Last updated · 10 categories · 0
claims · 33 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Lead Signal
The CNIL closed out a wave of high-value sanctions across 2025 and into 2026. The CNIL fined Free Mobile and Free a combined €42 million, treating the two entities as separate controllers each responsible for its own subscriber data despite their corporate affiliation. The CNIL separately sanctioned Free Mobile and Free for incomplete Article 34(2) GDPR breach notifications to affected subscribers. The CNIL also found that Free failed to sort and delete former-subscriber data once it was no longer needed for accounting purposes. France Travail, the public employment agency, is understood to have been fined €5 million, partly because data protection impact assessments had already identified necessary security measures that were never implemented. The CNIL fined the health-data analytics firm IQVIA €5 million, holding that re-identifiable health-data-warehouse data was pseudonymous rather than anonymous. NEXPUBLICA drew a €1.7 million penalty for structural Article 32 security weaknesses in its processing of disability data. A reported 2025 aggregate sanctions figure of €486,839,500 is understood to be concentrated overwhelmingly, on the order of 97-98 percent, in two large multinational decisions issued the same day, separate from the France-specific 2026 sanction wave described above. The EU AI Act's transparency-risk obligations for chatbots and generative content become applicable on 2 August 2026, beginning to layer AI-specific duties onto the GDPR transparency regime the CNIL already enforces.
Other Developments
The CNIL consolidated its cookie and tracker guidelines and recommendation in January 2026, supplemented by 2026 recommendations on multi-device consent. The authority continues to require that consent to trackers be a clear positive act, freely revocable, with refusal exactly as easy as acceptance. The CNIL is understood to identify cookie walls, meaning the conditioning of site access on tracker acceptance, as a distinct compliance-risk pattern under GDPR consent-validity standards. The CNIL is understood to treat GDPR-governed advertising-data processing and Article 82 tracker-deposit rules as separate legal and jurisdictional regimes, avoiding double sanction for the same conduct. The CNIL processed 539 health-data-warehouse authorisation applications in 2025. The CNIL operates a sector-specific authorisation gate for health-data warehouses, such as IQVIA's LRX and EMR warehouses, rather than a blanket data-localisation mandate. The technical référentiel that Arcom must adopt for pornography-site age verification under the SREN law remains at consultation stage; the CNIL opined on the draft on 26 September 2024, favouring privacy-preserving proof-of-majority methods over facial recognition. The G7 group of data protection authorities, meeting in Paris in June 2026, is understood to have adopted a declaration on privacy-preserving age verification and a set of children's-protection principles. The EDPB is understood to have adopted a common breach-notification template together with generative-AI anonymisation, web-scraping and blockchain guidance. The CNIL has sanctioned the scraping-based creation of a facial-recognition database as unlawful Article 9 GDPR biometric processing, and treats biometric-identification cameras as excluded from its general smart-camera guidance. The CNIL and its EU peer authorities are reported to have called for prohibiting AI systems that categorise individuals by inferred protected characteristics such as ethnicity, sex, and political or sexual orientation, though this appears to be an advocacy position rather than an adopted rule.
Cross-Monitor Connections
The CNIL's treatment of banks and insurers as paradigm cases triggering mandatory DPO designation through large-scale client-monitoring activity intersects with financial-crime and data-sharing obligations tracked by the financial-integrity monitor. The Free Mobile and Free telecoms sanctions may also bear on payments-specific subscriber data flows tracked by the world-payments monitor. The EU AI Act's 2 August 2026 transparency-obligation date and its interface with GDPR data protection impact assessments are primarily AI-Act-first developments; readers seeking the regulation-specific analysis should consult the artificial-intelligence monitor, while this brief retains the data-protection angle.
Outlook
The trajectory in France points toward continued high-materiality enforcement of accountability, security and breach-notification duties, alongside a widening interface between GDPR and the incoming EU AI Act. The health-data pseudonymisation question tested in the IQVIA decision, and the unresolved status of France's collective-redress mechanism for data protection claims, both remain open threads for future cycles.
trust tier: ai_unverified
Regulatory Status
France's data protection regime rests on the GDPR read together with the Loi Informatique et Libertés, most recently realigned by the Law of 20 June 2018, Ordonnance n°2018-1125 and Décret n°2019-536. The CNIL, composed of 18 members acting through a restricted sanctions committee, retains exclusive national competence over health data, criminal-offence data, the digital age of consent, post-mortem data, and Article 82 tracker compliance for France-located users. The regulator's 2025-2026 sanction wave, including the Free Mobile and Free, FRANCE TRAVAIL, IQVIA and NEXPUBLICA decisions, is understood to demonstrate sustained high-materiality enforcement of accountability, security and breach-notification duties, notwithstanding the concentration of the 2025 aggregate sanctions figure in two unrelated multinational decisions. The EU AI Act's 2 August 2026 transparency-obligation application date is beginning to layer new AI-specific duties onto the existing GDPR framework the CNIL enforces, including in the area of biometric and automated-decision-making governance.
Outlook
France's regulatory posture is tightening: sustained CNIL sanction activity and the incoming EU AI Act transparency-obligation date together signal an environment of expanding scrutiny across enforcement, algorithmic governance and health-data reuse, even as evidentiary gaps persist around cross-border transfer practice and collective redress.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — GreenComprehensive, GDPR-aligned omnibus framework with an active, well-resourced regulator; no material gaps identified in this cycle.
Sub-modules (5)
Regulator And AuthorityGreen
CNIL is composed of 18 members drawn from Parliament, senior courts and qualified experts, and acts through a restricted sanctions committee.
Claims: CLM-FR-a10001b1
Act And InstrumentsGreen
National framework = GDPR + Loi Informatique et Libertés as consolidated by the 2018 law, 2018 ordonnance and 2019 decree.
Claims: CLM-FR-a10002b2
Material ScopeGreen
GDPR displaces national law on most points; national law retains 'marges de manœuvre' for health data, criminal-offence data, digital age of consent, post-mortem data, and remains sole basis for penal/security files.
Claims: CLM-FR-a10003b3, CLM-FR-a10004b4
Territorial ScopeGreen
CNIL holds exclusive competence over Article 82 LIL / L.34-5 CPCE (cookies) compliance for users located in France, distinct from its GDPR jurisdiction over establishment-based controllers.
Claims: CLM-FR-a10005b5
Regulator Registration And FilingGreen
DPO designation, replacement and termination are handled exclusively via CNIL's dedicated online teleservice.
Claims: CLM-FR-a10006b6
Category narrative70 words
France applies the GDPR directly alongside the national Loi n° 78-17 du 6 janvier 1978 (Loi Informatique et Libertés), as substantially rewritten by the Law of 20 June 2018, Ordonnance n° 2018-1125 and Décret n° 2019-536 to align French law with the GDPR and the Law Enforcement Directive. The CNIL is the supervisory authority, an 18-member independent commission with investigative and sanctioning powers exercised through its restricted committee (formation restreinte).
No periodic updates recorded against this sub-brief.
Traffic-light rationale — GreenWell-evidenced, GDPR-aligned regime with active CNIL enforcement on special categories and anonymisation claims.
Sub-modules (4)
Lawful BasesGreen
GDPR Article 6 bases apply directly, replacing prior national equivalents.
Claims: CLM-FR-a10007b7
Consent ThresholdsGreen
Consent to trackers must be a clear positive act, freely revocable, and refusal must be as easy as acceptance.
Claims: CLM-FR-a10008b8
Special CategoriesGreen
Health data subject to Article 66 LIL enhanced safeguards and CNIL authorisation for data warehouses.
Claims: CLM-FR-a10009b9
Pseudonymisation And AnonymisationAmber
CNIL's IQVIA decision held re-identifiable warehouse data was pseudonymous, not anonymous, rejecting a post-SRB-judgment anonymisation defence.
Claims: CLM-FR-a1000ac0
Category narrative44 words
GDPR Article 6 lawful bases apply directly; consent for trackers must be a clear positive act under Article 82 LIL. Health and other special-category data receive enhanced national safeguards (Article 66 LIL), and CNIL enforcement (e.g., the IQVIA decision) actively tests the pseudonymisation/anonymisation boundary.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — AmberCore rights well evidenced via CNIL guidance and enforcement; portability and response-window specifics lack direct T1/T2 evidence this cycle.
Sub-modules (5)
Access RightGreen
Even consent-exempt audience-measurement processing remains subject to GDPR Arts 15-22 rights.
Claims: CLM-FR-a1000bd1
Rectification And ErasureGreen
GDPR's application strengthened minors' right to erasure within French law.
Claims: CLM-FR-a1000ce2
Restriction And ObjectionGreen
CNIL requires refusal of trackers to be exactly as easy as acceptance.
Claims: CLM-FR-a1000df3
Data PortabilityRed
No FR-specific portability findings surfaced in this research cycle.
Absence provenance: not recorded. Searched: not recorded.
Deadlines And Response WindowsRed
No FR-specific deviation from standard GDPR response windows was evidenced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Category narrative39 words
GDPR Articles 15-22 rights apply fully, including to processing nominally exempt from consent (e.g., audience measurement). CNIL has reinforced minors' erasure rights and equal-ease-of-refusal standards for trackers. Portability and specific response-deadline practice were not evidenced in this research cycle.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — GreenExtensive, recent (2025-2026) CNIL sanction practice directly evidences most sub-modules; ROPA remains a gap.
Sub-modules (7)
Accountability And DpiaAmber
FRANCE TRAVAIL's DPIAs had identified necessary security measures that were never actually implemented, a factor in its €5m fine.
Claims: CLM-FR-a1000eg4
Dpo RequirementsGreen
DPO designation is mandatory for public bodies, large-scale-monitoring organisations (banks, insurers, telecoms/ISPs) and large-scale sensitive-data processors; non-designation risks fines up to €10m/2% turnover, and CNIL has issued public mises en demeure to non-compliant communes.
CNIL sanctioned incomplete Article 34(2) breach notifications to affected FREE/FREE MOBILE subscribers.
Claims: CLM-FR-a10014m0
Retention And DisposalAmber
FREE failed to sort and delete former-subscriber data once no longer needed for accounting purposes.
Claims: CLM-FR-a10015n1
Category narrative40 words
CNIL's 2026 enforcement wave (FREE MOBILE/FREE, FRANCE TRAVAIL, IQVIA, NEXPUBLICA) evidences active application of accountability/DPIA, DPO, joint-controller, security, breach-notification and retention obligations under GDPR Arts 5, 24, 25, 28, 30, 32-35, 37-39. ROPA-specific findings were not separately evidenced this cycle.
No periodic updates recorded against this sub-brief.
No FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.
Primary frameworkGDPR Arts 44-49 (EU-level, applied uniformly in France)
Traffic-light rationale — RedNo FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.
Sub-modules (6)
Transfer MechanismsRed
No FR-specific transfer-mechanism findings this cycle.
Absence provenance: not recorded. Searched: not recorded.
Adequacy ReceivedRed
Adequacy decisions received are an EU Commission competence applied uniformly across Member States including France; no FR-specific instrument identified.
Absence provenance: not recorded. Searched: not recorded.
Adequacy GrantedRed
Adequacy decisions granted to third countries are adopted by the European Commission, not France individually.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsRed
No FR-specific SCC/BCR uptake data surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Transfer Impact AssessmentRed
No FR-specific TIA guidance surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Data LocalisationAmber
France operates a sector-specific CNIL authorisation gate for health-data warehouses (e.g., IQVIA's LRX/EMR warehouses) rather than a blanket localisation mandate.
Claims: CLM-FR-a10016o2
Category narrative37 words
France applies the GDPR's uniform EU transfer regime (adequacy decisions, SCCs, BCRs, derogations) as an EU Member State; no FR-specific derogation or localisation mandate beyond the sector-specific CNIL authorisation gate for health-data warehouses was evidenced this cycle.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — AmberStrong evidence for financial, health, telecoms and employment overlays; credit-scoring and education overlays remain unevidenced gaps.
Sub-modules (7)
Financial Sector OverlayGreen
Banks and insurers are cited by CNIL as paradigm cases triggering mandatory DPO designation via large-scale client-monitoring activity.
Claims: CLM-FR-a10017p3
Health Sector OverlayGreen
Health-data warehouses require CNIL authorisation and enhanced Article 66 LIL safeguards; CNIL processed 539 health-authorisation applications in 2025.
Claims: CLM-FR-a10018q4
Telecoms And EprivacyGreen
Article 82 LIL (transposing ePrivacy Art 5(3)) plus CPCE Art L.34-5 give CNIL exclusive tracker-compliance competence for France-located users, operating alongside GDPR.
Claims: CLM-FR-a10019r5
Employment DataAmber
CNIL fined the public employment agency FRANCE TRAVAIL €5m for failing to secure job-seekers' data after a major 2024 breach.
Claims: CLM-FR-a10020s6
Credit And ScoringRed
No FR-specific credit-scoring DP findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
EducationRed
No FR-specific education-sector DP findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
InsuranceGreen
Insurance is cited alongside banking as a large-scale-monitoring sector triggering DPO obligations.
Claims: CLM-FR-a10017p3
Category narrative29 words
Financial (banks/insurers), telecoms/ePrivacy and employment/public-sector data processing carry distinct overlays evidenced by CNIL DPO guidance and 2026 enforcement (FRANCE TRAVAIL). Credit-scoring and education-sector overlays were not evidenced this cycle.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — AmberCookies/trackers and cross-context advertising well evidenced; opt-out signals, clean rooms/DCR and direct marketing remain gaps.
Sub-modules (6)
Cookies And TrackersGreen
CNIL's guidelines/recommendation require a clear positive consent act, easy withdrawal and equal ease of refusal; consolidated January 2026 and supplemented by 2026 multi-device recommendations.
Claims: CLM-FR-a10021t7, CLM-FR-a10022u8
Dark PatternsAmber
CNIL identifies 'cookie walls' (conditioning access on tracker acceptance) as a distinct compliance-risk pattern under GDPR consent-validity standards.
Claims: CLM-FR-a10023v9
Opt Out SignalsRed
No FR-specific Global-Privacy-Control-style opt-out-signal findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Clean Rooms And DcrRed
No FR-specific clean-room/data-collaboration-room findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingGreen
CNIL treats GDPR-governed advertising-data processing and Article-82 tracker-deposit rules as separate legal/jurisdictional regimes, avoiding double sanction for identical conduct.
Claims: CLM-FR-a10024w0
Direct MarketingRed
No FR-specific direct-marketing consent/suppression findings beyond general cookie consent rules surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Category narrative43 words
CNIL's cookie/tracker regime (2020 guidelines and recommendation, consolidated January 2026, plus 2026 multi-device recommendations) is the dominant adtech-privacy instrument, alongside enforcement distinguishing GDPR-governed advertising processing from Article 82 tracker rules. Opt-out signals, clean rooms and direct marketing were not separately evidenced this cycle.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — AmberStrong biometric and AI Act interface evidence; genetic-data-specific regime remains an evidenced gap.
Sub-modules (6)
Profiling RestrictionsAmber
CNIL and EU peer DPAs called for prohibiting AI systems categorising individuals by inferred protected characteristics (ethnicity, sex, political/sexual orientation).
Claims: CLM-FR-a10025x1
Automated Decision Making TransparencyAmber
EU AI Act transparency-risk obligations (chatbots, generative content) apply from 2 August 2026, layered on GDPR transparency duties.
Claims: CLM-FR-a10026y2
Ai Risk AssessmentsAmber
AI Act's four-tier risk classification (unacceptable/high/transparency/minimal) imposes conformity-assessment and risk-management duties on high-risk systems (Annex III), interfacing with but not replacing GDPR DPIA.
Claims: CLM-FR-a10027z3
Biometric RegimeGreen
CNIL has sanctioned scraped facial-recognition-database creation as unlawful Article 9 GDPR biometric processing, and excludes biometric-identification cameras from its general smart-camera guidance given the distinct, in-principle-prohibited regime.
Claims: CLM-FR-a10028a4, CLM-FR-a10029b5
Genetic DataRed
No FR-specific genetic-data regime findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
State Surveillance CarveoutsAmber
Loi Informatique et Libertés remains the exclusive framework for penal-sphere and national-security/intelligence processing, carved out of GDPR's material scope.
Claims: CLM-FR-a10030c6
Category narrative41 words
CNIL actively enforces the Article 9 GDPR biometric special-category regime (sanctioning scraped facial-recognition databases) and is shaping the France/EU interface between GDPR and the EU AI Act, including risk-tiered obligations and profiling/biometric-categorisation restrictions. Genetic data was not separately evidenced this cycle.
No periodic updates recorded against this sub-brief.
Strong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.
Primary frameworkGDPR Art 8 + Loi Informatique et Libertés Art 45 + Loi SREN (2024)
Traffic-light rationale — AmberStrong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.
Sub-modules (5)
Age VerificationAmber
Arcom must adopt a technical référentiel for pornography-site age verification under the SREN law; CNIL opined on the draft on 26 September 2024 and favours privacy-preserving, locally-generated proof-of-majority methods over facial recognition.
Claims: CLM-FR-a10031d7, CLM-FR-a10032e8
Parental ConsentGreen
Article 45 LIL sets the digital consent age at 15; below that age, joint minor-and-parent consent is required for non-contractual, consent-based online processing.
Claims: CLM-FR-a10033f9
Minor Profiling BansAmber
CNIL has translated GDPR's minors provisions into recommendations for stronger safeguards against default profiling of under-18 users.
Claims: CLM-FR-a10034g0
Education SettingsRed
No FR-specific education-settings DP findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Dependent AdultsRed
No FR-specific dependent-adults/vulnerable-adult DP findings surfaced this cycle.
Absence provenance: not recorded. Searched: not recorded.
Category narrative49 words
France sets the digital age of consent at 15 (Article 45 LIL), requiring joint minor-plus-parent consent below that age. The SREN law and Arcom age-verification référentiel (subject to CNIL opinion) address pornography-site access, with CNIL favouring privacy-preserving verification methods. Education-settings and dependent-adults protections were not separately evidenced this cycle.
No periodic updates recorded against this sub-brief.
Traffic-light rationale — GreenVery well evidenced, high-materiality enforcement activity across multiple 2025-2026 decisions plus recent 180-day developments.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
CNIL's restricted committee imposes fines, mises en demeure and injunctions with daily penalty payments (e.g., €5,000/day FRANCE TRAVAIL, €10,000/day IQVIA); public-sector security-breach fines are capped at €10m rather than turnover-based.
Claims: CLM-FR-a10035h1, CLM-FR-a10036i2
Enforcement Activity IndexGreen
2025 total sanctions of €486,839,500; 2026 sanctions to date include Free Mobile/Free (€42m combined), FRANCE TRAVAIL (€5m), IQVIA (€5m) and NEXPUBLICA (€1.7m).
CNIL flagged the need to clarify collective-action ('action collective') conditions during the 2018 law-rewriting ordonnance process.
Claims: CLM-FR-a10039l5
Private Right Of ActionAmber
CNIL cannot award compensation; breach victims must pursue police complaints or civil courts for redress.
Claims: CLM-FR-a10040m6
Recent Developments 180DGreen
June 2026 G7 DPA meeting in Paris adopted a privacy-preserving age-verification declaration and children's-protection principles; EDPB adopted a common breach-notification template and generative-AI anonymisation/web-scraping and blockchain guidance.
Claims: CLM-FR-a10041n7, CLM-FR-a10042o8
Category narrative63 words
CNIL enforcement is highly active: 2025 fines totalled €486,839,500 and 2026 has already seen €27m/€15m (Free Mobile/Free), €5m (FRANCE TRAVAIL), €5m (IQVIA) and €1.7m (NEXPUBLICA) sanctions, backed by daily-penalty injunction powers. Collective redress is flagged as needing clarification; individuals cannot obtain compensation directly from CNIL. Recent 180-day developments include the June 2026 G7 DPA meeting in Paris and EDPB breach-notification-template and AI/anonymisation guidance.
No periodic updates recorded against this sub-brief.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for France
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 33 source(s) in the cumulative register.