Privacy policy: what should be published?
Personal data, cookies, GDPR rights and mandatory notices: what should a confidentiality policy contain in 2026?
This topic is part of our service
Business law support in France | Corporate secretarialExpert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.
Updated April 2026 - A privacy policy should not be generic text added to the footer. It is the cornerstone of your company's GDPR compliance and must clearly explain how you collect, use, store and protect the personal data of your customers, prospects and Internet users.
See also: Digitalization of businesses, File a complaint for breach of trust and legal AI.
What is a privacy policy?#
The privacy policy is a legal document which informs the people whose data you process about the conditions of this processing. It meets the information obligation provided for by Articles 13 and 14 of the General Data Protection Regulation (GDPR), in force since May 2018.
In practice, this document must be accessible from each page of your website, readable and understandable by a non-lawyer. The CNIL regularly reminds us of this in its guidelines: information must be "concise, transparent, understandable and easy to access".
Confidentiality policy and legal notices: what is the difference?#
Confusion is common, but the two documents have neither the same purpose nor the same legal basis.
| Legal notices | Privacy Policy | |
|---|---|---|
| Foundation | LCEN (art. 6-III) and Commercial Code | GDPR (art. 13 and 14) |
| Objective | Identify the site editor | Inform about data processing |
| Content | Company name, address, SIRET, publication director | Purposes, legal bases, rights, retention periods |
| Sanction | €75,000 (natural person), €375,000 (legal entity) | Up to 4% of global turnover or 20 million euros |
The two documents are therefore complementary and mandatory for any professional site. Not confusing them is the first step to successful compliance.
What should a privacy policy contain in 2026?#
Each company has specific treatments, but certain mentions are essential. Here is the complete list of sections to include:
1. Identity of the data controller#
This is generally your company (company name, head office address, SIRET number). If you have designated a data protection officer (DPO), their contact details must also appear.
2. Purposes of processing#
For each category of data collected, you must specify the objective pursued:
- management of contact requests via form;
- sending newsletters and commercial communications;
- execution of a contract or provision of a service;
- audience analysis and navigation statistics;
- management of applications and recruitment;
- order processing and invoicing.
3. Legal basis for each processing#
The GDPR requires that each processing operation be based on one of the six legal bases in Article 6:
- consent of the person (e.g.: marketing cookies, newsletter);
- execution of a contract (e.g.: billing data);
- legal obligation (e.g.: conservation of accounting documents);
- legitimate interest of the data controller (e.g.: security of the information system).
Specifying the legal basis for each purpose is not optional. The CNIL has reiterated this on numerous occasions in its practical guides.
4. Data recipients#
Who has access to the data? Your internal team? An IT service provider? A CRM tool hosted abroad? Each category of recipients must be mentioned.
5. Shelf life#
Data cannot be retained indefinitely. You must indicate precise durations:
- customer contact data: 3 years after the last contact (CNIL recommendation);
- invoices and accounting documents: 10 years (tax obligation);
- application data: 2 months maximum after the last exchange (unless explicitly agreed);
- audience measurement cookies: 13 months maximum.
6. Rights of individuals#
Any person whose data you process has rights that they can exercise at any time:
- right of access to its data;
- right of rectification;
- right to erasure ("right to be forgotten");
- right to limitation of processing;
- right to portability;
- right of opposition, in particular to profiling and commercial prospecting.
Specify the concrete terms of exercise: dedicated e-mail address, online form, response time (1 month maximum).
7. Transfers outside the European Union#
If you use tools whose servers are located outside the EU (Google Analytics, Meta, etc.), you must inform people and mention the guarantees put in place (standard contractual clauses, adequacy decisions).
Why many privacy policies are insufficient#
In our daily practice, we find that the majority of confidentiality policies presented on SME sites have the same shortcomings:
- text too generic, often copy-pasted from an online model without adaptation;
- absence of detail on the forms: no information at the time of collection;
- no mention of cookies or vague référence to a "banner" without a link to a dedicated policy;
- shelf life periods absent or indicated indefinitely ("as long as necessary");
- poorly presented rights: simple list of rights without terms of exercise;
- information on subcontractors missing: the customer does not know who processes his data.
These defects are not trivial. In 2025, the CNIL imposed sanctions totaling more than 70 million euros, several of which specifically concerned a failure to inform individuals. The risk is therefore not theoretical.
Hayot Expertise advice: start from the actual uses of your site: contact form, application, newsletter, analytics, cookies, CRM, payment, appointment making. Each use corresponds to a treatment which must be documented.
The sensitive point of cookies and trackers#
Managing cookies remains one of the most complex topics for businesses. The CNIL published clear guidelines in September 2020, since updated, which apply to all websites accessible from France.
To be compliant, you must put in place:
- a cookies banner visible upon arrival on the site, before any deposit of non-essential tracers;
- a préférence center allowing you to accept or refuse each category of cookies individually;
- detailed information on the nature of each tracer, its purpose and its lifespan;
- proof of consent (or refusal) kept for a maximum of 13 months.
Since 2026, European data protection authorities have been strengthening their cooperation on this subject. Several recent decisions have confirmed that consent must be "free, specific, informed and unambiguous". Simply continuing to browse no longer constitutes consent.
Good to know: cookies strictly necessary for the operation of the site (shopping cart, authentication, security) do not require consent. Audience measurement cookies are also "exempt", under strict conditions defined by the CNIL.
How to write a compliant privacy policy?#
The CNIL provides information notice models that can be adapted to your situation. We recommend the following approach:
- Map your processing: list all the data collected, their source, their purpose and their recipient.
- Identify the legal bases: each processing must be based on a valid basis.
- Write in accessible language: avoid legal jargon, use short sentences, structure with titles.
- Integrate the information in the right place: the policy must be accessible from each page, and specific information must be displayed at the time of collection (contact form, newsletter registration).
- Review regularly: with each new service, new tool or change in legislation, update your policy.
Conclusion#
A useful privacy policy is clear, concrete and aligned with the company's actual treatments. In 2026, the risk is not only legal: imprecise information also damages the trust your customers and prospects place in you.
Data protection authorities continue to strengthen their action. In France, the CNIL has increased inspections and formal notices. Taking the time to write a serious policy is not a constraint: it is an investment in the relationship of trust with your customers.
Make your mentions and GDPR documentation reliable
(Official sources: Entreprendre.Service-Public.fr on mandatory notices, CNIL on information notice models, CNIL on cookies, CNIL on the right to information)
Frequently asked questions
La politique de confidentialite est-elle obligatoire pour tous les sites ?
Oui, des lors que votre site collecte des données personnelles, même minimales (adresse e-mail via un formulaire de contact, adresse IP via les logs serveur). L'obligation d'information decoule des articles 13 et 14 du RGPD et s'applique a toute entreprise etablie dans l'UE ou ciblant des résidents europeens.
Quelle est la différence entre politique de confidentialite et politique de cookies ?
La politique de confidentialite couvre l'ensemble des traitements de données personnelles. La politique de cookies se concentre spécifiquement sur les traceurs deposes sur le terminal de l'internaute. En pratique, les deux peuvent être regroupes dans un même document, a condition que l'information sur les cookies soit suffisamment detaillee.
Combien de temps peut-on conserver les données personnelles ?
La durée depend de la finalite du traitement. La CNIL recommande 3 ans maximum pour les données de prospection commerciale après le dernier contact. Les factures doivent être conservees 10 ans pour des raisons fiscales. Les données de candidature 2 mois maximum. Chaque durée doit être justifiee et mentionnee dans votre politique.
Quelles sont les sanctions en cas de non-conformité ?
La CNIL peut prononcer des amendes allant jusqu'a 20 millions d'euros ou 4 % du chiffre d'affaires annuel mondial (le montant le plus eleve etant retenu). En 2025, plus de 70 millions d'euros de sanctions ont ete infliges. Au-dela de l'amende, un defaut de conformité peut entrainer une perte de confiance de vos clients et des difficultes contractuelles avec vos partenaires.
Peut-on utiliser un modèle de politique de confidentialite trouve en ligne ?
Les modèles peuvent constituer un point de depart, mais ils doivent imperativement être adaptes a votre situation réelle. Une politique qui mentionne des traitements que vous n'effectuez pas, ou qui omet des traitements que vous realisez, est inutile et potentiellement trompeuse. La CNIL privilegie l'exactitude de l'information a sa forme.

Article written by Samuel HAYOT
Chartered Accountant, registered with the Institute of Chartered Accountants.
Regulated French accounting and audit firm based in Paris 8, built to support companies across France with a digital and decision-oriented approach.
Sources
Official and operational sources cited for this page.
This topic is part of our service Business law support in France | Corporate secretarial
Need a quote or personalised advice?
Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.