🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
FR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing33 sources retrieved model claude-sonnet-5 · 2026-07-29

France

FR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 0 claims · 35 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
122Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 16 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

CNIL fined FREE MOBILE €27 million and FREE €15 million, a combined €42 million, on 13 January 2026 for inadequate security measures, following an October 2024 breach that exposed approximately 24 million subscriber contracts including IBAN data. This is the single largest sanction in this cycle's French data-protection activity and, taken together with two further large fines in the same period, indicates a structurally more aggressive CNIL enforcement posture rather than an isolated episodic spike.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, GDPR-aligned omnibus framework with an active, well-resourced regulator; no material gaps identified in this cycle.

Primary frameworkGDPR (Regulation (EU) 2016/679) + Loi n° 78-17 du 6 janvier 1978 modifiée (Loi Informatique et Libertés)
Traffic-light rationale — GreenComprehensive, GDPR-aligned omnibus framework with an active, well-resourced regulator; no material gaps identified in this cycle.

Sub-modules (5)

Regulator And AuthorityGreen

CNIL is composed of 18 members drawn from Parliament, senior courts and qualified experts, and acts through a restricted sanctions committee.

Claims (1):

  • CLM-FR-a10001b1 (claim on file)

Act And InstrumentsGreen

National framework = GDPR + Loi Informatique et Libertés as consolidated by the 2018 law, 2018 ordonnance and 2019 decree.

Claims (1):

  • CLM-FR-a10002b2 (claim on file)

Material ScopeGreen

GDPR displaces national law on most points; national law retains 'marges de manœuvre' for health data, criminal-offence data, digital age of consent, post-mortem data, and remains sole basis for penal/security files.

Claims (2):

  • CLM-FR-a10003b3 (claim on file)
  • CLM-FR-a10004b4 (claim on file)

Territorial ScopeGreen

CNIL holds exclusive competence over Article 82 LIL / L.34-5 CPCE (cookies) compliance for users located in France, distinct from its GDPR jurisdiction over establishment-based controllers.

Claims (1):

  • CLM-FR-a10005b5 (claim on file)

Regulator Registration And FilingGreen

DPO designation, replacement and termination are handled exclusively via CNIL's dedicated online teleservice.

Claims (1):

  • CLM-FR-a10006b6 (claim on file)
Category narrative70 words

France applies the GDPR directly alongside the national Loi n° 78-17 du 6 janvier 1978 (Loi Informatique et Libertés), as substantially rewritten by the Law of 20 June 2018, Ordonnance n° 2018-1125 and Décret n° 2019-536 to align French law with the GDPR and the Law Enforcement Directive. The CNIL is the supervisory authority, an 18-member independent commission with investigative and sanctioning powers exercised through its restricted committee (formation restreinte).

no periodic updates on record for this sub-brief

#

Well-evidenced, GDPR-aligned regime with active CNIL enforcement on special categories and anonymisation claims.

Primary frameworkGDPR Arts 6, 7, 9 + Loi Informatique et Libertés Arts 66, 82
Supervisory authorityCNIL
Traffic-light rationale — GreenWell-evidenced, GDPR-aligned regime with active CNIL enforcement on special categories and anonymisation claims.

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6 bases apply directly, replacing prior national equivalents.

Claims (1):

  • CLM-FR-a10007b7 (claim on file)

Special CategoriesGreen

Health data subject to Article 66 LIL enhanced safeguards and CNIL authorisation for data warehouses.

Claims (1):

  • CLM-FR-a10009b9 (claim on file)

Pseudonymisation And AnonymisationAmber

CNIL's IQVIA decision held re-identifiable warehouse data was pseudonymous, not anonymous, rejecting a post-SRB-judgment anonymisation defence.

Claims (1):

  • CLM-FR-a1000ac0 (claim on file)
Category narrative44 words

GDPR Article 6 lawful bases apply directly; consent for trackers must be a clear positive act under Article 82 LIL. Health and other special-category data receive enhanced national safeguards (Article 66 LIL), and CNIL enforcement (e.g., the IQVIA decision) actively tests the pseudonymisation/anonymisation boundary.

no periodic updates on record for this sub-brief

#

Core rights well evidenced via CNIL guidance and enforcement; portability and response-window specifics lack direct T1/T2 evidence this cycle.

Primary frameworkGDPR Arts 12-22
Supervisory authorityCNIL
Traffic-light rationale — AmberCore rights well evidenced via CNIL guidance and enforcement; portability and response-window specifics lack direct T1/T2 evidence this cycle.

Sub-modules (5)

Access RightGreen

Even consent-exempt audience-measurement processing remains subject to GDPR Arts 15-22 rights.

Claims (1):

  • CLM-FR-a1000bd1 (claim on file)

Rectification And ErasureGreen

GDPR's application strengthened minors' right to erasure within French law.

Claims (1):

  • CLM-FR-a1000ce2 (claim on file)

Restriction And ObjectionGreen

CNIL requires refusal of trackers to be exactly as easy as acceptance.

Claims (1):

  • CLM-FR-a1000df3 (claim on file)

Data PortabilityRed

No FR-specific portability findings surfaced in this research cycle.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

No FR-specific deviation from standard GDPR response windows was evidenced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Category narrative39 words

GDPR Articles 15-22 rights apply fully, including to processing nominally exempt from consent (e.g., audience measurement). CNIL has reinforced minors' erasure rights and equal-ease-of-refusal standards for trackers. Portability and specific response-deadline practice were not evidenced in this research cycle.

no periodic updates on record for this sub-brief

#

Extensive, recent (2025-2026) CNIL sanction practice directly evidences most sub-modules; ROPA remains a gap.

Primary frameworkGDPR Arts 5, 24, 25, 28, 30, 32-35, 37-39
Supervisory authorityCNIL
Traffic-light rationale — GreenExtensive, recent (2025-2026) CNIL sanction practice directly evidences most sub-modules; ROPA remains a gap.

Sub-modules (7)

Accountability And DpiaAmber

FRANCE TRAVAIL's DPIAs had identified necessary security measures that were never actually implemented, a factor in its €5m fine.

Claims (1):

  • CLM-FR-a1000eg4 (claim on file)

Dpo RequirementsGreen

DPO designation is mandatory for public bodies, large-scale-monitoring organisations (banks, insurers, telecoms/ISPs) and large-scale sensitive-data processors; non-designation risks fines up to €10m/2% turnover, and CNIL has issued public mises en demeure to non-compliant communes.

Claims (3):

  • CLM-FR-a1000fh5 (claim on file)
  • CLM-FR-a10010i6 (claim on file)
  • CLM-FR-a10011j7 (claim on file)

Ropa RequirementsRed

No FR-specific ROPA enforcement or guidance was surfaced in this cycle beyond the standard GDPR Art 30 baseline.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsGreen

CNIL treated FREE MOBILE and FREE as separate controllers each responsible for its own subscriber data despite corporate affiliation.

Claims (1):

  • CLM-FR-a10012k8 (claim on file)

Security MeasuresAmber

Article 32 GDPR breaches (NEXPUBLICA's structural security weaknesses processing disability data) attract multi-million-euro fines.

Claims (1):

  • CLM-FR-a10013l9 (claim on file)

Breach NotificationAmber

CNIL sanctioned incomplete Article 34(2) breach notifications to affected FREE/FREE MOBILE subscribers.

Claims (1):

  • CLM-FR-a10014m0 (claim on file)

Retention And DisposalAmber

FREE failed to sort and delete former-subscriber data once no longer needed for accounting purposes.

Claims (1):

  • CLM-FR-a10015n1 (claim on file)
Category narrative40 words

CNIL's 2026 enforcement wave (FREE MOBILE/FREE, FRANCE TRAVAIL, IQVIA, NEXPUBLICA) evidences active application of accountability/DPIA, DPO, joint-controller, security, breach-notification and retention obligations under GDPR Arts 5, 24, 25, 28, 30, 32-35, 37-39. ROPA-specific findings were not separately evidenced this cycle.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Two of this cycle's three major CNIL fines concern controller/processor security and accountability duties directly. CNIL fined France Travail €5 million on 22 January 2026 for failing to ensure the security of jobseekers' data; the central finding was that security measures identified in the organisation's own data protection impact assessments were never actually deployed into production, a gap between documented risk assessment and operational reality rather than an absence of risk assessment altogether. Separately, CNIL fined FREE MOBILE €27 million and FREE €15 million, a combined €42 million, on 13 January 2026, for inadequate security measures under Article 32, following an October 2024 breach that exposed approximately 24 million subscriber contracts including IBAN data.

Both actions concern the same underlying duty, adequate technical and organisational security measures, but manifest differently: the France Travail case is an accountability and DPIA-implementation failure, where the organisation had correctly identified the necessary controls but did not deploy them, while the Free/Free Mobile case is a security-measures failure that resulted in a large-scale breach involving financially sensitive IBAN data. The combined scale of these two sanctions, €47 million between them, is a significant enforcement signal for the accountability and security-measures dimension of France's data-protection regime this cycle.

Outlook

Whether CNIL's 2026 enforcement-priority focus on information and transparency, discussed under Enforcement & Redress, extends to further Article 32 security-measures or Article 35 DPIA-implementation actions is the key marker to watch for this module next cycle.

#

No FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.

Primary frameworkGDPR Arts 44-49 (EU-level, applied uniformly in France)
Supervisory authorityCNIL
Traffic-light rationale — Not assessedNo FR-specific T1/T2 evidence on transfer mechanisms, adequacy lists, SCC/BCR uptake or TIA practice was located this cycle; adequacy decisions are an EU-level Commission competence rather than a distinct French instrument.

Sub-modules (6)

Transfer MechanismsRed

No FR-specific transfer-mechanism findings this cycle.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

Adequacy decisions received are an EU Commission competence applied uniformly across Member States including France; no FR-specific instrument identified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

Adequacy decisions granted to third countries are adopted by the European Commission, not France individually.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No FR-specific SCC/BCR uptake data surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No FR-specific TIA guidance surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationAmber

France operates a sector-specific CNIL authorisation gate for health-data warehouses (e.g., IQVIA's LRX/EMR warehouses) rather than a blanket localisation mandate.

Claims (1):

  • CLM-FR-a10016o2 (claim on file)
Category narrative37 words

France applies the GDPR's uniform EU transfer regime (adequacy decisions, SCCs, BCRs, derogations) as an EU Member State; no FR-specific derogation or localisation mandate beyond the sector-specific CNIL authorisation gate for health-data warehouses was evidenced this cycle.

no periodic updates on record for this sub-brief

#

Strong evidence for financial, health, telecoms and employment overlays; credit-scoring and education overlays remain unevidenced gaps.

Primary frameworkGDPR + Loi Informatique et Libertés Art 82 (ePrivacy) + Art 66 (health)
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong evidence for financial, health, telecoms and employment overlays; credit-scoring and education overlays remain unevidenced gaps.

Sub-modules (7)

Financial Sector OverlayGreen

Banks and insurers are cited by CNIL as paradigm cases triggering mandatory DPO designation via large-scale client-monitoring activity.

Claims (1):

  • CLM-FR-a10017p3 (claim on file)

Health Sector OverlayGreen

Health-data warehouses require CNIL authorisation and enhanced Article 66 LIL safeguards; CNIL processed 539 health-authorisation applications in 2025.

Claims (1):

  • CLM-FR-a10018q4 (claim on file)

Telecoms And EprivacyGreen

Article 82 LIL (transposing ePrivacy Art 5(3)) plus CPCE Art L.34-5 give CNIL exclusive tracker-compliance competence for France-located users, operating alongside GDPR.

Claims (1):

  • CLM-FR-a10019r5 (claim on file)

Employment DataAmber

CNIL fined the public employment agency FRANCE TRAVAIL €5m for failing to secure job-seekers' data after a major 2024 breach.

Claims (1):

  • CLM-FR-a10020s6 (claim on file)

Credit And ScoringRed

No FR-specific credit-scoring DP findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No FR-specific education-sector DP findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

InsuranceGreen

Insurance is cited alongside banking as a large-scale-monitoring sector triggering DPO obligations.

Claims (1):

  • CLM-FR-a10017p3 (claim on file)
Category narrative29 words

Financial (banks/insurers), telecoms/ePrivacy and employment/public-sector data processing carry distinct overlays evidenced by CNIL DPO guidance and 2026 enforcement (FRANCE TRAVAIL). Credit-scoring and education-sector overlays were not evidenced this cycle.

Periodic update · new data 2026-09-28

Sectoral Watch

CNIL fined IQVIA Operations France €5 million on 26 May 2026 for failing to respect guarantees limiting risks to individuals in its management of a health-data warehouse. This is a sector-specific enforcement signal concerning the particular safeguards expected of health-data-warehouse operators, a category of controller handling especially sensitive categories of personal data at scale, and is distinct from the general-purpose security and accountability findings addressed elsewhere this cycle.

The health-data-warehouse context carries heightened regulatory expectations precisely because of the sensitivity and scale of the data involved, and this fine indicates CNIL is prepared to enforce those heightened guarantees with fines of the same order of magnitude as its general Article 32 security-measures actions this cycle. The finding stands alongside the France Travail and Free/Free Mobile fines as one of three major 2026 CNIL sanctions identified this cycle, together forming the basis for the assessment that CNIL's enforcement posture has structurally intensified in 2026 relative to prior years.

Outlook

Whether further health-sector-specific enforcement actions follow the IQVIA fine, and whether CNIL articulates sector-specific guidance for health-data-warehouse operators in response, are the developments to watch for this module next cycle.

#

Cookies/trackers and cross-context advertising well evidenced; opt-out signals, clean rooms/DCR and direct marketing remain gaps.

Primary frameworkLoi Informatique et Libertés Art 82 + GDPR
Supervisory authorityCNIL
Traffic-light rationale — AmberCookies/trackers and cross-context advertising well evidenced; opt-out signals, clean rooms/DCR and direct marketing remain gaps.

Sub-modules (6)

Cookies And TrackersGreen

CNIL's guidelines/recommendation require a clear positive consent act, easy withdrawal and equal ease of refusal; consolidated January 2026 and supplemented by 2026 multi-device recommendations.

Claims (2):

  • CLM-FR-a10021t7 (claim on file)
  • CLM-FR-a10022u8 (claim on file)

Dark PatternsAmber

CNIL identifies 'cookie walls' (conditioning access on tracker acceptance) as a distinct compliance-risk pattern under GDPR consent-validity standards.

Claims (1):

  • CLM-FR-a10023v9 (claim on file)

Opt Out SignalsRed

No FR-specific Global-Privacy-Control-style opt-out-signal findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No FR-specific clean-room/data-collaboration-room findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingGreen

CNIL treats GDPR-governed advertising-data processing and Article-82 tracker-deposit rules as separate legal/jurisdictional regimes, avoiding double sanction for identical conduct.

Claims (1):

  • CLM-FR-a10024w0 (claim on file)

Direct MarketingRed

No FR-specific direct-marketing consent/suppression findings beyond general cookie consent rules surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Category narrative43 words

CNIL's cookie/tracker regime (2020 guidelines and recommendation, consolidated January 2026, plus 2026 multi-device recommendations) is the dominant adtech-privacy instrument, alongside enforcement distinguishing GDPR-governed advertising processing from Article 82 tracker rules. Opt-out signals, clean rooms and direct marketing were not separately evidenced this cycle.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

CNIL's final recommendation on email tracking pixels, published 14 April 2026, set a hard compliance deadline: organisations were required to obtain explicit consent from existing subscribers, or stop tracking them, by 14 July 2026, with no transitional period at all for contacts collected from 14 April 2026 onward. As of the current cycle, that deadline has passed, meaning any organisation that had not obtained the required explicit consent by 14 July 2026 is now operating outside CNIL's stated compliance expectation for email-tracking-pixel use.

The absence of a transitional period for newly-collected contacts is a notably strict feature of the recommendation relative to typical phased-implementation approaches, since it applies the full consent requirement immediately to any contact acquired after the recommendation's publication date, even though the overall compliance deadline for existing subscribers extended a further three months. This recommendation reflects CNIL's continuing focus on granular consent mechanics in commercial email and tracking contexts, consistent with its broader 2026 enforcement-priority theme of information and transparency obligations.

Outlook

The key marker to watch is whether CNIL follows the passed 14 July 2026 deadline with enforcement action against organisations found not to have obtained the required consent, which would be the first concrete enforcement test of this specific recommendation.

#

Strong biometric and AI Act interface evidence; genetic-data-specific regime remains an evidenced gap.

Primary frameworkGDPR Art 9 + EU AI Act (Regulation (EU) 2024/1689) as applied via CNIL guidance
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong biometric and AI Act interface evidence; genetic-data-specific regime remains an evidenced gap.

Sub-modules (6)

Profiling RestrictionsAmber

CNIL and EU peer DPAs called for prohibiting AI systems categorising individuals by inferred protected characteristics (ethnicity, sex, political/sexual orientation).

Claims (1):

  • CLM-FR-a10025x1 (claim on file)

Automated Decision Making TransparencyAmber

EU AI Act transparency-risk obligations (chatbots, generative content) apply from 2 August 2026, layered on GDPR transparency duties.

Claims (1):

  • CLM-FR-a10026y2 (claim on file)

Ai Risk AssessmentsAmber

AI Act's four-tier risk classification (unacceptable/high/transparency/minimal) imposes conformity-assessment and risk-management duties on high-risk systems (Annex III), interfacing with but not replacing GDPR DPIA.

Claims (1):

  • CLM-FR-a10027z3 (claim on file)

Biometric RegimeGreen

CNIL has sanctioned scraped facial-recognition-database creation as unlawful Article 9 GDPR biometric processing, and excludes biometric-identification cameras from its general smart-camera guidance given the distinct, in-principle-prohibited regime.

Claims (2):

  • CLM-FR-a10028a4 (claim on file)
  • CLM-FR-a10029b5 (claim on file)

Genetic DataRed

No FR-specific genetic-data regime findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

Loi Informatique et Libertés remains the exclusive framework for penal-sphere and national-security/intelligence processing, carved out of GDPR's material scope.

Claims (1):

  • CLM-FR-a10030c6 (claim on file)
Category narrative41 words

CNIL actively enforces the Article 9 GDPR biometric special-category regime (sanctioning scraped facial-recognition databases) and is shaping the France/EU interface between GDPR and the EU AI Act, including risk-tiered obligations and profiling/biometric-categorisation restrictions. Genetic data was not separately evidenced this cycle.

no periodic updates on record for this sub-brief

#

Strong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.

Primary frameworkGDPR Art 8 + Loi Informatique et Libertés Art 45 + Loi SREN (2024)
Supervisory authorityCNIL
Traffic-light rationale — AmberStrong evidence on age of consent, parental consent and age-verification privacy safeguards; education-settings and dependent-adults sub-modules remain gaps.

Sub-modules (5)

Age VerificationAmber

Arcom must adopt a technical référentiel for pornography-site age verification under the SREN law; CNIL opined on the draft on 26 September 2024 and favours privacy-preserving, locally-generated proof-of-majority methods over facial recognition.

Claims (2):

  • CLM-FR-a10031d7 (claim on file)
  • CLM-FR-a10032e8 (claim on file)

Minor Profiling BansAmber

CNIL has translated GDPR's minors provisions into recommendations for stronger safeguards against default profiling of under-18 users.

Claims (1):

  • CLM-FR-a10034g0 (claim on file)

Education SettingsRed

No FR-specific education-settings DP findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No FR-specific dependent-adults/vulnerable-adult DP findings surfaced this cycle.

Absence provenance: unavailable. Searched: unavailable.

Category narrative49 words

France sets the digital age of consent at 15 (Article 45 LIL), requiring joint minor-plus-parent consent below that age. The SREN law and Arcom age-verification référentiel (subject to CNIL opinion) address pornography-site access, with CNIL favouring privacy-preserving verification methods. Education-settings and dependent-adults protections were not separately evidenced this cycle.

no periodic updates on record for this sub-brief

#

Very well evidenced, high-materiality enforcement activity across multiple 2025-2026 decisions plus recent 180-day developments.

Primary frameworkGDPR Arts 58, 77-84 + Loi Informatique et Libertés
Supervisory authorityCNIL
Traffic-light rationale — GreenVery well evidenced, high-materiality enforcement activity across multiple 2025-2026 decisions plus recent 180-day developments.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CNIL's restricted committee imposes fines, mises en demeure and injunctions with daily penalty payments (e.g., €5,000/day FRANCE TRAVAIL, €10,000/day IQVIA); public-sector security-breach fines are capped at €10m rather than turnover-based.

Claims (2):

  • CLM-FR-a10035h1 (claim on file)
  • CLM-FR-a10036i2 (claim on file)

Enforcement Activity IndexGreen

2025 total sanctions of €486,839,500; 2026 sanctions to date include Free Mobile/Free (€42m combined), FRANCE TRAVAIL (€5m), IQVIA (€5m) and NEXPUBLICA (€1.7m).

Claims (1):

  • CLM-FR-a10037j3 (claim on file)

Regulator Funding And CapacityAmber

CNIL processed 539 health-authorisation applications in 2025 alone, indicating substantial specialised operational capacity.

Claims (1):

  • CLM-FR-a10038k4 (claim on file)

Collective Redress And Class ActionsAmber

CNIL flagged the need to clarify collective-action ('action collective') conditions during the 2018 law-rewriting ordonnance process.

Claims (1):

  • CLM-FR-a10039l5 (claim on file)

Private Right Of ActionAmber

CNIL cannot award compensation; breach victims must pursue police complaints or civil courts for redress.

Claims (1):

  • CLM-FR-a10040m6 (claim on file)

Recent Developments 180DGreen

June 2026 G7 DPA meeting in Paris adopted a privacy-preserving age-verification declaration and children's-protection principles; EDPB adopted a common breach-notification template and generative-AI anonymisation/web-scraping and blockchain guidance.

Claims (2):

  • CLM-FR-a10041n7 (claim on file)
  • CLM-FR-a10042o8 (claim on file)
Category narrative63 words

CNIL enforcement is highly active: 2025 fines totalled €486,839,500 and 2026 has already seen €27m/€15m (Free Mobile/Free), €5m (FRANCE TRAVAIL), €5m (IQVIA) and €1.7m (NEXPUBLICA) sanctions, backed by daily-penalty injunction powers. Collective redress is flagged as needing clarification; individuals cannot obtain compensation directly from CNIL. Recent 180-day developments include the June 2026 G7 DPA meeting in Paris and EDPB breach-notification-template and AI/anonymisation guidance.

Periodic update · new data 2026-09-28

Enforcement & Redress

This cycle's enforcement activity in France is defined by the concurrence of at least three major CNIL fines: €42 million combined against FREE MOBILE and FREE (13 January 2026), €5 million against France Travail (22 January 2026), and €5 million against IQVIA Operations France (26 May 2026). Measured against CNIL's full historical enforcement record of 83 sanctions totalling approximately €486.8 million since GDPR's entry into force, these three 2026 actions together total roughly €52 million within a single reporting period, a concentration that exceeds typical historical annual norms and signals a structurally more aggressive enforcement posture rather than a one-off episodic spike.

CNIL has named information and transparency obligations as its 2026 enforcement-priority theme, mirroring the EDPB's designated focus theme for the year. This forward-looking signal suggests that the three fines already identified this cycle, which concern security measures and DPIA implementation rather than transparency specifically, may be followed by a distinct wave of transparency-focused enforcement action later in 2026, rather than representing the totality of CNIL's enforcement focus for the year.

Outlook

Whether CNIL's transparency-focused enforcement priority materialises into further sanctions in the second half of 2026, and whether the pace of large fines observed in January and May continues, are the two developments most likely to confirm or revise the assessment that CNIL's enforcement posture has structurally intensified.

No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct96.97
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for France
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s) (0 category placement(s)), 35 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 (CNIL primary decisions/guidance) coverage for regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, adtech_and_commercial_privacy (cookies), algorithmic_biometric_and_surveillance_governance (biometric/AI Act interface), children_and_vulnerable_groups (age of consent, age verification), and enforcement_and_redress (2025-2026 sanction wave). Partial/T3 coverage on data_subject_rights (portability and response windows unevidenced) and sectoral_watch (credit-scoring and education sub-modules unevidenced). cross_border_and_adequacy relies mainly on structural inference from France's EU membership plus one T1 anchor on health-data-warehouse authorisation; no direct T1/T2 evidence located on SCC/BCR uptake, TIA practice or a distinct national adequacy list this cycle. adtech opt-out signals, clean rooms and direct marketing, and children's education-settings/dependent-adults sub-modules carry explicit absent_field_provenance.

Unresolved questions (5):

  • Does France maintain any FR-specific SCC/BCR uptake statistics or supplementary transfer guidance beyond the EU-wide GDPR Chapter V regime?
  • What is the exact publication/entry-into-force date of the Arcom age-verification référentiel following the CNIL's September 2024 opinion, and has it been finalised as of mid-2026?
  • Is there FR-specific sectoral guidance on credit-scoring or education-sector personal data processing that was not surfaced by this cycle's searches?
  • What FR-specific genetic-data processing rules, if any, supplement GDPR Article 9 beyond the health-data-warehouse authorisation regime?
  • What is the current status of France's collective-redress ('action collective') mechanism for data-protection claims following the 2018 ordonnance's flagged clarification need?

Escalate to primary-source review: yes