LanderKit

Templates written in French — fully translatable in minutes

Legal requirements for a landing page: GDPR, cookies, legal notice, VAT, accessibility

By Clément Lacaille · published 22 September 2026 · 28 min read · method

This guide brings together our articles on the legal framework of a landing page (previously one per obligation). It is not legal advice: for each topic it states what the texts require and the most common pitfalls, with sources cited.

Sectors with regulated advertising (health, finance, training) have their own article: landing page in a regulated sector.

Accessible landing pages: what RGAA and the European Accessibility Act mean for your conversion rate

Since June 28, 2025, the European Accessibility Act has required accessibility rules for any site selling to European consumers. Beyond the legal box to tick, an accessible landing page reaches more visitors and often ranks better on Google — the 10 fixes that actually matter, and why accessibility never hurts a good conversion rate.

Why it matters even without a legal requirement

  • A bigger addressable market — visual, motor, cognitive, or hearing impairments, but also temporary situations: bright sunlight on a phone screen, one hand occupied, an arm in a cast, a slow connection on the go. An accessible landing page works for all of these, not just for the ideal visitor on a fast connection and a large screen.
  • Better rankings — accessibility criteria (heading structure, alt text, contrast, semantic HTML) overlap heavily with technical SEO criteria, see below.
  • A more robust conversion rate — sufficient contrast, large enough clickable areas, and clear error messages help a visitor rushing on mobile just as much as a visitor with low vision: the same principle covered in our guide to background color choices or to writing a headline that grabs attention.
  • Future-proofing your growth — fixing accessibility on a ten-section landing page today costs far less than retrofitting it later, once a business has grown past RGAA's thresholds or lost the EAA's microenterprise exemption.

The link between accessibility and SEO isn't just marketing intuition: a study by Elgharabawy and Ayu, published by IEEE, measured a positive correlation between WCAG conformance and the Webometrics ranking of the sites analyzed, concluding that accessibility can be recommended as a search engine optimization lever (see the study). More recently, a Finnish study by Laamanen, Ladonlahti, Puupponen and Kärkkäinen, published in 2022 in the journal Universal Access in the Information Society, analyzed the landing pages of 38 higher education institutions against WCAG 2.1 before and after stricter legislation took effect, revealing large gaps between institutions — and confirming that conformance rarely happens without a deliberate effort (see the study). The common thread: semantic HTML, a consistent heading hierarchy, and well-written alt text serve the screen reader and the search crawler at the same time.

Learning from a competitor's landing page without copying it: what the law (and strategy) says

Analyzing competitor landing pages is healthy practice — we devote a whole guide to it. But between “drawing inspiration” and “copying,” the line is both legal and strategic. What you can borrow, what exposes you to a lawsuit, and why the clone almost always loses.

Suppose the copy were legally safe: it would still usually be a mistake. First because a competitor's landing page is observed from the outside, without its data: you see the page, not its conversion rate, not the tests that led to this version, not the campaigns feeding it. You may be copying the losing variant of an A/B test. Second because what works for an established brand (awareness, reviews, ad budget) doesn't transfer to an unknown adopting the same words. Marketing research sheds a counter-intuitive light here: a landmark study by Peter Golder and Gerard Tellis published in 1993 in the Journal of Marketing Research (Golder & Tellis, 1993) showed, across the history of dozens of product categories, that pioneers fail far more often than the legend says — and that followers frequently win. But a complementary study by Venkatesh Shankar, Gregory Carpenter, and Lakshman Krishnamurthi published in 1998 in the same journal (Shankar et al., 1998) spells out the condition: the late entrants who outsell pioneers are the innovative ones, those bringing a perceived improvement — not pure imitators, who remain durably dominated. Applied to landing pages: following a competitor can pay off, provided you arrive with a better angle, not their photocopy.

The method: extract the patterns, rewrite the rest

  1. Analyze several competitors, never just one — three to five pages run through the analysis grid reveal market patterns rather than one brand's choices.
  2. Note the questions each page answers (price, timing, guarantee, proof) rather than its answers: those are your shared market's objections, and your answers will necessarily differ.
  3. Spot what nobody says: the real payoff of competitive analysis is the vacant angle, the one that will feed your value proposition — or even an explicit comparison page.
  4. Write your copy from your customers (their words, their objections, your reviews), not from the copy across the street.
  5. Keep a dated record of your creative work (brief, versions, sources) — useful the day you're the one being copied.

Dark patterns on a landing page: what works short term and costs you dearly later

A countdown that resets, a permanent "only 2 left", a pre-ticked box, a decline button that shames the visitor: dark patterns inflate this month's numbers — then get paid back in refunds, complaints and destroyed trust. The 7 most common ones on landing pages, and the honest alternative that converts just as well for each.

A dark pattern is an interface designed to push visitors into doing something they wouldn't have done had they understood what was happening: buying under fake pressure, accepting a box they never ticked, giving up on unsubscribing out of sheer exhaustion. The phenomenon is massive: a study by Arunesh Mathur and colleagues published in 2019, "Dark Patterns at Scale", automatically analysed around 11,000 e-commerce websites and detected dark patterns on roughly 11% of them — the most common being precisely fake urgency and deceptive social proof, two landing page classics. The problem isn't only ethical: these techniques inflate this month's conversions and then get paid back in refunds, complaints, churn and legal exposure. Here are the seven most common dark patterns on landing pages, why they "work", and the honest alternative that converts just as well without mortgaging your brand.

The 7 most common dark patterns on a landing page

Common landing page dark patterns and their honest alternative
Dark patternWhat it doesThe honest alternative that also converts
Fake urgencyA countdown that resets on every visit, for an offer that's actually permanentA real deadline, identical for everyone, with an offer that genuinely ends when it expires
Fake limited stockA decorative "only 2 left" frozen in place for monthsA counter wired to real inventory, or no counter at all
Pre-ticked boxesNewsletter, paid add-on or consent already ticked on the visitor's behalfActive consent: the visitor ticks the box themselves, knowing what they're agreeing to
ConfirmshamingA shaming decline button: "No thanks, I'd rather miss out on clients"A neutral decline ("No thanks") and an offer good enough to need no blackmail
Hidden feesA low teaser price, topped up with "processing" or "service" fees revealed at the last stepThe full price displayed on the landing page itself, with no surprise at checkout
Labyrinthine cancellationSign-up in one click, cancellation through seven screens, an email and a phone callLeaving as easy as joining — which also reassures people before they buy
Fake testimonialsInvented reviews, stock-photo faces, fictitious purchase countersReal, identifiable testimonials and real numbers, even if that means fewer of them

Cookieless analytics on a landing page: what French regulators actually exempt, and what it changes for your numbers

Google Analytics 4 drops a cookie that triggers the consent banner — and part of your traffic blocks it anyway. An audience-measurement tool configured for the French regulator's consent exemption (Matomo being the best-known example) avoids both problems at once: no banner, and numbers that no longer depend on an 'Accept' click.

The first hole is well known and covered in our article on the cookie banner: a meaningful share of visitors close the banner without choosing, which counts as a refusal. The second hole gets less attention: even among visitors who do accept, or who never saw a banner because it was implemented poorly, a portion of traffic never reaches GA4 because the browser or an extension blocks the request upstream. A 2017 study by Iqbal, Shafiq, and Qian presented at the ACM Internet Measurement Conference ("The Ad Wars: Retrospective Measurement and Analysis of Anti-Adblock Filter Lists") measured at scale how community-maintained filter lists (EasyList, EasyPrivacy) target the most widely used audience-measurement domains first — Google's leading the pack, precisely because they are the most widespread. In other words: the more popular a tracking tool is, the more it gets blocked, and GA4 sits mechanically at the top of that list. On a B2B or tech-savvy audience, the gap between actual and measured traffic can run into double-digit percentages — a bias no setting can fix, only a change of tool or collection method.

What French regulators actually exempt — and why GA4 doesn't qualify

  • the data serves only to measure the site's own audience for its own publisher, never cross-referenced with other processing;
  • no transmission to any third party, including for advertising or cross-site matching purposes;
  • the tracker cannot follow the visitor across other sites (no cross-domain tracking);
  • the visitor is informed of its existence and can easily object;
  • lifespan capped at 13 months, with data retention capped at 25 months.

AI-generated images on a landing page: what the AI Act changes (and what it does to trust)

Since August 2, 2026, the EU's AI Act imposes new transparency rules on AI-generated content. What they actually change for a landing page's hero image or a fabricated testimonial, the line between a plain illustration and a deepfake, and what two studies from Marketing Science and CHI reveal about how an "AI-generated" disclosure affects trust and conversion rate.

Even where nothing forces you to add a disclosure, the question is worth asking anyway: what happens when a visitor knows — or suspects — they're looking at AI-generated content? Two studies converge on the same answer: trust drops, often more sharply than expected. A study by Xueming Luo, Siliang Tong, Zheng Fang and Zhe Qu, published in 2019 in Marketing Science ("Frontiers: Machines vs. Humans"), found that explicitly disclosing that a sales chatbot wasn't human cut the purchase rate by nearly 80%, simply because customers grew warier once they knew they were talking to a machine. A second study, by Maurice Jakesch, Megan French, Xiao Ma, Jeffrey Hancock and Mor Naaman, presented at CHI 2019 ("AI-Mediated Communication"), goes further: the same piece of text is rated as less sincere and less trustworthy the moment a reader believes — rightly or wrongly — that it was written by an AI, a phenomenon the authors call the "Replicant effect."

What we do instead on our templates

  • An SVG illustration that owns being an illustration, rather than a generated photo pretending to be one: that's the choice behind our single-product e-commerce template, whose hero bottle is a vector drawing you later swap for your real product photo — never for a synthetic image disguised as a photo.
  • Real customer reviews and screenshots, with explicit permission, rather than a generated avatar standing in for a "typical" profile — the method detailed in our guide on UGC as social proof.
  • Video or written testimonials that stay identifiable and verifiable, as covered in our video vs. text testimonial comparison, rather than a synthetic voice or face.
  • A review widget connected to a real source (Google, Trustpilot) rather than a static, unverifiable reviews block, as detailed in our article on the Google reviews widget.

Cookie banners on a landing page: staying GDPR-compliant without wrecking conversion

Plenty of founders dread the cookie banner as an automatic conversion killer — and give in to the temptation of making it discreet, or outright misleading. What two studies show about consent banner design, what France's CNIL has actually been sanctioning since 2025, and how to build a compliant banner that costs you nothing in conversion.

The core rule, hammered home by the CNIL across several enforcement campaigns, fits in one sentence: rejecting cookies must be as easy as accepting them. In practice, the first layer of the banner must show a "Reject all" button at the same visual level and with the same look as the "Accept all" button — not a discreet text link tucked in a corner while "Accept" gets a bright, prominent button. No checkbox can be pre-ticked, non-essential cookies (non-anonymized analytics, advertising, social media) cannot be dropped before an explicit choice is made, and a "Customize" link must give access to the detail of purposes without forcing the visitor to dig through it just to say no. On a landing page that only runs for a few weeks around a single offer, the risk isn't just the fine: a complaint or audit can freeze a campaign mid-launch.

How to design a compliant banner that doesn't penalize your landing page

  1. A bottom banner, never a full-screen blocking overlay — both studies cited show the format doesn't affect the consent rate, so pick the one that doesn't cut into the message match between the ad that generated the click and your landing page headline. A visitor who has to clear a pop-up before seeing your hero has already lost a few precious seconds.
  2. Two buttons of equal visual weight — "Accept all" and "Reject all" at the same size, the same background color or contrast. This is the CNIL's requirement, and per the Nouwens et al. study, this choice carries no measurable downside on the overall acceptance rate compared to a banner that visually favors acceptance.
  3. A binary choice at the first layer, not a list of per-purpose toggles — save category detail (analytics, advertising, social media) for a second layer reachable via "Customize." The Nouwens et al. study puts the consent loss from imposing granular settings upfront at 8 to 20 percentage points.
  4. A technically lightweight CMP — some consent management solutions add several hundred kilobytes of script before the page's first meaningful render, which directly hurts your page load speed. Choose one that loads asynchronously and doesn't block the rest of the page from rendering.
  5. A choice that holds for the whole session — on a single-page landing page where the visitor scrolls down to the form, don't re-show the banner on every interaction or anchor change: that adds needless friction right before the step where you most need a smooth flow, like the contact form.

The GDPR consent checkbox: when it's required, when it's pointless

Under almost every landing page form, the same box waits for the visitor: "I accept the privacy policy." Sometimes it's essential, often it's pointless, and it's almost always badly worded. Here's how to untangle the legal basis, the duty to inform, and consent to marketing — and how to write the notice that actually matches your case.

When the checkbox really is necessary

  • Newsletter sign-up — the textbook case for consent: the person agrees to messages they didn't ask for one by one. The box must be dedicated, unticked by default, and separate from any other commitment; email confirmation is covered in the article on double opt-in vs. single opt-in.
  • Email or SMS prospecting to a consumer — the CNIL points out that electronic advertising in principle requires consent collected before the approach, with exceptions notably for existing customers contacted about similar products or services.
  • Adding someone to a mailing list after a quote request — two different purposes, so a separate box for the second one, and refusing it must never block the form from being submitted.
  • Sharing data with partners — as soon as the data serves a third party's prospecting, consent must be specific and the recipients identifiable by the person.
  • What doesn't belong in the form's checkbox — trackers follow a separate regime with their own interface, covered in the article on the cookie banner and conversion and, to avoid them altogether, the one on cookieless analytics.

Research on consent interfaces, built mostly around cookie banners, transfers reasonably well to form checkboxes: wording and design weigh far more than legal content. A study by Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, and Thorsten Holz published in 2019 at the ACM CCS conference, "(Un)informed Consent: Studying GDPR Consent Notices in the Field", tested several notice variants on more than 80,000 unique visitors of a real website: the notice's position strongly changes the interaction rate, and a binary choice gets more acceptances than a mechanism asking for permission category by category. The authors conclude that small implementation decisions substantially change how people respond. A study by Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal presented in 2020 at the CHI conference, "Dark Patterns after the GDPR", analysed the five most widespread consent management platforms across the 10,000 most visited UK websites and found only 11.7% of implementations met the minimal requirements derived from European law.

Images on your landing page: what the law actually says (stock photo libraries, AI-generated images, personality rights)

Someone on the team types "smiling coach" into Google Images, saves the first result, and it ends up at the top of the landing page. Nobody thinks twice about it at the time — yet that is exactly the scenario behind most unauthorized-image claims. Here's what the law says about the three sources of images on a landing page, and how to cover yourself without spending hours on it.

Free libraries like Unsplash or Pexels grant a broad license — commercial use allowed, attribution not required in the vast majority of cases. The point that often gets missed: that license covers your use of the image file, not the presence of recognizable people inside it. A stock photo showing an identifiable face is, in theory, supposed to have required that person's consent (a "model release") before the platform allowed it to be published — but nothing guarantees the contributor actually obtained one. Paid libraries (Shutterstock, Adobe Stock, Depositphotos) offer better protection on this specific point: their contracts typically include a contractual guarantee against third-party claims, which isn't a given on the free side.

Covering yourself without spending hours on it

  1. Never save an image directly from search engine results — always go through the original platform (stock library, the client's own account) to know the actual license.
  2. Keep proof for every image you publish: a screenshot of the license page, the download date, the source file name. A shared folder is enough — the goal is being able to respond within five minutes if a claim ever arrives.
  3. For any photo of an identifiable person (founder, client, team member), get explicit written consent naming the commercial use on the site, not just consent to be photographed.
  4. Reserve AI-generated images for generic or decorative visuals, not for elements meant to embody your offer's own identity — see the exclusivity issue above.
  5. Never reuse an image found on a competitor's site as-is, including their AI visuals or diagrams — see our article on what the law says about copying a competitor's landing page.
  6. If a demand letter arrives (Getty Images or another agency), don't pay in a rush or ignore it: taking the image down doesn't erase liability for the period it was live, and a specialized lawyer will almost always negotiate an amount well below the initial demand.

How long can you keep data from a landing page form? (GDPR)

GDPR compliance for a form doesn't stop at the checkbox — the data still has to be deleted after a set period. Here's what the retention rules actually require, and how to automate it instead of rethinking it every quarter.

Prospect or customer: two different clocks

  • Prospect (requested a quote, downloaded an ebook, joined a waitlist) who never became a customer: the standard reference is 3 years from the prospect's last active contact — a reply to an email, a click on a link, a new request. Simply opening an email doesn't count as active contact and doesn't reset the clock.
  • Customer (completed purchase, signed contract): data can be kept for the whole length of the business relationship, plus the legal limitation period applicable to contractual claims; accounting records (invoices) follow a separate, usually much longer, statutory retention period that's independent of GDPR.
  • Once the period has passed, the data must be deleted or anonymized — or, if a legal reason still requires it (ongoing dispute, accounting obligation), archived separately with restricted access, outside the active prospecting files.

This builds on an older, widely cited finding from Alessandro Acquisti, Laura Brandimarte and George Loewenstein in « Privacy and human behavior in the age of information », published in 2015 in Science: the decision to share personal data depends less on how sensitive it actually is than on the sense of control a person feels over how it will be used. Stating a precise retention period gives exactly that sense of control — it's a conversion argument as much as a legal requirement.

Mandatory e-invoicing in France: what it changes for a B2B landing page

September 1, 2026 isn't a distant deadline: as of that day, every French company, including a solo founder selling a single template from a landing page, must be able to receive a compliant electronic invoice. The obligation to issue one arrives in stages through 2027 — but what it actually changes for a sales page and its checkout flow is worth preparing for now, not the week before the deadline.

An SME or micro-business technically has a full year more than large companies before the issuance obligation kicks in. Nothing stops choosing an approved platform and adjusting a payment form now rather than in the deadline's final week, though. The tendency to postpone a costly task while the deadline still feels far away, only to discover it too late to handle properly, is documented in behavioral economics research: in a foundational 1999 paper in the American Economic Review, "Doing It Now or Later" (entry), economists Ted O'Donoghue and Matthew Rabin show that people who underestimate their own future self-control problems — agents they call "naive" — systematically procrastinate on exactly this kind of task, precisely the profile of an administrative compliance deadline that still feels distant. A B2B payment form that already cleanly captures a client company's SIREN is a minor adjustment today; the same adjustment made in a rush, the final week before September 1, 2027, is a very different task.

A checklist before the 2027 deadline

  1. Identify precisely what share of revenue falls under domestic, VAT-registered B2B, as distinct from consumer sales and export sales.
  2. Check your registration with an approved platform listed in the PPF directory — the receiving obligation already applies, independent of your issuance deadline.
  3. Adjust your B2B payment form to capture a professional client's SIREN (and intra-EU VAT number where relevant), rather than just a billing address.
  4. Check that your current invoicing or accounting tool supports the Factur-X, UBL or CII formats ahead of the September 1, 2027 issuance deadline, relying on your accountant rather than a last-minute scramble.

Google Fonts on a landing page: the GDPR risk and the speed you gain by self-hosting

Two lines pasted into your are enough to send every visitor's IP address to a third party — and to delay your headline. The fix takes about an hour and changes nothing about your design.

The issue reaches well beyond fonts. In their landmark measurement "Online Tracking: A 1-million-site Measurement and Analysis" (Steven Englehardt and Arvind Narayanan, ACM CCS, 2016), the authors crawled the top million websites and showed just how pervasive — and how concentrated in a few hands — third-party resources have become: scripts, fonts and stylesheets alike, each call amounting to a point of contact with a domain the visitor never chose to reach. Fonts appear twice over in this literature: the study "Cookieless Monster: Exploring the Ecosystem of Web-Based Device Fingerprinting" (Nick Nikiforakis and colleagues, IEEE Symposium on Security and Privacy, 2013) documented that the list of fonts installed on a machine is itself used as a fingerprinting signal to identify a browser without cookies. None of this accuses Google Fonts of spying on your visitors; it does explain why regulators and courts look closely at third-party calls, fonts included.

The fix: self-host your fonts in five steps

  1. Download the files from Google Fonts ("Get font" then "Download all"): Google's fonts are open-licensed, and self-hosting is explicitly allowed.
  2. Convert them to WOFF2 and drop every other format: it's the only format current browsers need, and the most compact.
  3. Keep only the weights you actually use. Two weights (400 and 700) cover 90% of landing pages; every extra weight is one more file to download.
  4. Subset the character set to latin + latin-ext for a Western-language page: there's no reason to ship Cyrillic and Greek.
  5. Declare them with @font-face and font-display: swap, serve them from your own domain, and add a fallback with close proportions to the font-family stack.

Legal notice and terms of sale on a landing page: what's actually required

A landing page shipped in a hurry often goes live with no legal notice at all, or with a wall of terms of sale copy-pasted from a competitor in a completely different industry. Both mistakes are costly — one in legal exposure, the other in credibility. Here's what the law actually requires, what's merely recommended, and what does nothing at all.

Unlike terms of sale, the legal notice doesn't depend on what the page sells. France's law for confidence in the digital economy (LCEN, law n° 2004-575 of June 21, 2004, now codified at article 1-1 of that text) requires every website publisher — brochure site, capture page or sales funnel — to display a set of identifying information, easily accessible from any page. A one-page landing page with no navigation menu isn't exempt: a discreet footer link is enough, but it has to exist.

Legal notice: required for every website, no exceptions

  • Publisher identity — full name for a sole trader, or company name, legal form and share capital for a registered company.
  • Address and contact method — the registered postal address plus a working email or phone number.
  • Registration number — SIRET, plus RCS or trade register number depending on the activity.
  • Intra-community VAT number, if the business is liable for it.
  • Publication director — usually the founder or the person running the project.
  • Hosting provider identity — the hosting company's name, address and phone number (this information is published in the terms of the hosting provider you use, Vercel or otherwise).

The SaaS subscription cancellation page: France's "3-click" law, and how to fit in an honest retention offer

A SaaS team reworks its pricing page A/B test for the tenth time, while its cancellation page requires a phone call during office hours and three back-and-forth emails. The first page is optional polish. The second is, since June 2023, a precise legal requirement in France. Here's what it mandates, and how to fit in a retention offer that doesn't cross the line.

American legal scholar and economist Cass Sunstein formalized, in an article that has become a reference in law and behavioral economics, the concept of "sludge" — administrative friction added on purpose (confusing forms, redundant steps, a mandatory phone call) that discourages an otherwise legitimate action by leaning on well-documented biases such as inertia and present bias. A study by Cass R. Sunstein, "Sludge and Ordeals," published in 2019 in the Duke Law Journal, shows this kind of friction produces a measurable, predictable effect: the more time and effort a process costs, the more people abandon it before completing it — even when finishing it is in their own interest. A convoluted cancellation page doesn't actually "retain" an unhappy customer: it mostly produces frustration in someone stuck trying to leave, with a direct knock-on effect on public reviews and bank chargeback requests.

The most common cancellation patterns to fix first

  • No cancel button in the account dashboard — reachable only through a help-center search or an email to support, which already exceeds the three-click limit.
  • A required phone call during office hours to confirm cancellation, when sign-up happened online at any hour — the clearest case of non-compliance with the law.
  • A mandatory reason field that blocks submission until filled in: collecting a departure reason is useful (see our guide on reactivating inactive customers), but that field must stay optional.
  • No written confirmation of the contract end date, when the law explicitly requires one on a durable medium.
  • Automatic renewal without a reminder before the charge, which compounds the penalty in an audit if cancellation itself is already difficult.

GDPR and landing pages: making your form compliant without killing conversion

A GDPR-compliant form and a form that converts aren't opposing goals — most compliance mistakes are also UX mistakes. Here's what GDPR actually requires from a landing page, and what it doesn't.

GDPR doesn't list rules specific to "landing pages": it applies to any processing of personal data, whether that's a contact form or a newsletter signup. Four principles cover most of what matters for a form.

The 4 principles that apply to any capture form

  • A legal basis for each purpose. Responding to a quote request is justified by pre-contractual necessity — no separate consent needed. Sending a newsletter or following up by email after a download, on the other hand, requires explicit consent — that's marketing.
  • Data minimization: only collect what's necessary for the stated purpose. This is also a conversion rule — see our guide on how many fields actually convert — but on the GDPR side, a "budget" or "company" field bolted onto a simple contact form out of sales curiosity is hard to justify.
  • Transparency: the visitor needs to know, before submitting, who's collecting their data, why, how long it's kept, and how to exercise their rights.
  • When consent is the legal basis relied on, it must be freely given, specific, informed and unambiguous — the EU Court of Justice confirmed this without ambiguity in the Planet49 ruling (C-673/17): a pre-checked box never counts as valid consent.

VAT on an ebook, template, or online course: what a landing page actually needs to handle

A €29 ebook, an €89 template, a €297 online course: sold from a landing page with a payment link, these digital products can reach any country in Europe from day one. What's almost never anticipated is that the VAT rate that applies depends on the buyer's country, not yours — a rule in place since 2015 that quickly catches up with a seller who never set it up.

A study published in 2024 in the Journal of Public Economics by Chao Fang and Shuzhong Ma measured the effect of a comparable cross-border VAT reform — the July 2021 removal of the VAT exemption on small parcels imported into the EU — using Chinese customs data and orders from an AliExpress seller: Chinese online exports to the EU fell by nearly 50%, and European buyers, more than sellers, bore most of the resulting tax increase (Fang & Ma, 2024). The lesson carries over directly to digital products: a change in cross-border VAT rules measurably reshapes who sells, who buys, and at what price — a seller who finds out after the fact that months or years of uncollected foreign VAT need to be settled takes on a real financial risk, well beyond a simple administrative checkbox.

The Digital Markets Act (DMA): why your Meta and Google ads target less precisely in Europe, and what it means for your landing page

Since 2024, the Digital Markets Act has forced platforms designated as "gatekeepers" — Meta and Google chief among them — to limit combining personal data across their services without explicit consent. The concrete result for a European advertiser: blurrier ad targeting, and a landing page that has to pick up the qualification work the algorithm used to do.

A share of European users are now choosing the less personalised option rather than consenting to full data combination. Mechanically, the bidding algorithm has less behavioural signal for that audience segment: automated optimisation systems (Advantage+ on Meta's side, Performance Max campaigns on Google's) need longer learning phases and converge on less finely qualified audiences in Europe than in other markets. This isn't a new phenomenon: a study by Avi Goldfarb and Catherine Tucker published in 2011 in Management Science, "Privacy Regulation and Online Advertising", already measured a 65% drop in display advertising effectiveness in Europe after the 2002 e-Privacy Directive took effect, precisely in the contexts where advertisers lost access to fine-grained behavioural data. The DMA is replaying the same mechanism fifteen years later, with broader reach since it directly touches the largest ad networks on the market.

Building a page that compensates for blurrier targeting

  • An explicit value proposition on the very first screen: don't count on the ad having already done 80% of the qualification work.
  • One conversion goal per page, so even a less-qualified visitor immediately understands the expected action.
  • Owned audience capture — an email list, a lead magnet — rather than full dependence on ad retargeting, whose precision is dropping for the same reasons as initial targeting.
  • A fast page, in the spirit of our Core Web Vitals guides: every click potentially costs more to qualify than before, so an abandonment caused by slowness now costs more than it used to.
  • A monitored quality score on Google Ads, since the quality score remains one of the few levers that partially offset less precise targeting by lowering cost per click.

LanderKit templates ship with legal notice and privacy pages to complete, and no third-party script loaded by default.

FAQ

Frequently asked questions

Does RGAA apply to my landing page if I'm a freelancer or small agency?

Rarely as a legal obligation: RGAA targets public bodies and private companies with more than €250 million in annual revenue in France. The European Accessibility Act, on the other hand, applies to e-commerce services sold to European consumers as of June 28, 2025, unless the microenterprise exemption applies (fewer than 10 employees, under €2 million in turnover or balance sheet) — an exemption that only covers services and disappears the moment you outgrow those thresholds.

Can you borrow the structure of a competitor's landing page?

Yes: section order, interface patterns (two-step forms, sticky CTAs, FAQs), and copywriting methods are ideas and methods, not protected by copyright. What's protected are concrete expressions: texts, images, videos, original code, and the overall design if it's original.

Are dark patterns illegal?

Many already are, depending on the mechanism: in France and the EU, fake urgency and fictitious scarcity fall under deceptive commercial practices monitored by the DGCCRF, pre-ticked boxes don't constitute valid consent under the GDPR, and the Digital Services Act explicitly prohibits deceptive interfaces at the European level. Even where a tactic sits in a grey area, the regulatory trend clearly points towards more enforcement, not less.

Can a site using Matomo really skip the cookie banner?

Yes, but only if the configuration meets every one of the CNIL's exemption criteria: hosting and purpose limited to the site's own audience measurement, anonymized IP, no data shared with third parties, no cross-site tracking, an easy opt-out for visitors, and a capped retention period. A default install with no check of these settings isn't enough.

Do I need to add an "AI-generated" label to my hero image?

In most cases, no: a generic illustration or product mockup doesn't meet the legal definition of a deep fake. The disclosure becomes necessary only if the image imitates a real person, place or event closely enough to appear authentic.

Does a cookie banner really lower a landing page's conversion rate?

According to two studies (Nouwens et al., 2020, CHI; Utz et al., 2019, ACM CCS), banner format — a bottom banner versus a full-screen blocking overlay — has no measurable effect on visitor behavior. What actually loses consent is the complexity of the choice presented (detailed settings imposed upfront), not the banner's mere presence.

Read next

Related articles