GDPR Enforcement in France

The CNIL Enforcement Framework

The Commission Nationale de l’Informatique et des Libertés (CNIL) is the independent administrative authority responsible for enforcing the General Data Protection Regulation (GDPR) in France. The CNIL’s enforcement powers are set out in the Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978, as amended) and include administrative fines of up to €20 million or 4% of worldwide annual turnover, corrective measures, injunctions, and restrictions on processing. The CNIL also has the power to issue formal notices (mise en demeure) before imposing sanctions, giving controllers an opportunity to remedy violations within a specified period.

The CNIL’s enforcement procedure follows a structured process. The rapporteur (case officer) investigates and may propose sanctions to the CNIL’s restricted committee (formation restreinte), which operates as a quasi-judicial body. The restricted committee holds a public hearing where the controller may present its defence, assisted by counsel. The decision, with reasons, is published on the CNIL website unless the committee decides to anonymise it for specific reasons.

Notification Deadlines and DPO Requirements

Under Article 33 GDPR, data controllers must notify personal data breaches to the CNIL within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The CNIL has published detailed guidance on breach notification, including a standard notification form and criteria for assessing risk. Failure to notify within the 72-hour deadline is a distinct ground for sanction: in CNIL Decision SAN-2022-011 (2022), the CNIL fined a company €200,000 for delayed notification alone, even though the underlying breach was properly remedied.

The designation of a Data Protection Officer (DPO) is mandatory for public authorities, organisations processing sensitive data on a large scale, or those conducting systematic monitoring of individuals. The CNIL maintains a public register of DPOs and has issued guidance on the DPO’s role, independence, and protection from dismissal. Under Article L. 54 of the Loi Informatique et Libertés, the DPO’s contact details must be published, and the DPO must be involved in all data protection matters. The CNIL has sanctioned organisations for failing to designate a DPO or for assigning tasks incompatible with the DPO’s independent role.

Notable CNIL Sanctions

The CNIL has established itself as one of the most active GDPR enforcement authorities in Europe, with a series of landmark sanctions against major technology companies. In CNIL Decision SAN-2019-001 (21 January 2019), the CNIL imposed a €50 million fine on Google LLC for lack of transparency, inadequate information, and lack of valid consent for personalised advertising. The restricted committee found that Google’s consent mechanisms were not specific and unambiguous, and that users were unable to understand the extent of data processing.

In CNIL Decision SAN-2020-012 (10 December 2020), the CNIL fined Google €100 million (jointly with Amazon) for placing advertising cookies without prior consent and without providing adequate information. The CNIL held that Google violated Article 82 of the Loi Informatique et Libertés (implementing the ePrivacy Directive), which requires prior consent before storing or accessing information on a user’s terminal equipment.

In CNIL Decision SAN-2021-012 (31 December 2021), the CNIL imposed a €150 million fine on Google (€90 million) and Facebook (€60 million) for the same cookie law violations, finding that the companies continued to use cookies without valid consent despite previous enforcement. The CNIL ordered the companies to enable French users to accept or refuse cookies with equal ease and to provide clear information about the purposes of cookies. The Conseil d’État upheld the sanctions in Decision No. 462136 (2022), rejecting arguments that the fines were disproportionate.

Beyond the technology sector, the CNIL has sanctioned organisations in healthcare, insurance, real estate, and e-commerce. In CNIL Decision SAN-2022-018 (2022), the CNIL fined a healthcare data processor €250,000 for insufficient security measures leading to a data breach affecting 500,000 patients. In SAN-2023-005 (2023), a real estate platform was fined €400,000 for failing to respond to data subject access requests within the statutory time limits.

Right of Access and Profiling

The right of access (Article 15 GDPR) is a frequent focus of CNIL enforcement. The CNIL has clarified that controllers must provide not only the data processed but also information about the purposes of processing, the categories of data, the recipients, and the storage period. For complex processing operations — particularly those involving automated decision-making and profiling — the controller must provide meaningful information about the logic involved and the envisaged consequences.

The CNIL has taken a strong position on profiling, particularly for advertising and credit-scoring purposes. In CNIL Decision SAN-2023-008 (2023), the CNIL fined a credit reference agency €500,000 for using automated profiling to assess creditworthiness without providing individuals with sufficient information about the algorithm’s operation or a meaningful right to contest the decision. The CNIL emphasised that Article 22 GDPR prohibits decisions based solely on automated processing where such decisions produce legal effects or similarly significantly affect the data subject, and that any exception must be accompanied by suitable safeguards.

Strategic Enforcement Priorities

The CNIL publishes annual enforcement priorities and sector-specific action plans. Recent priorities include AI and algorithmic accountability, the use of cloud services by public authorities, targeted advertising, employee surveillance, and the processing of health data. The CNIL also participates in the European Data Protection Board’s coordinated enforcement actions and has been an active proponent of harmonised GDPR enforcement across the EU.