Skip to content
Strategy 12 min read

Website Legal Notices: Your Obligations

Website legal notices: what's mandatory in France and Switzerland, the penalties for non-compliance, and how to write yours without missing anything.

Share
website legal notices

Every website published in France or Switzerland must display certain mandatory information, collectively known as legal notices. Failing to publish them means risking fines that can reach tens of thousands of euros, and more importantly, projecting an image of carelessness to visitors who want to know who they’re dealing with. Here’s what the law requires, what common sense recommends, and how to write your legal notices in a few minutes without missing anything.

Legal notices are a set of identifying information that every website publisher must make public so that visitors know who’s behind the pages they’re reading. Think of it like the sign on a physical store, except that on the internet nobody can glance at the storefront to figure out who owns it, and the law compensates for that opacity by requiring transparency.

website legal obligations

In France, this obligation comes primarily from the Law for Confidence in the Digital Economy (LCEN, Law No. 2004-575 of June 21, 2004), specifically articles 6 and 19. In Switzerland, identification requirements are covered by the Code of Obligations (art. 957 ff.) and by the new Federal Act on Data Protection (nFADP), which came into force on September 1, 2023, and imposes enhanced information obligations whenever personal data is collected. If your website is accessible from both countries, and virtually every French-language website is, you need to comply with both legal frameworks simultaneously.

Legal notices aren’t a decorative document you copy-paste from a template found online just to tick a box. They engage your responsibility, and the information they contain must be accurate, complete, and up to date. A change of address, a modification of share capital, or a new legal status must be reflected in your notices, or they become invalid.

What information must you display?

The list of mandatory information depends on your legal status, but a common baseline applies to all professional websites, regardless of their size or industry.

mandatory information legal notices

For a sole trader or freelancer, you must display your full name, the designation “entrepreneur individuel” or “EI” in France (or “raison individuelle” in Switzerland), your business address or registered office, a phone number and email address, your commercial register number (RCS in France, cantonal commercial register in Switzerland), your VAT identification number if applicable, and the name of the publication director.

For a company (SARL, SAS, SA in France, or Sàrl/SA in Switzerland), the same elements are required, plus the company name, legal form, share capital, registered office, and registration number. In Switzerland, the IDE (enterprise identification number, format CHE-xxx.xxx.xxx) replaces the French SIRET, and the cantonal commercial register number must also appear.

In all cases, you must also mention your hosting provider’s complete details: name or company name, postal address, and phone number. If your site is hosted with Infomaniak, o2switch, OVHcloud, or another provider, their information must appear in your notices, not just their name.

For regulated professions (lawyers, architects, accountants, doctors), the law also requires a reference to the applicable professional rules, the professional title, the state that issued it, and the professional body you’re registered with. When you have your website created, remember to share this information with your service provider from the start to avoid circling back after launch, as explained in our article on writing a website design brief.

Do e-commerce websites need different notices?

Yes, and the obligations are significantly broader. A website that sells products or services online to consumers (B2C) must, in addition to standard legal notices, publish terms and conditions of sale accessible before any transaction.

e-commerce legal notices

These terms must specify the characteristics of products or services, prices including all taxes in euros (or in Swiss francs for a site targeting Switzerland), shipping costs and delivery times, accepted payment methods, withdrawal conditions (French consumers have a 14-day right of withdrawal for most online purchases), legal guarantees (conformity and hidden defects), and the mediation procedure in case of a dispute. In France, the absence of terms and conditions for a B2C site can result in a fine of up to 3,000 euros for individuals and 15,000 euros for companies.

A showcase website that presents your business without selling directly online doesn’t need terms and conditions, but it still must display its legal notices and privacy policy. If you’re considering starting an online store, work the terms and conditions into your launch timeline, not at the last minute.

How do you write your privacy policy?

The privacy policy is the document that explains to your visitors how you process their personal data, and it’s become just as important as the legal notices themselves since the GDPR came into force in Europe and the nFADP in Switzerland.

GDPR privacy policy website

As soon as your website collects any personal data, whether it’s a contact form, a newsletter signup, a traffic analytics tool, or even a simple cookie, you’re required to inform your visitors clearly and completely. In practice, your privacy policy must specify the identity of the data controller (you or your company), the purpose of each processing operation (why you collect this data), the legal basis (consent, legitimate interest, contractual obligation), the categories of data collected, the retention period, any recipients (if you share data with service providers like an email tool or a payment processor), the rights of individuals (access, rectification, erasure, objection, portability), and the contact details of your data protection officer if you’ve appointed one.

In Switzerland, the nFADP goes further than the old Swiss law by extending the information obligation to the collection of all personal data, not just sensitive data. If your company is based in Switzerland or if your site targets the Swiss market, you must indicate the destination country in case of cross-border data transfers and the safeguards that govern the transfer. The nFADP also requires the implementation of data protection by design (Privacy by Design) and by default (Privacy by Default), which concretely means that your site’s privacy settings must be set to the highest level of protection by default, without your visitors having to adjust them.

One point that competitors consistently miss: if your business operates in both France and Switzerland, as many companies in the Lake Geneva region or border areas do, your privacy policy must satisfy both frameworks simultaneously. The simplest approach is to write a single document that covers both GDPR and nFADP requirements, explicitly mentioning both legal bases and the corresponding rights. Don’t treat compliance as a one-time exercise either: whenever you add a new contact form, integrate a third-party tool, or start sharing data with a new service provider, your privacy policy needs updating to reflect the change. The regulators on both sides of the border expect your documentation to match what your site actually does, not what it did when you launched it.

A common mistake is treating the privacy policy as a legal dump that nobody reads. Your visitors won’t read every word, but the CNIL and the Swiss Federal Data Protection Commissioner (FDPIC) will if they receive a complaint. More importantly, search engines increasingly reward sites that demonstrate trustworthiness, and a thorough, well-structured privacy policy is one of the signals that contribute to that perception.

How should you handle cookies on your website?

Cookies have become one of the most visible compliance topics on the web, mainly because consent banners are the first thing visitors see when they arrive on a site, and because France’s CNIL has ramped up inspections and penalties on this subject in recent years.

website cookie management

In France and the European Union, the rule is clear: you must obtain explicit consent from your visitors before placing non-essential cookies on their device. Pre-checked boxes are prohibited, refusing must be as easy as accepting, and consent expires after 13 months. Strictly necessary cookies (session management, language preferences, shopping cart) don’t require consent, but they still need to be mentioned in your cookie policy.

In Switzerland, the regulation is slightly different: the Federal Telecommunications Act (TCA) requires informing users about the cookies used and offering them the option to refuse, but it doesn’t systematically require prior consent for audience measurement cookies. In practice, if your site is accessible from both France and Switzerland, apply the stricter standard, the GDPR’s, and you’ll be compliant on both sides.

Concretely, your cookie banner must explain what types of cookies you use and why, allow a refusal in a single click (not a “manage preferences” button that hides the “reject all” option behind three screens), and place no non-essential cookies until the visitor has given their agreement. If you use a cookieless analytics tool like Plausible or Umami, you can simplify this step considerably, since these tools don’t place cookies and therefore don’t require consent. That’s actually one of the reasons more and more professional websites are moving away from Google Analytics in favour of these alternatives, as we discuss in our article about ranking your website on Google.

What penalties do you face for non-compliance?

The penalties for missing or insufficient legal notices aren’t symbolic. In France, the law provides for up to one year of imprisonment and a 75,000 euro fine for individuals, and up to 375,000 euros for companies, for failing to comply with the identification obligations imposed by the LCEN.

penalties missing legal notices

The penalties related to GDPR non-compliance are even steeper: the CNIL can impose fines of up to 20 million euros or 4% of annual global turnover for the most serious violations, such as processing personal data without a legal basis or failing to inform data subjects. In practice, SMEs are rarely hit with maximum penalties, but inspections are increasing and fines of a few thousand euros for common shortcomings (non-compliant cookie banner, form without data processing information) have become frequent.

In Switzerland, the nFADP introduced criminal sanctions that apply to the individuals responsible, not to the company itself. That’s an important difference from the GDPR, where the fine targets the legal entity. The director who doesn’t comply with information obligations when collecting data faces personal prosecution.

Beyond financial penalties, the absence of legal notices sends a signal of carelessness to your site’s visitors, to search engines that value transparency in their ranking criteria, and to business partners who often verify legal compliance before working with a provider. A website without legal notices is a bit like a shop without a sign and without a registration number on the storefront: technically you exist, but nobody has a reason to trust you.

Writing your legal notices is simpler than it seems if you proceed step by step, and the final result typically fits on a single page of your site, accessible from a link in the footer.

write website legal notices

Start by gathering all the factual information about your business: company name or full name, legal form, registered office address, registration numbers (SIRET and RCS in France, IDE and commercial register in Switzerland), share capital, VAT number, contact details. Add the publication director’s name (usually the manager or director), and your hosting provider’s complete details.

Then write a paragraph about intellectual property: specify that all site content (text, images, design, code) is protected by copyright and that any reproduction without authorisation is prohibited. It’s not strictly mandatory within the legal notices themselves, but it’s good practice that clarifies rights and can prove useful if someone copies your content.

Add your privacy policy, either on the same page or on a separate page with a clearly visible link. If your site uses cookies, integrate your cookie policy or link to a dedicated page.

For placement, the universal convention is a “Legal Notices” link in your site’s footer, visible on every page. That’s what your visitors and regulatory authorities expect. If you’re having your site built by a professional, ask them to include the legal notices page in the base template, with the footer link, from the very first version. Fixing this page after launch is simple, but forgetting it entirely creates unnecessary risk from day one.

If your information changes (new address, change of legal form, new hosting provider), update your notices immediately. It’s not the kind of task you’d normally schedule in your site’s regular maintenance, but it should be part of it.

One last practical point: if you use a generator, read the output carefully before publishing it. Most generators produce decent starting points, but they can’t know the specifics of your business, your profession’s regulatory requirements, or whether you operate across borders. A generator that only covers French law won’t include the Swiss nFADP disclosures, and one that covers generic GDPR won’t know that you share data with a payment processor based outside Europe. Treat the generated text as a draft, not a finished document, and adjust it to match your actual situation.

Legal notices aren’t a boring administrative exercise you rush through at the end of a project. They’re the first signal of transparency you send to your visitors, to Google, and to the partners who verify your credibility before entrusting you with a project. A site whose notices are complete, current, and easy to find gives the impression of a professional who pays attention to details, and that’s exactly the impression you want to leave when your website represents your business around the clock.

website legal compliance

If you’re launching a site or if yours has been running for months without proper notices, take an hour to gather your information, write your notices and privacy policy, and check your cookie banner. It’s the kind of task that doesn’t require any particular technical skills but protects your business against real financial penalties and, more importantly, builds the trust your clients expect before choosing to work with you.

Frequently asked questions

Every professional website must display the publisher's identity (name or company name, address, registration number, share capital for companies), the hosting provider's details, the publication director's name, and information about personal data processing in compliance with the GDPR.

In France, failing to display mandatory legal notices on a professional website can result in up to one year of imprisonment and a fine of 75,000 euros for individuals, or up to 375,000 euros for companies, under the LCEN law of 2004.

Yes. A personal website can limit itself to the hosting provider's name and contact details if the publisher chooses anonymity, but this protection only applies to strictly non-commercial content. As soon as the site generates revenue or collects personal data, the obligations are the same as for a professional website.

The basics are similar but not identical. France enforces the LCEN law and the GDPR, while Switzerland applies its new Federal Act on Data Protection (nFADP) since September 2023. A website targeting both markets must comply with both frameworks, especially regarding information obligations when collecting personal data.

No, terms and conditions of sale are only mandatory if you sell products or services online to consumers. A showcase website that presents your business without online transactions doesn't need them, but it still must display its legal notices and privacy policy.

The link to your legal notices should appear in the footer of every page on your site, accessible in one click from any content. That's the convention visitors and regulatory authorities expect.

Newsletter

Join us!

Enjoyed this article? Get my tips and advice to succeed with your website or SaaS, straight to your inbox. No spam, one-click unsubscribe.

By subscribing, you agree to receive my articles by email. Your data stays private, see the privacy policy .

Share this article
Nicolas Lecocq

Written by

Nicolas Lecocq

A developer-entrepreneur working between France and Switzerland, building custom SaaS products, e-commerce platforms and internal applications.

All articles