Cookies and GDPR on Your Website: The 2026 Compliance Guide for SMBs

Website cookies gdprCookie consent bannerGdpr compliance websiteCnil cookie finesCookie consent managementPrivacy policy websiteConsent management platformGdpr audit websiteCookies small businessGdpr 2026
September 2, 202611 vuesEcrit parMajoliMajoliÉquipe de Majoli.io

In 2025, France's CNIL issued 486.8 million euros in fines, including 21 organizations sanctioned over cookies. The complete step-by-step method to bring your website into GDPR compliance in 2026.

Entrepreneur working on a laptop at a wooden desk, screen showing a blurred website mockup with a soft consent-banner shape, coral red notebook resting next to the keyboard

In 2025, France's data protection authority, the CNIL, issued 486,839,500 euros in cumulative fines, a historic record driven largely by cookie and tracker violations. Twenty-one organizations were sanctioned on this ground alone, including two major players fined 325 million and 150 million euros. But the assumption that only large corporations are at risk no longer holds: 32% of the companies audited by the CNIL in 2025 were small and medium-sized businesses, and since January 2026, 23 sanctions have already targeted non-compliant cookies through the simplified procedure, for an average fine of 5,815 euros per case.

This surge is as technical as it is regulatory: the CNIL now uses an automated crawler that continuously scans French websites to check for a consent banner, verify that refusing is as easy as accepting, and confirm that no cookies are dropped before consent is collected. A showcase website, an online store, or even a simple contact form can be checked without any human involvement. Here is the complete method to bring your website into compliance in 2026, step by step.

What the regulation says in 2026

The legal framework for cookies rests on the GDPR and the ePrivacy Directive, transposed into French law through Article 82 of the Data Protection Act (loi Informatique et Libertés). Three principles structure every obligation.

Free, informed, unambiguous and prior consent

No non-essential cookie (non-exempt audience measurement, advertising, social media, embedded maps) can be dropped before the visitor has given explicit consent. Only cookies strictly necessary for the site to function (cart, login, language preferences) are exempt from this rule.

Refusing must be as easy as accepting

This is the most frequently sanctioned point: a prominent "Accept all" button paired with a refusal option hidden behind several clicks or a discreet small-print link is, on its own, grounds for a fine. The CNIL requires a refusal button placed at the same visual level as the acceptance button, with no pre-checked boxes, and with a choice available for each purpose (audience measurement, advertising, social media).

A regulated retention period

Consent (or refusal) must be renewed at most every 13 months, and proof that it was collected must be kept for at least 6 months so it can be produced during an inspection.

The most common mistakes on small business websites

Most fines issued through the simplified procedure sanction simple technical flaws that are easy to fix:

  • Cookies dropped before any consent is given, often through third-party scripts (video, maps, chat) embedded without going through the consent management tool.
  • A refusal option harder to find than acceptance: no "Refuse" button at the first level, or one that requires manually unchecking every purpose.
  • An outdated privacy policy, or one that fails to mention the actual subprocessors in use (hosting provider, email tool, CRM, review collection solution).

On this last point, the same vigilance should apply to the tools used internally: our guide on AI and GDPR for small businesses covers the same compliance requirements applied to artificial intelligence tools.

The 6-step method to bring your website into compliance

  1. Audit the cookies actually being dropped. Open your site in a private browsing window and list every cookie set before any click, using your browser's developer tools or a cookie scanner. This is the first step of a broader website audit, useful even outside of a redesign project.
  2. Choose a consent management platform (CMP) recognized by the CNIL, such as Axeptio, Didomi, or tarteaucitron.js for more technical websites. The choice depends on traffic volume, budget, and the level of customization needed, much like choosing a domain name or a hosting provider when launching the site.
  3. Set up purpose-by-purpose choices (audience measurement, advertising, social media, video) with a refusal button visible at the same level as the acceptance button, with no pre-checked boxes.
  4. Block third-party scripts until consent is given, including video, map, and chat widget integrations, which often escape this control.
  5. Update your privacy policy with the actual list of subprocessors, the purpose of each data processing activity, and retention periods, and verify that a data processing agreement (DPA) exists with every provider (hosting, CRM, email tool).
  6. Document proof of consent: date, choice made, version of the banner displayed, kept for at least 6 months to respond to a potential inspection.

This approach follows the same logic as preparing a website redesign without losing your search rankings: cookie compliance is prepared in advance, not rushed after a first warning from the CNIL.

What non-compliance actually costs

Amounts vary significantly depending on company size and the severity of the violation. Under the simplified procedure, the average fine recorded since January 2026 is 5,815 euros per case, with a total of 133,750 euros across 23 cookie-related sanctions. For more serious violations, the CNIL can issue fines of up to 2% of worldwide annual revenue for a breach of Article 82, and up to 4% or twenty million euros in the case of a concurrent GDPR violation, as illustrated by the 325 million euro fine against Google and the 150 million euro fine against Shein in 2025.

Beyond the financial penalty, a CNIL inspection triggers a public formal notice, a compliance deadline under supervision, and, for a small business, a negative trust signal toward customers at a time when legal obligations for websites are already multiplying (digital accessibility, legal notices, terms of sale).

Who is responsible: the web agency, the CMP provider, or the company?

Legal responsibility remains with the company publishing the website, as the data controller, even when design was outsourced to an agency. Three concrete divisions of responsibility help avoid gray areas:

  • The web agency technically integrates the CMP, configures third-party script blocking, and documents the choices made when the site is delivered.
  • The CMP provider guarantees the compliance of its tool (interface, consent logging) but is not responsible for how the website configures it.
  • The company validates the list of cookies actually in use, keeps its privacy policy up to date, and ensures every new provider (marketing tool, review platform, chat) goes through a compliance review before integration.

Clarifying these roles from the design or redesign stage avoids late discoveries during an inspection. Our team systematically builds this dimension into every website creation project, delivering a compliant site from launch rather than fixing it afterward. You can see examples of compliant sites we have delivered in our portfolio.

Frequently asked questions

Does a showcase website without an online store also need a cookie banner?

Yes, as soon as it drops non-exempt cookies, for example a non-anonymized audience measurement tool, an embedded Google Maps widget, or a social media button. Only cookies strictly necessary for the site's technical operation are exempt from this obligation.

How long does cookie consent remain valid?

The CNIL recommends a maximum duration of 13 months, after which the banner must be shown to the visitor again. Proof of consent (or refusal) must itself be kept for at least 6 months.

Does an audience measurement tool like Google Analytics require consent?

In its default configuration, yes. Only certain configurations that meet strict anonymization and statistical-purpose criteria listed by the CNIL can be exempt from prior consent. When in doubt, the safest approach is to subject the tool to consent.

What does a small business risk if it has never been inspected but remains non-compliant?

The CNIL's automated inspection works through continuous crawling and does not depend on a prior complaint. The absence of an inspection so far is therefore no guarantee: compliance should be addressed proactively rather than after receiving a formal notice.

Does the whole website need to be rebuilt to become compliant?

No, in most cases a targeted intervention is enough: installing or reconfiguring the CMP, blocking third-party scripts, updating the privacy policy. A full redesign is only necessary if the site has other structural issues, as discussed in our guide on auditing a site before a redesign.

To assess your website's current compliance or prepare an update, our team is available through the contact page.

Besoin d'un accompagnement ?

Découvrir les services Majoli

Création de site web, SEO et automatisations IA : explore nos offres pour accélérer ta croissance.

Découvrir les services Majoli

Découvrir les derniers articles