
Any website accessible from a country in the European Union must display a set of information identifying its publisher, its host, and the rules for processing personal data. These obligations, often grouped under the term “legal notices,” are based on several distinct texts whose scope goes beyond simply displaying a name and an address.
Legal basis of legal notices in France after the SREN law
In France, the historical legal basis for mandatory notices was Article 6 III of the Law for Confidence in the Digital Economy (LCEN) of June 21, 2004. Since May 2024, the SREN law has modified this framework: it is now Article 1-1 of the LCEN that sets the identification requirements for website publishers.
Read also : Everything You Need to Know About the Cost of an EDF Connection for Your New Home
This change is not cosmetic. The rewriting clarifies the obligations according to the legal status of the publisher and strengthens consistency with other European texts. Websites that merely replicate a model prior to this date risk presenting incomplete or poorly referenced notices.
A concrete example of a page compliant with these requirements: the legal information on Brussels Sunshine includes the identification of the publisher, the host, and information related to personal data in separate sections.
Identification notices: what each status must display

The exact content of the legal notices varies depending on whether the publisher is a natural person or a legal entity. Confusion between the two results in incomplete pages.
Natural person (sole proprietorship, micro-enterprise)
The publisher must publish their first and last name, the address of their residence (or a registered address), an email address, and a phone number. The registration number in the trade register or the directory of trades is also required when it exists.
Legal entity (company)
The company name, legal form, and amount of share capital must appear on the page. This is supplemented by the address of the registered office, contact details, registration number, and, where applicable, the VAT identification number.
For regulated activities or those subject to authorization (travel agencies, health professions, financial activities), mentioning the authority that granted the operating license is mandatory. This point is often overlooked.
Website host
Regardless of the publisher’s status, the name and contact details of the website host must appear in the legal notices. The host is the entity that stores and makes the online content accessible, not the provider who designed the site.
Three distinct documents: legal notices, privacy policy, cookie management
Recent compliance guides emphasize a point that most sites neglect: legal notices, privacy policy, and cookie policy are three separate documents. Merging them into a single page creates an unreadable block and may pose a compliance issue with the GDPR.
- The legal notices identify the publisher, the host, and remind of the intellectual property rights applicable to the site’s content.
- The privacy policy details the purposes of collecting personal data, the legal basis for processing, the data recipients, and the user’s rights (access, rectification, deletion, portability).
- The cookie policy explains which cookies are placed, their lifespan, and the methods for consent or refusal. The consent banner alone is not sufficient: a document accessible from the footer must complement the information.
Each of these documents must be accessible in one click from all pages of the site, typically via the footer.
European layer: DSA and additional information obligations

For a site operating in the European Union, the obligations do not stop at national legal notices. The Digital Services Act (DSA), which has come into effect across the EU, imposes additional transparency requirements on online platforms and e-commerce sites.
Sites that allow third parties to publish content or sell products must display information about reporting mechanisms, moderation processes, and available recourse for users. Online marketplaces must also verify and display certain information about their professional sellers.
The GDPR remains the foundation for everything related to personal data protection and privacy. User consent for data processing must be free, informed, and specific. Global consent (“by continuing to browse, you accept everything”) is not compliant.
- The DSA covers the transparency of digital services and the accountability of online intermediaries.
- The GDPR regulates the collection, storage, and use of personal data.
- The ePrivacy directive specifically governs cookies and unsolicited electronic communications.
Sanctions and concrete risks in case of non-compliance
The absence of legal notices on a professional website is punishable in France by a fine of up to one year in prison and a fine for natural persons. Legal entities face proportionately heavier penalties.
Beyond the fine, the main risk is operational. A site without compliant legal notices loses credibility with its visitors and business partners. Advertising agencies, payment processors, and certain affiliate platforms check for the presence of these pages before validating a partnership.
Non-compliance with the GDPR exposes one to sanctions from the CNIL (in France) or data protection authorities from other member states. These sanctions can be significantly higher than those related solely to legal notices.
Ensuring compliance for a European site is not just about copying a generic model found online. Each legal status, each activity, and each member country brings its specifics. Verifying the applicable legal basis since the SREN law of 2024, clearly separating the three mandatory documents, and integrating the DSA requirements constitutes the minimum foundation for a site publishing in 2026.