Short answer
No, an AI-generated website is not compliant by default
The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you.
What the website owner must decide
The website must clearly identify who operates the business. The Belgian FPS Economy lists information including identity, address, contact details, company number and, where relevant, VAT number and details for regulated professions.
As soon as a form, customer account, newsletter or measurement tool handles personal data, its purposes, legal ground, recipients, retention and individual rights must be defined. A copied privacy policy proves nothing if it does not describe the real flows.
- Before publication: identify the publisher, suppliers and every item of data collected.
- In the interface: inform people at the right moment and minimise fields.
- In the infrastructure: separate access, protect secrets, and provide deletion and export paths.
Risks differ and sanctions are not automatic
For certain infringements, the GDPR sets a ceiling of €20 million or 4% of total worldwide annual turnover, whichever is higher. Article 83 still requires a case-by-case assessment: nature, severity, duration, cooperation and corrective action matter.
For products and services within Belgium’s implementation of the European accessibility rules, FPS Economy states that the most serious cases can reach €200,000 or 6% of annual turnover. Scope, exceptions and timing must be checked before applying that figure to any business.
In e-commerce, enforcement may involve a warning, remediation, settlement, administrative fine or civil consequences depending on the infringement. Presenting a ceiling as a certain invoice would be misleading.
What Hebora checks and delivers
- Factual map. Pages, forms, cookies, network calls, accounts, roles, storage, processors and mandatory content.
- Repeatable tests. No consent, refusal, withdrawal, account creation and deletion, permissions, errors and mobile display.
- Technical corrections. Conditional tag loading, data minimisation, access control, notices, logs and security settings.
- Evidence file. Dated inventory, before/after captures, test results, remaining responsibilities and questions for a lawyer or DPO.
Hebora can correct product behaviour and prepare the facts. Final legal choices about a legal ground, retention period or sensitive clause belong with the appropriate professional.
Verified official sources
- EUR-Lex — General Data Protection Regulation (GDPR)
- FPS Economy — mandatory information on a business website (official source in French)
- FPS Economy — information obligations for e-commerce (official source in French)
- FPS Economy — European Accessibility Act (official source in French)
- Belgian Data Protection Authority — cookies and other trackers (official guidance in French)
Sources checked on 15 August 2026.