Data breaches expose personal data at a massive scale. In the second quarter of 2025 alone, nearly 94 million data records were leaked, impacting millions of individuals worldwide.
As these risks grow, governments have introduced stricter data protection laws to hold organisations accountable. In France, the Commission nationale de l’informatique et des libertés (CNIL) plays this role.
In this post, we explain what CNIL is, its mission and the best practices organisations can follow to stay compliant.
Key takeaways
- CNIL is France’s data protection authority, but its rules affect any organisation collecting or processing personal data from people in France.
- Beyond fines and enforcement, CNIL actually wants to help. They provide guidance, cybersecurity resources and practical tools to build stronger privacy programmes.
- Compliance starts with good data governance. Keep clear records of what data you collect and why, assess risks before launching new projects and set automatic retention policies so you don’t hoard data forever.
- If you’re using web analytics, take a hard look at your data collection practices. Are you transferring data to the US? Using third-party cookies? Tracking across sites? If so, consider privacy-focused alternatives like Matomo.
What is CNIL?
CNIL is France’s independent data protection authority. While based in France, CNIL’s authority is not limited to organisations established there; its requirements can also apply to any organisation that offers goods or services to individuals in France or processes their personal data.
History of CNIL
In 1970, the French government proposed a project called SAFARI that linked government records with unique identification numbers for each citizen. There was a widespread public concern about the use of technology to collect personal information.
In response, an independent commission studied the issue and created CNIL in 1978 to help protect personal data and individual rights.
CNIL’s missions
CNIL France has four core missions.
These include making people aware about data protection rights, foreseeing risks, offering support to businesses and enforcing regulations.
Protect individual rights and raise awareness
Many people don’t know how their personal information is stored or shared online. CNIL provides resources that make data protection easier to understand. It also gives individuals a way to report privacy concerns and can step in when organisations fail to respect their obligations.
Support compliance and provide guidance
For businesses, privacy rules can sometimes be difficult to interpret. CNIL helps organisations simplify this by offering practical guidance and toolkit on topics like data collection, consent and security. This way, organisations are able to include privacy considerations into their operations while also being innovative and developing products and services to meet business needs.
Anticipate risks and drive innovation
Technology changes quickly, and privacy challenges often emerge before clear rules are set. CNIL monitors and studies the new technologies and trends around personal data collection.
It also encourages organisations to treat privacy as a priority in their design process, and not as an afterthought.
CNIL also regularly engages with researchers, startups and other stakeholders. It does this to examine questions and debate around data innovation, privacy and public trust. For example, CNIL has created Phantom, a mobile application to help teenagers better understand and protect the personal information they share on social media platforms.
Investigate and enforce regulations
CNIL has the power to investigate organisations that don’t comply with data protection laws. Investigations can happen because of complaints or for sectors identified as high risk. When violations come to surface, CNIL can issue warnings, order corrective measures, impose relevant restrictions and apply financial penalties where appropriate.
CNIL and the French Data Protection Act
France’s data protection framework is a combination of national and European laws. Though CNIL oversees compliance in France, it’s also closely tied to both the French Data Protection Act and the GDPR.
The French Data Protection Act
CNIL was established under France’s Data Protection Act of 6 January 1978. The law was introduced to protect individuals from the misuse of personal information and remains a key part of France’s privacy framework today.
How the Act works with GDPR
GDPR came into effect in 2018. It created a common set of data protection rules across the European Union. In France, GDPR works alongside the French Data Protection Act and CNIL supervises and enforces these requirements.
The French framework also aligns with other European privacy laws, including:
- ePrivacy rules covering electronic communications and cookies.
- The Law Enforcement Directive governing certain data processing activities carried out by competent authorities.
What is personal data?
To understand better about how these principles work, we must understand what they were designed to protect: personal data.
Personal data refers to any information that helps identify a person, either directly or indirectly.
Examples include:
- Names
- Email addresses
- Phone numbers
- Location data
- Online identifiers
- Customer or account numbers linked to an individual
What is GDPR?
The GDPR is the European Union’s data protection law. It was created to give individuals greater control over their personal information and also to build a consistent compliance framework across EU member states.
Since GDPR is an important part of European privacy law, understanding it will help get more insight into CNIL’s responsibilities.
Rights provided under GDPR
GDPR gives individuals several important rights over their personal data, including the right to:
- Access the information an organisation holds about them
- Correct inaccurate or incomplete data
- Object to certain types of data processing
- Request the removal of search engine results in some circumstances
- Receive their data in a portable format
- Request the deletion of personal data where applicable
Organisations are expected to follow several key principles alongside above rights when handling personal data:
Purpose limitation
Personal data should be collected for a specific and legitimate purpose and not used in ways that are incompatible with that purpose.
Data minimisation
Only the information needed to achieve a particular purpose should be collected and processed.
Storage limitation
Personal data should not be kept for longer than necessary and retention periods should be clearly defined.
Security and confidentiality
Organisations should protect personal data through appropriate security measures and limit access to authorised individuals.
How does the CNIL work?
18 members representing different public institutions and areas of expertise lead CNIL. They meet every week to discuss and review laws that could affect the use of personal data in France. They also verify guidance documents, recommendations and other non-binding rules that let organisations understand their privacy-related responsibilities.
Alongside this body, CNIL has a separate restricted committee responsible for sanctions. When serious violations are identified, this committee decides whether warnings, corrective measures or financial penalties should be issued.
CNIL law enforcement process
Here’s a step-by-step explanation of how CNIL enforcement process works.
Step 1: Detecting an infringement
First, CNIL needs to identify a privacy issue which can come from several sources, including:
- Complaints submitted by individuals
- Investigations carried out by CNIL
- Reports published in the media or online
- Areas that CNIL has identified as enforcement priorities
- Referrals from other European data protection entities
With this approach, CNIL can identify individual complaints as well as broader compliance problems.
Step 2: Investigating the issue
After the verification of the concern, the next step for CNIL is to examine facts and validate whether an organisation has breached GDPR and other relevant laws. To do that, CNIL can:
- Do an on-site inspection
- Check websites, apps or online services remotely
- Request documents and written explanations
- Interview relevant individuals
The goal is to understand what happened and assess whether any corrective action is required.
Step 3: Deciding the next steps
After reviewing the findings, the Chair of CNIL can:
- Close the case where issues are limited or already resolved
- Issue a formal notice requiring the organisation to address the problem
- Refer the matter to the restricted committee for sanctions
If organisations receive corrective actions from CNIL, they also receive a deadline to comply with them.
Step 4: Sanctions procedure
For more serious cases, CNIL may refer the matter to its restricted committee.
Before the session
At this stage:
- CNIL appoints a rapporteur to review the case
- The organisation receives notice of the hearing date
- The rapporteur prepares a report proposing corrective measures
Written submissions
Before the hearing:
- The organisation can submit written observations
- The rapporteur can respond
- Both sides may provide additional comments if needed
This stage gives organisations an opportunity to explain their position before any decision is made.
Restricted committee hearing
The committee goes through the evidence and hears out both parties before reaching a conclusion.
Depending on the circumstances, it may:
- Issue a warning
- Order specific compliance measures
- Impose periodic penalty payments
- Levy a financial penalty
Step 5: Notification and publication
Whatever the decision is, CNIL notifies it to the organisation.
Depending on the case, CNIL may also:
- Publish the decision
- Share a statement publicly
- Publish details of corrective measures or sanctions
Public decisions help promote transparency and encourage organisations to take data protection obligations seriously.
CNIL and cybersecurity
Cybersecurity forms an important part of CNIL’s work in the following ways.
Educating general public
CNIL regularly publishes practical advice for everyday internet users on common issues like:
- Phishing emails or SMS
- Stolen accounts
- How to respond to social media account hacks
- Password security
- Online scams and fraud
The aim is to help people spot risks early and know what to do when something goes wrong.
Guiding professionals and organisations
CNIL also provides practical guidance on security practices for organisations, including:
- Password management recommendations
- Data security checklists
- Website and system security guidance
- Resources specially designed for SMEs, associations and public bodies
These help organisations strengthen security without having to interpret complex regulations on their own.
Regular sanctions
Security measures are one of the first things it reviews during investigations.
Common issues include:
- Weak password policies
- Personal data exposed through poorly designed websites
- Information sent without encryption
- Devices or systems left accessible to unauthorised users
- New applications released without adequate security testing
Many of these problems are preventable, which is why basic security controls remain so important.
Collaboration in broader cyber ecosystem
CNIL collaborates with cybersecurity agencies, industry groups and other organisations to share knowledge and improve awareness of emerging threats.
This helps organisations stay informed about new risks while encouraging stronger security practices across the wider digital ecosystem.
Web analytics and CNIL compliance: How Matomo helps
Web analytics measures visitor behaviour on your website, but traditional tools often transfer personal data outside the EU, combine datasets across clients or reuse data for advertising.
Matomo is different because it keeps data in the EU, never combines or reuses your data, and can be configured to qualify for CNIL’s consent exemption under French guidance.
Here’s how:
CNIL compliance mode
When you enable CNIL mode, you can assess your current setup against CNIL consent exemption conditions and apply supported settings in one click:
- Cookies are disabled
- IP anonymisation activates
- Cross-site tracking is blocked
- PII filtering runs
- And data retention is set to 180 days
You also see clearly what still needs your attention. Just go to Administration > Privacy > Compliance, select your site, and click “Enforce compliance where possible.”
You only add the opt-out link to your privacy policy.
Data stays in the EU
Matomo never transfers data to the US. Cloud data lives on EU servers in France or you host on your own infrastructure. No GDPR violations from cross-border transfers.
Full data ownership
Matomo is open-source and fully auditable. Data stays isolated per customer with no pooling. Matomo never reuses your data for its own commercial purposes.
Best practices for CNIL compliance
CNIL expects organisations to take real responsibility for the data they handle.
Here are some best practices to adopt.
Appoint a data protection officer (DPO)
Assign someone to manage data protection and act as your go-to person when questions arise about data handling. This can be an internal person or an external expert. Your DPO reviews projects before launch and ensures they meet privacy requirements.
Maintain a record of processing activities (ROPA)
Document exactly how and why you collect personal data. Track your legal basis for each data type, like legal obligation for tax records. If you can’t identify a valid legal reason for collecting a data type, don’t store it. ROPA shows CNIL you understand what data you hold and why. This record becomes your privacy blueprint.
Conduct data protection impact assessments (DPIA)
Some projects may have greater privacy risks than others. This is especially true for cases where organisations adopt new technologies or track individuals at scale. A DPIA is a structured review that helps identify privacy risks before a project goes live.
For example, if a company plans to deploy an AI-powered recruitment tool that analyses candidate profiles, a DPIA can help uncover issues such as excessive data collection or inadequate security controls before they affect real users.
Anonymise or pseudonymise data
Organisations can use two approaches to use data safely for analysis or innovation.
- Anonymisation permanently removes identifying elements so that an individual can no longer be identified.
- Pseudonymisation replaces identifiers with codes or references while allowing authorised users to reconnect the data when necessary.
Audit AI data for bias and quality
Inaccurate data used to train AI systems produce unfair outcomes. Regular reviews help organisations identify gaps, inconsistencies and hidden biases before they affect customers or employees.
Establish a data breach response plan
Even organisations with a strong security protocol can experience a breach. What differentiates it from others is having a clear response plan. A response plan should clearly define:
- How to detect and report incidents
- Who investigates the issue
- How to contain affected systems
- When to notify affected individuals and regulators
Automate data retention and deletion
Set automatic timelines to delete data once you no longer need it. Don’t store data without a clear purpose. CNIL’s consent exemption requires retention limits, and automated deletion ensures you never keep data longer than necessary.
Make privacy part of your strategy
CNIL plays a central role in guiding businesses towards better data practices and long-term accountability.
For organisations looking to align with CNIL practices, Matomo offers a privacy-focused analytics solution that avoids reliance on invasive tracking while still delivering useful insights. It helps teams stay compliant without overcomplicating their data strategy.
Start your 21-day free trial with Matomo. No credit card required.
FAQs
Who is subject to CNIL?
Any organisation that processes personal data of people in France is subject to CNIL, regardless of where the company is located. This includes businesses, public authorities, non-profits and websites targeting French users.
What are the penalties for violating CNIL rules?
CNIL has the power to impose significant fines. In 2025, CNIL issued €486.8 million in cumulative fines across 83 sanctions.
The most notable recent case: FREE MOBILE received a €27 million fine and FREE received €15 million for a data breach affecting 24 million subscribers in 2024. The exact fine amount depends on the severity, duration and whether the organisation acted intentionally or negligently.
Does a data controller have to notify a data breach to CNIL?
Yes. Data controllers must notify CNIL within 72 hours when a breach presents a risk to individuals’ rights and freedoms. You must also document all breaches internally and inform affected individuals if the risk is high.
When should I appoint a DPO?
You only need a DPO if your organisation processes large volumes of sensitive data (like health records), conducts regular large-scale monitoring of people, or is a public authority. Most regular businesses don’t legally require one. However, appointing a DPO (even internally or externally) is highly recommended.
Can CNIL fine organisations for GDPR violations?
Yes. If an organisation fails to comply with GDPR or French data protection rules, CNIL can investigate the matter and take action. Depending on the severity of the issue, this may include warnings, formal notices, orders to correct non-compliant practices or financial penalties.