20,000 (€100,000 above €50 million in turnover) under the simplified procedure, reserved for cases with no particular difficulty.

  • The Legalnest team
  • Updated on
  • Checked against the law in force on
  • Markdown version
Contents
  1. Is a privacy policy mandatory on a website in France?
  2. Does a brochure website with no contact form need a privacy policy?
  3. What must a GDPR privacy policy contain?
  4. Which legal basis should I state for each processing purpose?
  5. What is the difference between a privacy policy, a cookie policy and a legal notice?
  6. What should a privacy policy template say, section by section?
  7. Where should the privacy policy go on my website?
  8. What is the fine for not having a privacy policy in France?
  9. What are the most common privacy policy mistakes?
  10. Will the EU Digital Omnibus change the GDPR information duty?
  11. How do I check my privacy policy before publishing it?

On 19 September 2024, a gun shop selling online and in store was fined €20,000 by the CNIL (the French data protection authority) under its simplified procedure. Alongside data security and the right to erasure, the CNIL found two breaches you can read straight off a privacy policy: “information of individuals and transparency” and “retention period”. Not a tech giant: a shop with an e-commerce site.

The GDPR is EU-wide, so the core rules below are the same across the EU. What is French is the enforcer (the CNIL), its simplified sanction procedure, a criminal penalty on top, and a separate cookie provision in French law. A contact form is enough to make a « politique de confidentialité » (privacy policy) mandatory, and a brochure site with no form rarely escapes it. Here is what the text says, and an annotated template, section by section.

Is a privacy policy mandatory on a website in France?

Yes, as soon as the site collects any personal data: articles 13 and 14 of the GDPR require you to inform people at the time of collection. The regulation never uses the words “privacy policy”, but that is the form this information takes on a website.

What the law says

Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; […]

Regulation (EU) 2016/679 (GDPR), Article 13(1)(a) to (c)

Article 12 adds the how: information “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”. For data obtained from a third party (a bought list, contacts gathered from LinkedIn), article 14 requires you to inform people within a reasonable period of no more than one month, or at the latest when you first contact them.

What triggers the obligation on a small business website:

On your siteData collectedPrivacy policy
Contact or quote formName, email, phone, messageMandatory
Newsletter sign-upEmail, first name, opens and clicksMandatory
Customer accounts, online shopIdentity, addresses, orders, paymentMandatory
Online bookingName, contact details, time slot, subjectMandatory
Audience measurement toolTracker ID, pages viewed, IP addressMandatory, with the cookie information
Embedded video, map or social networkIP address sent to the provider, sometimes trackersMandatory
Plain page with no form or third-party toolIP address in server logsSee the next question

The official French government page on mandatory website information (in French) gives the contact form as an example and states that this policy must be separate from your « CGV » (terms of sale).

Does a brochure website with no contact form need a privacy policy?

In almost every case, yes. Even without a form, a site records IP addresses in its server logs, and the Court of Justice of the European Union has ruled that an IP address can be personal data for the website publisher.

In the Breyer judgment of 19 October 2016, the Court held that a dynamic IP address recorded by a website publisher is personal data for that publisher when it has legal means to have the person identified through their internet access provider.

Other processing almost always comes on top, often invisible:

  • an audience measurement tool installed by your agency or your theme;
  • a YouTube video, a map or a font loaded from a third-party server, which passes the visitor’s IP address to that third party;
  • a displayed email address: the messages you receive are data collected from the people who send them.

Only a site that collects strictly nothing escapes article 13, and that means checking every script and every embedded item. A ten-line policy costs less than that check.

flowchart TD
  A["Your website"] --> B{"Form, account or newsletter?"}
  B -->|Yes| P["Full policy mandatory"]
  B -->|No| C{"Analytics or embedded content?"}
  C -->|Yes| P2["Policy mandatory, with a cookie section"]
  C -->|No| D{"Server logs or contact email?"}
  D -->|Yes| P3["A short policy is enough"]
  D -->|No| E["No collection: check every script"]

To see what your home page actually loads, the free cookie scanner detects known trackers and the cookies set on first load.

What must a GDPR privacy policy contain?

The information listed in article 13 of the GDPR: who processes the data, why and on what basis, who it is shared with, where it goes, how long it is kept, and which rights people can exercise. Some items apply only “where applicable” (DPO, transfers, automated decision-making).

Required informationArticleWhat to write in practice
Identity and contact details of the controller13(1)(a)Company name, address, contact email
Contact details of the data protection officer13(1)(b)Only if you have appointed one
Purposes and legal basis13(1)(c)One line per use: answering enquiries, sending the newsletter, invoicing
Legitimate interests pursued13(1)(d)If a purpose relies on legitimate interest, which one
Recipients or categories of recipients13(1)(e)Team, host, email marketing tool, payment provider, accountant
Transfers outside the European Union13(1)(f)Country and safeguard: adequacy decision or standard contractual clauses
Retention period or criteria13(2)(a)One period per category of data
Rights of access, rectification, erasure, restriction, objection, portability13(2)(b)The list, and the address where to exercise them
Right to withdraw consent13(2)(c)For the newsletter and trackers that require consent
Right to lodge a complaint13(2)(d)With a supervisory authority: the CNIL in France, with its address or website
Whether providing the data is mandatory or optional13(2)(e)Which fields are required and what happens if they are missing
Automated decision-making, profiling13(2)(f)Only for fully automated decisions with legal or similarly significant effects (art. 22)

A data protection officer (DPO) is only mandatory in the cases set out in article 37 of the GDPR (public body, large-scale monitoring or large-scale sensitive data): a solo consultant does not have one, and the line disappears. And for any new use of the data, article 13(3) requires you to inform people before, not after.

For a US provider certified under the EU-US framework, cite the adequacy decision of 10 July 2023; otherwise, the safeguard you rely on, most often standard contractual clauses, and where to see it.

Each purpose rests on one of the six bases in article 6 of the GDPR: consent, contract, legal obligation, vital interests, public interest task, legitimate interest.

Common processingUsual legal basis
Answering a quote requestPre-contractual steps (art. 6(1)(b))
Answering a simple questionLegitimate interest in replying to enquiries (art. 6(1)(f))
Managing orders and deliveryPerformance of the contract (art. 6(1)(b))
Invoicing and keeping accounting recordsLegal obligation (art. 6(1)(c))
Newsletter to consumer prospectsConsent (art. 6(1)(a))
Offers to a customer for products similar to those boughtLegitimate interest, according to the CNIL standard (in French)
Non-exempt audience measurementConsent, collected through the cookie banner

The CNIL explains each basis on its legal bases page (in French). The choice shapes the rights: no objection to a legal obligation, while consent can always be withdrawn.

The legal notice says who publishes the site, the privacy policy what you do with personal data, the cookie policy which trackers are placed on the visitor’s device. Three texts, three legal foundations, often three pages.

Legal notice (« mentions légales »)Privacy policyCookie policy
LawLCEN, art. 1-1 (French)GDPR, art. 12 to 14 (EU-wide)French Data Protection Act, art. 82 (French)
AnswersWho publishes and hosts the site?What do you do with my data?Which trackers, what for, for how long?
Applies toEvery business websiteEvery site that collects dataEvery site that places trackers
PenaltyCriminalCNILCNIL

No text requires three separate pages: the cookie policy can be a section of the privacy policy. What matters is that the banner and both policies describe the same trackers, purposes and lifetimes. The detail is in our guides to the legal notice for a website in France and the CNIL-compliant cookie banner.

What should a privacy policy template say, section by section?

A good template follows the order of article 13 and describes your real processing. Example for Claire, an HR consultant running a SASU (a single-shareholder simplified joint-stock company): contact form, newsletter, online booking and audience measurement.

1. Controller. “The controller is Claire Martin Conseil, SASU, [registered office address]. For any question about your data: [dedicated email].” Comment: use an address someone reads regularly, because that is where access requests will land.

2. Data collected and whether it is mandatory. “Contact form: name, email and message are required, phone number is optional. Without an email address, we cannot reply to you.” Comment: this is article 13(2)(e), often forgotten. Mark the required fields in the form too.

3. Purposes and legal bases. “Answering your quote requests (pre-contractual steps); sending you our newsletter (consent); issuing and keeping invoices (legal obligation).” Comment: never “we use your data to improve our services” with nothing more specific.

4. Recipients. “Your data is intended for Claire Martin Conseil. It is processed on our behalf by our host, our newsletter tool, our booking tool and, for invoices, our accountant.” Comment: the category of provider is enough, but each one must be covered by a contract that complies with article 28 of the GDPR.

5. Transfers outside the European Union. “Our booking tool hosts data in the United States; this transfer is covered by [safeguard and link].” Comment: if everything is hosted in Europe, say so in one sentence.

6. Retention periods. “Contact requests with no follow-up: 3 years after your last message. Newsletter: until you unsubscribe. Invoices: 10 years. Audience measurement: trackers 13 months, data collected 25 months.” Comment: every period has a source. The 3 years for a prospect come from the CNIL standard on managing commercial activities (in French), the 10 years from article L123-22 of the « Code de commerce » (Commercial Code), the 13 and 25 months from the CNIL’s recommendations on audience measurement (in French).

7. Your rights. “You can access your data, rectify it, erase it, restrict its processing, object to its processing, request its portability and withdraw your consent at any time, by writing to [email].” Comment: article 12(3) gives you one month to respond, extendable by two months if you tell the person.

8. Complaints. “If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr).” Comment: article 13(2)(d), a right based on article 77. Its absence gives away an imported template.

9. Last updated. “Last updated: 7 October 2026.” Comment: not required as such, but it lets you prove what was displayed.

Your record of processing activities already contains sections 3, 4, 5 and 6: purposes, recipients, transfers and retention periods. Fill it in first, then write the policy from it: the two documents must say the same thing.

Where should the privacy policy go on my website?

On a dedicated page, reachable from every page of the site (usually in the footer), and summarised in a few lines under each form. The CNIL recommends layered information: the essentials at the point of collection, the detail one click away.

The official page on entreprendre.service-public.fr (in French) asks for a link that is “clearly visible on every page of the site”. In its guidance on informing individuals (in French), the CNIL puts the controller’s identity, the purposes and the rights in the first layer. It also publishes sample information notices (in French), including one for a data collection form. Under Claire’s contact form, that gives:

The information you enter is used by Claire Martin Conseil to answer your request and kept for 3 years after your last message. You can access, rectify or erase it by writing to [email]. Learn more: [privacy policy].

There is no need for an “I accept the privacy policy” checkbox: informing people is not collecting consent, and the box suggests the processing depends on it. Keep checkboxes for genuine consent, such as signing up to the newsletter.

What is the fine for not having a privacy policy in France?

A breach of articles 12 to 14 of the GDPR carries a fine of up to €20 million or 4% of worldwide annual turnover, whichever is higher. In a case with no particular difficulty, the CNIL can use its simplified procedure, capped at €20,000 for a business with turnover below €50 million.

The general cap is set by article 83(5)(b) of the GDPR, and applies across the EU. The simplified procedure (in French) is French: its cap is set by article 22-1 of the « loi Informatique et Libertés » (French Data Protection Act), in the version in force since 28 May 2026: a €20,000 fine and a €100 penalty per day of delay, raised to €100,000 and €500 per day when worldwide turnover exceeds €50 million. The decision is not made public.

There is also a French criminal side: article R625-10 of the « Code pénal » (Criminal Code) punishes failure to provide the information required by articles 13 and 14 of the GDPR with a fine for a 5th-class petty offence: up to €1,500 for an individual (art. 131-13) and €7,500 for a company (art. 131-41), excluding repeat offences.

What has actually been imposed, according to the CNIL’s list of sanctions (in French):

DateOrganisationBreaches found (extract)Sanction
12 March 2026Catalogue distance selling (simplified procedure)Information of individuals (exercising rights), right of access€5,000
3 July 2025Distance selling of furniture and home decorRetention period, information of individuals, cookies, marketing€600,000
3 April 2025Building works brokerage and project management (simplified procedure)Information of individuals (exercising rights), failure to cooperate€10,000 and an injunction
12 December 2024Communications and video production agency (simplified procedure)Transparency and information (exercising rights), right of access€6,000
19 September 2024Gun shop, online and in store (simplified procedure)Retention period, information and transparency, erasure, security€20,000

The landmark case is still Google: €50 million on 21 January 2019 (SAN-2019-001, in French), notably because the information required by article 13 was “excessively scattered” across several documents. The Conseil d’État (France’s highest administrative court) upheld (in French) the fine on 19 June 2020, noting that the information available was “sometimes incomplete, in particular as regards the data retention period”. Our guide to CNIL fines details the procedures and amounts.

What are the most common privacy policy mistakes?

A copied template that does not describe your business, forgotten providers, and retention periods that are missing or “unlimited”.

  • Forgetting your processors. The email marketing tool, the CRM, the booking tool, the payment provider, the host: each one receives data and must be listed among the recipients, with any transfer outside the EU flagged.
  • Writing “for as long as necessary”. Article 13(2)(a) accepts criteria when a fixed period is impossible, but a vague phrase is not a criterion. The CNIL says so on its page on retention periods (in French): “personal data cannot be kept indefinitely”.
  • Basing everything on consent. Invoicing is a legal obligation, delivery is a contract: relying on consent would suggest it can be withdrawn.
  • Never updating it. New tool, new provider: the policy must follow.

Will the EU Digital Omnibus change the GDPR information duty?

Not so far. On 19 November 2025 the European Commission proposed a “Digital Omnibus” regulation that amends the GDPR among other texts, but as of 7 October 2026 the procedure is still ongoing and article 13 applies as currently worded.

According to the European Parliament’s procedure file 2025/0360(COD), proposal COM(2025) 837 is still awaiting its committee vote and has been neither adopted nor published in the Official Journal: the CNIL checks compliance against the current text.

How do I check my privacy policy before publishing it?

Compare it point by point with article 13 and with your real processing, ideally starting from your record of processing.

Your privacy policy in 12 points0/12

To check that your home page links to your legal documents, run the free website audit. To see where your whole site stands, take the website compliance quiz. And if you sell online, read on with our guides to terms of sale in France and the mandatory legal documents for a French business.

Sources

  1. CNIL Regulation (EU) 2016/679 (GDPR), art. 12 to 14: transparency and information to be provided (in French)
  2. CNIL Regulation (EU) 2016/679 (GDPR), art. 5 and 6: principles and lawfulness of processing (in French)
  3. CNIL Regulation (EU) 2016/679 (GDPR), art. 28 and 37: processor and data protection officer (in French)
  4. CNIL Regulation (EU) 2016/679 (GDPR), art. 77 and 83: complaints and administrative fines (in French)
  5. EUR-Lex Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
  6. CNIL Conformité RGPD : comment informer les personnes et assurer la transparence ? (GDPR compliance: informing individuals and ensuring transparency, in French)
  7. CNIL RGPD : exemples de mentions d’information (GDPR: sample information notices, in French)
  8. CNIL Les bases légales (legal bases, in French)
  9. CNIL Les durées de conservation des données (data retention periods, in French)
  10. CNIL Référentiel relatif aux traitements de données à caractère personnel mis en œuvre aux fins de gestion des activités commerciales (CNIL standard on personal data processing for managing commercial activities, in French)
  11. CNIL Cookies : solutions pour les outils de mesure d’audience (cookies: solutions for audience measurement tools, in French)
  12. CNIL Les sanctions prononcées par la CNIL (sanctions issued by the CNIL, in French)
  13. CNIL La procédure de sanction simplifiée (the simplified sanction procedure, in French)
  14. Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act, « loi Informatique et Libertés »), art. 22-1 (version in force since 28 May 2026, amended by Loi n° 2026-403 du 26 mai 2026)
  15. Légifrance Loi n° 78-17 du 6 janvier 1978 (French Data Protection Act), art. 82
  16. Légifrance Code pénal (Criminal Code), art. R625-10
  17. Légifrance Code pénal (Criminal Code), art. 131-13
  18. Légifrance Code pénal (Criminal Code), art. 131-41
  19. Légifrance Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l’économie numérique (LCEN, Law on Confidence in the Digital Economy), art. 1-1
  20. Légifrance Code de commerce (Commercial Code), art. L123-22
  21. entreprendre.service-public.fr Mentions obligatoires sur le site internet d’un entrepreneur individuel (mandatory information on a sole trader’s website, in French)
  22. EUR-Lex CJEU, 19 October 2016, Breyer, C-582/14
  23. EUR-Lex Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (EU-US Data Privacy Framework)
  24. Parlement européen, Observatoire législatif Simplification of the digital legislative framework, Digital Omnibus (Omnibus VII), procedure 2025/0360(COD)
  25. Légifrance Délibération de la formation restreinte n° SAN-2019-001 du 21 janvier 2019 (CNIL restricted committee decision against Google, in French)
  26. Conseil d’État RGPD : le Conseil d’État rejette le recours dirigé contre la sanction de 50 millions d’euros infligée à Google par la CNIL (the Conseil d’État upholds the CNIL’s €50 million fine against Google, in French)

General information, not legal advice. This guide describes the rules that apply in France as of 7 October 2026. For a specific situation, consult a lawyer. Spotted a mistake or a change in the law? Write to us.

FAQ

Frequently asked questions.

Is a privacy policy mandatory on a website in France?

Yes, as soon as the site collects personal data: a contact form, newsletter sign-up, customer account, online booking or audience measurement tool. Articles 13 and 14 of the GDPR then require you to inform people at the time of collection. The GDPR does not dictate what the document is called, but on a website this information takes the form of a privacy policy that can be reached from every page.

Does a brochure website with no contact form need a privacy policy?

Almost always. Even without a form, a site usually records IP addresses in its server logs, and the Court of Justice of the European Union ruled in 2016 that an IP address can be personal data for the website publisher. On top of that there is often an audience measurement tool, an embedded map or video, or a contact email address. A short policy covering just those processing operations is then enough.

What must a GDPR privacy policy contain?

Article 13 of the GDPR lists it: the controller’s identity and contact details, the data protection officer’s contact details if there is one, purposes and legal bases, the legitimate interests relied on, recipients, transfers outside the European Union, retention periods, data subjects’ rights, the right to withdraw consent, the right to complain to a supervisory authority (the CNIL in France), whether providing the data is mandatory or optional, and the existence of automated decision-making. Each item must be written in a concise, clear and easily accessible way.

What is the fine for not having a privacy policy in France?

A breach of articles 12 to 14 of the GDPR falls under the higher cap in article 83: €20 million or 4% of worldwide annual turnover. In a straightforward case, the CNIL can use its simplified procedure, where the fine is capped at €20,000 (€100,000 above €50 million in worldwide turnover). The French Criminal Code also provides for a 5th-class petty offence: up to €1,500 for an individual and €7,500 for a company, excluding repeat offences.

Can I copy another website’s privacy policy or use a US template?

Copying another site’s text, or a US template, means describing processing, providers and retention periods that are not yours, which amounts to inaccurate information. A template gives you a structure, not the content: every purpose, tool and retention period must match what your business actually does, and your record of processing. US templates add a further problem: they often leave out the legal bases and the right to complain to the CNIL.

Do I need a separate cookie policy as well as a privacy policy?

Cookies fall under a separate French text, article 82 of the French Data Protection Act, which requires you to explain what trackers are for and to obtain consent when they are not exempt. That information can sit in a section of the privacy policy or on a dedicated page. What matters is that the banner, the cookie policy and the privacy policy describe the same trackers with the same lifetimes.

Read next

Related guides.