EnglishFrançais
France flag

France

GDPR in France: the Informatique et Libertés Law, the CNIL, and Your Rights

By Recording Law Editorial Team9 min read

Frequently Asked Questions

Are the GDPR and the loi Informatique et Libertes the same thing?

No, but they work together. The GDPR is the European regulation that applies directly in every member state. The loi n° 78-17 du 6 janvier 1978, the loi Informatique et Libertes, is the French text that implements the GDPR at the national level, specifies certain rules left to the member states, and designates the CNIL as the supervisory authority. To understand the content of the regulation itself, see our overview of the European data protection laws.

Can the CNIL compensate me if my data was misused?

No. This is the most widespread misconception. The CNIL can inspect an organisation, issue a formal notice, order compliance, and impose an administrative fine, but that fine is paid to the State, not to you. To obtain compensation for harm, you must bring a separate action before the civil court, on the basis of Article 82 of the GDPR and civil liability. The CNIL complaint and the action for damages are two separate steps that can be pursued in parallel.

How much can a CNIL fine cost a company?

The GDPR sets two levels. For the most serious breaches, such as violating the basic principles or the rights of individuals, the fine can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher. For lower-level breaches, the ceiling is 10 million euros or 2 percent of worldwide turnover. The CNIL adjusts the amount according to the seriousness, duration, and intentional character of the breach.

How do I exercise my rights over my personal data in France?

First send your request to the organisation that holds your data, stating the right invoked, for example access, rectification, erasure, or objection. The organisation has in principle one month to reply. If you do not get a satisfactory response, you can turn to the CNIL with a free online complaint. The data protection officer, where one exists, is your point of contact within the organisation.

What did the CNIL change in 2025 for artificial intelligence?

The CNIL published on 22 July 2025 its final recommendations on the development of artificial intelligence systems in compliance with the GDPR, following a public consultation and fact sheets released in June 2025. It sets out, in particular, the conditions for relying on the legitimate-interest legal basis and the safeguards to put in place when data is collected through moissonnage, or web scraping. These texts do not amend the law but indicate how the CNIL will oversee these practices.

Sources and References

  1. Loi n° 78-17 du 6 janvier 1978 on data processing, files, and freedoms (Legifrance)(legifrance.gouv.fr).gov
  2. CNIL - The General Data Protection Regulation (GDPR)(cnil.fr).gov
  3. CNIL - The sanctions issued by the CNIL(cnil.fr).gov
  4. CNIL - Filing a complaint(cnil.fr).gov
  5. CNIL - Development of AI systems: the recommendations for complying with the GDPR (22 July 2025)(cnil.fr).gov
  6. CNIL - Legitimate interest: focus on data collection through web scraping (moissonnage)(cnil.fr).gov
  7. Loi n° 2024-449 du 21 mai 2024 aimed at securing and regulating the digital space (Legifrance)(legifrance.gouv.fr).gov
  8. CNIL - The loi SREN entrusts new missions to the CNIL(cnil.fr).gov
  9. Service-Public.gouv.fr - Protection of personal data(service-public.gouv.fr).gov
Share: