Law No. 2014-038, rights of data subjects
Loi n° 2014-038, arts. 3, 22-27 (droits des personnes)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 9 January 2015.
A data subject rights rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Do not base a judicial decision assessing a person's conduct on automated profiling at all, and do not base an administrative or private decision assessing a person's conduct solely on automated profiling.
- Honour a data subject's request, made on a legitimate ground and free of charge, to object to processing of their data, and stop processing for prospecting purposes as soon as they object to it, without requiring a reason.
- Answer a request for access free of charge and without delay, giving the purposes, the data categories, the recipients, the data itself and its origin, and enough information to understand and contest any automated decision-making logic behind a decision that has legal effects.
- Rectify, complete, update, block, or erase inaccurate, incomplete, outdated, or unlawfully held data on request, free of charge, and tell any third party the data were disclosed to of the change.
- Tell a person, when you collect their personal data, who you are, the purpose of the processing, whether the information is mandatory or optional, the data categories, the recipients, their rights of objection, access, and rectification, and any transfer and its safeguards, and give the same notice, including how to object, before storing or reading information on their communications-terminal equipment.
What it reaches
Obligation class
Data subject rights, Disclosure, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 bars a judicial decision assessing a person's conduct from resting at all on automated data processing meant to profile the person or assess aspects of their personality, and bars an administrative or private decision assessing a person's conduct from resting solely on that kind of automated processing.
Article 22 gives a person with a legitimate reason the right to object at any time and free of charge to processing of personal data concerning them, gives an unqualified right to object to processing for prospecting purposes, and lets the CMIL judge a disputed reason's legitimacy, though the right does not apply where the processing meets a legal obligation or where the act authorizing the processing has expressly excluded it.
Article 23 gives every person the right to know whether they are concerned by a processing operation and, on proof of identity, to obtain the purposes, the categories of data processed, the recipients, the data itself in an intelligible form and its origin, and enough information to understand and contest automated logic behind a decision with legal effects, free of charge and without delay, and, for health data, directly or through a doctor the person designates; these access rights do not apply to processing concerning public security or the detection and prosecution of offenses, which article 26 governs instead.
Article 24 lets the controller refuse a manifestly abusive request, judged by its number or its repetitive or systematic character, with the burden of proving abuse on the controller who received it.
Article 25 gives a person the right to have inaccurate, incomplete, ambiguous, outdated, or unlawfully held, used, disclosed, or retained data rectified, completed, updated, blocked, or erased free of charge, and requires the controller to notify any third party the data were disclosed to of the changes made.
Article 26 substitutes an indirect procedure through a CMIL member drawn from the judiciary for the ordinary access and rectification rights where the processing concerns State security, defense, or public security.
Article 27 requires the controller to make sure the person data are collected from is told the controller's identity, the purpose of the processing, whether supplying the information is mandatory or optional, the data categories, the recipients, the rights of objection, access, and rectification and how to exercise them, and, where relevant, the transfers made and their article 20 safeguards, and requires equivalent clear notice, including the means to object, before storing or reading information on a user's terminal equipment for electronic communications, unless that access serves only to carry the communication or is strictly necessary for a service the user expressly requested; where data were not collected from the person, the same information is due when the data are recorded or, if disclosure to a third party is planned, by the first such disclosure at the latest.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisions
Read the law
Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)
not an official government-published copy
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.