Compliance

Is your real estate agency's cookie banner actually legal? The check almost every agency skips

August 13, 2026 · 8 min read

Club Immobilier's current site: a cookie banner whose 'learn more' link led to a general Wikipedia article instead of an actual privacy policy

When I tore down Club Immobilier's home page for an earlier article, one detail got a single sentence and nothing more: the cookie banner's “learn more” link pointed to a Wikipedia article, not to the agency's own privacy policy. I moved on to the six leaks that were actually costing them leads and never came back to it.

I shouldn't have. That one detail sits inside a rule the CNIL — France's data protection authority — is actively enforcing against small and mid-sized businesses right now, and checking whether your own site has the same problem takes about five minutes.

The rule, in one sentence

Straight from the CNIL: refusing cookies has to be exactly as easy as accepting them.If your banner shows a one-click “Accept all” button, it has to show an equally visible, equally sized “Reject all” button at the same level — not a second click, not a small text link, not a “customize” screen you have to open to find refuse.

That's not a paraphrase from a marketing blog. It's the CNIL's own framing, and it's the basis of a wave of formal notices (“mises en demeure”) the regulator has been sending to website operators specifically for this failure — an accept button front and center, and refusal buried behind an extra step or presented in a way that nudges the visitor toward consenting.

Free resource

Grab the checklist while you're at it

The 15-point checklist I use on every agency site covers structural conversion leaks — hero, listings, forms, footer. This cookie-banner check isn't on it, on purpose: compliance and conversion are two different audits, and conflating them makes both weaker. Run this article's check first, then the checklist.

Why this is worth five minutes of your time

Two reasons, and only one of them is about avoiding a fine.

The compliance risk is real, and it's not limited to large companies.Secondary compliance sources reporting on the CNIL's simplified-sanction procedure describe fines in the €3,000–€20,000 range for smaller structures, with a 2025 total of over 280 sanctions, more than 60% of them against SMEs — and cookie or tracker violations account for a meaningful share of all sanctions handed out. I want to be direct about sourcing here: the CNIL's own press releases confirm the underlying rule and the fact that formal notices are being sent out; the specific aggregate figures above come from compliance blogs summarizing CNIL's public sanction register, which I have not independently re-counted line by line, so treat the totals as reported, not as a number I verified myself. The rule itself is not in question. The exact count is secondhand.

The design failure and the compliance failure are usually the same failure.A banner that makes refusing harder than accepting isn't just a legal problem — it's the same instinct that shows up everywhere else on a neglected site: the one clear action is for the business, the alternative is deliberately awkward. If your banner is failing the CNIL's equal-prominence test, there's a good chance the rest of the site is making the same kind of decision without you having chosen it on purpose.

What I actually found on Club Immobilier — and what I didn't re-check

Here's the finding as it stood at the time of the original audit, stated as precisely as I can, no more: the banner's “learn more” link did not lead to a cookie policy or a privacy notice. It led to Wikipedia's general article on HTTP cookies. A visitor who wanted to understand what they were being asked to consent to would end up reading an encyclopedia entry with no connection to the agency, its actual trackers, or its actual data practices.

I'm not going to dress this up as a fresh live audit, because it isn't one — I'm reporting what the original teardown documented, not re-verifying the site again today. That distinction matters, and it's the same discipline I try to apply everywhere on this blog: state what you actually checked, and say plainly when you didn't re-check it.

What I can say with more confidence, because it doesn't depend on any one site staying the same: a banner link pointing somewhere other than an actual, specific privacy or cookie policy is a pattern I've seen more than once while auditing agency sites, and it fails the CNIL's separate requirement that the information given to the visitor has to be clear and has to actually explain what the cookies are for. A generic external link satisfies neither.

The banner checklist — five minutes, no lawyer required

Open your site in an incognito window (so the banner actually shows) and check these, in order:

  1. Is there a “Reject all”or equivalent button at the first level — the same screen as “Accept all” — not one click deeper?
  2. Are the two buttons visually equal— same size, same prominence? A bright “Accept” button next to a pale, small “Manage preferences” link fails the test even if a reject option technically exists somewhere behind it.
  3. Does the “learn more” / “cookie policy” link actually go to your own policy— one that names the specific cookies and trackers your site uses — rather than a generic external page?
  4. Does refusing actually stop the trackers, not just hide the banner? This one you can't fully verify by eye; it's the kind of check a developer or a cookie-scanning tool confirms, not a visitor.
  5. Is anything being dropped before any choice is made at all? Open your browser's dev tools, clear cookies, reload the page before clicking anything, and check whether analytics or marketing scripts already fired. If they did, consent came after the fact, which defeats the purpose of asking.

If you fail even one of these, you're not an outlier — you're the median, based on what the CNIL's enforcement pattern suggests about the sites it keeps sending notices to.

What I'm not telling you

I'm not a lawyer, and nothing above is legal advice. If a formal notice or a real compliance question ever lands on your desk, that's a conversation for a lawyer who can read your specific site, your specific trackers, and your specific data flows — not a web designer's blog post. What I can offer is the practical, non-legal version: the same visual and structural check I'd run on any element of a site before touching a redesign, applied here to a banner instead of a hero section.

Honest note on results:I have no data on how many real estate agency sites specifically fail this test, and I'm not going to invent a percentage to make the point land harder. What I have is one specific, previously documented finding on one real agency site, and a regulator that is visibly and publicly enforcing this exact rule on businesses of exactly this size, right now. That's enough to justify five minutes of checking. It's not enough to justify a scare number, so I haven't used one.

Where this fits if you're already planning a redesign

Chapter 7 of my guide covers the technical-hygiene checks most agencies skip during a redesign — console errors, a stale copyright year, the small things that quietly tell a visitor nobody's maintaining the site. A broken cookie banner belongs in exactly that category: invisible until you look, cheap to fix once you do, and worth folding into the same launch-week pass rather than treating as a separate project. If you're rebuilding anyway, add “reject button at the same level as accept, real policy link” to your brief as a one-line acceptance criterion — it costs the provider nothing to build correctly the first time, and it costs you a formal notice if nobody specified it.

Free resource

Run the structural checklist next

Get the 15-point audit checklist and go through the rest of your home page — hero to footer — in about 10 minutes. Compliance is one five-minute check; conversion is the other fifteen.

Want the full method rather than one chapter of it?“Rebuilding a real estate agency website that converts” is the eight-chapter guide — the 3-second test, the buyer/seller fork, social proof placement, listing cards, the valuation form, identity, technical hygiene, and a launch-week checklist. One-time purchase, $49, on Gumroad — never a subscription.

Hamza Benjaaba

Hamza Benjaaba

Web designer and no-code developer, specialized in websites for real estate agencies and local service businesses. The Wikipedia-link finding in this article comes from my own original audit of the Club Immobilier site, reported here as it stood at the time — not re-verified live for this piece. The CNIL rule and enforcement pattern are sourced directly from the CNIL's own published statements; the aggregate sanction figures are reported by secondary compliance sources and flagged as such, not independently re-counted by me.

Planning a redesign anyway?

Let's fold thisinto the brief.