Taxation07 February 2026

Privacy policy: what should be published?

Personal data, cookies, GDPR rights and mandatory notices: what should a confidentiality policy contain in 2026?

Samuel HAYOT
8 min read

Expert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.

Privacy policy: what should be published?

Updated April 2026 - A privacy policy should not be generic text added to the footer. It is the cornerstone of your company's GDPR compliance and must clearly explain how you collect, use, store and protect the personal data of your customers, prospects and Internet users.

See also: Digitalization of businesses, File a complaint for breach of trust and legal AI.

What is a privacy policy?

The privacy policy is a legal document which informs the people whose data you process about the conditions of this processing. It meets the information obligation provided for by Articles 13 and 14 of the General Data Protection Regulation (GDPR), in force since May 2018.

In practice, this document must be accessible from each page of your website, readable and understandable by a non-lawyer. The CNIL regularly reminds us of this in its guidelines: information must be "concise, transparent, understandable and easy to access".

Confidentiality policy and legal notices: what is the difference?

Confusion is common, but the two documents have neither the same purpose nor the same legal basis.

Legal noticesPrivacy Policy
FoundationLCEN (art. 6-III) and Commercial CodeGDPR (art. 13 and 14)
ObjectiveIdentify the site editorInform about data processing
ContentCompany name, address, SIRET, publication directorPurposes, legal bases, rights, retention periods
Sanction€75,000 (natural person), €375,000 (legal entity)Up to 4% of global turnover or 20 million euros

The two documents are therefore complementary and mandatory for any professional site. Not confusing them is the first step to successful compliance.

What should a privacy policy contain in 2026?

Each company has specific treatments, but certain mentions are essential. Here is the complete list of sections to include:

1. Identity of the data controller

This is generally your company (company name, head office address, SIRET number). If you have designated a data protection officer (DPO), their contact details must also appear.

2. Purposes of processing

For each category of data collected, you must specify the objective pursued:

  • management of contact requests via form;
  • sending newsletters and commercial communications;
  • execution of a contract or provision of a service;
  • audience analysis and navigation statistics;
  • management of applications and recruitment;
  • order processing and invoicing.

3. Legal basis for each processing

The GDPR requires that each processing operation be based on one of the six legal bases in Article 6:

  • consent of the person (e.g.: marketing cookies, newsletter);
  • execution of a contract (e.g.: billing data);
  • legal obligation (e.g.: conservation of accounting documents);
  • legitimate interest of the data controller (e.g.: security of the information system).

Specifying the legal basis for each purpose is not optional. The CNIL has reiterated this on numerous occasions in its practical guides.

4. Data recipients

Who has access to the data? Your internal team? An IT service provider? A CRM tool hosted abroad? Each category of recipients must be mentioned.

5. Shelf life

Data cannot be retained indefinitely. You must indicate precise durations:

  • customer contact data: 3 years after the last contact (CNIL recommendation);
  • invoices and accounting documents: 10 years (tax obligation);
  • application data: 2 months maximum after the last exchange (unless explicitly agreed);
  • audience measurement cookies: 13 months maximum.

6. Rights of individuals

Any person whose data you process has rights that they can exercise at any time:

  • right of access to its data;
  • right of rectification;
  • right to erasure ("right to be forgotten");
  • right to limitation of processing;
  • right to portability;
  • right of opposition, in particular to profiling and commercial prospecting.

Specify the concrete terms of exercise: dedicated e-mail address, online form, response time (1 month maximum).

7. Transfers outside the European Union

If you use tools whose servers are located outside the EU (Google Analytics, Meta, etc.), you must inform people and mention the guarantees put in place (standard contractual clauses, adequacy decisions).

Why many privacy policies are insufficient

In our daily practice, we find that the majority of confidentiality policies presented on SME sites have the same shortcomings:

  • text too generic, often copy-pasted from an online model without adaptation;
  • absence of detail on the forms: no information at the time of collection;
  • no mention of cookies or vague reference to a "banner" without a link to a dedicated policy;
  • shelf life periods absent or indicated indefinitely ("as long as necessary");
  • poorly presented rights: simple list of rights without terms of exercise;
  • information on subcontractors missing: the customer does not know who processes his data.

These defects are not trivial. In 2025, the CNIL imposed sanctions totaling more than 70 million euros, several of which specifically concerned a failure to inform individuals. The risk is therefore not theoretical.

Hayot Expertise advice: start from the actual uses of your site: contact form, application, newsletter, analytics, cookies, CRM, payment, appointment making. Each use corresponds to a treatment which must be documented.

The sensitive point of cookies and trackers

Managing cookies remains one of the most complex topics for businesses. The CNIL published clear guidelines in September 2020, since updated, which apply to all websites accessible from France.

To be compliant, you must put in place:

  • a cookies banner visible upon arrival on the site, before any deposit of non-essential tracers;
  • a preference center allowing you to accept or refuse each category of cookies individually;
  • detailed information on the nature of each tracer, its purpose and its lifespan;
  • proof of consent (or refusal) kept for a maximum of 13 months.

Since 2026, European data protection authorities have been strengthening their cooperation on this subject. Several recent decisions have confirmed that consent must be "free, specific, informed and unambiguous". Simply continuing to browse no longer constitutes consent.

Good to know: cookies strictly necessary for the operation of the site (shopping cart, authentication, security) do not require consent. Audience measurement cookies are also "exempt", under strict conditions defined by the CNIL.

How to write a compliant privacy policy?

The CNIL provides information notice models that can be adapted to your situation. We recommend the following approach:

  1. Map your processing: list all the data collected, their source, their purpose and their recipient.
  2. Identify the legal bases: each processing must be based on a valid basis.
  3. Write in accessible language: avoid legal jargon, use short sentences, structure with titles.
  4. Integrate the information in the right place: the policy must be accessible from each page, and specific information must be displayed at the time of collection (contact form, newsletter registration).
  5. Review regularly: with each new service, new tool or change in legislation, update your policy.

Frequently asked questions

Is the privacy policy mandatory for all sites?+
<p>Yes, as long as your site collects personal data, even minimal ones (e-mail address via a contact form, IP address via server logs). The information obligation arises from Articles 13 and 14 of the GDPR and applies to any company established in the EU or targeting European residents.</p>
What is the difference between privacy policy and cookies policy?+
<p>The confidentiality policy covers all processing of personal data. The cookie policy focuses specifically on trackers placed on the Internet user's terminal. In practice, the two can be grouped together in the same document, provided that the information on cookies is sufficiently detailed.</p>
How long can personal data be kept?+
<p>The duration depends on the purpose of the processing. The CNIL recommends a maximum of 3 years for commercial prospecting data after the last contact. Invoices must be kept for 10 years for tax reasons. Application data 2 months maximum. Each duration must be justified and mentioned in your policy.</p>
What are the penalties for non-compliance?+
<p>The CNIL can impose fines of up to 20 million euros or 4% of global annual turnover (whichever is higher). In 2025, more than 70 million euros in sanctions have been imposed. Beyond the fine, a lack of compliance can lead to a loss of confidence from your customers and contractual difficulties with your partners.</p>
Can we use a privacy policy template found online?+
<p>The models can be a starting point, but they must be adapted to your real situation. A policy that mentions treatments you do not perform, or omits treatments you do, is unnecessary and potentially misleading. The CNIL prioritizes the accuracy of information over its form.</p>

Need a quote or personalised advice?

Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.

Contact us

Quick and clear quote

Response within 24h • Confidential

By submitting, you agree to our privacy policy.