













Data breaches expose personal data at a massive scale. In the second quarter of 2025 alone, nearly 94 million data records were leaked, impacting millions of individuals worldwide.
As these risks grow, governments have introduced stricter data protection laws to hold organisations accountable. In France, the Commission nationale de l’informatique et des libertés (CNIL) plays this role.
In this post, we explain what CNIL is, its mission and the best practices organisations can follow to stay compliant.
CNIL is France’s independent data protection authority. While based in France, CNIL’s authority is not limited to organisations established there; its requirements can also apply to any organisation that offers goods or services to individuals in France or processes their personal data.
In 1970, the French government proposed a project called SAFARI that linked government records with unique identification numbers for each citizen. There was a widespread public concern about the use of technology to collect personal information.
In response, an independent commission studied the issue and created CNIL in 1978 to help protect personal data and individual rights.
CNIL France has four core missions.
These include making people aware about data protection rights, foreseeing risks, offering support to businesses and enforcing regulations.
Many people don’t know how their personal information is stored or shared online. CNIL provides resources that make data protection easier to understand. It also gives individuals a way to report privacy concerns and can step in when organisations fail to respect their obligations.
For businesses, privacy rules can sometimes be difficult to interpret. CNIL helps organisations simplify this by offering practical guidance and toolkit on topics like data collection, consent and security. This way, organisations are able to include privacy considerations into their operations while also being innovative and developing products and services to meet business needs.
Technology changes quickly, and privacy challenges often emerge before clear rules are set. CNIL monitors and studies the new technologies and trends around personal data collection.
It also encourages organisations to treat privacy as a priority in their design process, and not as an afterthought.
CNIL also regularly engages with researchers, startups and other stakeholders. It does this to examine questions and debate around data innovation, privacy and public trust. For example, CNIL has created Phantom, a mobile application to help teenagers better understand and protect the personal information they share on social media platforms.
CNIL has the power to investigate organisations that don’t comply with data protection laws. Investigations can happen because of complaints or for sectors identified as high risk. When violations come to surface, CNIL can issue warnings, order corrective measures, impose relevant restrictions and apply financial penalties where appropriate.
France’s data protection framework is a combination of national and European laws. Though CNIL oversees compliance in France, it’s also closely tied to both the French Data Protection Act and the GDPR.
CNIL was established under France’s Data Protection Act of 6 January 1978. The law was introduced to protect individuals from the misuse of personal information and remains a key part of France’s privacy framework today.
GDPR came into effect in 2018. It created a common set of data protection rules across the European Union. In France, GDPR works alongside the French Data Protection Act and CNIL supervises and enforces these requirements.
The French framework also aligns with other European privacy laws, including:
To understand better about how these principles work, we must understand what they were designed to protect: personal data.
Personal data refers to any information that helps identify a person, either directly or indirectly.
Examples include:
The GDPR is the European Union’s data protection law. It was created to give individuals greater control over their personal information and also to build a consistent compliance framework across EU member states.
Since GDPR is an important part of European privacy law, understanding it will help get more insight into CNIL’s responsibilities.
GDPR gives individuals several important rights over their personal data, including the right to:
Organisations are expected to follow several key principles alongside above rights when handling personal data:
Personal data should be collected for a specific and legitimate purpose and not used in ways that are incompatible with that purpose.
Only the information needed to achieve a particular purpose should be collected and processed.
Personal data should not be kept for longer than necessary and retention periods should be clearly defined.
Organisations should protect personal data through appropriate security measures and limit access to authorised individuals.
18 members representing different public institutions and areas of expertise lead CNIL. They meet every week to discuss and review laws that could affect the use of personal data in France. They also verify guidance documents, recommendations and other non-binding rules that let organisations understand their privacy-related responsibilities.
Alongside this body, CNIL has a separate restricted committee responsible for sanctions. When serious violations are identified, this committee decides whether warnings, corrective measures or financial penalties should be issued.
Here’s a step-by-step explanation of how CNIL enforcement process works.
First, CNIL needs to identify a privacy issue which can come from several sources, including:
With this approach, CNIL can identify individual complaints as well as broader compliance problems.
After the verification of the concern, the next step for CNIL is to examine facts and validate whether an organisation has breached GDPR and other relevant laws. To do that, CNIL can:
The goal is to understand what happened and assess whether any corrective action is required.
After reviewing the findings, the Chair of CNIL can:
If organisations receive corrective actions from CNIL, they also receive a deadline to comply with them.
For more serious cases, CNIL may refer the matter to its restricted committee.
At this stage:
Before the hearing:
This stage gives organisations an opportunity to explain their position before any decision is made.
The committee goes through the evidence and hears out both parties before reaching a conclusion.
Depending on the circumstances, it may:
Whatever the decision is, CNIL notifies it to the organisation.
Depending on the case, CNIL may also:
Public decisions help promote transparency and encourage organisations to take data protection obligations seriously.
Cybersecurity forms an important part of CNIL’s work in the following ways.
CNIL regularly publishes practical advice for everyday internet users on common issues like:
The aim is to help people spot risks early and know what to do when something goes wrong.
CNIL also provides practical guidance on security practices for organisations, including:
These help organisations strengthen security without having to interpret complex regulations on their own.
Security measures are one of the first things it reviews during investigations.
Common issues include:
Many of these problems are preventable, which is why basic security controls remain so important.
CNIL collaborates with cybersecurity agencies, industry groups and other organisations to share knowledge and improve awareness of emerging threats.
This helps organisations stay informed about new risks while encouraging stronger security practices across the wider digital ecosystem.
Web analytics measures visitor behaviour on your website, but traditional tools often transfer personal data outside the EU, combine datasets across clients or reuse data for advertising.
Matomo is different because it keeps data in the EU, never combines or reuses your data, and can be configured to qualify for CNIL’s consent exemption under French guidance.
Here’s how:
When you enable CNIL mode, you can assess your current setup against CNIL consent exemption conditions and apply supported settings in one click:
You also see clearly what still needs your attention. Just go to Administration > Privacy > Compliance, select your site, and click “Enforce compliance where possible.”
You only add the opt-out link to your privacy policy.
Matomo never transfers data to the US. Cloud data lives on EU servers in France or you host on your own infrastructure. No GDPR violations from cross-border transfers.
Matomo is open-source and fully auditable. Data stays isolated per customer with no pooling. Matomo never reuses your data for its own commercial purposes.
CNIL expects organisations to take real responsibility for the data they handle.
Here are some best practices to adopt.
Assign someone to manage data protection and act as your go-to person when questions arise about data handling. This can be an internal person or an external expert. Your DPO reviews projects before launch and ensures they meet privacy requirements.
Document exactly how and why you collect personal data. Track your legal basis for each data type, like legal obligation for tax records. If you can’t identify a valid legal reason for collecting a data type, don’t store it. ROPA shows CNIL you understand what data you hold and why. This record becomes your privacy blueprint.
Some projects may have greater privacy risks than others. This is especially true for cases where organisations adopt new technologies or track individuals at scale. A DPIA is a structured review that helps identify privacy risks before a project goes live.
For example, if a company plans to deploy an AI-powered recruitment tool that analyses candidate profiles, a DPIA can help uncover issues such as excessive data collection or inadequate security controls before they affect real users.
Organisations can use two approaches to use data safely for analysis or innovation.
Inaccurate data used to train AI systems produce unfair outcomes. Regular reviews help organisations identify gaps, inconsistencies and hidden biases before they affect customers or employees.
Even organisations with a strong security protocol can experience a breach. What differentiates it from others is having a clear response plan. A response plan should clearly define:
Set automatic timelines to delete data once you no longer need it. Don’t store data without a clear purpose. CNIL’s consent exemption requires retention limits, and automated deletion ensures you never keep data longer than necessary.
CNIL plays a central role in guiding businesses towards better data practices and long-term accountability.
For organisations looking to align with CNIL practices, Matomo offers a privacy-focused analytics solution that avoids reliance on invasive tracking while still delivering useful insights. It helps teams stay compliant without overcomplicating their data strategy.
Start your 21-day free trial with Matomo. No credit card required.
Any organisation that processes personal data of people in France is subject to CNIL, regardless of where the company is located. This includes businesses, public authorities, non-profits and websites targeting French users.
CNIL has the power to impose significant fines. In 2025, CNIL issued €486.8 million in cumulative fines across 83 sanctions.
The most notable recent case: FREE MOBILE received a €27 million fine and FREE received €15 million for a data breach affecting 24 million subscribers in 2024. The exact fine amount depends on the severity, duration and whether the organisation acted intentionally or negligently.
Yes. Data controllers must notify CNIL within 72 hours when a breach presents a risk to individuals’ rights and freedoms. You must also document all breaches internally and inform affected individuals if the risk is high.
You only need a DPO if your organisation processes large volumes of sensitive data (like health records), conducts regular large-scale monitoring of people, or is a public authority. Most regular businesses don’t legally require one. However, appointing a DPO (even internally or externally) is highly recommended.
Yes. If an organisation fails to comply with GDPR or French data protection rules, CNIL can investigate the matter and take action. Depending on the severity of the issue, this may include warnings, formal notices, orders to correct non-compliant practices or financial penalties.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。