Your site doesn’t just need to convert.
He must prove that he respects the data he collects.
1. Key figures
2. Introduction
At first glance, an acquisition site seems light: a few pages, a contact form, a newsletter, cookies, an audience tool, sometimes an advertising pixel, a CRM, a chat, a white paper download. However, this apparent simplicity hides a chain of treatments. An email address enters a form, flows to a tool, triggers a notification, joins a CRM, feeds an audience, sometimes sleeps longer than expected.
We defend a simple position: RGPD does not slow down marketing. It imposes a discipline of clarity. It requires us to say what we collect, why, for how long, with whom, on what basis, with what security and what rights for the person.
For an SME, the subject is not about playing lawyer. It consists of making the system defensible.
No proof, no trust.
3. Symptoms: when a site collects without governing
We quickly recognize a fragile device: cookies banner installed but never audited, form without clear mention, CRM connected without shelf life, advertising pixels active before consent, copied confidentiality policy, subcontractors not listed, exports of leads in spreadsheets, access shared between agency and client:
Collection exists, but governance is lacking.
Friction appears at the first incident. Who knows what scripts load on the site? Who can prove consent? Who deletes a contact at their request? Who knows the tools where the data passes? Who notifies the service provider in the event of a leak? Who documents the legal basis of a campaign?
Without a register, mastery remains theoretical.
Without verifiable consent, serenity disappears.
Without security, compliance does not hold.
A conversion page does not need to become an administrative file. Its collection must remain legible.
4. Actors: CNIL, DPO, web agency, CMP, CRM, advertising agencies, host
A RGPD marketing site audit must name the actors. Otherwise, responsibilities get lost in the fog.
Where the CNIL provides the framework, the DPO translates the risk. Where the agency sets up, marketing operates. Where CRM preserves, security must protect.
The page never works alone. She lives in a chain.
5. Definition: what is a marketing site audit RGPD
A RGPD marketing site audit is a structured review of forms, cookies, trackers, CRM tools, third-party scripts, information notices, legal bases, retention periods, subcontractors and security measures linked to data collection.
This definition matters. The audit goes beyond rereading a confidentiality policy at the end of the project. He must look at what is really happening in the browser, in the CMS, in the tags, in the CRM and in the procedures.
A page may appear compliant. The data flow can contradict this appearance.
6. Why this is becoming a priority in 2026
20 150 complaints received by the CNIL in 2025: data protection goes beyond the circle of specialists (CNIL, annual report 2025). It affects work, commerce, real estate, social media, data breaches, marketing practices and customer relationships.
The marketing device can be found at croisation of these issues. It collects identity, contact details, preferences, sometimes needs, behavior, downloads, pages viewed. With advertising and analytics tools, it can also trigger processing that is invisible to the visitor.
In its personal data security guide, the CNIL aims to help organizations implement appropriate protection measures. Its cookie rules also remind us that the use of trackers is particularly regulated by the Data Protection Act.
The right question therefore goes beyond: "do we have a banner?"
The right question is: "can we explain and prove what we are doing?"
7. Forms, cookies, CRM: the three risk areas
A landing page rarely exposes a single risk. It concentrates three areas which must be checked together.
Treating only the cookie banner is like repainting the front door without looking at the rooms behind it.
The RGPD plays in the stream.
8. Recommended method: 9 blocks to check without scattering
The method recommended below is not a proprietary method Logiks. It is based on RGPD requirements, CNIL recommendations, good security practices and the operational audit of a marketing site.
In the workshop, we move forward as in a professional kitchen: inventory, set-up, temperature control, service. No theater. Evidence.
8.1. Map collection points
List all the places where the site collects or transmits data: contact form, quote, newsletter, white paper, customer account, chat, appointment booking, analytics, pixels, maps, integrated videos, A/B test tools.
Without inventory, compliance is opinion.
8.2. Identify the purposes
Each collection must have a clear purpose: respond to a request, send a newsletter, measure the audience, personalize an advertisement, track a conversion, secure the site. A vague purpose makes everything else fragile.
The "just in case" does not constitute a compliance strategy.
8.3. Check the legal bases
Consent, contract, legitimate interest, legal obligation: the choice depends on the processing. Advertising cookies require special attention. Inbound requests don't have the same logic as a remarketing audience.
The legal basis must be documented, not improvised.
8.4. Audit cookies and scripts
Scan the actually loaded scripts. Check what leaves before consent, what remains after refusal, the categories displayed, the partners listed and the ability to withdraw your choice. The French authority points out that simply continuing to browse is not enough to express valid consent.
An apparently compliant banner can hide too early a trigger.
8.5. Reread the forms
Each form must explain the purpose, recipients, rights and necessary information. Collapse the fields. A contact form doesn't always need a phone number, a budget, a company size, and a mandatory message.
Minimization is not an abstract constraint. It is elegant.
8.6. Control the CRM
The CRM must have rules for retention, qualification, unsubscription, access, export and deletion. Old leads should not sleep in a base indefinitely.
Outdated marketing data turns into debt.
8.7. Check subcontractors
List the tools: CMS, host, analytics, CRM, emailing, advertising, chat, forms, appointment making, storage. For each, identify the role, contract, location, security, access.
The invisible service provider emerges as a visible risk on the day of the inspection.
8.8. Secure access
The CNIL guide 2024 and ANSSI good practices remind us of the importance of appropriate technical and organizational measures. MFA, limited rights, nominative accounts, deletion of agency access, backups, logging: the marketing presence must enter the cyber base.
Compliance without security looks like window dressing.
8.9. Document the evidence
Keep the mapping, CMP captures, form mentions, list of subcontractors, CRM rules, rights procedures, retention periods and verification date.
The subject is not limited to what we say. He cares about what we can show.
9. Logiks Tips: Start with visible evidence
We do not recommend starting with a major documentary project if the site has never been verified. The first lever consists of looking at what the user sees and what the browser loads.
First tip: audit forms and cookies before rewriting the privacy policy. If the actual collection escapes the team, the legal text will retain a decorative function.
Second tip: involve marketing, agency and DPO together. Marketing knows campaigns. The agency knows the scripts. The DPO knows the legal bases. Separating these three views produces blind spots.
Third tip: Reduce before you optimize. Fewer fields, fewer tags, fewer exports, fewer permanent accesses. Compliance often becomes simpler when collection becomes more sober.
Finally, we recommend a very concrete control table:
- form;
- data collected;
- purpose;
- recipient tool;
- legal basis;
- duration;
- proof;
- responsible.
This register is not paperwork. It establishes an architecture of trust.
10. Decision grid: is your site defensible?
If cookies and forms are in "Fragile", start there. The rest will follow with more clarity.
11. Frequent errors: six confusions that expose an SME
First trap: believe that a banner sets everything. The CMP is only valid if the scripts are properly categorized and triggered.
Second drift: copying a confidentiality policy. A generic text proves nothing if the tools, durations, purposes and subcontractors do not correspond to the real site.
Third weakness: collecting too many fields. The larger the data collected, the more the risk increases. Sobriety is often marketing’s best ally.
Fourth pitfall: forgetting advertising tools. A poorly configured pixel, enriched conversion, audience or tag can create uncontrolled processing.
Fifth risk: leave agency access open. An old service provider with CMS, Tag Manager or CRM access creates a blind spot.
Last point: separate RGPD and cybersecurity. The CNIL points out that data security is part of the subject. A compliant device in text but fragile in access remains exposed.
12. Action Plan 30 / 60 / 90 days
12.1. Within 30 days
- list all forms;
- scan cookies and scripts;
- check the CMP;
- re-read the notices near the forms;
- identify the recipient tools;
- remove unnecessary tags;
- enable MFA on CMS, CRM and Tag Manager.
We are not yet seeking legal completeness. Visible blind spots are closed.
12.2. Within 60 days
- document the purposes and legal bases;
- clarify retention periods;
- update the privacy policy;
- verify subcontracting contracts;
- create a rights response procedure;
- define a CRM purge rule;
- train people who handle leads.
The system is starting to become defensible.
12.3. Within 90 days
- integrate the RGPD control into each new landing page;
- create a quarterly tag review;
- document evidence of consent;
- audit provider access;
- link data incidents to the cyber plan;
- maintain a verification sheet in the CMS.
At this point, the topic ceases to be a one-off correction. It takes the form of a method.
13. FAQ: RGPD and marketing site
13.1. Is a showcase site affected by RGPD?
Yes, as soon as it collects or processes personal data: form, newsletter, cookies, analytics, advertising pixel, chat, appointment booking. A purely informative site, without tracker or form, is encountered less often than one might think.
13.2. Is a cookie banner enough?
No. The banner must be correctly configured, but it is also necessary to check the scripts, purposes, partners, refusal, withdrawal of consent and proof. The authority points out that simply continuing to browse does not constitute consent.
13.3. Can we use Google Analytics on an SME site?
Yes, but usage must be configured and documented. Consent or possible exemption must be verified depending on the tool, configuration, purposes, durations and transfers. The decision must be made with legal and technical reading.
13.4. How long to keep leads?
The duration depends on the purpose, the business cycle and the relationship with the person. The important thing is to define a rule, document it, respect it and purge data that no longer has any justification.
13.5. Who should cover the subject: marketing, DPO or agency?
The three must cooperate. Marketing knows the objectives, the agency knows the implementation, the DPO or consultancy RGPD secures the interpretation. Without this coordination, the system produces gray areas.
14. Conclusion: compliance becomes proof of seriousness
A compliant marketing site does not turn into a restricted site. It becomes a device that collects measuredly, explains clearly, secures methodically and documents seriously.
This requirement does not replace performance. It makes it more durable. It protects the relationship with the visitor, the quality of the CRM database, the credibility of the brand and the ability of the team to explain its choices.
For Logiks, the good reflex is to start with reality: forms, cookies, scripts, CRM, access, proofs. The text comes next.
It is no longer just a legal constraint.
Compliance becomes proof of control: collect, explain, protect.
15. Main sources
- CNIL - Annual report 2025 - published in May 2026 - https://www.cnil.fr/fr/rapport-annuel-2025
- CNIL - Annual report 2024 - published in 2025 - https://www.cnil.fr/fr/rapport-annuel-2024
- CNIL - Guide to the security of personal data: new edition 2024 - 26 March 2024 - https://www.cnil.fr/fr/guide-de-la-securite-des-donnees-personnelles-nouvelle-edition-2024
- CNIL - Personal data security guide - consulted on June 17 2026 - https://www.cnil.fr/fr/guide-de-la-securite-des-donnees-personnelles
- CNIL - Cookies and other trackers: final recommendations on multi-terminal consent - published in 2026 - https://www.cnil.fr/fr/cookies-et-autres-traceurs-recommandations-finales-sur-le-consentement-multi-terminaux
- CNIL - Questions and answers on the guidelines for cookies and other tracers - consulted on 17 June 2026 - https://cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ
- CNIL - Cookies and other tracers - consulted on 17 June 2026 - https://www.cnil.fr/fr/cookies-et-autres-traceurs
- ANSSI - Computer hygiene guide - consulted on June 17 2026 - https://messervices.cyber.gouv.fr/guides/guide-dhygiene-informatique
