What Is GDPR + Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés?
France was an early adopter of a national data-protection statute: the Loi Informatique et Libertés of 6 January 1978, which created the CNIL. Since 2018 that law operates as the national supplement to the EU GDPR: the GDPR provides the core rules and the French law fills the gaps left by GDPR opening clauses, including the age of digital consent and selected national rules. The CNIL publishes current enforcement actions and sanction decisions; amounts and case status should be checked in the latest official record. For data brokers, a key French rule is the free right to object to direct marketing: when a person objects to processing for that purpose, the controller must stop that marketing processing, subject to the applicable legal framework. From 11 August 2026, the former Bloctel opposition system ended and covered consumer telephone prospecting generally requires prior consent, with exceptions including calls related to an ongoing contract and journal, periodical, or magazine offers; current CNIL, DGCCRF, and Légifrance materials control the details.
At a glance
- Full name
- GDPR + Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés
- Short code
- Loi Informatique et Libertés
- Jurisdiction
- France
- Enacted
- 1978
- Last major update
- Realigned with the EU GDPR in 2018-2019; consumer telephone-prospecting consent regime effective 11 August 2026
- Regulator
- Commission Nationale de l'Informatique et des Libertés (CNIL)
- Private right of action
- Yes
- Statutory citation
- Loi n° 78-17 du 6 janvier 1978 + Règlement (UE) 2016/679
Scope, who Loi Informatique et Libertés covers
Protected data
Data subject rights
Right of access (Article 15): obtain a copy of your data
Right to rectification (Article 16)
Right to erasure / right to be forgotten (Article 17)
Right to restriction of processing (Article 18)
Right to data portability (Article 20)
Right to object: absolute and free for direct marketing/prospecting (Article 21)
Right to give post-mortem directives on your personal data (French-specific)
Right to lodge a complaint with the CNIL (Article 77)
Notable features
France combines a longstanding national privacy statute with the EU GDPR. Distinctive features include the free direct-marketing objection, the post-11 August 2026 prior-consent framework for covered telephone prospecting, the age of digital consent set at 15, and statutory post-mortem data directives. CNIL guidance also makes clear that publicly accessible online data is not automatically free to reuse for marketing; transparency, lawful basis, and objection rights still matter.
Enforcement & penalties
Regulator: Commission Nationale de l'Informatique et des Libertés (CNIL)
Penalties: GDPR two-tier fines: up to €10M or 2% of global turnover (lower tier) and up to €20M or 4% of global turnover (higher tier), whichever is greater. The CNIL also publishes administrative sanctions and corrective measures; do not treat a historical total or individual case amount as a current annual total without checking the latest CNIL record.
Private right of action: Under GDPR Article 82, individuals can claim compensation for material or non-material damage before the French civil courts. Collective ('class') actions are available under French law (action de groupe) for data-protection breaches, brought by approved consumer associations.
Relevance to data brokers
Data brokers ('courtiers de données') may be controllers under GDPR and must identify a lawful basis. A person can object to direct marketing, and the controller must stop that purpose-specific processing when the objection applies. French residents can use the current telephone-prospecting consent rules, GDPR access/erasure/objection routes, and CNIL complaints; downstream disclosure and notification duties depend on the processing and the applicable GDPR provisions.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who enforces data privacy in France?+
The CNIL (Commission Nationale de l'Informatique et des Libertés), which enforces both the EU GDPR and France's 1978 Loi Informatique et Libertés. Check the CNIL's current sanctions and corrective-measures pages for published enforcement figures and case status.
How do I stop telemarketing calls in France?+
Bloctel ended on 11 August 2026. Covered consumer telephone prospecting generally requires prior consent, subject to exceptions such as certain ongoing-contract calls and journal, periodical, or magazine offers; current official guidance also distinguishes non-commercial and professional calls. Check DGCCRF or CNIL instructions for the applicable exception and complaint route.
Can data brokers legally sell my data in France?+
Only with a valid lawful basis under GDPR and any applicable national rules. You have a free right to object to direct marketing, and the controller must stop that purpose-specific processing when the objection applies. Other uses, disclosures, and downstream obligations require a separate assessment.
How long does a French company have to answer a data request?+
Usually one month from receipt, extendable by up to two further months for complex requests when the controller gives the required notice. If the controller does not handle the request appropriately, you can use the current CNIL complaint route; do not treat a three-month complaint-handling statement as a universal deadline for every case.
Official sources & citations
- Loi Informatique et Libertés (Légifrance)
- CNIL: file a complaint
- CNIL: sanctions and corrective measures 2025
- CNIL: reuse of publicly accessible data for marketing
- CNIL: current commercial telephone-prospecting rules
- DGCCRF: telephone solicitation consent rules from 11 August 2026
- Légifrance: Consumer Code telephone-prospecting chapter
- Légifrance: Decree 2026-662 on telephone consent
Other international privacy regimes
Loi Informatique et Libertés sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
