GDPR for France
GDPR compliance for companies operating in France — CNIL enforcement, cookie consent requirements, and France-specific data protection rules.
Data Protection Authority
Commission Nationale de l'Informatique et des Libertés (CNIL)
Key Requirements
- →CNIL is one of the most active GDPR enforcement authorities in the EU
- →France requires explicit cookie consent — CNIL has fined major platforms for dark patterns
- →French Labour Code restricts employee monitoring more than GDPR alone
- →Loi Informatique et Libertés supplements GDPR with French-specific rules
The CNIL (Commission Nationale de l'Informatique et des Libertés) is one of the most active data protection authorities in the EU, particularly around cookie consent and algorithmic profiling. France supplements GDPR with the Loi Informatique et Libertés, which dates back to 1978 and includes provisions GDPR doesn't cover.
CNIL has issued significant fines and enforcement orders against Google, Facebook, Apple, and numerous other companies for cookie consent violations. The CNIL's position is clear: analytics cookies require explicit, freely given, specific, and informed consent before they're set. Pre-checked boxes, bundled consent, and consent walls (blocking access unless cookies are accepted) are all prohibited.
The CNIL published a cookie consent recommendation in 2020 that remains the de facto standard for cookie banners in France: users must be able to refuse with the same ease as accepting (equal reject button at the top level), consent cannot be implied from scrolling or continued browsing, and consent must be renewed at least every 13 months.
Employee monitoring in France is governed by both GDPR and the French Labour Code. Employers must inform employees before implementing any monitoring system and consult with employee representatives. Email monitoring, keyloggers, and GPS tracking are particularly restricted — even when disclosed, they must be proportionate and have a documented legitimate purpose.
For international data transfers, France follows EU GDPR standard contractual clauses (SCCs). The CNIL has published additional guidance on transfer impact assessments (TIAs) that goes beyond the EDPB's baseline requirements.
Check your GDPR compliance now
Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.
Run free GDPR compliance check →