Law note · France
CNIL Enforcement, GDPR Article 83 and Code Penal Articles 226-16 to 226-22-2
The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.
France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; this session could not resolve a working Legifrance URL for the codified text of these articles, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.
GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims was not independently confirmed this session and is not asserted here beyond the Article 82 baseline.
What it asks of an app
- Expect the CNIL to have General Data Protection Regulation (GDPR) Article 83 fining power, plus France's own criminal-offense exposure under Code penal Articles 226-16 to 226-22-2 for unlawful processing.
- Expect any person in France who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice
Primary source: CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (direct fetch, regulator commentary)
GDPR Art. 83