GDPR in France: the Informatique et Libertés Law, the CNIL, and Your Rights
The idea that the GDPR is a purely European regulation, disconnected from French law, is misleading. In France, the protection of donnees personnelles (personal data) rests on an old and robust national statute: the loi n° 78-17 du 6 janvier 1978, known as the loi Informatique et Libertes (the Data Protection Act), which was deeply overhauled in 2018 and 2019 to incorporate the General Data Protection Regulation. It is this French law, and not the European regulation alone, that organises oversight, sanctions, and the concrete exercise of rights on French territory.
This page presents the French application of the GDPR: the role of the Commission nationale de l'informatique et des libertes, the CNIL, how a person exercises their rights and files a complaint, and the recent French developments of 2024 and 2025. For the content of the European regulation itself, its definitions, principles, and legal bases, see our overview of data protection laws around the world, so as to avoid repetition.
Information last verified on 22 July 2026. This page presents general legal information, not legal advice.
The loi Informatique et Libertes: the GDPR applied in France
The loi n° 78-17 du 6 janvier 1978 is one of the oldest data protection laws in the world. It created the CNIL and lays down the principle that information technology must remain in the service of every citizen and must not infringe on human identity, human rights, or private life.
Since the GDPR took effect on 25 May 2018, the law has been rewritten to serve as the national implementing text. It specifies the points that the regulation leaves to each member state's discretion, for example the age of consent for minors, the regime for certain sensitive processing operations, or processing relating to State security.
In practice, a data controller established in France must comply with both the GDPR and the loi 78-17. The two texts are read together: the regulation sets the common European framework, and the French law ensures its implementation and entrusts oversight to the CNIL.
The CNIL: a supervisory authority, not a court
The CNIL is the independent administrative authority responsible for ensuring compliance with the rules. It informs individuals and professionals, investigates complaints, conducts checks on documents and on site, and holds a power of sanction exercised by a restricted committee (formation restreinte).
It is important to understand what the CNIL can and cannot do. It can issue a warning, a formal notice to bring processing into compliance, an injunction subject to a periodic penalty payment, a restriction or a ban on processing, and an administrative fine. These measures aim to correct the organisation's conduct and to protect all the people concerned.
By contrast, the CNIL does not settle a dispute between two private parties and awards no individual compensation. This is the point most often misunderstood. A fine issued by the CNIL is paid to the Tresor public, that is to say to the State, and not to the person who suffered the breach.
The ceilings are high. For the most serious breaches, the fine can reach 20 million euros or 4 percent of the company's annual worldwide turnover, whichever is higher. For lower-level breaches, the ceiling is 10 million euros or 2 percent of worldwide turnover. As an order of magnitude, the total amount of the public sanctions issued by the CNIL in 2025 came to several hundred million euros across all subjects combined, which covers very varied areas and not surveillance alone.
Obtaining compensation: the role of the civil court
If a GDPR breach has caused you harm, whether material or moral, the path to compensation is not the CNIL but the civil courts. Article 82 of the GDPR gives every person the right to obtain compensation from the controller or processor for the damage suffered.
Two logics must therefore be distinguished. A complaint to the CNIL aims to stop and sanction a breach in the general interest. An action before the civil court aims to repair your personal harm through damages. The two steps are independent and can be pursued in parallel.
A CNIL sanction decision can, moreover, serve as supporting evidence for a civil action, since it publicly establishes the existence of the breach, but it does not replace bringing the matter before the court. This is an essential distinction to keep in mind before starting any step.
Exercising your rights and filing a complaint
The GDPR and the loi 78-17 recognise for everyone a set of rights: the right of access, the right to rectification, the right to erasure, the right to object, the right to restriction of processing, and, in certain cases, the right to data portability.
The first step is always to contact the organisation concerned directly. The request can be made by post or electronically, clearly stating the right being invoked. The organisation must in principle reply within one month. Where a data protection officer has been appointed, they are your preferred point of contact.
If the organisation does not reply or refuses without valid grounds, you can turn to the CNIL. The complaint is filed online, free of charge, through the dedicated service on the CNIL website. Our guide on the complaint to the CNIL details the procedure step by step and the documents to attach.
Recent French developments: 2024 and 2025
Two developments mark the recent period. First, the loi n° 2024-449 du 21 mai 2024 aimed at securing and regulating the digital space, known as the loi SREN, broadened the CNIL's missions and placed it within a regulatory ecosystem aligned with the European regulations on digital services and digital markets. The CNIL is notably given a role in data altruism and online age verification.
Second, the CNIL has made artificial intelligence a priority. After an initial set of recommendations and a public consultation, it published on 22 July 2025 its final recommendations on the development of artificial intelligence systems in compliance with the GDPR. It sets out the conditions for relying on the legitimate-interest legal basis and, in particular, the safeguards to put in place when training data is collected through moissonnage, or web scraping.
These texts do not create a new law but clarify how the CNIL will apply the existing framework to AI processing. For businesses and individuals alike, they indicate the points on which oversight will focus. Workplace surveillance, video, and geolocation also remain priority subjects: see our page on employee monitoring and on video surveillance.
For an overview of the French framework, our France privacy law hub gathers the resources on data protection, the CNIL, and individuals' rights.
Frequently Asked Questions
Are the GDPR and the loi Informatique et Libertes the same thing?
No, but they work together. The GDPR is the European regulation that applies directly in every member state. The loi n° 78-17 du 6 janvier 1978, the loi Informatique et Libertes, is the French text that implements the GDPR at the national level, specifies certain rules left to the member states, and designates the CNIL as the supervisory authority. To understand the content of the regulation itself, see our overview of the European data protection laws.
Can the CNIL compensate me if my data was misused?
No. This is the most widespread misconception. The CNIL can inspect an organisation, issue a formal notice, order compliance, and impose an administrative fine, but that fine is paid to the State, not to you. To obtain compensation for harm, you must bring a separate action before the civil court, on the basis of Article 82 of the GDPR and civil liability. The CNIL complaint and the action for damages are two separate steps that can be pursued in parallel.
How much can a CNIL fine cost a company?
The GDPR sets two levels. For the most serious breaches, such as violating the basic principles or the rights of individuals, the fine can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher. For lower-level breaches, the ceiling is 10 million euros or 2 percent of worldwide turnover. The CNIL adjusts the amount according to the seriousness, duration, and intentional character of the breach.
How do I exercise my rights over my personal data in France?
First send your request to the organisation that holds your data, stating the right invoked, for example access, rectification, erasure, or objection. The organisation has in principle one month to reply. If you do not get a satisfactory response, you can turn to the CNIL with a free online complaint. The data protection officer, where one exists, is your point of contact within the organisation.
What did the CNIL change in 2025 for artificial intelligence?
The CNIL published on 22 July 2025 its final recommendations on the development of artificial intelligence systems in compliance with the GDPR, following a public consultation and fact sheets released in June 2025. It sets out, in particular, the conditions for relying on the legitimate-interest legal basis and the safeguards to put in place when data is collected through moissonnage, or web scraping. These texts do not amend the law but indicate how the CNIL will oversee these practices.
Sources and References
- Loi n° 78-17 du 6 janvier 1978 on data processing, files, and freedoms (Legifrance)(legifrance.gouv.fr).gov
- CNIL - The General Data Protection Regulation (GDPR)(cnil.fr).gov
- CNIL - The sanctions issued by the CNIL(cnil.fr).gov
- CNIL - Filing a complaint(cnil.fr).gov
- CNIL - Development of AI systems: the recommendations for complying with the GDPR (22 July 2025)(cnil.fr).gov
- CNIL - Legitimate interest: focus on data collection through web scraping (moissonnage)(cnil.fr).gov
- Loi n° 2024-449 du 21 mai 2024 aimed at securing and regulating the digital space (Legifrance)(legifrance.gouv.fr).gov
- CNIL - The loi SREN entrusts new missions to the CNIL(cnil.fr).gov
- Service-Public.gouv.fr - Protection of personal data(service-public.gouv.fr).gov