The CNIL has launched a new version of its online authorization request service for health and research data processing, integrating recent legal changes and simplifying the application process. Companies handling health data in France must use the updated form and prepare for reduced processing times.
The French CNIL has imposed 23 simplified procedure sanctions since January 2026, totaling €133,750 in fines, for violations including excessive video surveillance, non-compliant cookie banners, and failure to respond to data subject rights requests. This signals increased enforcement of GDPR and French data protection law.
The French National Gaming Authority (ANJ) and CNIL jointly published a guide on applying GDPR to player data processing in the gambling sector. It covers account management, excessive gambling prevention, and anti-money laundering, specifying data retention periods and emphasizing data minimization.
The French data protection authority (CNIL) has issued recommendations for the use of geolocation data from connected vehicles, emphasizing strict necessity, transparency, and security. Companies processing such data must limit collection, improve privacy notices, and implement user profiles for data rights.
The French CNIL issued new recommendations on the use of location data from connected vehicles, clarifying consent requirements under ePrivacy and GDPR. Companies in the automotive and telematics sectors must review their data processing practices to ensure compliance.
The Paris Judicial Court ordered TotalEnergies to include Scope 3 greenhouse gas emissions from customer product use in its legally mandated vigilance plan under France's duty of vigilance law. This ruling expands corporate climate liability to end-use emissions, requiring companies to identify and address climate risks across their value chain.
A Paris court has ordered TotalEnergies to report on risks from its greenhouse gas emissions under France's duty of vigilance law, signaling increased legal pressure on companies to enhance climate risk disclosure. This ruling may set a precedent for similar cases and underscores growing regulatory scrutiny on climate-related financial risks.
Since 2024, French public sector entities must send independent expertise reports on electronic voting systems for professional elections to the CNIL via a dedicated email address. This includes pre-election and final reports, with a 7 MB file size limit.
The French CNIL will examine draft opinions on modifications to the CFVR automated fraud-fighting system, a decree on consumer consent for telephone prospecting, and communications on European Health Data Space data access bodies. These actions signal upcoming regulatory changes in data privacy and fraud detection.
The French data protection authority (CNIL) published recommendations on the use of tracking pixels in emails, clarifying obligations under data protection law. Organizations using such pixels must ensure compliance with consent and transparency requirements.
France has released an amended draft law to transpose the EU Pay Transparency Directive, missing the June 7, 2026 deadline. The law introduces pre-employment transparency (ban on salary history inquiries, salary range disclosure in job ads) and expands criteria for equal work value, with progressive application from late 2026 to January 1, 2028.
The CNIL published guidance on May 28, 2026, clarifying the roles of cloud actors (data controller, joint controller, processor) under GDPR. This affects how cloud contracts and compliance documentation should be structured, with emphasis on case-by-case analysis.
The French data protection authority (CNIL) fined IQVIA OPERATIONS FRANCE €5 million for non-compliance with authorization conditions for health data warehouses, including inadequate transparency, data subject rights, and security measures. The data was deemed pseudonymous, not anonymous, highlighting re-identification risks. CNIL issued injunctions to remedy violations within six months, with daily penalties of €10,000 for non-compliance.
The French CNIL has updated reference methodologies MR-001 and MR-003 for health research, effective May 23, 2026. The updates expand scope to studies abroad, introduce new security annexes, and require multi-factor authentication by January 1, 2027. Organizations conducting health research involving residents in France or abroad must comply.
The CNIL's 2025 annual report shows record fines of €487 million and increased enforcement actions, signaling heightened GDPR scrutiny in France. The authority is also actively preparing for EU AI Act enforcement, requiring companies to strengthen data protection and AI compliance.
France requires certain organizations to conduct carbon accounting under the Bilan Carbone framework, covering Scope 1, 2, and 3 emissions. Companies must comply with French law and align reporting with international standards like the GHG Protocol.
The French CNIL released new recommendations on using personal data for creditworthiness assessment, replacing the former AU-005 authorization. The guidance emphasizes data minimization, transparency, and conditions for fully automated credit decisions, following CJEU rulings.
The French CNIL published recommendations in May 2026 requiring credit professionals to limit data collection, allow masking of non-essential data, and provide transparency on automated decision-making and scoring. This reinforces GDPR principles in the credit sector.
France has published a roadmap to end coal by 2030, oil by 2045, and natural gas by 2050, with interim targets including 66% electric car sales by 2030 and a ban on gas boilers in new buildings by 2026. Companies in energy, transport, and construction sectors must align with these decarbonization goals.
The CNIL has approved a GDPR code of conduct for French clothing and footwear retailers, covering data protection obligations for customer data in-store and online. Adherents must comply with the code and undergo verification by an approved control body.