By
Logiks Lab
Published on
June 17, 2026
Updated on
August 13, 2026

RGPD and marketing site: what an SME really needs to check in 2026

Avoid the invisible RGPD risk: forms, cookies, pixels and CRM must remain under control.

Work computer, illustrating ransomware protection for an SME.
Type
Practical guide
Level
Intermediate
Reading time
16
Progress0 %

Your site doesn’t just need to convert.
He must prove that he respects the data he collects.

1. Key figures

NumberWhat to UnderstandSource
20,150 complaintsIn 2025, the CNIL indicates having received 20 150 complaints, which is 10 % more than in 2024. Data protection is becoming a concrete expectation of users.CNIL - Annual Report 2025
1 900 complaintsApproximately 1 900 complaints received by the CNIL in 2025 directly concern data breaches. Marketing risk joins security risk.CNIL - Annual Report 2025
323 controls, 83 sanctionsThe French authority carried out 323 checks and imposed 83 sanctions in 2025. Control is not an abstract hypothesis.CNIL - Annual Report 2025
487 M€The total amount of fines imposed in 2025 reached nearly 487 million euros. Significant sanctions remain rare for an SME, but the order of magnitude highlights the stakes.CNIL - Annual Report 2025
6 167 violationsIn 2025, 6 167 personal data violations have been notified to the CNIL, i.e. +9,5 % in relation to 2024. One in two reported incidents involves hacking.CNIL - Annual Report 2025
42 measurementsThe ANSSI IT hygiene guide presents 42 measures to strengthen the security of an information system. A marketing site also depends on this base.ANSSI - IT hygiene guide

2. Introduction

At first glance, an acquisition site seems light: a few pages, a contact form, a newsletter, cookies, an audience tool, sometimes an advertising pixel, a CRM, a chat, a white paper download. However, this apparent simplicity hides a chain of treatments. An email address enters a form, flows to a tool, triggers a notification, joins a CRM, feeds an audience, sometimes sleeps longer than expected.

We defend a simple position: RGPD does not slow down marketing. It imposes a discipline of clarity. It requires us to say what we collect, why, for how long, with whom, on what basis, with what security and what rights for the person.

For an SME, the subject is not about playing lawyer. It consists of making the system defensible.
No proof, no trust.

3. Symptoms: when a site collects without governing

We quickly recognize a fragile device: cookies banner installed but never audited, form without clear mention, CRM connected without shelf life, advertising pixels active before consent, copied confidentiality policy, subcontractors not listed, exports of leads in spreadsheets, access shared between agency and client:
Collection exists, but governance is lacking.

Friction appears at the first incident. Who knows what scripts load on the site? Who can prove consent? Who deletes a contact at their request? Who knows the tools where the data passes? Who notifies the service provider in the event of a leak? Who documents the legal basis of a campaign?

Without a register, mastery remains theoretical.
Without verifiable consent, serenity disappears.
Without security, compliance does not hold.

A conversion page does not need to become an administrative file. Its collection must remain legible.

4. Actors: CNIL, DPO, web agency, CMP, CRM, advertising agencies, host

A RGPD marketing site audit must name the actors. Otherwise, responsibilities get lost in the fog.

ActorRoleWhat to check
CNILFrench data protection authority, recommendations, controls, sanctions.Cookie rules, security, violations, personal rights, transparency.
DPO or advice RGPDLegal and organizational interpretation.Register, legal bases, notices, contracts, rights procedures.
Web agencyCMS integration, scripts, forms, tags, hosting sometimes.Who installs what, with what access, what documentation, what responsibility.
CMPConsent Management Platform for cookies and trackers.Triggering before/after consent, proof, refusal as simple as acceptance.
CRM and marketing automationLead storage and activation.Legal basis, retention period, segmentation, unsubscription, exports.
Advertising agenciesGoogle Ads, Meta Ads, LinkedIn Ads, pixels, conversions.Purposes, consent, transfers, hearings, transmitted events.
Host and tools SaaSInfrastructure, forms, databases, files, logs.Subcontracting, security, location, access, backups.

Where the CNIL provides the framework, the DPO translates the risk. Where the agency sets up, marketing operates. Where CRM preserves, security must protect.
The page never works alone. She lives in a chain.

5. Definition: what is a marketing site audit RGPD

A RGPD marketing site audit is a structured review of forms, cookies, trackers, CRM tools, third-party scripts, information notices, legal bases, retention periods, subcontractors and security measures linked to data collection.

This definition matters. The audit goes beyond rereading a confidentiality policy at the end of the project. He must look at what is really happening in the browser, in the CMS, in the tags, in the CRM and in the procedures.
A page may appear compliant. The data flow can contradict this appearance.

6. Why this is becoming a priority in 2026

20 150 complaints received by the CNIL in 2025: data protection goes beyond the circle of specialists (CNIL, annual report 2025). It affects work, commerce, real estate, social media, data breaches, marketing practices and customer relationships.

The marketing device can be found at croisation of these issues. It collects identity, contact details, preferences, sometimes needs, behavior, downloads, pages viewed. With advertising and analytics tools, it can also trigger processing that is invisible to the visitor.

In its personal data security guide, the CNIL aims to help organizations implement appropriate protection measures. Its cookie rules also remind us that the use of trackers is particularly regulated by the Data Protection Act.

The right question therefore goes beyond: "do we have a banner?"
The right question is: "can we explain and prove what we are doing?"

7. Forms, cookies, CRM: the three risk areas

A landing page rarely exposes a single risk. It concentrates three areas which must be checked together.

AreaTypical riskExpected proof
FormsAbsent mentions, excessive fields, unclear recipients, undefined retention.Clear statement, purpose, recipient, duration, rights, legal basis.
Cookies and trackersDeposit before consent, refusal more difficult than acceptance, vague purposes.Script audit, CMP configured, proof of consent, readable categories.
CRM and activationLeads kept too long, opaque segmentation, uncontrolled exports.Duration, purge rules, unsubscribe, access, registry and documentation.

Treating only the cookie banner is like repainting the front door without looking at the rooms behind it.
The RGPD plays in the stream.

8. Recommended method: 9 blocks to check without scattering

The method recommended below is not a proprietary method Logiks. It is based on RGPD requirements, CNIL recommendations, good security practices and the operational audit of a marketing site.

In the workshop, we move forward as in a professional kitchen: inventory, set-up, temperature control, service. No theater. Evidence.

8.1. Map collection points

List all the places where the site collects or transmits data: contact form, quote, newsletter, white paper, customer account, chat, appointment booking, analytics, pixels, maps, integrated videos, A/B test tools.
Without inventory, compliance is opinion.

8.2. Identify the purposes

Each collection must have a clear purpose: respond to a request, send a newsletter, measure the audience, personalize an advertisement, track a conversion, secure the site. A vague purpose makes everything else fragile.
The "just in case" does not constitute a compliance strategy.

8.3. Check the legal bases

Consent, contract, legitimate interest, legal obligation: the choice depends on the processing. Advertising cookies require special attention. Inbound requests don't have the same logic as a remarketing audience.
The legal basis must be documented, not improvised.

8.4. Audit cookies and scripts

Scan the actually loaded scripts. Check what leaves before consent, what remains after refusal, the categories displayed, the partners listed and the ability to withdraw your choice. The French authority points out that simply continuing to browse is not enough to express valid consent.
An apparently compliant banner can hide too early a trigger.

8.5. Reread the forms

Each form must explain the purpose, recipients, rights and necessary information. Collapse the fields. A contact form doesn't always need a phone number, a budget, a company size, and a mandatory message.
Minimization is not an abstract constraint. It is elegant.

8.6. Control the CRM

The CRM must have rules for retention, qualification, unsubscription, access, export and deletion. Old leads should not sleep in a base indefinitely.
Outdated marketing data turns into debt.

8.7. Check subcontractors

List the tools: CMS, host, analytics, CRM, emailing, advertising, chat, forms, appointment making, storage. For each, identify the role, contract, location, security, access.
The invisible service provider emerges as a visible risk on the day of the inspection.

8.8. Secure access

The CNIL guide 2024 and ANSSI good practices remind us of the importance of appropriate technical and organizational measures. MFA, limited rights, nominative accounts, deletion of agency access, backups, logging: the marketing presence must enter the cyber base.
Compliance without security looks like window dressing.

8.9. Document the evidence

Keep the mapping, CMP captures, form mentions, list of subcontractors, CRM rules, rights procedures, retention periods and verification date.
The subject is not limited to what we say. He cares about what we can show.

9. Logiks Tips: Start with visible evidence

We do not recommend starting with a major documentary project if the site has never been verified. The first lever consists of looking at what the user sees and what the browser loads.

First tip: audit forms and cookies before rewriting the privacy policy. If the actual collection escapes the team, the legal text will retain a decorative function.

Second tip: involve marketing, agency and DPO together. Marketing knows campaigns. The agency knows the scripts. The DPO knows the legal bases. Separating these three views produces blind spots.

Third tip: Reduce before you optimize. Fewer fields, fewer tags, fewer exports, fewer permanent accesses. Compliance often becomes simpler when collection becomes more sober.
Finally, we recommend a very concrete control table:

  • form;
  • data collected;
  • purpose;
  • recipient tool;
  • legal basis;
  • duration;
  • proof;
  • responsible.

This register is not paperwork. It establishes an architecture of trust.

10. Decision grid: is your site defensible?

CriterionFragileCorrectMastered
FormsMissing mentionsNotices presentClear notices, minimized fields, known recipients
CookiesGeneric bannerCMP configuredAudited scripts, simple refusal, evidence available
CRMFuzzy conservationPartial rulesDuration, purge, unsubscription, access and exports controlled
SubcontractorsNot listedKnown toolsDocumented contracts, roles, location, security
SecurityShared accountsLimited accessMFA, nominative rights, departures, backups, logging
Rights of peopleImpromptu responseDedicated addressProcedure, deadline, response model, traceability
DocumentationPolicy copiedPartial registerEvidence, dates, responsible, regular review

If cookies and forms are in "Fragile", start there. The rest will follow with more clarity.

11. Frequent errors: six confusions that expose an SME

First trap: believe that a banner sets everything. The CMP is only valid if the scripts are properly categorized and triggered.

Second drift: copying a confidentiality policy. A generic text proves nothing if the tools, durations, purposes and subcontractors do not correspond to the real site.

Third weakness: collecting too many fields. The larger the data collected, the more the risk increases. Sobriety is often marketing’s best ally.

Fourth pitfall: forgetting advertising tools. A poorly configured pixel, enriched conversion, audience or tag can create uncontrolled processing.

Fifth risk: leave agency access open. An old service provider with CMS, Tag Manager or CRM access creates a blind spot.

Last point: separate RGPD and cybersecurity. The CNIL points out that data security is part of the subject. A compliant device in text but fragile in access remains exposed.

12. Action Plan 30 / 60 / 90 days

12.1. Within 30 days

  • list all forms;
  • scan cookies and scripts;
  • check the CMP;
  • re-read the notices near the forms;
  • identify the recipient tools;
  • remove unnecessary tags;
  • enable MFA on CMS, CRM and Tag Manager.

We are not yet seeking legal completeness. Visible blind spots are closed.

12.2. Within 60 days

  • document the purposes and legal bases;
  • clarify retention periods;
  • update the privacy policy;
  • verify subcontracting contracts;
  • create a rights response procedure;
  • define a CRM purge rule;
  • train people who handle leads.

The system is starting to become defensible.

12.3. Within 90 days

  • integrate the RGPD control into each new landing page;
  • create a quarterly tag review;
  • document evidence of consent;
  • audit provider access;
  • link data incidents to the cyber plan;
  • maintain a verification sheet in the CMS.

At this point, the topic ceases to be a one-off correction. It takes the form of a method.

13. FAQ: RGPD and marketing site

13.1. Is a showcase site affected by RGPD?

Yes, as soon as it collects or processes personal data: form, newsletter, cookies, analytics, advertising pixel, chat, appointment booking. A purely informative site, without tracker or form, is encountered less often than one might think.

13.2. Is a cookie banner enough?

No. The banner must be correctly configured, but it is also necessary to check the scripts, purposes, partners, refusal, withdrawal of consent and proof. The authority points out that simply continuing to browse does not constitute consent.

13.3. Can we use Google Analytics on an SME site?

Yes, but usage must be configured and documented. Consent or possible exemption must be verified depending on the tool, configuration, purposes, durations and transfers. The decision must be made with legal and technical reading.

13.4. How long to keep leads?

The duration depends on the purpose, the business cycle and the relationship with the person. The important thing is to define a rule, document it, respect it and purge data that no longer has any justification.

13.5. Who should cover the subject: marketing, DPO or agency?

The three must cooperate. Marketing knows the objectives, the agency knows the implementation, the DPO or consultancy RGPD secures the interpretation. Without this coordination, the system produces gray areas.

14. Conclusion: compliance becomes proof of seriousness

A compliant marketing site does not turn into a restricted site. It becomes a device that collects measuredly, explains clearly, secures methodically and documents seriously.

This requirement does not replace performance. It makes it more durable. It protects the relationship with the visitor, the quality of the CRM database, the credibility of the brand and the ability of the team to explain its choices.

For Logiks, the good reflex is to start with reality: forms, cookies, scripts, CRM, access, proofs. The text comes next.

It is no longer just a legal constraint.
Compliance becomes proof of control: collect, explain, protect.

15. Main sources

  • CNIL - Annual report 2025 - published in May 2026 - https://www.cnil.fr/fr/rapport-annuel-2025
  • CNIL - Annual report 2024 - published in 2025 - https://www.cnil.fr/fr/rapport-annuel-2024
  • CNIL - Guide to the security of personal data: new edition 2024 - 26 March 2024 - https://www.cnil.fr/fr/guide-de-la-securite-des-donnees-personnelles-nouvelle-edition-2024
  • CNIL - Personal data security guide - consulted on June 17 2026 - https://www.cnil.fr/fr/guide-de-la-securite-des-donnees-personnelles
  • CNIL - Cookies and other trackers: final recommendations on multi-terminal consent - published in 2026 - https://www.cnil.fr/fr/cookies-et-autres-traceurs-recommandations-finales-sur-le-consentement-multi-terminaux
  • CNIL - Questions and answers on the guidelines for cookies and other tracers - consulted on 17 June 2026 - https://cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ
  • CNIL - Cookies and other tracers - consulted on 17 June 2026 - https://www.cnil.fr/fr/cookies-et-autres-traceurs
  • ANSSI - Computer hygiene guide - consulted on June 17 2026 - https://messervices.cyber.gouv.fr/guides/guide-dhygiene-informatique