The legal notices and online data protection fall under two distinct legal frameworks, often confused by website publishers. The Law for Confidence in the Digital Economy (LCEN) of June 21, 2004, requires every professional website to display identification information. The GDPR, on the other hand, regulates the collection and processing of users’ personal data.
These two obligations intersect on the same web page, but their requirements, sanctions, and recent developments deserve to be examined separately.
Control of cookie banners: what the CNIL has sanctioned since 2025
The topic of legal notices seems stabilized since the LCEN. However, the issue of cookies has been subject to concrete tightening. The CNIL strengthened its control over cookie banners in 2025, targeting sites that placed trackers requiring consent before any user action.
The central principle can be summed up in one sentence: refusing must be as easy as accepting. A “Accept All” button with one click requires the site to offer an equivalent refusal button. Redirecting the user to a complex customization screen to refuse may constitute a violation of Article 82 of the Data Protection Act.
The CNIL has issued more than twenty new sanctions under the simplified procedure on this subject. These decisions do not only target large groups. Smaller sites have been sanctioned for non-compliant banners, showing that the risk also concerns smaller entities.
For publishers looking to verify the compliance of their regulatory page, it is possible to discover the mentions of Racing Fans as an example of structured presentation, before comparing with the CNIL’s recommendations.

Mandatory legal notices: the legal foundation and criminal risk
The absence of legal notices is not a mere administrative oversight. The lack of legal notices constitutes a criminal offense under the LCEN. Sanctions can reach up to one year of imprisonment and significant fines for individuals.
The required information varies depending on the publisher’s status. A sole proprietor must indicate their name, first name, address, registration number with the RCS, contact details (email and phone), VAT identification number, and the contact details of the site’s host.
- The complete identity of the publisher, including the mention “sole proprietor” or the initials EI for micro-entrepreneurs
- The contact details of the site’s host: name or company name, address, and phone number
- For regulated activities (pharmacy, beverage sales), the name and address of the authority that issued the authorization
- The VAT identification number when the business is subject to it
These mentions must remain easily accessible from any page of the site. A footer link is sufficient, provided it is visible and functional. Jurisprudence has confirmed that incomplete or deliberately incorrect mentions expose the publisher to the same sanctions as their total absence.
GDPR and personal data: responsibility does not stop at your form
The GDPR requires sites that collect personal data to inform users on several points: the purpose of processing, its legal basis, the recipients of the data, and the rights of the individuals concerned (access, rectification, deletion).
A often underestimated point concerns prospecting files transmitted by partners. The company that uses purchased data remains responsible for their compliance. The CNIL reminds that companies must verify the collection conditions of files transmitted by brokers or contest organizers, particularly the existence of valid consent and the provision of clear information to individuals.
This upstream verification is rarely performed. Buying an “opt-in” email address file is not enough if the initial consent did not explicitly cover the intended use. The CNIL has opened a consultation on proof of consent in the context of marketing, indicating that this topic will be subject to regulatory clarifications in the coming months.
Contact form and newsletter
A showcase site with a simple contact form already collects personal data. The CNIL recommends providing “CNIL mentions” at the bottom of each form, a means of contact to exercise rights electronically, and legal notices identifying the publisher.
Subscribing to a newsletter should not condition access to the site’s content. This principle, stemming from the concept of data protection by design, is frequently ignored by sites that require registration to view an article or download a document.

Digital accessibility: a distinct obligation added since June 2025
The European Accessibility Act has been applicable since June 28, 2025 to certain commercial services aimed at consumers. This obligation does not replace legal notices or the GDPR: it adds to them.
Online commerce sites, digital banking services, and other categories of services must now comply with specific accessibility standards. Field feedback varies on the level of compliance actually achieved by the companies concerned, especially since control methods vary among member countries.
For a site publisher, this means managing three regulatory layers simultaneously: LCEN legal notices, GDPR compliance (privacy policy, cookie banner, processing register), and, for certain sectors, digital accessibility requirements stemming from European law.
The overlap of these obligations creates a compliance burden that goes beyond merely drafting a “legal notices” page. Each layer has its own reference texts, its own control authorities, and its own sanctions. A site can be perfectly compliant with its legal notices while violating the GDPR due to a poorly configured cookie banner, or ignoring its new accessibility obligations.



