Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces biometrique
stage In effect
since 2019-01-10
source CNIL, Deliberation n. 2019-001 du 10 janvier 2019 (PDF, direct fetch)
CNIL's binding standard regulation for workplace biometric access control (English: Standard Regulation on the Implementation of Biometric Access-Control Devices) replaces the prior authorization regime with an accountability model: the controller must justify necessity and proportionality, run a data protection impact assessment before deployment, and document why a less intrusive alternative was rejected.
A companion CNIL page states the standard regulation's definition of biometrics names fingerprints, iris, facial recognition, gait, and voice as covered modalities, though CNIL's own worked operational guidance emphasizes the physical modalities and carries no voice-specific worked example.
CNIL guidance states that employee consent alone is not a valid legal basis for a workplace biometric system, since workplace hierarchy undermines the General Data Protection Regulation (GDPR)'s freely-given requirement; the employer must rely on a legal obligation or legitimate-interest basis instead, or offer a genuinely equivalent non-biometric alternative where consent is used.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify the CNIL within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms. This session found no France-specific derogation from the General Data Protection Regulation (GDPR) timeline or threshold; treat this as the GDPR-uniform baseline rather than an independently confirmed French addition.
What it asks of an app →
Comprehensive regime
cite Loi n. 78-17 du 6 janvier 1978 relative a l'informatique, aux fichiers et aux libertes, as amended (JORFTEXT000000886460)
stage In effect
since 2018-05-25
source Legifrance, consolidated text (direct fetch)
France gives the General Data Protection Regulation (GDPR) domestic effect through the Loi Informatique et Libertes (Law on Information Technology, Data Files and Civil Liberties), enacted 6 January 1978 and amended for GDPR alignment. Article 6 cross-references Regulation (EU) 2016/679 for the special-category exceptions, Article 8 gives the CNIL authority to prescribe measures for biometric-data processing, and Article 19 sets the CNIL's on-site inspection powers, all confirmed by a direct fetch of the consolidated text. Lawful bases follow the GDPR Article 6 list, with no French derogation identified in this pass.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. A CNIL guidance page confirmed by direct fetch lists exactly this toolkit, plus administrative arrangements for public-authority exchanges requiring CNIL authorization, and names no France-specific localization mandate beyond it.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Individuals in France have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless a contract, explicit consent, or an EU or French law exception applies. The CNIL enforces this alongside the general General Data Protection Regulation (GDPR) Articles 12-23 rights of access, rectification, erasure, restriction, portability, and objection.
What it asks of an app →
cite Loi n. 78-17 du 6 janvier 1978, Art. 47
stage In effect
since 1978-01-06
source Legifrance, consolidated text (direct fetch, promulgation date only
Loi 78-17 Article 47 extends an automated-decision explicability duty specifically to French government decisions, beyond General Data Protection Regulation (GDPR) Article 22's own scope. This session did not independently read Article 47's text; a direct fetch of the law's landing page did not surface it before truncating, and a follow-up attempt at the article-level page was met with a CAPTCHA, a full stop under crawling rules, not something to solve.
No date specific to Article 47's own insertion or last amendment could be established. The date recorded here is Loi n. 78-17's own promulgation date, 6 January 1978, confirmed by direct fetch of the consolidated text elsewhere in this document; it is the parent Act's promulgation date, not a confirmed commencement date for Article 47 itself, which almost certainly postdates it given the article's subject matter.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Art. 83; Code penal, Arts. 226-16 to 226-22-2
stage In effect
since 2018-05-25
source CNIL, "La loi Informatique et Libertes" and "Les sanctions penales" (direct fetch, regulator commentary)
The CNIL is France's supervisory authority, sanctioning through a formation restreinte or, under a simplified procedure, its president, up to the General Data Protection Regulation (GDPR) Article 83 ceiling.
France separately criminalizes unlawful processing in Code penal Articles 226-16 through 226-22-2 (five years' imprisonment and up to EUR 300,000 for the primary offenses), per CNIL's own regulator commentary; this session could not resolve a working Legifrance URL for the codified text of these articles, so the criminal-offense detail rests on CNIL's commentary rather than a direct statute read.
GDPR Article 82 arms an individual with a direct private right of action; France's own collective "action de groupe" mechanism for data-protection claims was not independently confirmed this session and is not asserted here beyond the Article 82 baseline.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; Loi n. 78-17, Art. 6
stage In effect
since 2018-05-25
source Legifrance, consolidated text, Loi 78-17 Art. 6 (direct fetch)
General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category of personal data. Loi 78-17 Article 6 restates this special-category list with a cross-reference to the Regulation rather than a separate French list, confirmed by a direct fetch of the consolidated Legifrance text. No general publicly-available carve-out narrows this coverage in France; only Article 9(2)(e)'s narrow self-disclosure exception applies.
What it asks of an app →