🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
FR · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 33 sources retrieved model claude-sonnet-5 ·

France

FR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 33 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

The CNIL closed out a wave of high-value sanctions across 2025 and into 2026. The CNIL fined Free Mobile and Free a combined €42 million, treating the two entities as separate controllers each responsible for its own subscriber data despite their corporate affiliation. The CNIL separately sanctioned Free Mobile and Free for incomplete Article 34(2) GDPR breach notifications to affected subscribers. The CNIL also found that Free failed to sort and delete former-subscriber data once it was no longer needed for accounting purposes. France Travail, the public employment agency, is understood to have been fined €5 million, partly because data protection impact assessments had already identified necessary security measures that were never implemented. The CNIL fined the health-data analytics firm IQVIA €5 million, holding that re-identifiable health-data-warehouse data was pseudonymous rather than anonymous. NEXPUBLICA drew a €1.7 million penalty for structural Article 32 security weaknesses in its processing of disability data. A reported 2025 aggregate sanctions figure of €486,839,500 is understood to be concentrated overwhelmingly, on the order of 97-98 percent, in two large multinational decisions issued the same day, separate from the France-specific 2026 sanction wave described above. The EU AI Act's transparency-risk obligations for chatbots and generative content become applicable on 2 August 2026, beginning to layer AI-specific duties onto the GDPR transparency regime the CNIL already enforces.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, GDPR-aligned omnibus framework with an active, well-resourced regulator; no material gaps identified in this cycle.

Primary frameworkGDPR (Regulation (EU) 2016/679) + Loi n° 78-17 du 6 janvier 1978 modifiée (Loi Informatique et Libertés)
Traffic-light rationale — GreenComprehensive, GDPR-aligned omnibus framework with an active, well-resourced regulator; no material gaps identified in this cycle.

Sub-modules (5)

Regulator And AuthorityGreen

CNIL is composed of 18 members drawn from Parliament, senior courts and qualified experts, and acts through a restricted sanctions committee.

Claims: CLM-FR-a10001b1

Act And InstrumentsGreen

National framework = GDPR + Loi Informatique et Libertés as consolidated by the 2018 law, 2018 ordonnance and 2019 decree.

Claims: CLM-FR-a10002b2

Material ScopeGreen

GDPR displaces national law on most points; national law retains 'marges de manœuvre' for health data, criminal-offence data, digital age of consent, post-mortem data, and remains sole basis for penal/security files.

Claims: CLM-FR-a10003b3, CLM-FR-a10004b4

Territorial ScopeGreen

CNIL holds exclusive competence over Article 82 LIL / L.34-5 CPCE (cookies) compliance for users located in France, distinct from its GDPR jurisdiction over establishment-based controllers.

Claims: CLM-FR-a10005b5

Regulator Registration And FilingGreen

DPO designation, replacement and termination are handled exclusively via CNIL's dedicated online teleservice.

Claims: CLM-FR-a10006b6

Category narrative70 words

France applies the GDPR directly alongside the national Loi n° 78-17 du 6 janvier 1978 (Loi Informatique et Libertés), as substantially rewritten by the Law of 20 June 2018, Ordonnance n° 2018-1125 and Décret n° 2019-536 to align French law with the GDPR and the Law Enforcement Directive. The CNIL is the supervisory authority, an 18-member independent commission with investigative and sanctioning powers exercised through its restricted committee (formation restreinte).

No periodic updates recorded against this sub-brief.

#

Well-evidenced, GDPR-aligned regime with active CNIL enforcement on special categories and anonymisation claims.

Primary frameworkGDPR Arts 6, 7, 9 + Loi Informatique et Libertés Arts 66, 82
Supervisory authorityCNIL
Traffic-light rationale — GreenWell-evidenced, GDPR-aligned regime with active CNIL enforcement on special categories and anonymisation claims.

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6 bases apply directly, replacing prior national equivalents.

Claims: CLM-FR-a10007b7

Special CategoriesGreen

Health data subject to Article 66 LIL enhanced safeguards and CNIL authorisation for data warehouses.

Claims: CLM-FR-a10009b9

Pseudonymisation And AnonymisationAmber

CNIL's IQVIA decision held re-identifiable warehouse data was pseudonymous, not anonymous, rejecting a post-SRB-judgment anonymisation defence.

Claims: CLM-FR-a1000ac0

Category narrative44 words

GDPR Article 6 lawful bases apply directly; consent for trackers must be a clear positive act under Article 82 LIL. Health and other special-category data receive enhanced national safeguards (Article 66 LIL), and CNIL enforcement (e.g., the IQVIA decision) actively tests the pseudonymisation/anonymisation boundary.

No periodic updates recorded against this sub-brief.

#

Core rights well evidenced via CNIL guidance and enforcement; portability and response-window specifics lack direct T1/T2 evidence this cycle.

Primary frameworkGDPR Arts 12-22
Supervisory authorityCNIL
Traffic-light rationale — AmberCore rights well evidenced via CNIL guidance and enforcement; portability and response-window specifics lack direct T1/T2 evidence this cycle.

Sub-modules (5)

Access RightGreen

Even consent-exempt audience-measurement processing remains subject to GDPR Arts 15-22 rights.

Claims: CLM-FR-a1000bd1

Rectification And ErasureGreen

GDPR's application strengthened minors' right to erasure within French law.

Claims: CLM-FR-a1000ce2

Restriction And ObjectionGreen

CNIL requires refusal of trackers to be exactly as easy as acceptance.

Claims: CLM-FR-a1000df3

Data PortabilityRed

No FR-specific portability findings surfaced in this research cycle.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

No FR-specific deviation from standard GDPR response windows was evidenced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Category narrative39 words

GDPR Articles 15-22 rights apply fully, including to processing nominally exempt from consent (e.g., audience measurement). CNIL has reinforced minors' erasure rights and equal-ease-of-refusal standards for trackers. Portability and specific response-deadline practice were not evidenced in this research cycle.

No periodic updates recorded against this sub-brief.

#

Extensive, recent (2025-2026) CNIL sanction practice directly evidences most sub-modules; ROPA remains a gap.

Primary frameworkGDPR Arts 5, 24, 25, 28, 30, 32-35, 37-39
Supervisory authorityCNIL
Traffic-light rationale — GreenExtensive, recent (2025-2026) CNIL sanction practice directly evidences most sub-modules; ROPA remains a gap.

Sub-modules (7)

Accountability And DpiaAmber

FRANCE TRAVAIL's DPIAs had identified necessary security measures that were never actually implemented, a factor in its €5m fine.

Claims: CLM-FR-a1000eg4

Dpo RequirementsGreen

DPO designation is mandatory for public bodies, large-scale-monitoring organisations (banks, insurers, telecoms/ISPs) and large-scale sensitive-data processors; non-designation risks fines up to €10m/2% turnover, and CNIL has issued public mises en demeure to non-compliant communes.

Claims: CLM-FR-a1000fh5, CLM-FR-a10010i6, CLM-FR-a10011j7

Ropa RequirementsRed

No FR-specific ROPA enforcement or guidance was surfaced in this cycle beyond the standard GDPR Art 30 baseline.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsGreen

CNIL treated FREE MOBILE and FREE as separate controllers each responsible for its own subscriber data despite corporate affiliation.

Claims: CLM-FR-a10012k8

Security MeasuresAmber

Article 32 GDPR breaches (NEXPUBLICA's structural security weaknesses processing disability data) attract multi-million-euro fines.

Claims: CLM-FR-a10013l9

Breach NotificationAmber

CNIL sanctioned incomplete Article 34(2) breach notifications to affected FREE/FREE MOBILE subscribers.

Claims: CLM-FR-a10014m0

Retention And DisposalAmber

FREE failed to sort and delete former-subscriber data once no longer needed for accounting purposes.

Claims: CLM-FR-a10015n1

Category narrative40 words

CNIL's 2026 enforcement wave (FREE MOBILE/FREE, FRANCE TRAVAIL, IQVIA, NEXPUBLICA) evidences active application of accountability/DPIA, DPO, joint-controller, security, breach-notification and retention obligations under GDPR Arts 5, 24, 25, 28, 30, 32-35, 37-39. ROPA-specific findings were not separately evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

No FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.

Primary frameworkGDPR Arts 44-49 (EU-level, applied uniformly in France)
Supervisory authorityCNIL
Traffic-light rationale — RedNo FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.

Sub-modules (6)

Transfer MechanismsRed

No FR-specific transfer-mechanism findings this cycle.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Adequacy decisions received are an EU Commission competence applied uniformly across Member States including France; no FR-specific instrument identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Adequacy decisions granted to third countries are adopted by the European Commission, not France individually.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No FR-specific SCC/BCR uptake data surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No FR-specific TIA guidance surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationAmber

France operates a sector-specific CNIL authorisation gate for health-data warehouses (e.g., IQVIA's LRX/EMR warehouses) rather than a blanket localisation mandate.

Claims: CLM-FR-a10016o2

Category narrative37 words

France applies the GDPR's uniform EU transfer regime (adequacy decisions, SCCs, BCRs, derogations) as an EU Member State; no FR-specific derogation or localisation mandate beyond the sector-specific CNIL authorisation gate for health-data warehouses was evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

Strong evidence for financial, health, telecoms and employment overlays; credit-scoring and education overlays remain unevidenced gaps.

Primary frameworkGDPR + Loi Informatique et Libertés Art 82 (ePrivacy) + Art 66 (health)
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong evidence for financial, health, telecoms and employment overlays; credit-scoring and education overlays remain unevidenced gaps.

Sub-modules (7)

Financial Sector OverlayGreen

Banks and insurers are cited by CNIL as paradigm cases triggering mandatory DPO designation via large-scale client-monitoring activity.

Claims: CLM-FR-a10017p3

Health Sector OverlayGreen

Health-data warehouses require CNIL authorisation and enhanced Article 66 LIL safeguards; CNIL processed 539 health-authorisation applications in 2025.

Claims: CLM-FR-a10018q4

Telecoms And EprivacyGreen

Article 82 LIL (transposing ePrivacy Art 5(3)) plus CPCE Art L.34-5 give CNIL exclusive tracker-compliance competence for France-located users, operating alongside GDPR.

Claims: CLM-FR-a10019r5

Employment DataAmber

CNIL fined the public employment agency FRANCE TRAVAIL €5m for failing to secure job-seekers' data after a major 2024 breach.

Claims: CLM-FR-a10020s6

Credit And ScoringRed

No FR-specific credit-scoring DP findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

No FR-specific education-sector DP findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

InsuranceGreen

Insurance is cited alongside banking as a large-scale-monitoring sector triggering DPO obligations.

Claims: CLM-FR-a10017p3

Category narrative29 words

Financial (banks/insurers), telecoms/ePrivacy and employment/public-sector data processing carry distinct overlays evidenced by CNIL DPO guidance and 2026 enforcement (FRANCE TRAVAIL). Credit-scoring and education-sector overlays were not evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

Cookies/trackers and cross-context advertising well evidenced; opt-out signals, clean rooms/DCR and direct marketing remain gaps.

Primary frameworkLoi Informatique et Libertés Art 82 + GDPR
Supervisory authorityCNIL
Traffic-light rationale — AmberCookies/trackers and cross-context advertising well evidenced; opt-out signals, clean rooms/DCR and direct marketing remain gaps.

Sub-modules (6)

Cookies And TrackersGreen

CNIL's guidelines/recommendation require a clear positive consent act, easy withdrawal and equal ease of refusal; consolidated January 2026 and supplemented by 2026 multi-device recommendations.

Claims: CLM-FR-a10021t7, CLM-FR-a10022u8

Dark PatternsAmber

CNIL identifies 'cookie walls' (conditioning access on tracker acceptance) as a distinct compliance-risk pattern under GDPR consent-validity standards.

Claims: CLM-FR-a10023v9

Opt Out SignalsRed

No FR-specific Global-Privacy-Control-style opt-out-signal findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No FR-specific clean-room/data-collaboration-room findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingGreen

CNIL treats GDPR-governed advertising-data processing and Article-82 tracker-deposit rules as separate legal/jurisdictional regimes, avoiding double sanction for identical conduct.

Claims: CLM-FR-a10024w0

Direct MarketingRed

No FR-specific direct-marketing consent/suppression findings beyond general cookie consent rules surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Category narrative43 words

CNIL's cookie/tracker regime (2020 guidelines and recommendation, consolidated January 2026, plus 2026 multi-device recommendations) is the dominant adtech-privacy instrument, alongside enforcement distinguishing GDPR-governed advertising processing from Article 82 tracker rules. Opt-out signals, clean rooms and direct marketing were not separately evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

Strong biometric and AI Act interface evidence; genetic-data-specific regime remains an evidenced gap.

Primary frameworkGDPR Art 9 + EU AI Act (Regulation (EU) 2024/1689) as applied via CNIL guidance
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong biometric and AI Act interface evidence; genetic-data-specific regime remains an evidenced gap.

Sub-modules (6)

Profiling RestrictionsAmber

CNIL and EU peer DPAs called for prohibiting AI systems categorising individuals by inferred protected characteristics (ethnicity, sex, political/sexual orientation).

Claims: CLM-FR-a10025x1

Automated Decision Making TransparencyAmber

EU AI Act transparency-risk obligations (chatbots, generative content) apply from 2 August 2026, layered on GDPR transparency duties.

Claims: CLM-FR-a10026y2

Ai Risk AssessmentsAmber

AI Act's four-tier risk classification (unacceptable/high/transparency/minimal) imposes conformity-assessment and risk-management duties on high-risk systems (Annex III), interfacing with but not replacing GDPR DPIA.

Claims: CLM-FR-a10027z3

Biometric RegimeGreen

CNIL has sanctioned scraped facial-recognition-database creation as unlawful Article 9 GDPR biometric processing, and excludes biometric-identification cameras from its general smart-camera guidance given the distinct, in-principle-prohibited regime.

Claims: CLM-FR-a10028a4, CLM-FR-a10029b5

Genetic DataRed

No FR-specific genetic-data regime findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

Loi Informatique et Libertés remains the exclusive framework for penal-sphere and national-security/intelligence processing, carved out of GDPR's material scope.

Claims: CLM-FR-a10030c6

Category narrative41 words

CNIL actively enforces the Article 9 GDPR biometric special-category regime (sanctioning scraped facial-recognition databases) and is shaping the France/EU interface between GDPR and the EU AI Act, including risk-tiered obligations and profiling/biometric-categorisation restrictions. Genetic data was not separately evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

Strong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.

Primary frameworkGDPR Art 8 + Loi Informatique et Libertés Art 45 + Loi SREN (2024)
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.

Sub-modules (5)

Age VerificationAmber

Arcom must adopt a technical référentiel for pornography-site age verification under the SREN law; CNIL opined on the draft on 26 September 2024 and favours privacy-preserving, locally-generated proof-of-majority methods over facial recognition.

Claims: CLM-FR-a10031d7, CLM-FR-a10032e8

Minor Profiling BansAmber

CNIL has translated GDPR's minors provisions into recommendations for stronger safeguards against default profiling of under-18 users.

Claims: CLM-FR-a10034g0

Education SettingsRed

No FR-specific education-settings DP findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No FR-specific dependent-adults/vulnerable-adult DP findings surfaced this cycle.

Absence provenance: not recorded. Searched: not recorded.

Category narrative49 words

France sets the digital age of consent at 15 (Article 45 LIL), requiring joint minor-plus-parent consent below that age. The SREN law and Arcom age-verification référentiel (subject to CNIL opinion) address pornography-site access, with CNIL favouring privacy-preserving verification methods. Education-settings and dependent-adults protections were not separately evidenced this cycle.

No periodic updates recorded against this sub-brief.

#

Very well evidenced, high-materiality enforcement activity across multiple 2025-2026 decisions plus recent 180-day developments.

Primary frameworkGDPR Arts 58, 77-84 + Loi Informatique et Libertés
Supervisory authorityCNIL
Traffic-light rationale — GreenVery well evidenced, high-materiality enforcement activity across multiple 2025-2026 decisions plus recent 180-day developments.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CNIL's restricted committee imposes fines, mises en demeure and injunctions with daily penalty payments (e.g., €5,000/day FRANCE TRAVAIL, €10,000/day IQVIA); public-sector security-breach fines are capped at €10m rather than turnover-based.

Claims: CLM-FR-a10035h1, CLM-FR-a10036i2

Enforcement Activity IndexGreen

2025 total sanctions of €486,839,500; 2026 sanctions to date include Free Mobile/Free (€42m combined), FRANCE TRAVAIL (€5m), IQVIA (€5m) and NEXPUBLICA (€1.7m).

Claims: CLM-FR-a10037j3

Regulator Funding And CapacityAmber

CNIL processed 539 health-authorisation applications in 2025 alone, indicating substantial specialised operational capacity.

Claims: CLM-FR-a10038k4

Collective Redress And Class ActionsAmber

CNIL flagged the need to clarify collective-action ('action collective') conditions during the 2018 law-rewriting ordonnance process.

Claims: CLM-FR-a10039l5

Private Right Of ActionAmber

CNIL cannot award compensation; breach victims must pursue police complaints or civil courts for redress.

Claims: CLM-FR-a10040m6

Recent Developments 180DGreen

June 2026 G7 DPA meeting in Paris adopted a privacy-preserving age-verification declaration and children's-protection principles; EDPB adopted a common breach-notification template and generative-AI anonymisation/web-scraping and blockchain guidance.

Claims: CLM-FR-a10041n7, CLM-FR-a10042o8

Category narrative63 words

CNIL enforcement is highly active: 2025 fines totalled €486,839,500 and 2026 has already seen €27m/€15m (Free Mobile/Free), €5m (FRANCE TRAVAIL), €5m (IQVIA) and €1.7m (NEXPUBLICA) sanctions, backed by daily-penalty injunction powers. Collective redress is flagged as needing clarification; individuals cannot obtain compensation directly from CNIL. Recent 180-day developments include the June 2026 G7 DPA meeting in Paris and EDPB breach-notification-template and AI/anonymisation guidance.

No periodic updates recorded against this sub-brief.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for France
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 33 source(s) in the cumulative register.