EnglishFrançais
France flag

France

France Data Privacy Laws: GDPR & CNIL Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 42 primary sources cited on this page. How we verify our legal content

France Data Privacy Laws: GDPR & CNIL Compliance Guide (2026)

Frequently Asked Questions

What is the CNIL and what authority does it have in France?

The CNIL (Commission nationale de l'informatique et des libertés) is France's independent data protection authority, created in 1978 by the Loi Informatique et Libertés. It has broad powers to investigate data processing activities, conduct on-site inspections, impose fines of up to EUR 20 million or 4% of global annual turnover, issue injunctions, and order temporary or permanent processing bans. In 2025, the CNIL issued 83 sanctions totaling EUR 486.8 million, making it one of the most active data protection authorities in Europe.

How does French data privacy law differ from the standard GDPR?

France applies the GDPR directly but supplements it with national provisions under the Loi Informatique et Libertés. French-specific rules include a digital age of consent set at 15 (GDPR allows 13 to 16), mandatory Health Data Hosting certification for anyone hosting care-context health data on behalf of others, post-mortem data directives that let individuals specify what happens to their data after death, and particularly strict rules on employee workplace monitoring. France also maintains criminal penalties for data protection violations, with up to five years' imprisonment and EUR 300,000 in fines.

What are France's cookie consent requirements?

France requires prior, informed, and freely given consent before placing non-essential cookies. Refusing cookies must be as easy as accepting them: a single-click refuse option must appear at the same level as the accept button. Pre-checked boxes and continued browsing do not constitute valid consent. Cookie walls are not banned outright: the CNIL assesses them case by case against criteria it published in May 2022, the central one being whether the user has a real and fair alternative way to reach the content without accepting trackers. In 2025, the CNIL imposed EUR 325 million on Google and EUR 150 million on Shein for cookie violations, and EUR 50 million on Orange in late 2024.

What are the penalties for data privacy violations in France?

Administrative fines under GDPR reach EUR 20 million or 4% of global annual turnover for serious violations, and EUR 10 million or 2% for less severe breaches. The CNIL also issues injunctions, processing bans, and orders to notify individuals. France's Penal Code adds criminal penalties of up to five years' imprisonment and EUR 300,000 for individuals, or EUR 1.5 million for legal entities. For straightforward cases, the CNIL's simplified procedure can impose fines up to EUR 20,000 without a public hearing, rising to EUR 100,000 where the controller's worldwide turnover exceeds EUR 50 million, a ceiling raised by Law No. 2026-403 of May 26, 2026.

How does France handle data breach notification?

Organizations must notify the CNIL within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms. Notification is submitted through the CNIL's online portal. When the breach poses a high risk, affected data subjects must also be informed without undue delay. The CNIL treats inadequate security as a standalone violation: FREE was fined EUR 42 million and France Travail EUR 5 million in January 2026 for security failures that enabled breaches, not just for the breaches themselves.

How does the EU AI Act apply in France?

The EU AI Act entered into force on August 1, 2024. Prohibitions on highest-risk AI practices applied from February 2025. Governance rules and GPAI obligations applied from August 2025. Transparency obligations have applied since August 2, 2026, with a grace period to December 2, 2026 for marking synthetic content generated by systems already on the market. The high-risk AI requirements were moved by the July 2026 Digital Omnibus to December 2, 2027 for Annex III systems and August 2, 2028 for high-risk AI built into regulated products. France has not yet designated its AI Act authorities in law: the government's September 2025 scheme would give the CNIL market surveillance over most Annex III systems, but it depends on the DDADUE bill, adopted by the Senate in February 2026 and still in first reading at the Assemblée nationale. The CNIL has published GDPR compliance recommendations for AI developers. Organizations deploying high-risk AI must complete Data Protection Impact Assessments and implement human oversight mechanisms.

What is France's digital age of consent?

France set the digital age of consent at 15 years, exercising the GDPR's option to allow member states to choose between 13 and 16. Children under 15 require joint consent from a parent or guardian and the child themselves for data processing by online services. Children 15 and older can independently consent to cookie settings, social media privacy choices, and similar digital data processing. The CNIL has published eight sets of recommendations specifically addressing children's digital rights.

What is Health Data Hosting (HDS) certification in France?

HDS certification is mandatory for anyone hosting health data collected in a prevention, diagnosis, care, or medico-social context on behalf of a third party, under Article L. 1111-8 of the Public Health Code. The certificate is issued by certification bodies accredited by COFRAC or by another EU member state's national accreditation body, not by the Agence du Numérique en Santé, which maintains the certification referential and publishes the register of certified hosters. There is no equivalent guarantees alternative: a non-French provider must be certified. Since July 1, 2025 the SREN law also requires contract terms on storage within the EU or the EEA and on the risk of transfer to or access by countries outside it.

Updates

Corrected the French-law specifics that had gone out of date or were wrong: the CNIL's simplified-procedure fine ceiling now rises to EUR 100,000 (and EUR 500 per day) for controllers with worldwide turnover above EUR 50 million under the law of 26 May 2026; the Amazon France Logistique fine was cut from EUR 32 million to EUR 15 million by the Conseil d'Etat on 23 December 2025, which also held the scanner monitoring indicators lawful and left only the 31-day retention, information and security breaches standing; health data hosting has no equivalent-guarantees alternative to HDS certification, which is issued by accredited certification bodies rather than the Agence du Numerique en Sante, and now carries EU or EEA storage and contract duties; a Criteo detail about a refusal option hidden behind an Accept cookies button was removed as unsupported and the March 2026 appeal outcome added; cookie walls are assessed case by case rather than generally prohibited; the AI Act transparency duties are described as in force since 2 August 2026, with the December 2026 dates added and France's still-undecided authority designation explained; and 2026 enforcement (IQVIA, EXTIA), the January 2026 cookie recommendation, the 2026 statutes and current DPO figures were added.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Expanded to cover EU AI Act implementation and CNIL market surveillance authority role; added constitutional basis section; documented 2025 enforcement record (83 sanctions, EUR 486.8 million total) including Orange (EUR 50M, November 2024), Google (EUR 325M) and Shein (EUR 150M) in September 2025; added 2026 actions (FREE EUR 42M, France Travail EUR 5M, NEXPUBLICA EUR 1.7M); expanded simplified sanction procedure, cross-border transfers, and Transfer Impact Assessment guidance.

Clarified AI Act transition period reference: the May 7, 2026 political agreement is the Digital Omnibus AI Act simplification (not the GDPR/cookie Digital Omnibus which remains in trilogue); added Council press release citation; content_reviewed_at updated.

Initial publication covering Loi Informatique et Libertés history, CNIL structure and enforcement, cookie consent rules, breach notification, health data hosting, digital age of consent, post-mortem data directives, and employee privacy protections.

Reviewed and approved by an editor

Sources and References

  1. Loi Informatique et Libertés (Law 78-17 of January 6, 1978) - CNIL Overview(cnil.fr).gov
  2. Loi n° 78-17 du 6 janvier 1978 - Full Text on Legifrance(legifrance.gouv.fr).gov
  3. Decree No. 2019-536 of 29 May 2019 - Application Decree for Loi Informatique et Libertés(legifrance.gouv.fr).gov
  4. Conseil Constitutionnel Decision 2018-765 DC - Data Protection Law Constitutionality Review(conseil-constitutionnel.fr).gov
  5. CNIL - The French National Data Protection Framework(cnil.fr).gov
  6. CNIL - Sanctions and Corrective Measures: Actions in 2025(cnil.fr).gov
  7. CNIL - Sanctions and Corrective Measures: Actions in 2024(cnil.fr).gov
  8. Google Fined EUR 325 Million for Cookies and Email Advertising - CNIL(cnil.fr).gov
  9. Shein Fined EUR 150 Million for Cookie Consent Violations - CNIL(cnil.fr).gov
  10. Orange Fined EUR 50 Million for Email Advertising Without Consent - CNIL(cnil.fr).gov
  11. Conseil d'Etat, 4 March 2026, No. 482872 - Criteo appeal rejected, EUR 40 million CNIL fine upheld(legifrance.gouv.fr).gov
  12. Conseil d'Etat, 23 December 2025, No. 492830 - Amazon France Logistique: CNIL fine reduced to EUR 15 million(legifrance.gouv.fr).gov
  13. FREE Mobile and FREE Fined EUR 42 Million for Data Breach - CNIL(cnil.fr).gov
  14. France Travail Fined EUR 5 Million for Data Security Failure - CNIL(cnil.fr).gov
  15. NEXPUBLICA FRANCE Fined EUR 1.7 Million for Data Security Failures - CNIL(cnil.fr).gov
  16. Loyalty Programme Company Fined EUR 3.5 Million for Unlawful Social Network Data Transfer - CNIL(cnil.fr).gov
  17. CNIL Simplified Sanction Procedure - Overview(cnil.fr).gov
  18. CNIL Practice Guide - Security of Personal Data (2024 edition)(cnil.fr).gov
  19. CNIL Practical Guide for Data Protection Officers(cnil.fr).gov
  20. CNIL AI Recommendations for GDPR-Compliant AI Development(cnil.fr).gov
  21. EU AI Act Entry into Force - CNIL Questions and Answers(cnil.fr).gov
  22. CNIL Digital Rights of Children - Recommendations(cnil.fr).gov
  23. EU General Data Protection Regulation - Rules for Business(europa.eu).gov
  24. Article 85 - Loi Informatique et Libertés - Post-Mortem Data Directives(legifrance.gouv.fr).gov
  25. CNIL 10th Innovation Report - Our Data After Us (Digital Death)(cnil.fr).gov
  26. Council of the EU - AI Act Simplification Political Agreement (May 7, 2026)(consilium.europa.eu).gov
  27. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  28. Article 22-1, Loi n° 78-17 du 6 janvier 1978, as amended by LOI n° 2026-403 du 26 mai 2026 art. 60 (simplified sanction procedure ceilings) - Legifrance(legifrance.gouv.fr).gov
  29. LOI n° 2026-403 du 26 mai 2026 de simplification de la vie economique - Legifrance(legifrance.gouv.fr).gov
  30. Article L. 1111-8, Code de la sante publique (health data hosting certification), in force since 1 July 2025 - Legifrance(legifrance.gouv.fr).gov
  31. Agence du Numerique en Sante - HDS certification: referential, accredited certification bodies and register of certified hosters(esante.gouv.fr).gov
  32. CNIL - Cookie walls: the rules(cnil.fr).gov
  33. CNIL - Cookie walls: first criteria for assessing lawfulness (16 May 2022)(cnil.fr).gov
  34. CNIL - Final recommendations on cross-device consent (16 January 2026)(cnil.fr).gov
  35. CNIL - Health data: EUR 5 million fine against IQVIA (26 May 2026)(cnil.fr).gov
  36. CNIL - EUR 300,000 fine against EXTIA for failure to respect data subject rights (21 July 2026)(cnil.fr).gov
  37. Conseil constitutionnel, decision No. 2026-911 DC of 14 August 2026 (law on minors and social networks)(conseil-constitutionnel.fr).gov
  38. LOI n° 2026-813 du 24 aout 2026 visant a proteger les mineurs des risques auxquels les expose l'utilisation des reseaux sociaux - Legifrance(legifrance.gouv.fr).gov
  39. Direction generale des Entreprises - National competent authorities for the EU AI Act (9 September 2025)(entreprises.gouv.fr).gov
  40. Assemblee nationale - DDADUE bill dossier (AI Act authority designation, art. 24), first reading(assemblee-nationale.fr).gov
  41. CNIL - La CNIL en bref, edition 2026 (key figures, 109,249 organisations with a designated DPO)(cnil.fr).gov
  42. CNIL - Les DPO a l'heure de l'IA, enquete 2025 (published July 2026)(cnil.fr).gov
Share: