Skip to main content
Accueil >Blogs >L'IA dans le web

GDPR and You

Personal data, cookies, consent, and user rights: discover the essential steps to strengthen your website's GDPR compliance and protect your visitors.

GDPR and You
Sur cette page4 sections
Hello everyone, today we're talking about GDPR!

The GDPR, or General Data Protection Regulation, is the European regulation that protects the personal data of EU citizens. All businesses, regardless of size, must ensure their website follows these rules. Why? To guarantee user privacy and avoid heavy penalties. Unsure about your site's compliance? Don't panic, we explain everything in detail in this blog.

What is GDPR?

History of GDPR to the present day

The emergence of a need for regulation

With the digital explosion, it quickly became crucial to regulate the collection and processing of personal data. Why? Because this data is sensitive and often exploited. As the saying goes: if you're not paying for the product, you are the product.

The early days: the 1995 directive

It all started in 1995 with Directive 95/46/EC on data protection. Pioneering for its time, it nevertheless quickly became outdated in the face of rapid technological evolution. Furthermore, each EU country could transpose the directive in its own way, leading to gaps in its application.

The birth of GDPR

To meet these challenges, the GDPR as we know it was born in April 2016. Its goal? To strengthen and harmonise personal data protection within the EU. Member States had two years to prepare until 25 May 2018, the date of its official entry into force, replacing the 1995 directive.

A constantly evolving framework

Since 2018, the GDPR has evolved alongside digital challenges. Landmark cases, such as Schrems II in July 2020, have shaped its application. This ruling invalidated the Privacy Shield, affecting data transfers between the EU and the USA.

Today, the GDPR remains a vital pillar of data protection in Europe, and its story continues to be written.

The concrete impacts of GDPR on our privacy

Strengthened rights for individuals

The GDPR has revolutionised how our personal data is managed. Among the rights it guarantees:

  • Right of access: You can ask what data a company holds about you.
  • Right to rectification: In case of an error, you have the right to correct your information.
  • Right to erasure (right to be forgotten): You can request the deletion of your data under certain conditions.
  • Right to portability: Your data must be easily transferable from one service to another.
Organizations must also clearly inform users about the collection and use of their data, promoting increased transparency. You maintain total control over your information, limiting abuses such as excessive profiling or intrusive advertisements.

Privacy by design

The GDPR introduces the concept of privacy by design, requiring companies to integrate security and confidentiality from the very start of developing their products or services. It is therefore unthinkable to hear "We'll deal with it later"; it has to be now.

Authorities enforce the GDPR to the letter for everyone, as proven by these recent cases:

  • Google Analytics under fire: In 2022, France and Austria ruled its use non-compliant due to data transfers to the United States.
  • Meta and AI: In June 2024, Meta was accused of using users' personal data to train its artificial intelligence models, raising doubts about consent and transparency.

Record fines

Large companies have paid a high price for non-compliance:

  • Amazon: €32 million in December 2023 for an intrusive and poorly secured monitoring system for its employees.
  • Google: €150 million for failing to add a “Reject all” button on its consent banner.


Indeed, non-compliance with GDPR can lead to devastating consequences for businesses:

  • Financial fines:
    • Up to€20 million or 4% of annual global turnoverfor serious infringements (Article 83 GDPR).
    • For minor infringements, fines can reach€10 million or 2% of annual global turnover.
  • Formal notices and injunctions:
    • Obligation to comply within a given timeframe, under penalty of daily fines (up to €100,000 per daydepending on severity).
  • Other corrective measures:
    • Temporary or permanent limitation/suspension of data processing.
    • Suspension of data flows to third countries.
    • Withdrawal of certifications or authorisations.
With the GDPR, authorities are showing they don't mess around when it comes to protecting our data.

How to make your site GDPR compliant?

If you manage a site or plan to create one, respecting the GDPR is essential to avoid unnecessary sanctions. Here are the key measures to put in place:

That famous banner that appears when arriving on a site has specific requirements:

GDPR compliance illustration
  • List all third-party services: You must identify those that collect data, such as Google Analytics or Google Maps, even if they don't use cookies.
  • Granular consent: Offer clear options:“Accept all”,“Reject all”and a custom configuration to allow case-by-case acceptance.
  • Transparency on purpose: Explain why data is collected (e.g., improving user experience, analysing traffic).
Note: Any third-party service collecting data, whether it installs cookies or not, must be included (e.g., integration of a Google Maps card).

These documents must be easily accessible (via a link in the footer, for example) and include:

  • Data collected: How it's used, the recipients, and the protection measures in place.
  • Publisher information: Identity, contact details, and mandatory legal information.
  • Clear language: These pages must be written simply to be understandable by any user, not just legal experts.

Appoint a Data Protection Officer (DPO)

Mandatory for:

  • Public bodies.
  • Companies that regularly and systematically monitor individuals on a large scale.
The DPO's role:

  • Ensure the organisation's compliance.
  • Advise on best practices.
  • Serve as an intermediary between the company, users, and supervisory authorities.

Apply data minimisation

Only data strictly necessary for the activity or processing involved should be collected. Any excessive or unjustified collection constitutes a serious breach.

In summary: implementing these practices shows that you take data protection seriously, thereby ensuring user trust and legal peace of mind for your business.

GDPR challenges for small businesses

Even today, many sites, particularly those of small businesses, do not comply with the GDPR. This problem is explained by several factors:

A sometimes prohibitive cost

Becoming compliant can represent a significant expense for small and medium-sized enterprises (SMEs). Costs include:

  • Professional intervention for implementation.
  • Consent management tools.
  • Security audits.
  • Training to raise team awareness.
For a small structure, these expenses can quickly eat up a large part of the web budget.

A lack of regulatory knowledge

Some small structures are completely unaware of the obligations imposed by the GDPR, often due to a lack of information or awareness. This ignorance leads to errors that can be costly, especially in the event of an audit or complaint. The key lies in better awareness and an effort to follow legal developments, which is sometimes easier said than done.

Constantly evolving regulation

The GDPR is not a static framework. Between new legal decisions, technical updates, and necessary adjustments, companies must constantly adapt. For a small structure, which doesn't always have a dedicated team, following these developments can quickly become a real headache, especially when frequent modifications, such as adjustments to consent banners, are required.


In summary: Small businesses often find themselves facing a wall: too many constraints, not enough resources or information to move forward confidently. However, with adapted support and a progressive approach, they can overcome these challenges and align their practices with GDPR requirements. It's not easy, but it's possible

Our approach: GDPR without compromise

Aware of the challenges that GDPR compliance represents, we have chosen to integrate these requirements directly into the development of our sites. By collaborating with us, you can be assured that your site will be fully compliant. Here is an overview of the solutions we put in place to guarantee your peace of mind.

We use Klaro, a reliable and privacy-respecting open-source solution. Suitable for both small and large structures, Klaro allows for precise management of user consent.

Why Klaro?

  • Compatible with most third-party services.
  • Customisable and designed not to overlook external services.
  • Requests consent before any personal data transfer.
Our implementation includes an automatic notification if the services offered on the site are modified. Thus, your users stay informed, their choices are respected, and their data protected.

Traffic tracking with self-hosted Matomo

Replacing Google Analytics, we use Matomo, an open-source alternative that combines performance and data respect.

The advantages of Matomo:

  • Analysis of user behaviour without transferring data to third parties.
  • Anonymised data (such as IP addresses) and stored locally.
  • The collected data, limited to audience measurement, is not considered confidential under GDPR.
Furthermore, Matomo offers an opt-out option, allowing users to disable tracking if they wish.

Strengthening security and best practices

Beyond tools, our practices guarantee a high level of security to prevent data leaks:

  • SSL certificates via Let’s Encrypt for secure connections.
  • Regular password change recommendations for users, improving account protection.
  • Continuous updates to use libraries without known vulnerabilities.
  • Mastered and optimised code to avoid vulnerabilities.
  • Regular vulnerability analysis with tools like Nessus or OWASP ZAP.
  • Encrypted backups, protecting data in case of failure or technical problem
We make security and data protection a priority. Every solution, every practice aims to respect your users' privacy while guaranteeing the integrity and reliability of your business. With us, GDPR becomes a strength, not a constraint.