Law note · France

CNIL Enforcement, GDPR Article 83 and Code Penal Articles 226-16 to 226-22-2

cite Regulation (EU) 2016/679, Art. 83; Code penal, Arts. 226-16 to 226-22-2 stage In effect since 2018-05-25 reviewed 2026-08-24

The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.

France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; this session could not resolve a working Legifrance URL for the codified text of these articles, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.

GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims was not independently confirmed this session and is not asserted here beyond the Article 82 baseline.

What it asks of an app

  • Expect the CNIL to have General Data Protection Regulation (GDPR) Article 83 fining power, plus France's own criminal-offense exposure under Code penal Articles 226-16 to 226-22-2 for unlawful processing.
  • Expect any person in France who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice

Primary source: CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (direct fetch, regulator commentary)
GDPR Art. 83

← Back to the example  ·  Lint your app →