GDPR and You
Personal data, cookies, consent, and user rights: discover the essential steps to strengthen your website's GDPR compliance and protect your visitors.

Sur cette page4 sections
Hello everyone, today we're talking about GDPR!
The GDPR, or General Data Protection Regulation, is the European regulation that protects the personal data of EU citizens. All businesses, regardless of size, must ensure their website follows these rules. Why? To guarantee user privacy and avoid heavy penalties. Unsure about your site's compliance? Don't panic, we explain everything in detail in this blog.
Today, the GDPR remains a vital pillar of data protection in Europe, and its story continues to be written.
Indeed, non-compliance with GDPR can lead to devastating consequences for businesses:

In summary: implementing these practices shows that you take data protection seriously, thereby ensuring user trust and legal peace of mind for your business.
In summary: Small businesses often find themselves facing a wall: too many constraints, not enough resources or information to move forward confidently. However, with adapted support and a progressive approach, they can overcome these challenges and align their practices with GDPR requirements. It's not easy, but it's possible
Why Klaro?
The advantages of Matomo:
The GDPR, or General Data Protection Regulation, is the European regulation that protects the personal data of EU citizens. All businesses, regardless of size, must ensure their website follows these rules. Why? To guarantee user privacy and avoid heavy penalties. Unsure about your site's compliance? Don't panic, we explain everything in detail in this blog.
What is GDPR?
History of GDPR to the present day
The emergence of a need for regulation
With the digital explosion, it quickly became crucial to regulate the collection and processing of personal data. Why? Because this data is sensitive and often exploited. As the saying goes: if you're not paying for the product, you are the product.The early days: the 1995 directive
It all started in 1995 with Directive 95/46/EC on data protection. Pioneering for its time, it nevertheless quickly became outdated in the face of rapid technological evolution. Furthermore, each EU country could transpose the directive in its own way, leading to gaps in its application.The birth of GDPR
To meet these challenges, the GDPR as we know it was born in April 2016. Its goal? To strengthen and harmonise personal data protection within the EU. Member States had two years to prepare until 25 May 2018, the date of its official entry into force, replacing the 1995 directive.A constantly evolving framework
Since 2018, the GDPR has evolved alongside digital challenges. Landmark cases, such as Schrems II in July 2020, have shaped its application. This ruling invalidated the Privacy Shield, affecting data transfers between the EU and the USA.Today, the GDPR remains a vital pillar of data protection in Europe, and its story continues to be written.
The concrete impacts of GDPR on our privacy
Strengthened rights for individuals
The GDPR has revolutionised how our personal data is managed. Among the rights it guarantees:- Right of access: You can ask what data a company holds about you.
- Right to rectification: In case of an error, you have the right to correct your information.
- Right to erasure (right to be forgotten): You can request the deletion of your data under certain conditions.
- Right to portability: Your data must be easily transferable from one service to another.
Privacy by design
The GDPR introduces the concept of privacy by design, requiring companies to integrate security and confidentiality from the very start of developing their products or services. It is therefore unthinkable to hear "We'll deal with it later"; it has to be now.Latest GDPR-related scandals
Authorities enforce the GDPR to the letter for everyone, as proven by these recent cases:- Google Analytics under fire: In 2022, France and Austria ruled its use non-compliant due to data transfers to the United States.
- Meta and AI: In June 2024, Meta was accused of using users' personal data to train its artificial intelligence models, raising doubts about consent and transparency.
Record fines
Large companies have paid a high price for non-compliance:- Amazon: €32 million in December 2023 for an intrusive and poorly secured monitoring system for its employees.
- Google: €150 million for failing to add a “Reject all” button on its consent banner.
Indeed, non-compliance with GDPR can lead to devastating consequences for businesses:
- Financial fines:
- Up to€20 million or 4% of annual global turnoverfor serious infringements (Article 83 GDPR).
- For minor infringements, fines can reach€10 million or 2% of annual global turnover.
- Formal notices and injunctions:
- Obligation to comply within a given timeframe, under penalty of daily fines (up to €100,000 per daydepending on severity).
- Obligation to comply within a given timeframe, under penalty of daily fines (up to €100,000 per daydepending on severity).
- Other corrective measures:
- Temporary or permanent limitation/suspension of data processing.
- Suspension of data flows to third countries.
- Withdrawal of certifications or authorisations.
How to make your site GDPR compliant?
If you manage a site or plan to create one, respecting the GDPR is essential to avoid unnecessary sanctions. Here are the key measures to put in place:Use a consent manager
That famous banner that appears when arriving on a site has specific requirements:- List all third-party services: You must identify those that collect data, such as Google Analytics or Google Maps, even if they don't use cookies.
- Granular consent: Offer clear options:“Accept all”,“Reject all”and a custom configuration to allow case-by-case acceptance.
- Transparency on purpose: Explain why data is collected (e.g., improving user experience, analysing traffic).
Draft a privacy policy and legal notices
These documents must be easily accessible (via a link in the footer, for example) and include:- Data collected: How it's used, the recipients, and the protection measures in place.
- Publisher information: Identity, contact details, and mandatory legal information.
- Clear language: These pages must be written simply to be understandable by any user, not just legal experts.
Appoint a Data Protection Officer (DPO)
Mandatory for:- Public bodies.
- Companies that regularly and systematically monitor individuals on a large scale.
- Ensure the organisation's compliance.
- Advise on best practices.
- Serve as an intermediary between the company, users, and supervisory authorities.
Apply data minimisation
Only data strictly necessary for the activity or processing involved should be collected. Any excessive or unjustified collection constitutes a serious breach.In summary: implementing these practices shows that you take data protection seriously, thereby ensuring user trust and legal peace of mind for your business.
GDPR challenges for small businesses
Even today, many sites, particularly those of small businesses, do not comply with the GDPR. This problem is explained by several factors:A sometimes prohibitive cost
Becoming compliant can represent a significant expense for small and medium-sized enterprises (SMEs). Costs include:- Professional intervention for implementation.
- Consent management tools.
- Security audits.
- Training to raise team awareness.
A lack of regulatory knowledge
Some small structures are completely unaware of the obligations imposed by the GDPR, often due to a lack of information or awareness. This ignorance leads to errors that can be costly, especially in the event of an audit or complaint. The key lies in better awareness and an effort to follow legal developments, which is sometimes easier said than done.Constantly evolving regulation
The GDPR is not a static framework. Between new legal decisions, technical updates, and necessary adjustments, companies must constantly adapt. For a small structure, which doesn't always have a dedicated team, following these developments can quickly become a real headache, especially when frequent modifications, such as adjustments to consent banners, are required.In summary: Small businesses often find themselves facing a wall: too many constraints, not enough resources or information to move forward confidently. However, with adapted support and a progressive approach, they can overcome these challenges and align their practices with GDPR requirements. It's not easy, but it's possible
Our approach: GDPR without compromise
Aware of the challenges that GDPR compliance represents, we have chosen to integrate these requirements directly into the development of our sites. By collaborating with us, you can be assured that your site will be fully compliant. Here is an overview of the solutions we put in place to guarantee your peace of mind.Consent management with Klaro
We use Klaro, a reliable and privacy-respecting open-source solution. Suitable for both small and large structures, Klaro allows for precise management of user consent.Why Klaro?
- Compatible with most third-party services.
- Customisable and designed not to overlook external services.
- Requests consent before any personal data transfer.
Traffic tracking with self-hosted Matomo
Replacing Google Analytics, we use Matomo, an open-source alternative that combines performance and data respect.The advantages of Matomo:
- Analysis of user behaviour without transferring data to third parties.
- Anonymised data (such as IP addresses) and stored locally.
- The collected data, limited to audience measurement, is not considered confidential under GDPR.
Strengthening security and best practices
Beyond tools, our practices guarantee a high level of security to prevent data leaks:- SSL certificates via Let’s Encrypt for secure connections.
- Regular password change recommendations for users, improving account protection.
- Continuous updates to use libraries without known vulnerabilities.
- Mastered and optimised code to avoid vulnerabilities.
- Regular vulnerability analysis with tools like Nessus or OWASP ZAP.
- Encrypted backups, protecting data in case of failure or technical problem




