Law / France

France

privacy

France's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties, Loi n. 78-17 du 6 janvier 1978).

France adds its own Code penal criminal-offense regime for unlawful processing, the CNIL's own administrative sanctioning procedure, and the most developed biometric-authorization framework surveyed in this wave: a binding standard regulation for workplace biometric access control and a facial-recognition policy position.

WebSearch was exhausted before this jurisdiction's research began; every finding rests on WebFetch against Legifrance and CNIL pages, and a specific named CNIL biometric enforcement decision (for example, its Clearview AI matter) could not be verified against a fetched source this session.

18 instruments named 8 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)

cite CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces biometrique stage In effect since 2019-01-10 source CNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF, direct fetch)

CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.

A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.

CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify the CNIL within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms. This session found no France-specific derogation from the General Data Protection Regulation (GDPR) timeline or threshold; treat this as the GDPR-uniform baseline rather than an independently confirmed French addition.

What it asks of an app

Comprehensive regime

Loi Informatique et Libertes, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act)

cite Loi n. 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, as amended (JORFTEXT000000886460) stage In effect since 2018-05-25 source Legifrance, consolidated text (direct fetch)

France gives the General Data Protection Regulation (GDPR) domestic effect through the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties), enacted 6 January 1978 and amended for GDPR alignment. Article 6 cross-references Regulation (EU) 2016/679 for the special-category exceptions, Article 8 gives the CNIL authority to prescribe measures for biometric-data processing, and Article 19 sets the CNIL's on-site inspection powers, all confirmed by a direct fetch of the consolidated text. Lawful bases follow the GDPR Article 6 list, with no French derogation identified in this pass.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. A CNIL guidance page confirmed by direct fetch lists exactly this toolkit, plus administrative arrangements for public-authority exchanges requiring CNIL authorization, and names no France-specific localization mandate beyond it.

What it asks of an app

Data subject rights

GDPR Article 22, Right Against Automated Individual Decision-Making

cite Regulation (EU) 2016/679, Art. 22 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Individuals in France have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless a contract, explicit consent, or an EU or French law exception applies. The CNIL enforces this alongside the general General Data Protection Regulation (GDPR) Articles 12-23 rights of access, rectification, erasure, restriction, portability, and objection.

What it asks of an app

Loi 78-17 Article 47, Automated Administrative Decisions

cite Loi n. 78-17 du 6 janvier 1978, Art. 47 stage In effect since 1978-01-06 source Legifrance, consolidated text (direct fetch, promulgation date only

Loi 78-17 Article 47 extends an automated-decision explicability duty specifically to French government decisions, beyond General Data Protection Regulation (GDPR) Article 22's own scope. This session did not independently read Article 47's text; a direct fetch of the law's landing page did not surface it before truncating, and a follow-up attempt at the article-level page was met with a CAPTCHA, a full stop under crawling rules, not something to solve.

No date specific to Article 47's own insertion or last amendment could be established. The date recorded here is Loi n. 78-17's own promulgation date, 6 January 1978, confirmed by direct fetch of the consolidated text elsewhere in this document; it is the parent Act's promulgation date, not a confirmed commencement date for Article 47 itself, which almost certainly postdates it given the article's subject matter.

What it asks of an app

Enforcement supervision

CNIL Enforcement, GDPR Article 83 and Code Penal Articles 226-16 to 226-22-2

cite Regulation (EU) 2016/679, Art. 83; Code penal, Arts. 226-16 to 226-22-2 stage In effect since 2018-05-25 source CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (direct fetch, regulator commentary)

The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.

France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; this session could not resolve a working Legifrance URL for the codified text of these articles, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.

GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims was not independently confirmed this session and is not asserted here beyond the Article 82 baseline.

What it asks of an app

Sensitive categories

GDPR Article 9 Special Categories, as Implemented by Loi 78-17 Article 6

cite Regulation (EU) 2016/679, Art. 9; Loi n. 78-17, Art. 6 stage In effect since 2018-05-25 source Legifrance, consolidated text, Loi 78-17 Art. 6 (direct fetch)

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category of personal data. Loi 78-17 Article 6 restates this special-category list with a cross-reference to the Regulation rather than a separate French list, confirmed by a direct fetch of the consolidated Legifrance text. No general publicly-available carve-out narrows this coverage in France; only Article 9(2)(e)'s narrow self-disclosure exception applies.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.