Rights
The GDPR applied through the loi Informatique et Libertés, policed by the CNIL
France applies the GDPR alongside its pioneering 1978 Data Protection Act. The CNIL, the world's oldest data-protection regulator, supervises compliance and issues some of Europe's largest fines.
Key rules
- The GDPR is directly applicable; the loi Informatique et Libertés fills national margins.
- The CNIL can impose fines up to 4% of worldwide turnover.
- Specific French rules govern health data and the numéro de sécurité sociale.
Governing law
- Règlement général sur la protection des données (RGPD) (2016)
- Loi Informatique et Libertés (1978)
Penalties and consequences
- Administrative fines up to EUR 20m or 4% of global turnover
- Formal notices and processing bans
In practice
The CNIL has led enforcement on cookies and advertising identifiers, so consent banners are a frequent audit target.