Loi Informatique et Libertés
Tier 2 In forceFrance's data protection act, predating the GDPR by four decades and amended to implement it. Two mechanics catch out practitioners working from the GDPR alone: the headline cookie fines against large platforms were issued under Article 82 of this law transposing the ePrivacy Directive, NOT under the GDPR — so the one-stop-shop did not apply — and the CNIL operates a simplified sanction procedure with its own much lower ceiling.
Identity
- Citation
- Loi n° 78-17 du 6 janvier 1978, as amended
- Jurisdiction
- France
- Type
- implementing
Criminal liability
A distinct track, separate from the regulatory penalties below. The same failure can attract both — a penalty notice against the organisation and a prosecution of the individual.
Code pénal arts 226-16 to 226-24 — Atteintes aux droits de la personne résultant des fichiers
A dedicated chapter of the Penal Code criminalising unlawful processing, held separately from the CNIL's administrative powers.
- Penalty
- Up to 5 years, plus substantial fines
- Imprisonment
- Available
Regulatory enforcement
A simplified sanction procedure introduced in 2022 carries a ceiling of €20,000 and is published anonymised — a materially different exposure from the headline GDPR ceiling, and the route most enforcement actually takes.
Sources
- Primary Loi n° 78-17 du 6 janvier 1978 Légifrance no verified URL yet
URL unconfirmed.
Never independently verified — seeded from the prototype.