Data Protection Atlas

Loi Informatique et Libertés

Tier 2 In force

France's data protection act, predating the GDPR by four decades and amended to implement it. Two mechanics catch out practitioners working from the GDPR alone: the headline cookie fines against large platforms were issued under Article 82 of this law transposing the ePrivacy Directive, NOT under the GDPR — so the one-stop-shop did not apply — and the CNIL operates a simplified sanction procedure with its own much lower ceiling.

Identity

Citation
Loi n° 78-17 du 6 janvier 1978, as amended
Jurisdiction
France
Type
implementing

← France overview

Criminal liability

A distinct track, separate from the regulatory penalties below. The same failure can attract both — a penalty notice against the organisation and a prosecution of the individual.

Code pénal arts 226-16 to 226-24 — Atteintes aux droits de la personne résultant des fichiers Custodial available

A dedicated chapter of the Penal Code criminalising unlawful processing, held separately from the CNIL's administrative powers.

Penalty
Up to 5 years, plus substantial fines
Imprisonment
Available

Regulatory enforcement

A simplified sanction procedure introduced in 2022 carries a ceiling of €20,000 and is published anonymised — a materially different exposure from the headline GDPR ceiling, and the route most enforcement actually takes.

Sources

  • Primary Loi n° 78-17 du 6 janvier 1978 Légifrance no verified URL yet

    URL unconfirmed.

Never independently verified — seeded from the prototype.