lumevel
WorkServicesPricingBlogAboutContact
Let's talk

Studio

WorkPricingAboutContact

Connect

InstagramComing soonFacebookComing soonLinkedInComing soonXComing soonEmail

Legal

Legal noticePrivacy policy
© 2026 Lumevel StudioLimoges, France
lumevel
← Back to the journal
Myth bustPublished on 28 June 2026·Lumevel

French website legal requirements for small businesses in 2026

If you sell anything from a workshop in Limoges, run a B&B, or take restaurant bookings online, French law applies whether your site is in French or in English. Most small business sites miss at least one of the six layers of rules. Here is what each one requires and the order to fix them in.

French website legal requirements for small businesses in 2026

If you sell anything from a workshop in Limoges, run a B&B, or take restaurant bookings online, French law applies whether your site is in French or in English. Most small business sites miss at least one of the six layers of rules. Here is what each one requires and the order to fix them in.

What the law actually covers

French website law is not one single text. It is a stack: the Loi pour la Confiance dans l'Économie Numérique (LCEN, 2004) governs identifying information. The Règlement Général sur la Protection des Données (RGPD, 2018) governs personal data. The ePrivacy directive, transposed into French law in 2020, governs cookies and trackers. The Code de la consommation governs e-commerce. Since June 2025, the European Accessibility Act (EAA), transposed into French law, governs accessibility. Each layer is enforced independently, and penalties stack.

Two practical consequences. First, a site can be fully compliant on three layers and still face fines on a fourth. Second, the regulator that acts depends on which layer is broken. The CNIL handles personal data and cookies. DGCCRF handles consumer law. The Défenseur des droits handles accessibility complaints.

Mentions légales: the page most small businesses forget

Every site published from or targeting France needs a "mentions légales" page. The LCEN lists what it must contain:

  • Identity of the site editor (legal name, business form, registered address, share capital for companies, SIRET number, intra-community VAT number if applicable)
  • Name and contact details of the publication director (responsable de la publication)
  • Identity and contact details of the web host (name, address, phone number)
  • For sites publishing press-style content, the director of publication must be named in writing

The page is supposed to be reachable from anywhere on the site in two clicks. Most agencies put it in the footer. That is fine. Burying it in a 2019 archive under "About" is not.

The Orange Pro guide on the topic notes that micro-enterprises (auto-entrepreneurs) are exempt from share-capital disclosure but still need SIRET, host, and director information. There is no exemption for being too small to bother.

Personal data: RGPD in plain language

If your site collects an email address through a contact form, runs Google Analytics, or stores any customer information, RGPD applies. The core obligations:

  • A privacy policy that names the data controller, the legal basis for each processing operation, the retention period, and the contact for data-subject requests
  • A way for users to exercise their rights: access, rectification, deletion, portability. A contact email is enough for small businesses
  • A record of processing activities (registre des traitements) if you employ fewer than 250 people, this is required only for processing that is not occasional or that poses a risk

The CNIL has published a simplified framework for very small businesses that covers the basics in a few pages. Following it does not make you bulletproof, but it moves you out of the "obviously negligent" category.

What trips up most small sites: forms that collect data without stating why, mailing lists built from trade-show contacts without documented consent, and analytics that run before the user has had a chance to object. Each of these is a known RGPD violation.

Cookies: consent first, always

France interprets the ePrivacy directive strictly. No non-essential cookie can be set before the user has given explicit consent, and refusal must be as easy as acceptance. A banner with an "Accept all" button and a hidden "Manage preferences" link does not count.

What is actually required:

  • A consent banner that appears on the first visit, before any non-essential tracker fires
  • Equal-prominence buttons for "Accept" and "Refuse". The Refuse button cannot be styled smaller or greyed out
  • A way for the user to change their mind later, usually through a persistent link in the footer
  • A cookies policy that lists each tracker, what it does, who sets it, and how long it lives

Google Analytics, Meta Pixel, Hotjar, and most advertising tools are non-essential. They all require prior consent. A small business that ships a new site and forgets the consent layer is in violation from day one.

Selling online: extra rules for e-commerce

If the site accepts payment, RGPD is not enough. The Code de la consommation imposes a separate set of obligations:

  • General conditions of sale (CGV) that the customer accepts before paying. They must include identity, price, delivery terms, right of withdrawal, and dispute resolution
  • A withdrawal period of 14 days for sales to consumers, with specific wording
  • Display of VAT (TTC for B2C sales in France)
  • Secure payment handling. PCI-DSS compliance is delegated to the payment provider, but you still need to use one
  • Confirmation by email within a reasonable time

Simplébo's 2025 update on the topic reminds site owners that the same rules apply to booking systems and reservation deposits, not just physical product sales. A restaurant that takes a deposit through its own form is doing e-commerce.

Accessibility: the 2025 rule everyone missed

Since 28 June 2025, the EAA applies in France. Any business selling a digital service to consumers must meet the European standard EN 301 549, which aligns with WCAG 2.1 AA. The penalty structure is not as visible as RGPD's, but complaints reach the Défenseur des droits and can lead to injunctions.

The practical scope: text contrast, image alt text, keyboard navigation, captions on video, and form labels. A small business with a five-page site can audit itself in an afternoon using the WebAIM checklist. The BTG article on 2026 accessibility obligations cites a WebAIM scan that found 95.9% of the top one million home pages have at least one detectable WCAG failure, so the base rate for serious issues is not subtle.

If your site is older than three years, it almost certainly fails. Fixing it is mostly small edits to colour contrast, alt text, and form structure. None of it requires a redesign.

A checklist you can finish this week

Most small businesses can reach a defensible compliance level in two focused days. Order matters:

  1. Write the mentions légales page from the LCEN template. Keep it under one printed page
  2. Add or update the privacy policy. The CNIL model is enough to start
  3. Install a consent banner that meets French rules. Tarteaucitron, Axeptio, and Didomi all work. Test the "Refuse" path manually
  4. Audit accessibility with axe DevTools or the WebAIM contrast checker. Fix the red-flag issues first
  5. If you sell anything, write the CGV and add a withdrawal link to the checkout flow

That sequence covers roughly 80% of what the regulators look for. The remaining 20% is edge cases specific to your activity (regulated professions, large-scale processing, third-country data transfers).

What actually happens if you skip this

The penalties are real but unevenly enforced. The CNIL publishes its annual report each year and most of the formal notices go to small companies. Average fine for a first offence on cookies: a few thousand euros. Repeat or wilful: up to 4% of global revenue or 20 million euros, whichever is higher. In practice, the regulator prefers to publish the offender's name and force a remediation period. The reputational cost is usually worse than the fine.

Accessibility is enforced less visibly today, but the wave of EAA complaints is starting to arrive through consumer associations. Litigation risk is real for any business selling across borders.

The honest framing: most small business sites are partly compliant and partly not. Closing the gap is not a matter of installing a magic plugin. It is an afternoon of structured edits, followed by a habit of asking "is this legal?" before adding the next feature.

If you want a starting point, the Lumevel studio walks small businesses through the legal stack as part of a site rebuild. The audit is shorter than most agencies quote and the fix list comes out in plain English.

Sources

  • Mentions légales d'un site web : France Num
  • Mentions obligatoires d'un site internet : Burguin Digital
  • Création de site internet : obligations légales : LegalVision
  • Mentions obligatoires selon la loi : Orange Pro
  • Obligations légales d'un site professionnel : Simplébo
  • Accessibilité web : obligations 2026 : BTG Communication