DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇫🇷 France Data Privacy Laws

The CNIL is the most consequential regulator in Europe for advertisers because it enforces cookies under national law, outside the one-stop-shop. That is how Google took EUR 150M and Meta EUR 60M in cookie fines, and how Criteo, an adtech company, took EUR 40M in 2023. If a French user can see your banner, assume the CNIL can reach you directly.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
GDPR + Loi Informatique et Libertés (1978, as amended)
Year
2018
Authority
CNIL
Marketing consent
GDPR legal basis plus the CNIL's cookie doctrine, under which refusing must be as easy as accepting.
Transfers
GDPR Chapter V.
Penalties
Up to EUR 20M or 4% of global turnover; separate national cookie fines.

The GDPR baseline

As an EU member state, this jurisdiction applies the General Data Protection Regulation directly: every use of personal data needs one of six legal bases, individuals hold rights to access, correct, delete and port their data, breaches are reportable within 72 hours, and fines reach EUR 20M or 4% of global turnover. Layered on top, the ePrivacy Directive's national implementation requires prior consent for cookies and similar tracking, with electronic marketing on an opt-in basis softened only by the existing-customer exception.

For advertisers that means the EU standard playbook applies here in full: consent before tracking and behavioral targeting, a compliant consent platform, documented transfer mechanics for any non-EU stack, and one eye on the Digital Omnibus negotiations, which could amend the cookie rules once a final text is adopted. The national details below are what this member state adds or emphasizes.

The national layer

The national implementing act is the Loi Informatique et Libertés (1978, as amended), and day-to-day supervision belongs to the CNIL. The CNIL is the most consequential regulator in Europe for advertisers because it enforces cookies under national law, outside the one-stop-shop. That is how Google took EUR 150M and Meta EUR 60M in cookie fines, and how Criteo, an adtech company, took EUR 40M in 2023. If a French user can see your banner, assume the CNIL can reach you directly.

Key instruments

Loi Informatique et Libertés, Article 82 (cookies)

1978, amended · In force

Implements the ePrivacy cookie rule in national law. Because ePrivacy sits outside the GDPR one-stop-shop, the CNIL fines foreign platforms directly for cookie violations affecting French users, without routing through a lead authority.

Official source →

Marketing and advertising

GDPR legal basis plus the CNIL's cookie doctrine, under which refusing must be as easy as accepting. Treat the consent note above as the planning rule; the penalty line below is what mispricing it costs.

For media buyers, reject buttons must be one click, cookie walls are tolerated only with a real alternative, and dark patterns in consent flows are an enforcement priority. The CNIL publishes recurring cookie sweep results and has sanctioned publishers, retailers and platforms alike.

Cross-border transfers

GDPR Chapter V applies in full, so personal data leaves the EEA only under an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, with a transfer impact assessment expected where the destination has surveillance-law exposure. The mechanics are identical across the bloc, so a transfer stack built for one member state travels to all of them.

Enforcement and penalties

The GDPR's ceiling applies, with fines up to EUR 20M or 4% of global annual turnover, whichever is higher, levied by the national supervisory authority, and the EDPB can force a harder line through the dispute mechanism. Member states share the ceiling and differ in enforcement appetite.

Primary sources

Cite this page: "France Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/france.html. Accessed [date].