France
Tier 2 Comprehensive law EuropePrincipal framework: GDPR + Loi Informatique et Libertés (2018). Regulator: CNIL. Age 15 with joint parental consent below; CNIL certification schemes and class-action provisions.
At a glance
- Criminal offences
- Yes — Code pénal arts 226-16 to 226-24, up to 5 years
- Public-sector fines
- Yes
- Principal law
- GDPR + Loi Informatique et Libertés
- Regulator
- Commission Nationale de l'Informatique et des Libertés (CNIL)
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- DPO required
- Public authorities; large-scale regular monitoring or special-category processing (Art 37)
- Digital consent age
- 15
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
- National implementing act
- Loi Informatique et Libertés (as amended)
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- FR
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
- Holds EU adequacy
- Yes
EU/EEA member — intra-EEA transfers need no adequacy decision.
Instruments
Also applies here
Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.
Sources
- Regulator Commission Nationale de l'Informatique et des Libertés (CNIL)
- Primary GDPR — EUR-Lex
- Primary Loi Informatique et Libertés — Légifrance
- Regulator CNIL — regulator
Never independently verified — seeded from the prototype.